Skip to main content
Run any Skill in Manus
with one click

repo-scan

Stars1
Forks0
UpdatedJune 14, 2026 at 16:35

Security-vet a third-party GitHub repository BEFORE using, cloning into a project, or installing it. Clones to an isolated directory (never executes repo code) and statically scans for credential theft, hidden outbound connections, install-time attacks (malicious postinstall / setup.py), obfuscated payloads, supply-chain risks, leaked secrets, and dangerous CI workflows. Outputs a verdict report (BLOCK / CAUTION / PASS). Use this skill whenever the user asks "is this repo safe", "scan this repo", "can I trust this project", "會不會偷 key", "這個 repo 安全嗎", "掃描這個 repo", "幫我檢查這個專案可不可以用", or pastes a GitHub URL of an unfamiliar project they intend to install or run. Not for reviewing the user's own code (use /review) and not for auditing changes on the current branch (use /security-review).

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
2 files
SKILL.md
readonly