@cleocode/caamp
Central AI Agent Managed Packages - unified provider registry and package manager for AI coding agents
100
Versions
MIT
License
No
Install Scripts
Attested
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation (unverified)
npm registry signatures
No source commit
Maintainers
kryptobaseddev
Keywords
aiagentskillscliclaudecursorwindsurfcodexgemini
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@cleocode/paths | AI (dependencies): Same-org sibling package pinned to matching version; consistent with monorepo release pattern. | ai | |
| phantom-deps | phantom-dep:@cleocode/ct-skills | AI (phantom-deps): Same-org dep; likely re-exported or used indirectly — stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@clack/prompts | AI (phantom-deps): @clack/prompts is explicitly declared in dependencies in package.json; phantom-dep flag is a false positive for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @cleocode/cant is a sibling package in the same @cleocode monorepo, versioned identically (2026.4.9). New sibling deps added in lockstep are expected for this package's release pattern. | ai | |
| dependencies | unvetted-dep:@cleocode/cant | AI (dependencies): Same-org scoped package pinned to matching version — consistent monorepo release pattern. Not an independent risk. | ai | |
| dependencies | unvetted-dep:env-paths | AI (dependencies): env-paths is a well-known, widely-used npm utility for getting standard OS paths. Not a meaningful risk for this package. | ai | |
| provenance | slsa-provenance | AI (provenance): Package consistently publishes via CI/CD with Sigstore SLSA attestation — this is a stable, positive signal for this package. | ai |
Versions (showing 100 of 286)
Showing 100 of 286
Next page →