- Does PreClone run any of the repo's code?
- No. It downloads the archive that GitHub, GitLab or Bitbucket serve for a commit, reads the files in memory and throws them away. Nothing is cloned, installed, built or executed, on our servers or on yours. Zip uploads are read inside your browser tab.
- So “Nothing flagged” means the repo is safe?
- No, and PreClone never says that. It means nothing risky is set to run on its own when you open the folder, install it or start an AI agent in it, and no known malware patterns turned up. Routine tooling like Husky may still run, and the report lists it. Code that downloads more code later, compiled binaries and encrypted payloads can still hide from any static read. If you don't trust the sender, use a throwaway VM or Codespace anyway.
- They pushed a fix and asked me to pull again. Should I check again?
- Yes. Lures often arrive clean and get their payload in a later push, with a message saying a bug was fixed. Paste the same link again. If the commit has changed, the report opens with what's newly set to run and any new findings since the last check, and links to the earlier report.
- What do you keep?
- For a link you check, we keep the report (findings, file paths, the flagged lines) so the share link works. We don't keep the code. Zips never leave your browser; only package names and versions go to our server so they can be looked up on npm and OSV.
- Can it check private repositories?
- Yes, on Pro. You paste a read-only token with the URL; it's used for that one download and never stored or logged. The report is private to your account.
- Isn't this what Workspace Trust is for?
- Workspace Trust is one yes/no prompt at the moment you open a folder, with no detail about what will run. Most people click Trust, and Cursor ships with it off. PreClone tells you what you'd be trusting, before the code is on your disk.
- What about false positives?
- Each engine release is checked against 57 well-known repos, including Express, Next.js, React, VS Code, Prisma and pytest. The current engine rates 28 of them clear and 27 “Worth a look”, mostly for install scripts or AI-agent settings you'd want to know about. Two are too big for the web check, and none is rated higher. A sweep of 213 more popular repos turned up false positives, which were fixed, and two real “Read first” cases: dev containers that mount your SSH keys or run with full access to the host. On a saved report, every finding has a “Wrong? Tell us” link, and the report is stored with the rule and the commit it was about, so the rule can be fixed.
- Does it replace Socket or npm audit?
- No. Those watch your dependencies over time. PreClone answers a narrower question once: what will this particular repo do to my machine if I open it? It does look dependencies up on npm and OSV for known malware, as one part of that answer.
- Aren't there other repo scanners?
- A few. Most are scripts you run after cloning, which is too late for a task that runs when the folder opens. GuardDog, Datadog's free open-source scanner, is a good one for packages: it looks for malicious code patterns in npm, PyPI and other packages, including a folder you've downloaded. Its docs don't mention editor tasks or AI-agent settings, so the two work well together. There are hosted checkers too, such as ScanRepo and DoubleCheck. Going by what their sites list, they give a verdict but don't sort findings by when each thing would run or read AI-agent settings, and DoubleCheck charges $3.99 for the full report. PreClone's whole report is free.
- How do I use it without the website?
- The CLI runs the same engine on your machine for links, folders and zips; the browser extension adds a button next to GitHub's Code button; and you can put preclone.dev/ in front of any GitHub link. Setup for each is on the docs page.