live · scanning repos
Scanrepo
github.com
github.com / greensock

greensock/gsap-skills

44 files·commit aed9cfd·scanned 5d ago·cached ✓
12/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
verdict accurate?
13,858 stars
threat-state: lowlive

FINDINGS ░▒▓

warningPossible typosquat: nuxt"nuxt" is only 1 character(s) away from the popular package "next". This is a common supply-chain attack vector.package.json+4
warningDependency runs install scripts"<root>/postinstall" executes code during installation. Malicious packages use this to drop payloads before the app even runs.package.json+3

Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.

15 files scanned @ aed9cfd | 8/20/2026 | heuristic scan — always review manually

risk by category
code execution0
network & exfiltration0
file system access0
obfuscation0
supply chain7
owasp / injection0
telemetry
files 15/44rules hit 2engine v5commit aed9cfd

github

greensock/gsap-skills

Official AI skills for GSAP. These skills teach AI coding agents how to correctly use GSAP (GreenSock Animation Platform), including best practices, common animation patterns, and plugin usage.

13858
820
174d
44 files
15 scanned(34%)
aed9cfd

architecture░▒▓

entry (3) flagged (0) pkg (34)
42 nodes · 40 edgesscroll to zoom · click node to jump to finding
LOW (12/100) — greensock/gsap-skills — ScanRepo