Skip to content
PreClone

Example report: an inert, made-up repo

A normal library: Husky and a build step, nothing hidden

The project: For comparison: an ordinary library where only well-known tooling runs.

tiny-slugify

Source
Inert example of an ordinary project
Files
6

Nothing flagged

Only routine setup runs on its own.

On its own, this runs husky when you install dependencies. Nothing else is set to run on open, install or agent start, and no malware patterns turned up. The app's own code still runs when you start it.

  • A static check can't prove code is harmless. It shows you where code would run, not everything it does.
  • For code from people you don't know, a VM or a Codespace is still the safest place to run it.

Everything that runs

Every entry point PreClone found, including the ordinary ones, so you can see the whole picture and not just the alarms.

6 routine entries, nothing flagged in them
  • Installnpm install (and git installs)
    huskypackage.json:10"prepare" in package.json
    AutomaticExpected
  • Runnpm test
    vitest runpackage.json:8
    Expected
  • Runnpm run build
    tscpackage.json:7
    Expected
  • Runnpm run lint
    eslint .package.json:9
    Expected
  • RunDev server, build, lint or editor extensions
    Loads eslint.config.js as codeeslint.config.js
    Expected
  • Commitgit commit
    npm test.husky/pre-commitHusky (installed by npm install)
    Expected

Dependencies

4 direct dependencies. Checked against npm (packages it removed as malware, install scripts, downloads) and OSV malware advisories on Oct 11, 2026, when this example was captured. None matched a malware advisory or looked like a typo of a popular package.

Show the list
  • eslint^9.27.0dev
  • husky^9.1.7dev
  • typescript^5.8.3dev
  • vitest^3.1.4dev

What this report can't tell you

  • PreClone reads files; it never runs them. Code that is downloaded later from somewhere else, compiled binaries and encrypted payloads can hide from a static read.
  • “Nothing flagged” means nothing risky is set to run on its own, not that the code is trustworthy. When in doubt, open strangers' repos in a throwaway VM or Codespace.

Engine 1.4.2. 5 of the 6 files read as text.