Verune

Plugin

githits

GitHits is the code context layer for Claude Code. It provides two capabilities: (1) Code navigation: indexed search, grep, and file reading across packages from 11 registries (npm, PyPI, Crates, Hex, Maven, NuGet, Go, RubyGems, Packagist, vcpkg, Zig) and any GitHub repository by URL, plus package metadata like docs, changelogs, vulnerability advisories, and dependency graphs, all without cloning. (2) Code examples: verified, canonical usage patterns drawn from global open source with source attribution and license provenance. Together, these give Claude deep visibility into the libraries and repos you're actually working with and real examples when you need them. Requires a free GitHits account (githits.com).

Analysed
Last observed

What the code does

  • Runs shell commands Code that starts system commands on the machine it runs on.
  • Starts other processes Code that launches separate programs.
  • Evaluates code at runtime Code that builds and runs code while it executes.
  • Runs an AI coding agent unsupervised Code that starts an AI coding agent with its approval prompts switched off.

Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.

This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.

Risk

Sign in to see this tool's overall risk level and what drives it. Free.

Sign in to see the risk level

Coverage

Complete static analysis

How coverage is measured

Detailed report

4 findings from automated static analysis of the latest version, with severities and explanations.

Sign in to view detailed report

Using this tool across your team? We can assess your whole inventory.

Request an inventory assessment