Offline, read-only repository triage for documented software supply-chain and coding-agent attacks, with explicit coverage and fail-closed results
-
Updated
Sep 24, 2026 - Python
Offline, read-only repository triage for documented software supply-chain and coding-agent attacks, with explicit coverage and fail-closed results
A client-side Debian APT repository workbench for reviewable source files, install commands, and a static API.
Local static repository ZIP analysis with public-safe decision receipts.
Audit repositories across GitHub, GitLab, Gitea, Forgejo, and Bitbucket Cloud from one binary.
Sensitive data detection and redaction for AI prompts, plus local GitHub repository secret scanning on Windows. Desktop app, browser extension and web app.
Public deployment mirror for reusable repository privacy checks
Private, local malware and supply-chain scanner for unfamiliar repositories and coding assignments
Read-only GitHub Actions security linter for unsafe triggers, permissions, secrets, checkouts, runners, and unpinned actions.
Advanced Repository Security Posture Engine (DevSecOps CLI)
Zero-trust Claude Code skill for reviewing external repositories, detecting prompt injection, protecting secrets, and reporting execution risk.
Deterministic repository boundaries for AI coding agents and the humans who direct them.
Trust-handoff firewall for AI-written repositories: delta-aware activation graphs and quarantine-first promotion for coding-agent changes.
To associate your repository with the repository-security topic, visit your repo's landing page and select "manage topics."