https://github.com/JKHeadley/instar
· scanned 2026-05-15 20:53 UTC (2 weeks, 6 days ago)
· 10 languages
779 findings (209 legacy + 570 scanner) 4th percentile · Typescript · huge (>500K LoC) Scanner says 70 (higher by 2)
Last scanned 2 weeks, 6 days ago · v1 · 199 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
58.4 | 0.25 | 14.60 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
69.6 | 0.15 | 10.44 |
practices_score |
65.0 | 0.15 | 9.75 |
code_quality |
54.8 | 0.10 | 5.48 |
| Overall | 1.00 | 72.0 |
web: 1.6 ·
agent: 3.2 ·
authz: 39.8 ·
docker: 1.2 ·
threat: 10.3 ·
journey: 5.4
Showing 64 of 199 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/server/routes.ts:2403
authlegacy
src/server/routes.ts:3684
authlegacy
src/server/routes.ts:1817
authlegacy
src/server/routes.ts:2610
authlegacy
src/moltbridge/routes.ts:73
authlegacy
src/server/routes.ts:2474
authlegacy
src/server/routes.ts:2392
authlegacy
src/server/routes.ts:2157
authlegacy
src/server/routes.ts:4541
authlegacy
src/server/routes.ts:2486
authlegacy
src/server/routes.ts:2136
authlegacy
src/server/routes.ts:2260
authlegacy
src/server/routes.ts:2200
authlegacy
src/server/routes.ts:1091
authlegacy
src/server/routes.ts:2146
authlegacy
src/server/worktreeRoutes.ts:245
authlegacy
src/server/routes.ts:2211
authlegacy
src/server/routes.ts:2248
authlegacy
src/server/routes.ts:2225
authlegacy
src/server/worktreeRoutes.ts:108
authlegacy
src/server/routes.ts:2403
authlegacy
src/server/AgentServer.ts:207
authlegacy
src/server/machineRoutes.ts:150
authlegacy
src/server/routes.ts:2157
authlegacy
src/server/AgentServer.ts:223
authlegacy
src/server/routes.ts:2000
authlegacy
src/server/routes.ts:2006
authlegacy
src/moltbridge/routes.ts:178
authlegacy
src/server/routes.ts:1967
authlegacy
src/server/routes.ts:2011
authlegacy
playbook-scripts/playbook-failsafe.py:171
error_handlinglegacy
playbook-scripts/playbook-retirement.py:169
error_handlinglegacy
playbook-scripts/build-state.py:192
error_handlinglegacy
src/messaging/WhatsAppAdapter.ts:329
error_handlinglegacy
src/messaging/TelegramAdapter.ts:487
error_handlinglegacy
src/core/DispatchExecutor.ts:373
error_handlinglegacy
src/commands/jobMigrate.ts:110
deserializationlegacy
src/scheduler/AgentMdJobLoader.ts:715
deserializationlegacy
src/scheduler/InstallBuiltinJobs.ts:151
deserializationlegacy
skills/instar-session/SKILL.md:48
qualitylegacy
src/core/FeedbackManager.ts:69
qualitylegacy
src/core/DispatchManager.ts:135
qualitylegacy
dashboard/index.html:3325
authlegacy
dashboard/index.html:3305
authlegacy
Dockerfile.relay:26
dockerlegacy
src/monitoring/SessionWatchdog.ts:499
qualitylegacy
src/monitoring/CommitmentTracker.ts:837
qualitylegacy
src/core/reviewers/escalation-resolution.ts:86
qualitylegacy
src/core/SecretStore.ts:78
qualitylegacy
src/core/AutoUpdater.ts:437
qualitylegacy
playbook-scripts/playbook-offline-adapt.py:186
qualitylegacy
.instar/hooks/instar/claim-intercept.js:7
qualitylegacy
src/core/PostUpdateMigrator.ts:1604
qualitylegacy
src/cli.ts:214
logginglegacy
print-pii
· CWE-532
· A09:2021
src/cli.ts:97
logginglegacy
print-pii
· CWE-532
· A09:2021
src/cli.ts:57
logginglegacy
print-pii
· CWE-532
· A09:2021
src/cli.ts:55
logginglegacy
print-pii
· CWE-532
· A09:2021
src/cli.ts:52
logginglegacy
print-pii
· CWE-532
· A09:2021
.well-known/security.txt
qualitylegacy
.dockerignore
dockerlegacy
scripts/attachments-sync/main.go:206
error_handlinglegacy
CLAUDE.md
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/00f3e9b4-a692-4d73-b1d2-2e06abed64cd/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/00f3e9b4-a692-4d73-b1d2-2e06abed64cd/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.