Observed arrival · 2026-09-28
cqx: a Rust repository behavior analyzer
A browser-based analyzer for public Rust repositories that reports runtime-relevant behavior, including spawned processes, environment-variable reads, and checks whose results are ignored.
- For
- Rust maintainers reviewing agent-written or unfamiliar code
- Worth noticing
- The homepage says the analyzer runs as four-thread WebAssembly in-browser and can inspect repositories that do not compile.
Field notes
One displayed scan covers 327 files and 96,683 lines in 0.7 seconds, with findings pointing to an ignored enforce_read result, a shell command, and --allow-all passed to a child process. The interface groups results under containment, legibility, modularity, quality, and security, and says category thresholds can be configured per repository. The page reports browser-side WebAssembly execution; the extracted material does not independently verify its performance or privacy claims.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue