I watched a video recently on malicious code injection into OSS repo PRs and how they can go undetected because of how well they're hidden and decided to do a project for this. This tool is essentially used in unison with ai code review bots like greptile.
Source: [Hacker News](https://github.com/marketplace/actions/vigil-pr-scanner)