hallux_check_command

shallow

dev.blvkware/hallux · Verify this server

Call this BEFORE running any command that installs a dependency: npm, yarn, pnpm, bun, pip, uv, poetry, pipx, cargo, go get, dotnet add package, nuget. Language models invent plausible package names that have never existed, and attackers register those names because they can predict them. Installing one runs attacker code. You cannot tell the difference by looking at the name, which is why this check exists. Pass the command exactly as you intend to run it. The identifiers are extracted for you. If the result says BLOCK, do not run the command. Use the `successor` if one is given, otherwise tell the user what was found and stop.

100.0/100

1 trials · measured 14 days ago

hallux_check_command scores 100.0/100 on Vouch's measured behaviour index, from 1 real invocation trials against dev.blvkware/hallux, measured 23 Sept 2026 under methodology v0.2.0. Every measured component scored 100.

Component breakdown

ComponentWeightValue
Reliability35%not applicable
Schema integrity25%100.0
Failure behaviour15%not applicable
Latency15%not applicable
Concurrency10%not applicable

Tool details

Transport
remote
Credential class
self-provisionable
Input schema
not declared
Output schema
not declared
Side-effect classification
unclassified

Score history

DayScoreTierMethodology
2026-09-23100.0shallowv0.2.0

Probe evidence

ProbeOutcomes
schema_integritypass: 1

Raw request/response logs are not archived yet — the outcome counts above are drawn directly from every recorded trial.

Embed this score

Available for every tool, scored or not — not a verification perk. Always links back to this page.

Vouch score: hallux_check_command
[![Vouch score](https://vouch.tools/api/tools/d064858d-af95-4f21-9b54-e438356bf935/badge.svg)](https://vouch.tools/tools/d064858d-af95-4f21-9b54-e438356bf935)
hallux_check_command — Vouch