Detect Project Malware
Detects obfuscated or malicious code injected across a project — in build/tooling
configs, application source, helper scripts, install hooks, and CI files. Built
after a real incident in this workspace where a contributor injected an
infostealer payload into postcss.config.js, got it reverted, and re-injected
it weeks later behind an unrelated feature commit.
When to run
Run this skill when any of the following happen:
npm run devornpm run buildhangs fo
[Description truncada. Veja o README completo no GitHub.]