Plugin
nlpm
NLPM lints, scores, fixes, and trend-tracks the natural-language artifacts that make up a Claude Code plugin — skills, agents, commands, rules, hooks, manifests — against a 50-rule rubric on a 100-point scale. Ships focused agents (scanner, scorer, checker, fixer, tester, security-scanner, vague-scanner, vocab-drift-scanner) and a standalone Python validator (bin/nlpm-check) that runs in pre-commit hooks and CI without Claude Code installed, plus a shields.io "Validated by NLPM" badge.
- Analysed
- Last observed
What the code does
- Runs shell commands Code that starts system commands on the machine it runs on.
- Evaluates code at runtime Code that builds and runs code while it executes.
Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.
This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.
Risk
Sign in to see this tool's overall risk level and what drives it. Free.
Coverage
Detailed report
4 findings from automated static analysis of the latest version, with severities and explanations.
Using this tool across your team? We can assess your whole inventory.
Request an inventory assessment