Catch malicious pull requests before they merge. A GitHub Action that scans a diff for supply-chain attack patterns — pwn-request workflows, obfuscated payloads, secret exfiltration, droppers — backed by deterministic evidence a model cannot suppress. No API key required. -
View it on GitHub