Code review summary via Grok AI I pulled the full content and inspected the JavaScript: No external network calls to third-party domains (no http://, https://, WebSockets, etc. outside the expected path). The only fetch is to the same-origin ordinals recursion endpoint /r/blockheight (standard for recursive inscriptions on explorers like ordinals.com). This is used to read the current Bitcoin block height for in-game bonuses. No eval(), new Function(), dynamic code execution, or similar. innerHTML is used only to render cards from the game’s own internally generated deck data (not from untrusted user input). No cookie theft, localStorage/sessionStorage abuse for exfiltration, redirects, or other common malicious patterns. Everything runs client-side in the browser when you view the inscription; it is a pure front-end game.