Skip to the card

Card 682 of 9842026-09-28 issue

Observed arrival · 2026-09-28

RepoCanary asks whether that GitHub repo is a trap

repocanary.com Visit website
Editorial interest 86/100 Selection signal · not a rating of the site

A free scanner checks unfamiliar GitHub repositories for fake-interview malware before you install them or open them in an editor.

Landing page captured for the 2026-09-28 issue.
For
Developers reviewing unfamiliar or interview-task repositories
Worth noticing
Its checks include code that can run just by opening a folder, including VS Code tasks, MCP servers, dev containers, and editor configuration.

Field notes

The coverage list reaches beyond package install scripts: it names VS Code tasks, MCP servers, AI-agent hooks, dev containers, and Emacs or Neovim project configuration as possible auto-run paths. Its CLI example uses `npx repocanary owner/repo`, while the GitHub Action can return JSON or SARIF and provide pipeline-gating exit codes. The page frames results as heuristic signals, not a safety guarantee.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central

One card from the complete issue

Regulated by Arithmetic

233,109 arrived 1,000 judged 984 catalogued Enter the complete issue
repocanary.com

Landing page observed 2026-09-28. The live site may have changed.