Free GitHub Action that scans PR diffs for malicious code, not quality
Free GitHub Action that scans PR diffs for malicious code, not quality
I watched a video recently on malicious code injection into OSS repo PRs and how they can go undetected because of how well they're hidden and decided to do a project for this. This tool is essentially used in unison with ai code review bots like greptile. While tools like greptile reason because they run with LLMs, this is a deterministic step before greptile that scans for malicious code (command execution, credential access, exfil, auto-run hooks, obfuscation, and prompt injection; regex + semgrep, no LLM), then can trigger the ai code reviewer like greptile or coderabbit, pointing it to its findings. It's free/MIT and runs in your CI.
Share cardActual performance
Launch Intel predictions
Analyze your own launch →Correct prediction on native model
Similar products
GitHub – Specify that a PR must be merged after another PR
Nextrelease – GitHub Action to publish the next release by merging a PR
Asciidoctor GitHub Action
GitHub Action to find Log4j vulnerabilities
OpenHands' GitHub Action
GitEnforcer – GitHub PR and Issue Quality Assurance Bot
Interactively explore every GitHub PR between 2012 and 2017
PR Guard – A GitHub Action to ensure authors understand their PRs
PR-Codex, a GitHub app to summarize PR code diffs with ChatGPT
OAuth 2.0 Authorization Code Injection Attack in Action