
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
The dependency picker for coding agents: an MCP server that recommends, compares and scores GitHub repositories, plus a daily dashboard of the most-starred new repos.
The dependency picker for coding agents. Ask which library to use and get a scored, verified answer instead of a guess.
whichlib is an MCP server with three tools. Every repository it returns carries a transparent 0–100 score (momentum, maintenance, adoption including npm and PyPI downloads, license), a tier, a one-line verdict and the full breakdown, so the agent can justify the pick and you can read why.
For teams (waitlist): alerts when a dependency your repos use goes stale, and rules your team's coding agents must follow when they add one. Add a 👍 to the waitlist issue; at 20 signups it gets built. whichlib itself stays free.
Claude Code:
claude mcp add whichlib -- npx -y whichlib
Cursor, Windsurf and other MCP clients:
{ "mcpServers": { "whichlib": { "command": "npx", "args": ["-y", "whichlib"] } } }
Requires Node 22 or newer. No account, no API key.
| Tool | Ask | You get |
|---|---|---|
recommend_repos | need in plain words, optional language, limit 1–10 | The best repositories for the need, ranked by fit (score × relevance), with downloads and a verdict each |
compare_repos | repos: 2–10 names as owner/repo | The repositories side by side, best first, same breakdown |
trending_repos | period day / week / month / rising, optional language, limit | Most-starred repositories created in the period, scored; rising: repositories of any age by stars gained this week |
Example, in Claude Code: "which Python PDF parser should I use?" → MinerU, pdfplumber, pypdf with scores, weekly downloads and verdicts like "Rising fast, 26k downloads/wk, pushed 3 days ago, Apache-2.0".
| Part | Weight | Signal |
|---|---|---|
| Momentum | 40% | Stars gained over 7 days (from daily star counts when available), else stars per day since creation, scaled by the npm/PyPI download trend when known (0.5–2x). Log scale. |
| Maintenance | 25% | Days since last push, full marks to 30 days, zero at a year. Widely used repos (10k+ stars or 100k+ weekly downloads) never drop below half. |
| Adoption | 25% | Stars, forks and npm / PyPI weekly downloads, log scale. |
| License | 10% | Permissive 1.0, weak copyleft 0.75, strong copyleft 0.5, none 0. |
Tiers: Strong ≥ 75, Solid ≥ 50, Watch ≥ 25, Avoid; repos younger than 30 days are New ("Too new to judge"), whatever their score. Archived repos are capped at 20. On a 20-need eval the top recommendation is an accepted answer 75% of the time and the top five contain one 100% of the time; the eval and its reports live in the repository.
GITHUB_TOKEN: raises GitHub's search limit from 10 to 30 per minute. A
fine-grained token with no permissions is enough. Recommend makes three
searches per call.WHICHLIB_HISTORY=off: do not download daily star counts. By default the
server keeps the last 10 days in ~/.whichlib/stars/, refreshed in the
background at most every 12 hours from raw.githubusercontent.com, so
momentum uses real stars gained per week for the top 1,000 repos per
language and new trending repos. Nothing is sent with that download.FRESH_REPOS_DATA_DIR: a folder of daily snapshots or star counts to use
instead (see the repository's data branch).WHICHLIB_TELEMETRY=off or DO_NOT_TRACK=1: disables anonymous call
counting. What is counted: tool name, a random install id, version,
platform, Node major version. Never queries, repository names or results.
The aggregate numbers are public at
https://whichlib-telemetry.todorovskijosif.workers.dev/stats.Repository: https://github.com/josifb/whichlib (MIT). It also holds the Fresh Repos dashboard (most-starred new repositories, day / week / month, sortable, one HTML file), the nightly snapshot and enrichment jobs, the recommendation eval, and 80+ unit tests.
Development, from the whichlib/ folder of the repository:
npm test # unit tests, no network
npm run mcp:smoke # start the server over stdio and call every tool live
npm run eval # 20-need recommendation eval (set GITHUB_TOKEN)
npm run snapshot # today's top repos per period and language -> data/snapshots/
npm run enrich # add npm / PyPI packages and weekly downloads to the latest snapshot
npm run score # top repos from the latest snapshot with score and verdict
npm run pull-data # copy snapshots from the data branch
Layout:
mcp/server.mjs MCP entry (stdio) mcp/tools.mjs tool logic
mcp/expand.mjs query expansion mcp/telemetry.mjs anonymous call counting
mcp/github-api.mjs GitHub client + cache mcp/data.mjs snapshot history provider
mcp/eval/ needs, metrics, runner, inspect, results/
lib/score.js the score, shared by browser and Node
snapshot/src/ query, normalize, github, registry, enrich, history, run, score-report, pull-data
dashboard/index.html Fresh Repos
FAQs
The dependency picker for coding agents: an MCP server that recommends, compares and scores GitHub repositories, plus a daily dashboard of the most-starred new repos.
The npm package whichlib receives a total of 794 weekly downloads. As such, whichlib popularity was classified as not popular.
We found that whichlib demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.