Audit JS/TS project code for signs of infection, malware, backdoors, or supply-chain attacks. Use when evaluating untrusted code, onboarding to a new project, or vetting open-source dependencies.