live · scanning repos
Scanrepo
github.com
github.com / SongYuhui14

SongYuhui14/dsh-code-vetter

JavaScript·7 files·commit 5bc09a9·scanned 4d ago·cached ✓
19/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
verdict accurate?
Created 1 days ago
Crypto/Web3 project
Created in the last 7 days
threat-state: lowlive

FINDINGS ░▒▓

warningHigh-entropy string literalsFound 3 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.lib/index.js+3
warningHigh-entropy string literalsFound 11 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.rules/security-rules.js+3
infoAuthor has no other public repositoriesGitHub user "SongYuhui" has no other public repositories, common for burner accounts used in scams.+2

Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.

4 files scanned @ 5bc09a9 | 8/20/2026 | heuristic scan — always review manually

risk by category
code execution0
network & exfiltration0
file system access0
obfuscation6
supply chain2
owasp / injection0
telemetry
files 4/7rules hit 3engine v5commit 5bc09a9

github

SongYuhui14/dsh-code-vetter

DSH plugin: AI code security reviewer — scan code for SQL/command injection, hardcoded secrets, dangerous functions, weak crypto, auth bypass (OWASP/CWE-aligned). AI 代码安全审查器

JavaScript
1
0
5d
7 files
4 scanned(57%)
5bc09a9

architecture░▒▓

entry (3) flagged (2) pkg (0)
3 nodes · 2 edgesscroll to zoom · click node to jump to finding