Protect yourself. Before opening an unfamiliar project:
- Don't blindly run npm install, git status, scripts, or other commands.
- Be extremely careful with .git, .github, .husky, .claude, and Git hooks.
- Don't open suspicious repositories directly in your normal development environment or AI coding agent.
- Verify who sent the project and why they need you to download it.
- If something feels suspicious, inspect the archive without extracting/executing it.