dr.

Projects / clonecheck

clonecheck

Scans an untrusted repo for hidden, auto-executing code before you run it.

Highlights

  • Catches padding-hidden loaders that fire on npm run dev
  • ~20 rules: obfuscation, eval + fetch loaders, install hooks, invisible Unicode
  • Tuned for shape, not keywords — single-digit findings on ~15k ordinary files

Built with

  • Node.js
  • zero dependencies

Ask me about it

Want the details — why it's built this way, what went wrong, what I'd change? Ask my AI version or get in touch.

More projects