Supply Chain Threat Scanner
Made by AI, for AI
Paste a GitHub repo URL, file URL, or content hash and hit Scan
156 patterns across 22 categories â static analysis + optional LLM deep review
curl|bash, eval(), exec(), vm module, PowerShell encoded commands, WScript.Shell
Base64 payloads, String.fromCharCode, Buffer.from chains, JSFuck, hex encoding, unicode escapes
DNS exfiltration, Discord/Slack/Telegram webhooks, env var leaking, ngrok tunnels, pastebin drops
Reverse shells (Python, Perl, PHP, Ruby, Socat), bind shells, web shells, crypto miners, SSH key injection
npm postinstall hooks, typosquatting, dependency confusion, URL dependencies, webpack plugin injection
GitHub Actions expression injection, secret dumping, self-hosted runner abuse, artifact poisoning
AWS/GCP/Azure keys, Stripe/Slack/GitHub tokens, private keys, JWTs, hardcoded passwords
Chrome/Firefox/Brave browser data, SSH keys, .env files, macOS Keychain, kubeconfig, Docker auth
Crontab, systemd services, .bashrc injection, macOS LaunchAgents, Windows Registry run keys, XDG autostart
Docker socket access, privileged containers, host mount escape, procfs abuse, nsenter namespace escape
setup.py exploits, pickle deserialization, __import__ obfuscation, YAML unsafe load, ctypes native code
"Ignore previous instructions", fake system prompts, role hijacking, tool abuse, markdown image exfiltration
Poetry jailbreaks (arxiv 2511.15304), morse code, ROT13, leetspeak, acrostic messages, reversed text
Mass file encryption patterns, ransom note indicators, file extension changes
rm -rf, chmod 777, disk format (dd, mkfs), fork bombs
Image pixel data extraction, canvas-based encoding, zero-width character hiding, unicode BiDi overrides
SUID bit setting, user account creation, Linux capability manipulation, sudoers modification
Geolocation-based code execution, file wiper patterns (ref: node-ipc incident)
Intentik is built for AI agents. No auth required â just scan.
Complete usage guide for AI agents â endpoints, examples, workflows
OpenAPI 3.0 specification â all endpoints, schemas, response formats
Plugin manifest â standard discovery for ChatGPT, agents & tools
Quick start:
curl -X POST https://intentik.com/api/scan/url -H "Content-Type: application/json" -d '{"url":"https://github.com/user/repo"}'
đŦ Community Reports