New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

whichlib

Package Overview
Dependencies
Maintainers
1
Versions
6
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

whichlib

The dependency picker for coding agents: an MCP server that recommends, compares and scores GitHub repositories, plus a daily dashboard of the most-starred new repos.

latest
Source
npmnpm
Version
0.1.5
Version published
Weekly downloads
571
Maintainers
1
Weekly downloads
 
Created
Source

whichlib

The dependency picker for coding agents. Ask which library to use and get a scored, verified answer instead of a guess.

whichlib is an MCP server with three tools. Every repository it returns carries a transparent 0–100 score (momentum, maintenance, adoption including npm and PyPI downloads, license), a tier, a one-line verdict and the full breakdown, so the agent can justify the pick and you can read why.

For teams (waitlist): alerts when a dependency your repos use goes stale, and rules your team's coding agents must follow when they add one. Add a 👍 to the waitlist issue; at 20 signups it gets built. whichlib itself stays free.

Install

Claude Code:

claude mcp add whichlib -- npx -y whichlib

Cursor, Windsurf and other MCP clients:

{ "mcpServers": { "whichlib": { "command": "npx", "args": ["-y", "whichlib"] } } }

Requires Node 22 or newer. No account, no API key.

Use it without installing (hosted, no Node needed):

claude mcp add --transport http whichlib https://whichlib.com/mcp

Limits and the web API: https://whichlib.com/docs/

Tools

ToolAskYou get
recommend_reposneed in plain words, optional language, limit 1–10The best repositories for the need, ranked by fit (score × relevance), with downloads and a verdict each
compare_reposrepos: 2–10 names as owner/repoThe repositories side by side, best first, same breakdown
trending_reposperiod day / week / month / rising, optional language, limitMost-starred repositories created in the period, scored; rising: repositories of any age by stars gained this week

Example, in Claude Code: "which Python PDF parser should I use?" → MinerU, pdfplumber, pypdf with scores, weekly downloads and verdicts like "Rising fast, 26k downloads/wk, pushed 3 days ago, Apache-2.0".

Score

PartWeightSignal
Momentum40%Stars gained over 7 days (from daily star counts when available), else stars per day since creation, scaled by the npm/PyPI download trend when known (0.5–2x). Log scale.
Maintenance25%Days since last push, full marks to 30 days, zero at a year. Widely used repos (10k+ stars or 100k+ weekly downloads) never drop below half.
Adoption25%Stars, forks and npm / PyPI weekly downloads, log scale.
License10%Permissive 1.0, weak copyleft 0.75, strong copyleft 0.5, none 0.

Tiers: Strong ≥ 75, Solid ≥ 50, Watch ≥ 25, Avoid; repos younger than 30 days are New ("Too new to judge"), whatever their score. Archived repos are capped at 20. On a 20-need eval the top recommendation is an accepted answer 75% of the time and the top five contain one 100% of the time; the eval and its reports live in the repository.

Environment variables, all optional

  • GITHUB_TOKEN: raises GitHub's search limit from 10 to 30 per minute. A fine-grained token with no permissions is enough. Recommend makes three searches per call.
  • WHICHLIB_HISTORY=off: do not download daily star counts. By default the server keeps the last 10 days in ~/.whichlib/stars/, refreshed in the background at most every 12 hours from raw.githubusercontent.com, so momentum uses real stars gained per week for the top 1,000 repos per language and new trending repos. Nothing is sent with that download.
  • FRESH_REPOS_DATA_DIR: a folder of daily snapshots or star counts to use instead (see the repository's data branch).
  • WHICHLIB_TELEMETRY=off or DO_NOT_TRACK=1: disables anonymous call counting. What is counted: tool name, a random install id, version, platform, Node major version. Never queries, repository names or results. The aggregate numbers are public at https://whichlib-telemetry.todorovskijosif.workers.dev/stats.

Source, dashboard, data

Repository: https://github.com/josifb/whichlib (MIT). It also holds the Fresh Repos dashboard (most-starred new repositories, day / week / month, sortable, one HTML file), the nightly snapshot and enrichment jobs, the recommendation eval, and 80+ unit tests.

Development, from the whichlib/ folder of the repository:

npm test           # unit tests, no network
npm run mcp:smoke  # start the server over stdio and call every tool live
npm run eval       # 20-need recommendation eval (set GITHUB_TOKEN)
npm run snapshot   # today's top repos per period and language -> data/snapshots/
npm run enrich     # add npm / PyPI packages and weekly downloads to the latest snapshot
npm run score      # top repos from the latest snapshot with score and verdict
npm run pull-data  # copy snapshots from the data branch

Layout:

mcp/server.mjs         MCP entry (stdio)        mcp/tools.mjs       tool logic
mcp/expand.mjs         query expansion          mcp/telemetry.mjs   anonymous call counting
mcp/github-api.mjs     GitHub client + cache    mcp/data.mjs        snapshot history provider
mcp/eval/              needs, metrics, runner, inspect, results/
lib/score.js           the score, shared by browser and Node
snapshot/src/          query, normalize, github, registry, enrich, history, run, score-report, pull-data
dashboard/index.html   redirect to whichlib.com/repos (Fresh Repos)

Keywords

mcp

FAQs

Package last updated on 03 Oct 2026

Related posts