Transparent rule-based GitHub fake-star detector — LOW/MEDIUM/HIGH with per-rule evidence.
A transparent, dependency-free GitHub fake-star checker. One Python file, no token, no install — point it at a repo and get a / / risk verdict with every rule explained. auditrepouvxfake-star-auditio.github.ardev-lab/fake-star-auditclaudedesktopconfig.jsonjson "args": ["fake-star-audit"] pip install -r requirements.txt installs "command": "python3", "args":…
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Forge read 0 source files from the published package tarball and matched no MCP tool registrations. Extraction is pattern-based over shipped source: a server that builds its tool list at runtime, or that ships only bundled or minified code, registers nothing this can see. Treat it as “not detected”, not as “exposes none”.
A transparent, dependency-free GitHub fake-star checker. One Python file, no token, no install — point it at a repo and get a / / risk verdict with every rule explained. auditrepouvxfake-star-auditio.github.ardev-lab/fake-star-auditclaudedesktopconfig.jsonjson "args": ["fake-star-audit"] pip install -r requirements.txt # installs "command": "python3", "args": ["/absolute/path/to/fake-star-audit/mcpserver.py"]…
Forge's dependency resolver reads npm metadata only, so this PyPI package has no resolved tree. That is a gap in coverage, not a clean bill of health.