is-malicious
这是 lu4p_ 公开的项目资料。本站按原始来源展示项目信息,用中文说明适用场景和阅读边界;项目名、源帖与代码保持原样,便于逐项核对。
这条案例记录了什么
安全与权限门禁、编码 Agent
提供风险或支持程度的判断信号;执行权限仍归应用规则。
本站直接测试
原始来源:lu4p_ via Reddit。作者自述,本站未独立复现。
lu4p_
记录日期:2026-09-18。日期与身份应以原始资料为准。
怎样核对这个项目
- 先打开原始来源,确认作者、日期与 Jev 在项目中的具体用途。
- 如果提供仓库,再检查代码、运行要求和许可证;仓库存在不代表本站已经运行成功。
- 对速度、成本、准确率和规模数字,查看原文的任务、环境和计算口径。
- 高风险动作是否单独授权。
- 误判后的阻断和恢复。
- 规则是否由程序执行。
- 仓库状态和测试是否完整。
原始文字与技术细节
以下内容保留原语言,供核对事实。中文页的场景说明是阅读提示,不是逐句翻译或实测结论。
展开英文项目摘要与原帖
项目摘要
The author built is-malicious, a codebase scanner that asks whether code is obviously malicious, points to suspicious parts of files, and can serve as a first line of defense for pull requests or a coding-agent skill.
来源原文
I played around with jev from typesafe a little today, and thought this is a pretty good application of it. is-malicious scans an entire codebase for hidden, deceptive, or data-stealing behavior, and points you directly at the suspicious parts of files if it finds any. It can also be used as a first line defense on pull requests on your own repos, or integrated into your coding agent via the skill.
原记录的限制
- The source post reports no false-positive or false-negative measurements.
- The author describes the tool as an application of Jev, not a security guarantee.