Offline, read-only repository triage for documented software supply-chain and coding-agent attacks, with explicit coverage and fail-closed results
-
Updated
Sep 24, 2026 - Python
Offline, read-only repository triage for documented software supply-chain and coding-agent attacks, with explicit coverage and fail-closed results
A client-side Debian APT repository workbench for reviewable source files, install commands, and a static API.
Local static repository ZIP analysis with public-safe decision receipts.
Audit repositories across GitHub, GitLab, Gitea, Forgejo, and Bitbucket Cloud from one binary.
Public deployment mirror for reusable repository privacy checks
Private, local malware and supply-chain scanner for unfamiliar repositories and coding assignments
Redaxa by Aurelio Avila: sensitive-data checks and redaction for AI prompts, plus local repository secret reviews on Windows. Desktop, browser extension and web app.
Read-only GitHub Actions security linter for unsafe triggers, permissions, secrets, checkouts, runners, and unpinned actions.
Advanced Repository Security Posture Engine (DevSecOps CLI)
Zero-trust Claude Code skill for reviewing external repositories, detecting prompt injection, protecting secrets, and reporting execution risk.
Trust-handoff firewall for AI-written repositories: delta-aware activation graphs and quarantine-first promotion for coding-agent changes.
Deterministic repository boundaries for AI coding agents and the humans who direct them.
To associate your repository with the repository-security topic, visit your repo's landing page and select "manage topics."