Using Wirecheck with Claude Code

Claude Code will happily remove a credential, MCP server, or integration it thinks is unused; it has no way to know what else in your organization depends on it. Wirecheck supplies that evidence. The agent still decides what to do with it; Wirecheck never returns a verdict, only known dependants, unknowns, and evidence.

Add this to your repository's CLAUDE.md

CLAUDE.md
## Before changing AI/integration dependencies

This repository is tracked by Wirecheck. Before modifying or removing an
existing credential, MCP server, webhook, scheduled job, external API
integration, or agent/model integration:

1. Run `wirecheck preflight <name> --json` against the target.
2. Read `direct_dependants`, `indirect_dependants`, and
   `unknown_relationships`. A component with zero known dependants but one
   or more unknown relationships is NOT confirmed safe to remove; say so
   explicitly rather than proceeding as if it were.
3. Inspect `evidence` (or run `wirecheck evidence <name> --json`) before
   claiming to understand why the dependency exists.
4. Make the requested change.
5. Report the known and unknown dependants you found, and whether any of
   them still need updating, before considering the task complete.
6. If verification is needed after a merge and rescan, run
   `wirecheck verify retirement <name> --json` and report its `status`
   (`REMOVAL_VERIFIED`, `UNRESOLVED_REMAIN`, or `CONSUMERS_REMAIN`)
   rather than asserting the removal succeeded on your own.

What this looks like in practice

You ask Claude Code to remove an unused MCP server:

example
> Remove the stripe-mcp server, we don't use it anymore.

wirecheck preflight stripe-mcp --json
→ 3 known dependants, 1 unknown relationship, 4 evidence locations

Claude Code: stripe-mcp has 3 known consumers (billing-agent,
refund-workflow, invoice-sync) and one unresolved reference in
scripts/legacy-sync.sh that I can't confirm is dead code. I'll update the
three known consumers, but I'm not removing stripe-mcp itself until that
unresolved reference is checked. I'd recommend reviewing it before I proceed.

That “I'm not removing it yet” is the point: zero known dependants plus an open unknown is a reason to pause, not a green light.

Command reference for this workflow

CommandAnswers
wirecheck preflight <name> --jsonWhat depends on this, right now, before I touch it?
wirecheck context <name> --jsonOne bundle: identity, owner, lifecycle, impact, evidence, retirement status
wirecheck evidence <name> --jsonWhy does Wirecheck believe this exists?
wirecheck compare <owner/repo> --jsonWhat changed between two scans?
wirecheck verify retirement <name> --jsonAfter a rescan, does anything still reference this?

--agent is accepted as an alias for --json everywhere above; it never runs different logic, only adds a recommended_next_queries hint to the response. See the CLI reference for full command details.

What this does not do yet

There is no native Claude Code / MCP integration; this is a CLI you call from CLAUDE.md instructions, deliberately deferred until this workflow is proven with real use. There is also no wirecheck scan .; compare diffs two already-scanned snapshots by scan id, not a local git diff against HEAD.

See removing an MCP server safely and checking AI agent change impact for worked examples of this workflow end to end.