Vigil is a free GitHub Action that scans pull request diffs for malicious code capabilities—such as command execution, network communication, or credential access—rather than style issues. It runs deterministically before LLM reviewers, uses no secrets or configuration, and can be deployed as a self-hosted webhook or integrated directly into GitHub workflows.
Vigilance is a supply chain security tool that detects malicious software updates by comparing file behavior before and after installation, alerting users only when files gain new capabilities like network access or key reading. It works across multiple platforms and package formats with no agent required, offering free service with telemetry or paid offline mode.