A repository, a model, a VS Code or Docker Desktop extension, a GitLab project, a Claude skill or plugin — scored on published checks before it reaches your machine. In the browser, and on your agent's command line. And the only tool that knows when an AI recommended it to you.
The same published checks answer you in the browser and your agent on the command line — and each surface says plainly what it cannot see.
A 0–100 trust board on the page, and a download that fails your policy is held and cancelled before it reaches your downloads folder — including release assets, the path the FakeGit campaign actually used. Overrides are yours, and recorded.
github.com (22 checks), huggingface.co (18) and gitlab.com (22).
The Claude Code plugin's hook reads the exact Bash line before it runs — git clone, npm install, code --install-extension, docker extension install, npx skills add — and refuses one that names something blocked.
Claude Code only, Bash tool only. An extension installed from the editor's own Extensions pane is not a shell line, and no hook sees it.
An MCP server any agent can call before it fetches — repositories, npm and PyPI packages, VS Code Marketplace extensions (17 checks), Docker Desktop extensions (11) and agent skills and plugins (15) — with a hard-gate verb that fails a step instead of returning prose a model can argue with.
Advisory: an agent that never calls it is not stopped.
Arrived from Claude, ChatGPT, Gemini or an MCP directory? RepoGates raises the bar and tells you. Agent-recommended repositories are a known malware seeding channel, and only code inside the browser can see that the recommendation happened.
The one signal no backend, CLI or scanner can read.
FakeGit, 2026 — the campaign RepoGates was built after.
A checker that flags everything is useless, so every roster is run against the most popular things on its platform before it ships, and the result is printed.