whichlib
Dependency picker for coding agents: recommends, compares and scores GitHub repos with a verdict.
- 0.2.0
- Version
- remote + npm
- Transport
- 3
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 3 tools scanned
- metadata: scanned
- packages: 1 checked
No findings.
Tools (3)
recommend_repos
Find the best open-source library for a need before adding a dependency. Give the need in plain words and get up to `limit` GitHub repositories ranked by fit = score x relevance to the need. Each result has a 0-100 score (momentum 40% (stars gained per week; without history, lifetime stars per week scaled by the npm/PyPI download trend), maintenance 25%, adoption incl. npm/PyPI weekly downloads 25%, license 10%), a tier (Strong >=75, Solid >=50, Watch >=25, Avoid <25; New for repos under 30 days old, too new to judge), a one-line verdict and the full breakdown. Use this when you do not yet have candidates; use compare_repos when you already have names. Makes 3 GitHub searches plus npm/PyPI lookups for the shortlist. Hosted: 50 free tool calls per day per user; send header X-GitHub-Token with your own GitHub token for unlimited use, or run the npm package locally (npx -y whichlib).
compare_repos
Compare 2-10 known GitHub repositories side by side, best score first: score and tier, stars, forks, open issues, last push, license, npm/PyPI weekly downloads (only when the registry links back to the repository) and a verdict. Each result has a 0-100 score (momentum 40% (stars gained per week; without history, lifetime stars per week scaled by the npm/PyPI download trend), maintenance 25%, adoption incl. npm/PyPI weekly downloads 25%, license 10%), a tier (Strong >=75, Solid >=50, Watch >=25, Avoid <25; New for repos under 30 days old, too new to judge), a one-line verdict and the full breakdown. Use this to choose between candidates you already have (for example zod vs valibot) or to check a dependency the project already uses; use recommend_repos to find candidates. One GitHub API call per repository plus npm/PyPI lookups. A repository that does not exist is listed under notFound and the rest are still compared; the call fails only if none can be fetched, or when GitHub's rate limi
trending_repos
Discover projects: the most-starred GitHub repositories created in the last day, week or month, or with period "rising" repositories of any age that gained the most stars this week (like GitHub Trending; risingRank keeps that order). Optionally one language; each scored and returned sorted by score (starsRank keeps the stars order). Each result has a 0-100 score (momentum 40% (stars gained per week; without history, lifetime stars per week scaled by the npm/PyPI download trend), maintenance 25%, adoption incl. npm/PyPI weekly downloads 25%, license 10%), a tier (Strong >=75, Solid >=50, Watch >=25, Avoid <25; New for repos under 30 days old, too new to judge), a one-line verdict and the full breakdown. Not the right tool for picking a dependency, since new repositories have little maintenance history; use recommend_repos for that. One GitHub search (rising: one download of the daily list from raw.githubusercontent.com instead), plus one npm/PyPI lookup per repository when withDownloads