Offline, read-only repository triage for documented software supply-chain and coding-agent attacks, with explicit coverage and fail-closed results
-
Updated
Sep 1, 2026 - Python
Offline, read-only repository triage for documented software supply-chain and coding-agent attacks, with explicit coverage and fail-closed results
A client-side Debian APT repository workbench for reviewable source files, install commands, and a static API.
Local static repository ZIP analysis with public-safe decision receipts.
Public deployment mirror for reusable repository privacy checks
Audit repositories across GitHub, GitLab, Gitea, Forgejo, and Bitbucket Cloud from one binary.
Zero-trust Claude Code skill for reviewing external repositories, detecting prompt injection, protecting secrets, and reporting execution risk.
Advanced Repository Security Posture Engine (DevSecOps CLI)
Read-only GitHub Actions security linter for unsafe triggers, permissions, secrets, checkouts, runners, and unpinned actions.
Deterministic repository boundaries for AI coding agents and the humans who direct them.
To associate your repository with the repository-security topic, visit your repo's landing page and select "manage topics."