Plugin
claude-crap
Deterministic Quality Assurance plugin for Claude Code. CRAP stands for Change Risk Anti-Patterns — a metric originally developed by Alberto Savoia and Bob Evans at Google in 2007 to identify code that is both complex and under-tested. Inspired by their work. Claude-crap wraps every Write, Edit, and Bash tool call with a PreToolUse gatekeeper, a PostToolUse verifier, and a Stop quality gate backed by the CRAP index, Technical Debt Ratio, tree-sitter AST metrics, and SARIF 2.1.0 reports. Auto-detects and runs ESLint, Semgrep, Bandit, and Stryker at boot so users get real A..E quality grades out of the box. Forbids the agent from writing functional code before a test safety net exists (the Golden Rule).
- Analysed
- Last observed
What the code does
- Refers to credential files Code that names files such as SSH keys or cloud credentials.
- Downloads and runs code Code that fetches a script and pipes it into a shell.
- Evaluates code at runtime Code that builds and runs code while it executes.
- Runs hooks automatically Hooks that execute without being called explicitly.
Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.
This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.
Risk
Sign in to see this tool's overall risk level and what drives it. Free.
Coverage
Detailed report
5 findings from automated static analysis of the latest version, with severities and explanations.
Using this tool across your team? We can assess your whole inventory.
Request an inventory assessment