Observed arrival · 2026-09-28
RepoCanary asks whether that GitHub repo is a trap
A free scanner checks unfamiliar GitHub repositories for fake-interview malware before you install them or open them in an editor.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- Developers reviewing unfamiliar or interview-task repositories
- Worth noticing
- Its checks include code that can run just by opening a folder, including VS Code tasks, MCP servers, dev containers, and editor configuration.
Field notes
The coverage list reaches beyond package install scripts: it names VS Code tasks, MCP servers, AI-agent hooks, dev containers, and Emacs or Neovim project configuration as possible auto-run paths. Its CLI example uses `npx repocanary owner/repo`, while the GitHub Action can return JSON or SARIF and provide pipeline-gating exit codes. The page frames results as heuristic signals, not a safety guarantee.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central
One card from the complete issue