Verune

Plugin

compounded

compounded turns Claude Code skills into a trust-gradient system: every skill earns its autonomy through demonstrated reliability. New skills the agent proposes start as .proposed/, get replayed on a real follow-up task by a verifier subagent (Haiku 4.5) to graduate to .verified/, build a track record to reach .trusted/, and finally graduate to .autonomous/ after 10+ uses with a clean recent run. One correction sends a skill back a tier. Three corrections in 30 days drop it to .proposed. Includes cross-project memory (a user-global USER.md auto-injected into every session) and a portable .tar.gz archive for moving your earned skills across machines. v1.1 adds an auto-proposer hook that scores each turn (tool calls, distinct file edits, recovery from failure) and nudges the agent to save high-signal procedures — so you don't have to remember to ask. No daemon. No cloud. No telemetry. Python stdlib only. All state in ~/.claude/compounded/ (SQLite + flat files). MIT licensed.

Analysed
Last observed

What the code does

  • Downloads and runs code Code that fetches a script and pipes it into a shell.
  • Runs hooks automatically Hooks that execute without being called explicitly.

Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.

This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.

Risk

Sign in to see this tool's overall risk level and what drives it. Free.

Sign in to see the risk level

Coverage

Complete static analysis

How coverage is measured

Detailed report

4 findings from automated static analysis of the latest version, with severities and explanations.

Sign in to view detailed report

Using this tool across your team? We can assess your whole inventory.

Request an inventory assessment