endor-score

Evaluate open source package health with a 10-point scorecard.

2|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/endorlabs/skills-ideas --skill endor-score-endorlabs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: endor-score
Source: https://github.com/endorlabs/skills-ideas/tree/main/skills/endor-score
Command: npx skills add https://github.com/endorlabs/skills-ideas --skill endor-score-endorlabs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Evaluate open source package health before adoption. This section should succinctly describe why evaluating package health matters in software decisions and reduce risk when choosing dependencies.

Core Features & Use Cases

  • Scorecard-based health evaluation across ecosystems (npm, Python, Go, Java, Maven, Rust, etc.) to inform dependency choices.
  • Compare packages, assess activity, popularity, security, and quality signals, and identify risk indicators.
  • Use cases include evaluating whether to adopt a package, selecting between alternatives, and monitoring ongoing health.

Quick Start

Provide a package name (and optional version) to receive an endor-score health assessment and comparison guidance.

Frequently Asked Questions about endor-score

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I evaluate open-source package health before adoption?

To evaluate open-source package health before adoption, provide a package name to receive a 10-point scorecard. This assessment checks vulnerabilities and presents activity, popularity, security, and quality bars to guide dependency choices.

Can I check vulnerabilities and compare npm or Python dependencies?

Yes, you can compare packages and check vulnerabilities across ecosystems like npm, Python, Go, Java, and Rust. The evaluation fetches package metrics and CVE history to help you select between alternatives and identify risk indicators.

What metrics are included in the open-source package scorecard?

The package scorecard includes metrics for activity, popularity, security, and quality. It also provides CVE history and recommended actions to help you assess risk and monitor ongoing health for your dependencies.

How do I assess risk when selecting between alternative open-source packages?

To assess risk when selecting between alternatives, compare their scorecard metrics. The evaluation highlights activity, popularity, security, and quality signals alongside CVE history to identify risk indicators and inform your dependency choices.

Do I need to specify a package version to get a dependency health assessment?

No, you only need to provide the package name to get a dependency health assessment, though specifying a version is optional. The tool will fetch package metrics and present a scorecard with recommended actions.

When should I use a package health scorecard for my dependencies?

You should use a package health scorecard when deciding whether to adopt a package, selecting between alternatives, or monitoring ongoing health. It performs vulnerability checks and assesses activity, popularity, security, and quality to reduce dependency risk.