Read-only public repository scan

GitHub security scanner for vibe-coded apps.

Check a public repository for the mistakes AI coding agents cannot see after deployment: committed secrets, unsafe workflows, exposed client keys, missing database boundaries, and risky code patterns.

We never execute repository code Secret values stay out of the report

Scan a public GitHub repository

Private repository connection is coming through a GitHub App.

The public scanner reads up to 60 security-relevant files from the current tree. It does not search full Git history.

What the repo scan checks

The mistakes hidden behind a working demo.

Secrets and credentials

Committed .env files, private keys, provider tokens, database URLs, and secret-like literals.

GitHub Actions

Broad token permissions, mutable action tags, secret output, and dangerous pull_request_target flows.

Client exposure

Public environment secrets, raw HTML sinks, dynamic code execution, wildcard CORS, and source maps.

Database boundaries

Supabase service-role exposure and SQL migrations that create tables without visible RLS enablement.

Known vulnerable dependencies

Exact versions from npm, Python, Go, and Rust lock data checked against the OSV advisory database.

Codex, Claude, Cursor, and MCP

Agent permissions, remote MCP transport, unpinned tool packages, destructive commands, and secret-transfer paths.

Two scans, two surfaces

Scan the repository before launch. Scan the public app after launch.

Repository checks catch secrets and configuration mistakes. The website scanner checks the deployed headers, TLS, cookies, files, routes, and browser-facing behavior.

Open website scanner