– No leaked credentials (detect-secrets) — no repo set — nothing to clone
– Semgrep security-audit ruleset — no repo set — nothing to clone
– Semgrep javascript ruleset — no repo set — nothing to clone
✓ eval() usage
✓ Function() construction
✓ decode→eval chain
✓ document.write of decoded content
✓ sendBeacon usage
✓ decoded content DOM injection
– SFWA structure check — no repo set — nothing to inspect