← Back to home

Free and open source (MIT)

Live

RepoCanary

A recruiter sends a take-home task and asks you to run it. RepoCanary checks it first, without ever executing a line of it. No account, no telemetry, and one engine behind the website, the CLI and a GitHub Action.

01Previews

repocanary.com
RepoCanary, Paste a link: desktop view
RepoCanary, Paste a link: phone view
Paste a link. No account and nothing downloaded: paste a repository link and scan it.

Captured from the public repocanary.com site, signed out.

02Overview

Fake-interview campaigns hide a payload in a postinstall hook, an obfuscated config, or a dependency pinned deep in a lockfile, and it runs the moment you type npm install: browser passwords, SSH keys, cloud tokens and wallets, gone before you have read a line.

RepoCanary is for the person that repository was sent to. Paste a link on the website or run npx repocanary owner/repo, and read a verdict where every finding names the file and line, says why it matters in plain language, and says what to do next.

03Process

  1. Step 1: Select

    The repository tree is ranked by where a trap has to live to fire before anyone reads it: install hooks, editor and agent autoruns, lockfiles, build scripts. Each kind has a quota, so none can spend the whole budget.

  2. Step 2: Follow

    Whatever a file says will execute, a postinstall that runs a script, an npm run chain, a VS Code task, is fetched on a reserved budget of its own, so a large repository cannot crowd out the one file that decides the verdict.

  3. Step 3: Judge

    Every rule runs on every file in isolation. A rule that fails on crafted input costs that file's findings and is reported, never the scan.

  4. Step 4: Score

    Severity decides the colour. Weak context signals, such as a brand-new account, can raise a caution but never a red on their own, and the same input always produces the same result.

04By design

  • It never runs the target. RepoCanary never clones, installs, executes, evaluates or imports the repository. It reads a bounded set of files as plain text through the GitHub API, so scanning malware is exactly as dangerous as reading it in a browser.

  • Green is never "safe". Green means nothing known matched, and the tool never says anything stronger. A scan that could not complete is never reported as green.

  • Measured, with its limits written down. Detection is measured against a corpus of the techniques these campaigns actually use, and the evasions it cannot catch are written into the threat model rather than hidden.

  • Open, not open-core. The detection rules ship public on purpose, because a security tool nobody can audit does not deserve trust.

05Honest status

Live

Live, and free permanently, because the person this is for cannot buy a scanner. Measured on 4,002 unseen repositories, with 101 of 101 documented techniques flagged.

Check a repository

Paste a link on the website, or run npx repocanary owner/repo in a terminal. Either way, nothing from the repository is run on your computer.

Scan a repo(opens in a new tab)

Live at repocanary.com. Questions go to chris@zyric.de.