Attackers can inject indirect prompts in normal-looking repositories to trick Claude Code into spawning a reverse shell.
An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious ...
× python setup.py bdist_wheel did not run successfully. │ exit code: 1 ╰─> [20 lines of output] running bdist_wheel running build running build_py creating build creating ...
Customer stories Events & webinars Ebooks & reports Business insights GitHub Skills ...
You get a SARIF file to upload to GitHub code scanning, a CycloneDX SBOM, and a self-contained HTML report for the humans. No agent, no cloud, no code leaving your runner. It even works fully offline.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results