@jrcx7scc/claude-code-source
BMCP server package claude-code-source
Install
agr install @jrcx7scc/claude-code-source --target claudeThis artifact does not publish files for Claude.
Document
{ "name": "claude-code-source", "version": "2.1.88-source.0", "private": true, "type": "module", "description": "Source-first Bun + Ink workspace scaffold for the Claude Code snapshot.", "packageManager": "bun@1.3.10", "engines": { "node": ">=18.0.0" }, "scripts": { "dev": "bun --watch src/entrypoints/dev-cli.tsx", "start": "bun src/entrypoints/dev-cli.tsx", "start:home": "env CLAUDE_CONFIG_DIR="$HOME/.claude" bun src/entrypoints/dev-cli.tsx", "mcp": "bun src/entrypoints/dev-mcp.ts" }, "dependencies": { "@alcalzone/ansi-tokenize": "^0.3.0", "@anthropic-ai/bedrock-sdk": "^0.27.0", "@anthropic-ai/claude-agent-sdk": "^0.2.90", "@anthropic-ai/foundry-sdk": "^0.2.3", "@anthropic-ai/mcpb": "^2.1.2", "@anthropic-ai/sandbox-runtime": "^0.0.44", "@anthropic-ai/sdk": "^0.80.0", "@anthropic-ai/vertex-sdk": "^0.14.4", "@aws-sdk/client-bedrock": "^3.1022.0", "@aws-sdk/client-bedrock-runtime": "^3.1022.0", "@aws-sdk/client-sts": "^3.1022.0", "@aws-sdk/credential-provider-node": "^3.972.29", "@aws-sdk/credential-providers": "^3.1022.0", "@azure/identity": "^4.13.1", "@commander-js/extra-typings": "^14.0.0", "@growthbook/growthbook": "^1.6.5", "@modelcontextprotocol/sdk": "^1.29.0", "@opentelemetry/api": "^1.9.1", "@opentelemetry/api-logs": "^0.214.0", "@opentelemetry/core": "^2.6.1", "@opentelemetry/exporter-logs-otlp-grpc": "^0.214.0", "@opentelemetry/exporter-logs-otlp-http": "^0.214.0", "@opentelemetry/exporter-logs-otlp-proto": "^0.214.0", "@opentelemetry/exporter-metrics-otlp-grpc": "^0.214.0", "@opentelemetry/exporter-metrics-otlp-http": "^0.214.0", "@opentelemetry/exporter-metrics-otlp-proto": "^0.214.0", "@opentelemetry/exporter-prometheus": "^0.214.0", "@opentelemetry/exporter-trace-otlp-grpc": "^0.214.0", "@opentelemetry/exporter-trace-otlp-http": "^0.214.0", "@opentelemetry/exporter-trace-otlp-proto": "^0.214.0", "@opentelemetry/resources": "^2.6.1", "@opentelemetry/sdk-logs": "^0.214.0", "@opentelemetry/sdk-metrics": "^2.6.1", "@opentelemetry/sdk-trace-base": "^2.6.1", "@opentelemetry/semantic-conventions": "^1.40.0", "@smithy/core": "^3.23.13", "@smithy/node-http-handler": "^4.5.1", "ajv": "^8.18.0", "asciichart": "^1.5.25", "auto-bind": "^5.0.1", "axios": "^1.14.0", "bidi-js": "^1.0.3", "cacache": "^20.0.4", "chalk": "^5.6.2", "chokidar": "^5.0.0", "cli-boxes": "^4.0.1", "cli-highlight": "^2.1.11", "code-excerpt": "^4.0.0", "commander": "^14.0.3", "diff": "^8.0.4", "emoji-regex": "^10.6.0", "env-paths": "^4.0.0", "execa": "^9.6.1", "fflate": "^0.8.2", "figures": "^6.1.0", "fuse.js": "^7.1.0", "get-east-asian-width": "^1.5.0", "google-auth-library": "^10.6.2", "highlight.js": "^11.11.1", "https-proxy-agent": "^8.0.0", "ignore": "^7.0.5", "indent-string": "^5.0.0", "jsonc-parser": "^3.3.1", "lodash-es": "^4.17.23", "lru-cache": "^11.2.7", "marked": "^17.0.5", "p-map": "^7.0.4", "picomatch": "^4.0.4", "plist": "^3.1.0", "proper-lockfile": "^4.1.2", "qrcode": "^1.5.4", "react": "^19.2.4", "react-reconciler": "^0.33.0", "semver": "^7.7.4", "sharp": "^0.34.5", "shell-quote": "^1.8.3", "signal-exit": "^4.1.0", "stack-utils": "^2.0.6", "strip-ansi": "^7.2.0", "supports-hyperlinks": "^4.4.0", "tree-kill": "^1.2.2", "turndown": "^7.2.2", "type-fest": "^5.5.0", "undici": "^7.24.6", "usehooks-ts": "^3.1.1", "vscode-jsonrpc": "^8.2.1", "vscode-languageserver-protocol": "^3.17.5", "vscode-languageserver-types": "^3.17.5", "wrap-ansi": "^10.0.0", "ws": "^8.20.0", "xss": "^1.0.15", "yaml": "^2.8.3", "zod": "^4.3.6" }, "devDependencies": { "@types/react": "^19.2.14", "bun-types": "^1.3.11", "typescript": "^6.0.2" } }
Trustgrade B
- passBody integrity
Whether the stored document is plausibly the kind of file the artifact declares, rather than something fetched by mistake.
- warnType matchbest-effort: server code not analyzed
Whether the artifact is really the kind of thing its metadata claims it is.
- passFreshness
How long since the source repository was last pushed to.
- passPrompt injection
Scans the artifact's own text for instructions aimed at your agent rather than at you.
- warnLicenseno SPDX license detected
Whether the source repository declares an SPDX license permissive enough to redistribute.
How the grade is calculated
Each check contributes 0 points when it passes, 1 when it warns, and 2 when it fails. The total maps to a letter:
- Aevery check passed
- Bone warning
- Ctwo warnings
- Dprompt injection or body integrity failed, or three warnings
- Fone of those failed, and something else is wrong
These are automated hygiene checks, not a security audit, and not a dependency or vulnerability scan. A grade of A means nothing was flagged — not that the artifact is safe.
Versions
git-ac18e1e5cb2b2026-08-06