Guide

Drill in — one keystroke deeper

Press Enter on any row and octoscope opens a rich detail view of that repo, pull request or issue — without losing your place in the list.

octoscope — Repos / repo detail
octoscope repository drill-in: description, languages, latest release, checks and a star-history sparkline
A repository drill-in: description, languages, latest release, the CI Checks breakdown and a 12-month star-history sparkline.

What you can reach

  • Repos → description, languages, release, a Checks section (c expands it past the first eight), and a 12-month star-history sparkline — v toggles it between density and a cumulative curve.
  • Pull requests → metadata, reviewers, timeline, and an inline diff viewer (f → files → Enter).
  • Issues → the full body rendered as markdown, labels and timeline.
octoscope — PRs / file diff
octoscope inline diff viewer showing a changed file with syntax highlighting
The inline diff viewer — syntax-highlighted, paginated per file, reached from a PR's changed-files list.

Reached from the action menu

Press space on a row for its action menu — open on github.com, copy the URL, view details, and (on a repo) run the integrity scan.

octoscope — action menu
octoscope action menu overlaid on a repository row

Supply-chain integrity scan

An on-demand, read-only check for the Shai-Hulud / Miasma class of self-replicating implant — the kind pushed to your own repos via a stolen token, that auto-executes the moment a repo is opened in an AI editor or npm install-ed.

It scores four filename-agnostic axes, explains the verdict with the evidence behind it, and now openly declares when its coverage was partial — because in a security tool a false negative is the expensive direction to be wrong in.

Verdicts run clean → watch → suspicious → likely compromised. When there's something to act on, y copies a remediation script and the report deep-links the right OAuth-grant revoke pages. It never mutates the repo.

octoscope — integrity scan
octoscope supply-chain integrity scan report with a verdict and scored findings
A scan report — verdict, risk score, the scored findings behind it, the auto-execution surface, and per-branch provenance.

The full detection model — the four axes, the weighting, and the honest gaps — is written up in the supply-chain scan design doc.