https://github.com/pwncollege/challenges
· scanned 2026-06-15 23:43 UTC (2 months, 4 weeks ago)
87 raw signals (0 security + 87 graph)
Last scanned 2 months, 4 weeks ago · v1 · 70 actionable findings from 1 signal source. 17 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
Showing 66 of 70 actionable findings. 87 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.claude/skills/authoring-challenges/SKILL.md:94
SecretsClaude instruction
challenges/advent-of-pwn/2025/day-08/challenge/workshop.py:79
securityAuth flask unauth route
challenges/advent-of-pwn/2025/day-06/challenge/north_poole.py:120
securityAuth flask unauth route
challenges/advent-of-pwn/2025/day-07/challenge/turkey.py:53
securityAuth flask unauth route
challenges/advent-of-pwn/2025/day-08/challenge/workshop.py:35
securityAuth flask unauth route
challenges/advent-of-pwn/2025/day-08/challenge/workshop.py:94
securityAuth flask unauth route
challenges/advent-of-pwn/2025/day-06/challenge/north_poole.py:193
securityAuth flask unauth route
challenges/advent-of-pwn/2025/day-08/challenge/workshop.py:52
securityAuth flask unauth route
challenges/linux-luminarium/paths/absolute-cwd-2/challenge/.env
ConfigEnv fileRuntime env
challenges/linux-luminarium/paths/absolute-cwd/challenge/.env
ConfigEnv fileRuntime env
challenges/linux-luminarium/paths/relative-dot-local/challenge/.env
ConfigEnv fileRuntime env
challenges/linux-luminarium/paths/relative-dot/challenge/.env
ConfigEnv fileRuntime env
challenges/linux-luminarium/paths/relative-naked/challenge/.env
ConfigEnv fileRuntime env
challenges/what-is-a-bug/apache-httpd-cve-2014-0117/challenge/Dockerfile:8challenges/what-is-a-bug/bash-cve-2014-7186/challenge/Dockerfile:19challenges/what-is-a-bug/libcue-cve-2023-43641/challenge/Dockerfile:3challenges/what-is-a-bug/libpng-cve-2017-12652/challenge/Dockerfile:3challenges/what-is-a-bug/libxml-cve-2023-28484/challenge/Dockerfile:3challenges/what-is-a-bug/mutt-cve-2023-4874/challenge/Dockerfile:3challenges/what-is-a-bug/readelf-cve-2021-20294/challenge/Dockerfile:3challenges/what-is-a-bug/sudo-cve-2021-3156/challenge/Dockerfile:2.github/workflows/check-maintainers.yml:17.github/workflows/publish-challenges.yml:47.github/workflows/sync-maintainers.yml:24.github/workflows/sync-maintainers.yml
CI/CD securitySupply chainGithub actions
.github/actions/determine-modified-challenges/action.yml:59
Node child process
challenges/advent-of-pwn/2025/day-07/challenge/duck.js:3
Node child process
challenges/advent-of-pwn/2025/day-07/challenge/turkey.py:115
Subprocess shell true
challenges/advent-of-pwn/2025/day-06/challenge/init-northpoole.sh
Ports
challenges/what-is-a-bug/apache-httpd-cve-2014-0117/challenge/Dockerfile:1
containersPinned dependencies
challenges/what-is-a-bug/bash-cve-2014-7186/challenge/Dockerfile:2challenges/what-is-a-bug/libcue-cve-2023-43641/challenge/Dockerfile:1challenges/what-is-a-bug/libpng-cve-2017-12652/challenge/Dockerfile:1challenges/what-is-a-bug/libxml-cve-2023-28484/challenge/Dockerfile:1challenges/what-is-a-bug/mutt-cve-2023-4874/challenge/Dockerfile:1challenges/what-is-a-bug/readelf-cve-2021-20294/challenge/Dockerfile:1challenges/what-is-a-bug/sudo-cve-2021-3156/challenge/Dockerfile:1.github/workflows/check-maintainers.yml:14.github/workflows/sync-maintainers.yml:21.github/workflows/test-challenges.yml:45challenges/computing-101/common/secret-value-checker.py:86
challenges/computing-101/common/secret-value-checker.py:184
challenges/what-is-a-bug/apache-httpd-cve-2014-0117/challenge/backend.py:4
challenges/advent-of-pwn/2025/day-08/challenge/workshop.py:22
tools/pwnshop/src/pwnshop/lib/__init__.py:63
tools/pwnshop/src/pwnshop/lib/__init__.py:28
This page is publicly accessible at:
https://repobility.com/scan/002aebb9-a68c-4723-8e30-c1e2f697d78e/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/002aebb9-a68c-4723-8e30-c1e2f697d78e/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.