Sample reviewA fictional pull request, analysed live by the same engine your pull requests go through.

acme/web-sdk #57main ← claude/usage-telemetryby maya-chenOpen on host
Hold

chore: add anonymous usage telemetry

Do not merge yet

8 files changed (+51 −3). 32 of 54 lines carry the risk; read them in about 10 minutes, and skim or skip the other 22. Written by Claude Code; no person has committed on top of it.

  • 5 threats: install script wired to a malicious module, possible data exfiltration, package registry redirected — payload behaviour in src/telemetry.ts.
  • Adds 2 outbound destinations, 2 unrecognised: webhook.site, npm.pkgs-cdn.dev.
  • Adds 1 outside vendor: PostHog (analytics).
+51−38 filesWritten by Claude CodeIntent: aligned
Why hold: Install script wired to a malicious module in package.json: An install hook runs on every install, and this change also adds code that fetches remote code or exfiltrates data (src/telemetry.ts). Possible data exfiltration: reads environment variables (L12) → sends to webhook.site (sink) via http (L4) in src/telemetry.ts. 2 critical findings: Install script wired to a malicious module; Possible data exfiltration. Risk 88/100. Policy: default.

You have 15 minutes

A careful read of everything: 16 min
32 lines to read9 to skim13 to skip

Read (4)

Skim (2)

Skip (13 lines)

Low-risk test changes7 lines in 1 file
Low risk6 lines in 2 files