‹ The Index

Githits

npm

Search public open-source code, documentation, metadata, vulnerabilities, changelogs, and examples.

Works with: Claude Code, Cursor, Claude Desktop, Codex CLI, Gemini CLI, Cline, Windsurf, VS Code

Category: Security — see all ranked ›

Install (Claude Code):

claude mcp add ithits -- npx -y githits
deep

“Twenty real invocations with package specs; names vcpkg/Zig as lacking advisory data”

Security audit

scanned 2026-07-30

Every finding is shown in full. A licence adds the detail needed to act on it — which advisory, what the install script does, the version that fixes it.

No known advisoriesclearchecked against OSV for 0.6.6
Makes network requestsfrom declared dependencies
Can carry remote content into your agentunlock detail
Signed build provenancepublished from public CI with an attestation

1 finding here has detail behind a licence. You can see it exists above, free, permanently — Pro tells you what third-party content it can pull into your agent.

Unlock the fix — $6/mo ›or check your whole config free with npx tashan-cli doctor

npm ↗  ·  source ↗  ·  pkg:githits

Already running this? npx tashan-cli doctor checks your whole config against the Index — how it works ›