All tools
Live tool · /v1/repo-scan

Repo Risk Scanner

Scan a GitHub URL or paste manifests before you clone that “test assignment”. Static analysis + npm/PyPI metadata — we never execute the project.

Covers npm lifecycle scripts, obscure/new registry packages, lockfile install hooks, Python packaging, Cargo/Go/Composer smells, git hooks, and CI workflows.

Try:

Example: https://github.com/org/repo or …/tree/branch — public repos only. Nothing is executed.