RepoGates vs Socket.dev

Two tools that are often put side by side and mostly look at different things. What each one sees, what it does not, and when to use the other one.

The short answer. Socket reads the packages your project depends on — the artefact a registry publishes — when a dependency is added or installed. RepoGates reads the repository you are about to download — its owner, its history, its file list and its releases — before the download reaches your downloads folder. If your risk is your dependency tree, Socket is built for it and RepoGates is not. If your risk is a stranger's repository, an AI assistant's recommendation, or a release ZIP, that is the question RepoGates was built to answer.

Two different objects

Socket's unit is a package version: left-pad@1.3.0 on npm, a wheel on PyPI. It inspects the published tarball — what the registry will actually hand your build — and raises alerts such as Install scripts, Native code, typosquats, Recently published, New author and Unstable ownership. Its author signals are registry signals: who publishes to npm, and when that changed.

RepoGates' unit is a repository: owner/repo on GitHub. It asks the GitHub API who the owner is and since when, whether the stars match the history, what is attached to the releases, and — from one recursive file-list call, with no clone — what runs the moment you open the folder: a .devcontainer, .vscode/tasks.json, build.rs, a nested bare repository, an agent configuration file carrying hidden Unicode. None of those is in a package tarball, and most repositories people download are not packages at all.

The distinction is not a criticism of either. It is the reason the two are rarely substitutes.

Side by side

Socket.devRepoGates
What it assessesPublished package versions in the registries it supportsA GitHub repository (and, through the MCP server, gitlab.com projects, Hugging Face models, agent skills and plugins)
WhenWhen a dependency is added (pull request) or installedWhen you open a repository page, and when you press Download
Where it runsYour repositories, your CI, your install commandYour browser; your AI agent, if it calls the MCP server
Author signalRegistry events: new author, ownership changesThe GitHub owner account's age (a 45-point finding under 90 days)
Fake starsYes — its alert reference lists Suspicious Stars on GitHubYes — stars against repository age (C3)
Install scripts, native codeYes, in the published packageInstall scripts and committed binaries in the repository tree (C15, C16)
What runs when a folder opensNot its objectdevcontainer, editor tasks, build scripts, bare repositories, .envrc (C10–C17)
Release-asset ZIPsNot its objectThe binaries attached to releases (C9) — the FakeGit delivery path
Agent configuration filesNot its objectCLAUDE.md, .cursorrules, MCP launch configs, hidden Unicode (C18–C21)
That an AI assistant sent youNoYes, in the browser only (C22)
Your dependency tree and lockfileYes — this is what it is forNo

Socket's column is taken from its public alert reference as we read it for our coverage matrix in August 2026. Socket ships quickly; read its own list for today's.

What Socket sees that RepoGates does not

Your dependencies. RepoGates does not read your manifest or your lockfile, and it does not follow a package to the packages it pulls in. It does not look at a pull request. A malicious version of a popular package, published an hour ago to a registry by a hijacked maintainer account, is exactly the shape Socket's model is built to raise and RepoGates' is not: the repository behind that package may be years old, well-starred and entirely clean.

The artefact, not the source. A package tarball can differ from the repository it claims to come from. Socket reads what the registry serves; RepoGates reads the repository. When the question is "what will my build actually install", the tarball is the right object.

What RepoGates sees that Socket does not

A repository that is not a package. The FakeGit campaign published roughly 7,600 repositories from about 6,600 fabricated accounts, and its payload was a ZIP attached to a release, downloaded 14,084,688 times through a browser. Most of those repositories were never on npm or PyPI, so there was no package for a dependency tool to see. What gave them away was the repository itself: an owner account created the same month, stars out of proportion to the history, a binary where a library's source release should be.

What runs before you read a line. A checked-in devcontainer runs a command when the folder opens; a VS Code task runs on workspace trust; build.rs runs when rust-analyzer starts. These live in the repository tree, not in a package, and in our August 2026 survey of about 45 products no vendor documented a rule for the devcontainer one.

Where the link came from. If an AI assistant recommended the repository, the browser can see that you arrived from the assistant. A backend cannot, a CLI cannot, and a dependency scanner is not there at that moment. That is check C22, and it is the one signal only code running in the browser at navigation time can read.

When to use Socket instead

RepoGates is not a substitute for any of those, and we would rather say so here than have you find out.

When RepoGates is the one you want

What RepoGates does not cover

RepoGates gates browser-initiated downloads — Download ZIP, release-asset archives, Save Link As. It does not see git clone, package managers, curl, or fetches made by AI agents outside the browser. Inside Claude Code with the RepoGates plugin, a hook refuses a clone or install that names a blocked repository on the command line, before it runs — it sees Bash tool calls in that one client and nothing else. VS Code extensions and skills are answered through the MCP server and the plugin, not in the browser.

Questions

Is RepoGates a replacement for Socket? No. Socket assesses the packages a project depends on — the published npm or PyPI artefact, when a dependency is added or installed. RepoGates assesses a GitHub repository you are about to download, from the repository's own tree and its owner's history, before the download reaches your downloads folder. A team that ships software with third-party dependencies wants Socket or something like it. RepoGates answers a question Socket's model does not ask: should I download this stranger's repository at all?

Does RepoGates check my dependencies? Not the way Socket does. RepoGates does not read your lockfile or your manifest, and it does not resolve transitive dependencies. Inside Claude Code with the RepoGates plugin, a package named on an install command line is resolved to the source repository it declares and that repository is assessed — direct dependencies named on the command line only; transitive dependencies and lockfiles are not resolved. For your dependency tree, use a dependency tool.

Can I use both? Yes, and they do not overlap much. Socket sits in your pull requests and your installs; RepoGates sits in your browser at the moment you press Download on a repository, and answers your AI agents through its MCP server. Nothing in either conflicts with the other.

Add RepoGates to Chrome or Edge The 22 checks

Numbers on this page: Island and BleepingComputer, July 2026 (FakeGit); our coverage matrix of 22 checks against about 45 products, 13 August 2026. Socket is a trademark of its owner; this page is our reading of its public documentation, not a statement by Socket. Also compare: RepoGates vs OpenSSF Scorecard.