Verune

Plugin

cleo

cleo is a dependency manager for Claude Code that lets teams pin and share their .claude/ configuration — rules, skills, agents, slash commands, hooks, and MCP server configs — through a single cleo.json manifest and lockfile. Run `cleo install` and every teammate's environment matches, with commit SHAs pinned so CI and laptops stay in sync. Three scopes (project, local, user) handle team-wide vs. personal vs. machine-wide installs. No registry — packages resolve directly to GitHub, GitLab, SSH remotes, private hosts, or local paths.

Analysed
Last observed

What the code does

  • Runs shell commands Code that starts system commands on the machine it runs on.

Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.

This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.

Risk

Sign in to see this tool's overall risk level and what drives it. Free.

Sign in to see the risk level

Coverage

Complete static analysis

How coverage is measured

Detailed report

2 findings from automated static analysis of the latest version, with severities and explanations.

Sign in to view detailed report

Using this tool across your team? We can assess your whole inventory.

Request an inventory assessment