Public repositories
Review a public repository and its release, dependency, workflow, licensing, and source context.
When someone requests an extension, package, repository, or source archive, turn the code into prioritized evidence and a deployment decision your team can explain.
This abbreviated example shows the report structure and omits parts of the complete interactive experience.
Browser extension · Source review · Completed today
src/background/messages.jsHIGHMessage origin validation should be restricted before broad deployment.
manifest.jsonMEDIUMRequested host permissions are broader than the stated business workflow.
Use the source format you actually have. Direct private-repository connections are not currently supported.
Review a public repository and its release, dependency, workflow, licensing, and source context.
Evaluate permissions, install behavior, provenance, dependencies, and code signals in packaged software.
Upload source you are legally authorized to submit when a public repository is not available.
The system organizes code evidence. Your team applies business context and owns the final approval.
Provide a public repository, extension, package, or authorized source archive.
Review provenance, install behavior, permissions, vulnerabilities, risk patterns, and licensing.
Use prioritized, evidence-linked findings and explicit uncertainty to focus human review.
Share a link to the web report or export it as HTML or PDF, then document why the software was approved, limited, or rejected.
Development scanners produce finding feeds for software your team owns. CIRT produces decision support for software someone else wants to introduce into your environment.
Findings remain informational indicators. They can contain false positives, false negatives, incomplete analysis, or misinterpretations and should be reviewed by a qualified person.
CIRT states the boundaries of automated analysis and does not ask you to retain source indefinitely.
Code files are not retained after processing. Cryptographic file hashes and underlying file-level results are retained indefinitely by default, including after the code review assessment is deleted. For a sensitive codebase, an option available during the initial scan can delete the stored hashes and results created for unique files first seen in that repository after report generation. This option is generally not recommended because it reduces retained analysis history and reuse. Each result is primarily a generated summary of the file's purpose and its associated security findings; rare circumstances may include a small code snippet. It cannot identify or reconstruct the submitted source file.
Repository scanning is designed primarily for open source. An authorized ZIP can be used when you have the right to submit the code.
CIRT is decision support, not a guarantee, certification, professional engagement, or transfer of liability.
BYOK Starter includes a seven-day trial, 10 code assessments, 2 vendor reviews, and an observed early-access Anthropic average of less than $2 per code assessment.
The labor example is illustrative. Actual provider spend, review time, and organizational savings vary.
Start with a repository, extension, package, or authorized source archive.