Plugin
cleo
cleo is a dependency manager for Claude Code that lets teams pin and share their .claude/ configuration — rules, skills, agents, slash commands, hooks, and MCP server configs — through a single cleo.json manifest and lockfile. Run `cleo install` and every teammate's environment matches, with commit SHAs pinned so CI and laptops stay in sync. Three scopes (project, local, user) handle team-wide vs. personal vs. machine-wide installs. No registry — packages resolve directly to GitHub, GitLab, SSH remotes, private hosts, or local paths.
- Analysed
- Last observed
What the code does
- Runs shell commands Code that starts system commands on the machine it runs on.
Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.
This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.
Risk
Sign in to see this tool's overall risk level and what drives it. Free.
Coverage
Detailed report
2 findings from automated static analysis of the latest version, with severities and explanations.
Using this tool across your team? We can assess your whole inventory.
Request an inventory assessment