GitHub AI Code Inspector

GitHub AI Code Inspector

ID: eehioomghiofdfagcddlikaighpkimef

Supported Languages

🇺🇸English

Extension Info & Metadata

Status
Active
Version
0.3.0
Size
0.10 MB
Rating
5.0/5
Reviews
1
Users
20
Type
Extension
Updated
May 7, 2026
Category
Developer tools
Price
Free
Featured
No
Visibility
Listed
Mature
No
By Google
No
Trusted
No

Publisher Contextual Analysis

Author
catalayer.comView Profile
MX records exist
Yes
Domain exists
Yes
Is disposable
No
Is role-based
No
Mailbox exists
Yes
Total Extensions
2
Active
2
Obsolete
0
Listed
2
Unlisted
0
Total Users
26
Screenshot 1
Screenshot 2
Screenshot 3
Screenshot 4

Chrome side panel for inspecting AI-generated GitHub repos, PRs, and files. Workflow, Unicode, command, package, MCP risk.

GitHub AI Code Inspector is a Chrome side panel extension for inspecting AI-generated GitHub repositories, pull requests, package files, workflow files, and agent/MCP configs directly inside GitHub. It helps developers, maintainers, and AI-assisted builders quickly review public GitHub repositories before cloning, running, merging, or trusting them. GitHub AI Code Inspector is rule-based and runs inspection logic locally in your browser. No external AI API is required. Key features: • Native GitHub page detection Automatically detects whether you are viewing a repository, pull request, PR files page, single file, package.json, lockfile, GitHub Actions workflow, MCP config, or agent config. • One-click repository inspection Review public repositories for README accuracy, runability, security signals, implementation quality, maintenance signals, and overall trust score. • One-click pull request inspection Scan pull requests directly from GitHub pages when available. If the full PR diff cannot be read from the page, the extension provides a manual paste fallback. • File-level inspection Inspect individual GitHub files directly from the side panel, including package.json, workflow files, lockfiles, MCP configs, agent configs, and general source files. • Package and dependency risk checks Review package scripts and dependency-related signals such as postinstall, preinstall, install, prepare scripts, suspicious lifecycle behavior, and risky shell execution patterns. • GitHub Actions workflow risk checks Detect risky GitHub Actions patterns, including pull_request_target usage, broad permissions, secrets usage, unpinned actions, suspicious shell commands, and potentially dangerous CI behavior. • MCP and agent config checks Review MCP server configs, Claude/Cursor/Cline-style agent files, and tool descriptions for risky command access, suspicious endpoints, prompt-injection-like text, and overly permissive behavior. • Hidden Unicode detection Detect invisible or suspicious Unicode characters that may hide misleading code behavior. • Secrets-like pattern detection Flag common token and credential-like patterns such as API keys, private keys, GitHub tokens, cloud keys, Slack tokens, and password-shaped strings. • Suspicious command detection Flag risky command patterns such as eval-like behavior, curl | bash, wget | sh, PowerShell IEX, shell download execution, and other potentially dangerous code execution patterns. • AI-code signal detection Identify common AI-generated code signals, incomplete implementation patterns, placeholder-heavy code, and mismatches between documentation and actual source files. • Safe Signals Highlight positive engineering signals when detected, such as no obvious secrets, no hidden Unicode, lockfile presence, security files, or safer workflow patterns. • Copyable Markdown reports Copy a clean Markdown inspection report for PR review, documentation, or collaboration. Privacy and security: GitHub AI Code Inspector runs inspection logic locally in your browser. No external AI API is required. Pasted diffs are analyzed locally. Repository code is not sent to third-party AI services. No GitHub OAuth is required. The extension does not request repo write permissions and does not automatically comment on pull requests. For public GitHub pages, the extension can work without a GitHub token. An optional GitHub token may be added only to improve GitHub API access or rate limits where supported. If provided, the token is stored in Chrome storage and used only for requests to GitHub API endpoints. Important limitations: GitHub AI Code Inspector is a developer assistance tool. It does not replace manual code review, security review, dependency auditing, or professional security assessment. It provides heuristic risk signals and recommendations, but it cannot guarantee that every issue or vulnerability will be detected. Some repository scans may be partial depending on what GitHub page data is visible or accessible. Best used for: • Reviewing AI-generated GitHub projects • Checking repositories before cloning or running them • Inspecting pull requests before merge • Reviewing package.json and dependency scripts • Checking GitHub Actions workflows • Reviewing MCP and agent configuration files • Finding README and implementation mismatches • Spotting risky package scripts or workflow changes • Creating lightweight Markdown audit reports Built by Catalayer.

Item
Type
Severity
Description
Contextual Risk Factors
Risk Factor
High
The following context increases the overall risk: • 19% increase: Access to sensitive domains increases potential impact
storage
Permission
Medium
This permission allows storing data locally in the browser. Rated Medium because it can persist sensitive user data, track user activities over time, and potentially store malicious payloads.
activeTab
Permission
Medium
This permission grants temporary access to the current tab. Rated Medium because it can access current page content when invoked, though limited to user-initiated actions.
tabs
Permission
Medium
This permission enables tab management and monitoring. Rated Medium because it can track open tabs, access tab metadata, and monitor user browsing patterns.
https://api.github.com/*
Host
Medium
Host permission — access limited to this URL pattern.
https://raw.githubusercontent.com/*
Host
Medium
Host permission — access limited to this URL pattern.
Access to Sensitive Domains
Risk Factor
Medium
This extension requests access to sensitive domains: https://api.github.com/*, https://raw.githubusercontent.com/*
sidePanel
Permission
Low
This permission adds custom panels to the browser interface. Rated Low because it only affects browser UI elements and cannot access page content.
contextMenus
Permission
Low
This permission adds items to browser context menus. Rated Medium because it only modifies right-click menus without access to page content.
URLs
0
IPv4
0
IPv6
0

URLs

View the external URLs this extension communicates with to understand its network activity and data interactions.

Gain full insight into all external connections.

Upgrade for full visibility.

No URLs found

Gain full insight into all external connections.

Upgrade for full visibility.

No IP addresses found
Version
Size
Is Malicious
Findings
Permhash
0.3.0
Latest
0.10 MB
Benign
—
Showing 1 to 1 of 10 rows
Rows per page:

Browse and explore files within this extension package

Gain full insight into all external connections.

Upgrade for full visibility.