88OUT OF 100
Likely safeLikely safeStatic read

abi/screenshot-to-code

The repository is a well-documented, highly popular open-source project. Static analysis reveals no malicious behavior. The flagged network activity (Poetry installation) and configuration references are consistent with the project's documented setup requirements for a local development environment. No malicious behavior observed in our static read; full runtime behavior was not executed in a sandbox on this pass.

Repository size
11142 KB
Packages
0
Stars
78865
Created
18 yr ago
Reputation signals
abi avatar
Abi Raja
@abi
Account age18 yr
Public repos98
Forks9.6k
Community sentiment100

Very positive

Code & behavior signals
Provisioning fetch to recognized software-distribution host
LowBehavior

The script uses curl to fetch the Poetry installer from install.python-poetry.org, which is a standard and expected step for setting up the Python environment as documented in the project's setup instructions.

Internal configuration references
LowCode

Hardcoded IP references (127.0.0.1 and example documentation IPs) are used for local development configuration and environment variable defaults, consistent with a local FastAPI/Vite setup.

Per-package scoring
Final verdict

No malicious behavior in our static read. The caveats above are worth noting and the owner is not yet long-established. Runtime was not executed in a sandbox on this pass.

What we could not verify
—Full runtime behavior (this repo was not executed in a sandbox on this pass)
—Every conditional and time-triggered branch
—Behavior under real credentials (no sandbox was run on this pass)
End-to-end logs
Clone
›Repository cloned successfully
›Metadata verified
Static scan
›No obfuscation detected
›No credential access detected
›No embedded secrets found
Reputation
›Owner is highly established
›Repository has high community trust
Read
›README intent matches observed configuration patterns
›Network activity identified as standard build-time dependency management
Score
›Score computed by formula: 88/100 (deterministic, code-driven)
›-6 [code] network: Code has outbound network capability (fetch / child_process / hardcoded IP URL).
›-6 [code] model_findings: 2 code/behavior finding(s) reported by the read model.
›+8 [reputation] established_owner: Owner account is established (older than a year with multiple public repos).
›+6 [reputation] many_stars: Strong community signal (78,865 stars).
›+4 [reputation] good_sentiment: Positive community sentiment (100/100).
Auto-published at clauderabbit.in/abi/screenshot-to-code · re-checked when the repo changes