Using Wirecheck with Claude Code
Claude Code will happily remove a credential, MCP server, or integration it thinks is unused; it has no way to know what else in your organization depends on it. Wirecheck supplies that evidence. The agent still decides what to do with it; Wirecheck never returns a verdict, only known dependants, unknowns, and evidence.
Add this to your repository's CLAUDE.md
## Before changing AI/integration dependencies This repository is tracked by Wirecheck. Before modifying or removing an existing credential, MCP server, webhook, scheduled job, external API integration, or agent/model integration: 1. Run `wirecheck preflight <name> --json` against the target. 2. Read `direct_dependants`, `indirect_dependants`, and `unknown_relationships`. A component with zero known dependants but one or more unknown relationships is NOT confirmed safe to remove; say so explicitly rather than proceeding as if it were. 3. Inspect `evidence` (or run `wirecheck evidence <name> --json`) before claiming to understand why the dependency exists. 4. Make the requested change. 5. Report the known and unknown dependants you found, and whether any of them still need updating, before considering the task complete. 6. If verification is needed after a merge and rescan, run `wirecheck verify retirement <name> --json` and report its `status` (`REMOVAL_VERIFIED`, `UNRESOLVED_REMAIN`, or `CONSUMERS_REMAIN`) rather than asserting the removal succeeded on your own.
What this looks like in practice
You ask Claude Code to remove an unused MCP server:
> Remove the stripe-mcp server, we don't use it anymore. wirecheck preflight stripe-mcp --json → 3 known dependants, 1 unknown relationship, 4 evidence locations Claude Code: stripe-mcp has 3 known consumers (billing-agent, refund-workflow, invoice-sync) and one unresolved reference in scripts/legacy-sync.sh that I can't confirm is dead code. I'll update the three known consumers, but I'm not removing stripe-mcp itself until that unresolved reference is checked. I'd recommend reviewing it before I proceed.
That “I'm not removing it yet” is the point: zero known dependants plus an open unknown is a reason to pause, not a green light.
Command reference for this workflow
| Command | Answers |
|---|---|
| wirecheck preflight <name> --json | What depends on this, right now, before I touch it? |
| wirecheck context <name> --json | One bundle: identity, owner, lifecycle, impact, evidence, retirement status |
| wirecheck evidence <name> --json | Why does Wirecheck believe this exists? |
| wirecheck compare <owner/repo> --json | What changed between two scans? |
| wirecheck verify retirement <name> --json | After a rescan, does anything still reference this? |
--agent is accepted as an alias for --json everywhere above; it never runs different logic, only adds a recommended_next_queries hint to the response. See the CLI reference for full command details.
What this does not do yet
There is no native Claude Code / MCP integration; this is a CLI you call from CLAUDE.md instructions, deliberately deferred until this workflow is proven with real use. There is also no wirecheck scan .; compare diffs two already-scanned snapshots by scan id, not a local git diff against HEAD.
See removing an MCP server safely and checking AI agent change impact for worked examples of this workflow end to end.