HookGuard – scanner for malicious Claude.md and agent config files
Catches invisible Unicode tricks and RCE hooks in CLAUDE.md files.

Client-side scanner catches Unicode steganography linters miss.
Security engineers, open source maintainers
Snyk · SonarQube
Vibe Check is a browser-based scanner that detects these characters across 14 invisible Unicode ranges (zero-width spaces, variation selectors supplement, tag characters, bidi overrides, etc.) and flags sequences of 3+ consecutive invisible characters as likely payloads. Entirely client-side JS — no code leaves your browser.
Not a full SAST tool. Solves one specific problem: detecting characters that are invisible in every editor and terminal but can encode payloads decoded via eval() at runtime.
Scanner logic is in scanner.js, viewable in browser. Site runs on Cloudflare Pages free tier.
Catches invisible Unicode tricks and RCE hooks in CLAUDE.md files.
Client-side Unicode scanner for stego artifacts, honestly admits token AI watermarks are undetectable.
Axe-core wrapper with AI fix suggestions when WAVE and Lighthouse already exist.
No-login security scans emailed to you beats forcing signup for quick checks.
Unicode tag character steganography is clever, but novelty exceeds utility and threat model.
Detects AI design slop with CSS checks, not LLM vision.