perplexityai/bumblebee
Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software supply-chain compromises.
About the project
A Go tool that scans developer machines for supply-chain exposure by reading on-disk package, extension, and MCP config metadata and matching it against a catalog of known compromises.
Useful for
- Check developer machines for packages listed in a known supply-chain compromise
- Collect an NDJSON inventory of installed packages and extensions via cron or launchd
- Run the built-in selftest before rolling the scanner out across a fleet
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 4 stars today.
- Top new repositories in the last 4 months: #95.
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 5,007
- Stars in a day
- 4
- Forks
- 449
- Issues and pull requests
- 78
- Watchers
- 25
- Language
- Go
- License
- Apache-2.0
- Latest release
- v0.1.2 · June 18, 2026
- Created
- May 20, 2026
- Last push
- August 7, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- September 13, 2026Top new repositories in the last 4 months: #95
Similar projects
-
7.0
SnailSploit/Claude-Red
A curated library of drop-in SKILL.md files for the Claude Skills system that primes Claude with offensive security methodology, from SQL injection to EDR evasion and exploit development.
-
6.2
vxcontrol/pentagi
Autonomous multi-agent system in Go for automated penetration testing: AI agents plan and execute steps in an isolated Docker sandbox with 20+ tools (nmap, metasploit, sqlmap).
-
5.0
hezhanleiok/freesub
Automatically tests and publishes subscription pools of free proxy nodes (VLESS, VMess, Trojan, Shadowsocks, Hysteria2, TUIC, AnyTLS), filtering out dead and hijacked nodes via real HTTPS handshakes and TLS validation.
-
4.9
tsymbaluyk/maskgate
PII masking service that detects passports, tax IDs, SNILS, bank cards, phones, medical data and secrets in text and files and masks them before they reach ChatGPT, Claude, Gemini. Source code is proprietary; this repo…
-
4.3
zhihui-hu/one-ip
Web tool for IP lookups: identifies datacenter, VPN, Tor and proxy usage, rates reputation from 0 to 100, shows ASN, WHOIS, DNS, CDN, geolocation and checks AI service reachability.
-
4.2
realchendahuang/feedsieve
A Chrome extension that flags spam accounts on X (Twitter) with a yellow border and lets you block them manually or in bulk via the native API, synced across all devices.