github.com / Javis603
Javis603/ token-monitor
JavaScript·992 files·commit d7316c5·scanned 2h ago·cached ✓
25/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
score capped at 25 — 2,360 stars — findings likely legitimate code patterns
verdict accurate?
Crypto/Web3 project
Partial architecture graph
Electron app detected
threat-state: lowlive
FINDINGS ░▒▓
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.src/electron/edgeDock/controller.js+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.src/shared/providers/codex/auth.js+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.src/shared/providers/cursor/auth.js+3
warningHigh-entropy string literalsFound 4 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/agent/agent.js+3
warningHigh-entropy string literalsFound 9 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/electron/renderer/dashboard.js+3
warningHigh-entropy string literalsFound 4 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/electron/renderer/edgeDock/dock.js+3
infoSuspicious file in repoVery large source file (731KB) — could contain obfuscated payloadsrc/electron/renderer/app.js+2
infoSuspicious file in repoVery large source file (601KB) — could contain obfuscated payloadsrc/electron/renderer/i18n.js+2
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
705 files scanned @ d7316c5 | 9/25/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration0
file system access0
obfuscation15
supply chain4
owasp / injection0
telemetry
files 705/992rules hit 9engine v6commit d7316c5
github
Javis603/token-monitor
Local-first desktop widget for tracking token usage, costs, and limits across 40+ AI coding tools—including Claude Code, Codex, Cursor, OpenCode, and OpenClaw—with multi-device sync.
2360
234
129d
992 files
705 scanned(71%)
d7316c5
architecture░▒▓
entry (0) flagged (113) pkg (21)
421 nodes · 672 edgesscroll to zoom · click node to jump to finding