github.com / tt-a1i
tt-a1i/ archify
HTML·422 files·commit 82e63c9·scanned 5d ago·cached ✓
15/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
score capped at 15 — 14,474+ stars — findings likely false positives
verdict accurate?
14,474 stars
Crypto/Web3 project
45% file coverage
CLI tool detected
threat-state: lowlive
FINDINGS ░▒▓
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.archify/brand-marks/catalog.json+4
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.archify/delta/architecture-delta.mjs+4
warningExtremely long lines (>1000 chars)Very long lines in source files (not minified bundles) can hide malicious code.archify/renderers/shared/generated-brand-marks.mjs+4
warningHigh-entropy string literalsFound 8 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.archify/scripts/check-render-output.mjs+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.archify/scripts/check-render-output.mjs+3
warningHigh-entropy string literalsFound 4 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.archify/scripts/generate-brand-marks.mjs+3
warningHigh-entropy string literalsFound 6 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.integrations/deepseek-harness/scripts/distribution-acceptance.mjs+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.integrations/deepseek-harness/scripts/distribution-acceptance.mjs+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.scripts/check-release-identity.mjs+3
warningLarge base64-encoded blobA 92-character base64 blob was found. May hide a remote payload or encoded executable code.archify/test/brand-marks.test.mjs
iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mNk...+3
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
191 files scanned @ 82e63c9 | 8/19/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration0
file system access0
obfuscation15
supply chain0
owasp / injection0
telemetry
files 191/422rules hit 11engine v5commit 82e63c9
github
tt-a1i/archify
Agent skill for beautiful, verifiable architecture, workflow, sequence, data-flow, and lifecycle diagrams—self-contained HTML with motion and crisp export.
14474
1047
132d
422 files
191 scanned(45%)
82e63c9
architecture░▒▓
entry (0) flagged (41) pkg (8)
136 nodes · 96 edgesscroll to zoom · click node to jump to finding