Free and open source (MIT)
LiveRepoCanary
A recruiter sends a take-home task and asks you to run it. RepoCanary checks it first, without ever executing a line of it. No account, no telemetry, and one engine behind the website, the CLI and a GitHub Action.
01Previews


Captured from the public repocanary.com site, signed out.
02Overview
Fake-interview campaigns hide a payload in a postinstall hook, an obfuscated config, or a dependency pinned deep in a lockfile, and it runs the moment you type npm install: browser passwords, SSH keys, cloud tokens and wallets, gone before you have read a line.
RepoCanary is for the person that repository was sent to. Paste a link on the website or run npx repocanary owner/repo, and read a verdict where every finding names the file and line, says why it matters in plain language, and says what to do next.
03Process
Step 1: Select
The repository tree is ranked by where a trap has to live to fire before anyone reads it: install hooks, editor and agent autoruns, lockfiles, build scripts. Each kind has a quota, so none can spend the whole budget.
Step 2: Follow
Whatever a file says will execute, a postinstall that runs a script, an npm run chain, a VS Code task, is fetched on a reserved budget of its own, so a large repository cannot crowd out the one file that decides the verdict.
Step 3: Judge
Every rule runs on every file in isolation. A rule that fails on crafted input costs that file's findings and is reported, never the scan.
Step 4: Score
Severity decides the colour. Weak context signals, such as a brand-new account, can raise a caution but never a red on their own, and the same input always produces the same result.
04By design
It never runs the target. RepoCanary never clones, installs, executes, evaluates or imports the repository. It reads a bounded set of files as plain text through the GitHub API, so scanning malware is exactly as dangerous as reading it in a browser.
Green is never "safe". Green means nothing known matched, and the tool never says anything stronger. A scan that could not complete is never reported as green.
Measured, with its limits written down. Detection is measured against a corpus of the techniques these campaigns actually use, and the evasions it cannot catch are written into the threat model rather than hidden.
Open, not open-core. The detection rules ship public on purpose, because a security tool nobody can audit does not deserve trust.
05Honest status
Live, and free permanently, because the person this is for cannot buy a scanner. Measured on 4,002 unseen repositories, with 101 of 101 documented techniques flagged.
Check a repository
Paste a link on the website, or run npx repocanary owner/repo in a terminal. Either way, nothing from the repository is run on your computer.
Live at repocanary.com. Questions go to chris@zyric.de.