Maine Street Partners

[ MSP.SCAN ] Free AI code scan

What did the AI leave in the code?

Paste a public GitHub repository. In under a minute you see how much recent work carries AI-tool markers, which model providers the product depends on, and the known vulnerabilities in its dependencies.

[ MSP.SCAN.01 ] What it checks

Four signals, from public data only.

AI-marked commits

The last 100 commits on the default branch, checked for the markers AI coding tools leave: co-author trailers such as Claude Code's, agent accounts such as GitHub Copilot's and Devin's, and message conventions such as Aider's prefix. Most AI-assisted code carries no marker, so the share is a minimum.

Model dependencies

The dependency files (package.json, requirements and pyproject) checked for model provider SDKs such as OpenAI, Anthropic, Google and Mistral, frameworks such as LangChain and the Vercel AI SDK, and libraries for running models in-house.

Dependency vulnerabilities

Every package and version matched against OSV.dev, Google's open vulnerability database. Exact versions come from lock files where they exist; otherwise from the lowest version a range allows, which can over-report.

Hygiene and key-person risk

Committed environment and key files (by name only), test files, a build pipeline, and how concentrated authorship is in the commit sample.

Why it matters: in Veracode's 2025 tests, AI models introduced security flaws in 45% of 80 coding tasks, and Black Duck found vulnerable open source in 86% of 965 commercial codebases. More on AI-generated code risk.

[ MSP.SCAN.02 ] Questions

Before you scan.

Can you detect AI-generated code in a repository?
Partly. Several AI coding tools sign their commits with co-author trailers, agent accounts or message conventions, and those can be counted. Most AI-assisted code carries no marker, so a count from the commit history is a minimum, not a total.
Does the scan read private repositories?
No. It reads public GitHub data only, through GitHub's public API, and stores results for 15 minutes to avoid repeat requests. For a private repository, AI due diligence works with read-only access under NDA.
Is the scan a due diligence?
No. It shows signals worth asking about. A due diligence adds the full git history, secrets scanning, licences, model costs per customer, the EU AI Act position and interviews, with a verdict per area.
  1. Veracode, 2025 GenAI Code Security Report (press release, 30 July 2025)
  2. Black Duck, 2025 Open Source Security and Risk Analysis (press release)
  3. OSV.dev, querybatch API
  4. CHAOSS AI detection action