Every request starts with strict owner/repo validation and the repo is never executed locally.
Check the repo before it touches your machine.
Paste a public GitHub repo. Get a trust read on install files, MCP and agent surfaces, maintainer signals, dependency clues, risky paths, and the first thing to inspect before you run anything.
© Christo 2026 — Created by Christo and Nova
Treat the repo like hostile input until the evidence says otherwise.
Codebase Archaeologist is moving out of challenge-demo mode and into a real pre-install trust product. The default path is now a live GitHub scan, not a canned dossier.
The scanner stays bounded, deterministic, and readable: exact evidence, exact rule hits, exact caveats.
The large calibration corpus stays out of runtime. Netlify only serves the generated scoring policy.
Low coverage and weak provenance do not become reassurance. Thin evidence stays caution.
Need a known-good walkthrough first?
The Codex sample stays available as a reference artifact, but it is no longer the default product path.