[English](https://unpkg.com/scriptspect@0.1.2/README.md) | [简体中文](https://unpkg.com/scriptspect@0.1.2/README.zh-CN.md)

<p align="center"><img src="https://raw.githubusercontent.com/Tom409114/scriptspect/6f439bb974b297d5a334cebe989b4b50d7483677/docs/assets/brand/hero.svg" width="100%" alt="ScriptSpect finds cross-shell portability problems before package scripts run"></p>

> **Package edition:** `scriptspect@0.1.2` · source `6f439bb974b297d5a334cebe989b4b50d7483677`

ScriptSpect statically checks `package.json` scripts without running them. It pinpoints constructs that change meaning across POSIX shell, Windows cmd, and optional PowerShell targets.

## Run in 30 seconds

Requires Node.js 22 or newer. Run this exact version without a global install:

```bash
npx --yes scriptspect@0.1.2 .
pnpm dlx scriptspect@0.1.2 .
```

Findings exit `1`; a clean scan exits `0`; invalid input, configuration, or I/O exits `2`. Start with `--fix-dry-run` before applying a reviewed fix.

## Before, result, and after

```json
{"scripts":{"build":"NODE_ENV=production vite build","clean":"rm -rf dist"}}
```

![Real ScriptSpect output generated from the versioned demo fixture](https://raw.githubusercontent.com/Tom409114/scriptspect/6f439bb974b297d5a334cebe989b4b50d7483677/docs/assets/demo/terminal.svg)

```diff
-"build": "NODE_ENV=production vite build"
-"clean": "rm -rf dist"
+"build": "cross-env NODE_ENV=production vite build"
+"clean": "rimraf dist"
```

The demo uses dependencies already declared by the fixture. Ambiguous changes remain manual; ScriptSpect never installs dependencies or rewrites a lockfile.

## GitHub Actions

```yaml
- uses: Tom409114/scriptspect@v0.1.2
  with:
    path: .
```

For the strongest supply-chain pin, replace `v0.1.2` with `6f439bb974b297d5a334cebe989b4b50d7483677`.

[Rules](https://github.com/Tom409114/scriptspect/tree/6f439bb974b297d5a334cebe989b4b50d7483677/docs/rules) · [Config schema](https://github.com/Tom409114/scriptspect/blob/6f439bb974b297d5a334cebe989b4b50d7483677/schema/config.schema.json) · [Report a vulnerability](https://github.com/Tom409114/scriptspect/security/advisories/new) · [Source](https://github.com/Tom409114/scriptspect/tree/6f439bb974b297d5a334cebe989b4b50d7483677)
