
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
cover-my-repo
Advanced tools
Generate three distinct GitHub social preview cards with Codex or Cursor.
Give your GitHub repo a social preview worth clicking.

npx cover-my-repo owner/repo
Pass any public GitHub repository. The CLI detects an authenticated Codex or Cursor CLI, creates three design options, renders them with your local Chrome, and opens a comparison preview.
To use the repository in your current directory instead, run this inside it.
npx cover-my-repo
It uses no image model and sends no repository credentials.
Node.js 20 and Chrome are required. Upload stays manual under Settings → Social preview, so nothing changes on GitHub without you.


The CLI leaves the final GitHub upload to you.
The design agent never receives README, issue, or raw manifest text. The parent process supplies fixed placeholders and text lengths, then inserts the HTML-escaped repository name and description after generation.
The CLI resolves Codex, Cursor, Git, Chrome, and the system opener outside the target repository. Codex runs read-only with shell and file tools disabled. Cursor runs in Ask mode inside an empty temporary workspace. Both return a bounded JSON object instead of writing files. The parent process accepts only the bundled Google Fonts stylesheet and inline PNG data, adds a restrictive content security policy, and checks every card before Chrome renders it.
Every example is a live page in the gallery. Click through to view its source.
| editorial. Warm paper, a Fraunces wordmark, and restrained corner arcs | ![]() |
| poster. A deep field mixed from the language color and a cropped initial | ![]() |
| blueprint. Navy grid, mono type, corner ticks, and a derived plate number | ![]() |
| gallery. A museum wall label with centered, light serif type | ![]() |
| terminal. The repo as a terminal session with window chrome and EXIT 0 | ![]() |
The accent comes from the primary language. Layout details are seeded by the repository name, so the options keep a shared system without becoming clones.
The original repo-cover skill remains available for compatible agents. Its
internal name stays unchanged.
# Agent Skills CLI
npx skills add sjh9714/cover-my-repo
# Claude Code plugin marketplace
/plugin marketplace add sjh9714/cover-my-repo
/plugin install repo-cover@repo-cover
# Codex
codex plugin marketplace add sjh9714/cover-my-repo
codex plugin add repo-cover@repo-cover
# Pi
pi install https://github.com/sjh9714/cover-my-repo
# fx
/skills install sjh9714/cover-my-repo --skill repo-cover
Then ask your agent to make a social preview card for the repository.
skills/repo-cover/scripts/check_card.py checks canvas size,
self-containment, contrast, CJK line breaking, and downscale legibility.

Korean uses word-break:keep-all and Noto Sans KR. Japanese and Chinese use
Noto Sans JP and Noto Sans SC with their own line-breaking rules.
The bundled Action can render an existing HTML card again in CI.
- uses: sjh9714/cover-my-repo@main
with:
card: assets/my-repo-cover.html
output: cover.png
MIT
FAQs
Generate three distinct GitHub social preview cards with Codex or Cursor.
We found that cover-my-repo demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.