Observed arrival · 2026-08-20
Takehome Scan checks coding assignments before you run them
A static malware scanner that inspects public GitHub, GitLab, or Bitbucket repositories for suspicious behavior without cloning, running, or storing the code.
Why it surfaced
The site targets a concrete recruiting-security problem: fake take-home assignments that can steal keys, browser logins, or crypto wallets during npm install. Its blunt warning—“A recruiter sent you a repo. Check it isn't out to rob you.”—is matched by unusually clear limits: a clean result is not proof of safety, and the safest test still happens in a disposable VM.
A static malware scanner that inspects public GitHub, GitLab, or Bitbucket repositories for suspicious behavior without cloning, running, or storing the code.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue