Scans code changes for leaked secrets and insecure config, with actionable fixes for AI agents.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Scans code changes for leaked secrets and insecure config, with actionable fixes for AI agents.