
Security News
Happy Birthday, Shai-Hulud
It has been one year since Shai-Hulud made its first appearance on npm.
anti-default
Advanced tools
Inclusive language review for AI-generated and human copy — CLI fix, MCP tools, GitHub Action, and browser extension
Anti-Default reviews copy, docs, UI strings, and live pages for colonial defaults, gendered assumptions, ableist metaphors, and documented dogwhistles. It explains what it noticed and offers clearer alternatives.
No account. No AI required for matching. Open rules you can tune.
Try the web app · Add the Chrome extension · Star on GitHub
npx anti-default .
That is the whole local setup. It prints findings and exits non-zero on clear hits. Ambiguous or quoted matches stay advisory.
To pin it in a team project:
npm install --save-dev anti-default
Want the complete project setup?
npx anti-default init
init adds an ignore file, changed-files GitHub workflow, Cursor skill + MCP
config, and inclusive-check / inclusive-fix scripts. Existing files are
never overwritten.
npx anti-default fix . # safe 1:1 autofixes only
npx anti-default . # remaining findings
Agents should not mark UI/docs work done until hard findings are cleared or explicitly marked fine in context. Soft/coded hits stay advisory.
# Preview autofixes without writing
npx anti-default fix . --dry-run
# Intentional language — suppress locally + share structured feedback
npx anti-default feedback --kind fine_in_context \
--rule guys-generic --match "guys" --context "…snippet…" \
--note "Quoted lyric" --open-issue
npx anti-default mcp
Tools: anti_default_scan · anti_default_fix · anti_default_feedback
init writes .cursor/mcp.json when missing.
# Paths
npx anti-default ./src ./docs README.md
# CI formats
npx anti-default . --format json -o report.json
npx anti-default . --format sarif -o results.sarif
# Batch URLs — no Review UI
npx anti-default --urls https://example.com https://example.com/about
npx anti-default --urls-file urls.txt --format json
# Only files changed in this branch
npx anti-default . --changed-from origin/main
# Keep existing findings quiet; report only new ones
npx anti-default baseline .
Commit a .antidefaultignore so day-two noise doesn’t drown the team (example):
node_modules/
vendor/
*.min.js
rule:guys # turn off one rule for this repo
Keep inclusive language in the PR loop. This scans only changed files, fails on clear new findings, and leaves a checklist comment:
# .github/workflows/anti-default.yml
name: Anti-Default
on: [pull_request]
permissions:
contents: read
pull-requests: write
security-events: write
jobs:
scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- uses: NomadBuilder/anti-default@v1
with:
changed-from: ${{ github.event.pull_request.base.sha }}
format: json
comment-on-pr: "true"
Prefer SARIF for Code Scanning? Set format: sarif and output-file: anti-default.sarif. Full inputs: action.yml.
npx anti-default init installs .cursor/skills/anti-default/SKILL.md — the
definition-of-done workflow for AI-generated copy: fix → scan → ask or
feedback → re-scan.
Source: skills/anti-default/SKILL.md ·
feedback model: feedback/README.md
The npm package has no runtime dependencies and exposes the same analyzer used by the CLI and web app:
import { analyzeText, LANGUAGE_RULES } from "anti-default";
const result = analyzeText("Welcome, you guys.");
console.log(result.findings);
Same rules as the app — on the page you’re already looking at.
Runs offline from a bundled rule list. No tracking. No AI calls.
Dev / unpacked: npm run extension:pack → Load unpacked → extension/ · details in extension/README.md
npm install && npm run dev # localhost:3000
Every suggestion cites the style guides and references behind it → /sources
src/lib/rules.tsnpm run corpusnpm run build → out/STATIC_EXPORT=true BASE_PATH=/anti-default npm run buildProduction lives at darkai.ca/anti-default and is also vendored in DarkAI.
FAQs
Un-Default — catch racist, sexist & ableist defaults in AI and human copy (CLI, MCP, GitHub Action, extension). npm name is anti-default because un-default is blocked by an unrelated package.
The npm package anti-default receives a total of 17 weekly downloads. As such, anti-default popularity was classified as not popular.
We found that anti-default demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.