Six sources · one verdict · before it runs

Your agent installs things. RepoGates checks them first.

A repository, a model, a VS Code or Docker Desktop extension, a GitLab project, a Claude skill or plugin — scored on published checks before it reaches your machine. In the browser, and on your agent's command line. And the only tool that knows when an AI recommended it to you.

A recording of the real trust board on an invented repository: the score, the ticker that names six platforms, the four verdicts for what you are about to do. 16 seconds, no sound.

Four ways in, one verdict

The same published checks answer you in the browser and your agent on the command line — and each surface says plainly what it cannot see.

In the browser

A 0–100 trust board on the page, and a download that fails your policy is held and cancelled before it reaches your downloads folder — including release assets, the path the FakeGit campaign actually used. Overrides are yours, and recorded.

github.com (22 checks), huggingface.co (18) and gitlab.com (22).

The real block and warn pages from the unpacked extension, on invented repositories. 14 seconds, no sound.

On the command line

The Claude Code plugin's hook reads the exact Bash line before it runs — git clone, npm install, code --install-extension, docker extension install, npx skills add — and refuses one that names something blocked.

Claude Code only, Bash tool only. An extension installed from the editor's own Extensions pane is not a shell line, and no hook sees it.

A replay of the hook's real answers from production on 21 September 2026 — a deny, two asks, a pass and a line it did not need to send. 19 seconds, no sound.

For your agents

An MCP server any agent can call before it fetches — repositories, npm and PyPI packages, VS Code Marketplace extensions (17 checks), Docker Desktop extensions (11) and agent skills and plugins (15) — with a hard-gate verb that fails a step instead of returning prose a model can argue with.

Advisory: an agent that never calls it is not stopped.

See the AI's hand

Arrived from Claude, ChatGPT, Gemini or an MCP directory? RepoGates raises the bar and tells you. Agent-recommended repositories are a known malware seeding channel, and only code inside the browser can see that the recommendation happened.

The one signal no backend, CLI or scanner can read.

The threat is not hypothetical

FakeGit, 2026 — the campaign RepoGates was built after.

7,600fake repositories from ~6,600 fabricated accounts
14M+malicious release-asset downloads — the path nobody else gates
800+AI-skill & MCP imposters your assistant recommended

Measured, and published — including our misses

A checker that flags everything is useless, so every roster is run against the most popular things on its platform before it ships, and the result is printed.

0false blocks on the skills.sh leaderboard, Anthropic's official plugin marketplace and the first 100 of its community one
50 / 50Docker Desktop extensions — the whole marketplace — pass
99 / 100most-installed VS Code extensions pass; the one flagged is named, with why
Honest coverage: RepoGates gates browser downloads — Download ZIP, release assets, Save-Link-As. It does not see git clone, package managers or curl — outside Claude Code with the RepoGates plugin, whose hook refuses a clone or install that names a blocked repository on the command line, before it runs; nothing browser-based can see other processes. A PASS means every check that could run, ran, and none fired — never a guarantee. We measured ourselves against all 7,648 attributed FakeGit repositories and published the validation that made our number smaller. Read the measurement → · Skills: the campaigns and the run → · VS Code extensions → · Docker Desktop → · The plugin, and what it does not see →