https://github.com/1jehuang/jcode.git
· scanned 2026-05-16 12:49 UTC (1 day, 8 hours ago)
· 10 languages
102 findings (14 legacy + 88 scanner) 2/10 scanners ran 40th percentile · Rust · large (100-500K LoC) Scanner says 85 (lower by 15)
Last scanned 1 week ago · v4 · 100 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
80.4 | 0.25 | 20.10 |
testing_score |
36.0 | 0.20 | 7.20 |
documentation_score |
86.0 | 0.15 | 12.90 |
practices_score |
65.0 | 0.15 | 9.75 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 69.7 |
threat: 19.6
Showing 91 of 100 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
crates/jcode-desktop/src/session_launch.rs:1391
secrets
crates/jcode-desktop/src/session_launch.rs:1397
secrets
crates/jcode-protocol/src/lib.rs:1185
secrets
scripts/jcode_harbor_agent.py:216
llm_injectionlegacy
src/auth/copilot.rs:209
credential_exposurelegacy
scripts/compare_token_usage.py:311
credential_exposurelegacy
scripts/oauth_helper.py:52
credential_exposurelegacy
src/cli/login.rs:43
ssrflegacy
ios/Sources/JCodeMobile/QRScannerView.swift:95
ssrflegacy
scripts/oauth_helper.py:39
ssrflegacy
scripts/bench_memory_cli.py:421
error_handlinglegacy
scripts/benchmark_takehome.py:189
error_handlinglegacy
scripts/jcode_monitor.py:104
error_handlinglegacy
scripts/jcode_harbor_agent.py:216
llm_injectionlegacy
scripts/analyze_runtime_memory_log.py:281
dead-code
scripts/analyze_runtime_memory_log.py:246
dead-code
scripts/jcode_harbor_agent.py:202
dead-code
This page is publicly accessible at:
https://repobility.com/scan/02c0aa3c-2fdb-4a26-b86f-531b60354fee/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/02c0aa3c-2fdb-4a26-b86f-531b60354fee/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.