We found this by crawling public sources and nobody has attested to it. That is how most of the registry gets here, and it is not a mark against the artifact — it only means no authenticated act of publication is on record. An artifact can be the vendor's own and still appear here.
Choose your runtime: the CLI writes the mcpServers config entry for that target.
nerlo install --target claude-code -- react-forge
Install respects the composite badge: Clean proceeds, Caution prompts for confirmation, and Flagged is refused. Write operations require an API token.
7 of 12 scanners examined this package. The rest do not apply to it — language, ecosystem and packaging decide which analyzers can say anything, and a scanner that cannot examine an artifact reports nothing rather than passing it.
v2.0.11
9 findings · 10.1s
1 scan on record. Every scan's full results are retained immutably for 24 months.
| Completed | Composite | Change | Scanners | Status |
|---|---|---|---|---|
| Aug 15, 2026 | Clean100 | — | agentshield ·n/a: not applicablecisco-skill-scanner: completeagent-audit-kit: completebearer: completenerlo-behavioral: completenerlo-install-instruction: completecapslock ·n/a: not applicabletrivy: completeosv-scanner: completetrivy_image ·n/a: not applicable |
Are you the author and believe a verdict is inaccurate? Appeal this badge.
v0.3.26
2 findings · 0.9s
v2.0.2
0 findings · 5.0s
v0.1.0
0 findings · 4.5s
v0.1.0
0 findings · 4.5s
v0.71.0
0 findings · 0.3s
v2.3.8
0 findings · 0.3s
v1.4.0
None of the entry points this scanner reads were found in this artifact. What each scanner covers
0 findings · 0.2s
vv0.3.2
No Go packages were found in this artifact. What each scanner covers
0 findings · 0.2s
v0.71.0
No container image was published for this artifact. What each scanner covers
0 findings · 0.0s
vv1.6.0
No Go modules were found in this artifact. What each scanner covers
0 findings · 0.1s
No report in this scan: nerlo-multi-source.
| completed |