Scan timing: clone 2.74s · analysis 7.06s · 10.1 MB · GitHub API rate-limit (preflight)
https://github.com/coleam00/Archon.git
· scanned 2026-05-29 03:46 UTC (1 week ago)
· 10 languages
552 findings (111 legacy + 441 scanner) 35th percentile · Typescript · large (100-500K LoC) Scanner says 49 (higher by 23)
Last scanned 1 week ago · v1 · 552 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
57.3 | 0.25 | 14.32 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
77.0 | 0.15 | 11.55 |
code_quality |
52.2 | 0.10 | 5.22 |
| Overall | 1.00 | 72.1 |
Showing 427 of 552 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
packages/paths/src/telemetry.ts:46
credential_exposurelegacy
packages/paths/src/telemetry.ts:46
secrets
packages/core/src/utils/port-allocation.ts:24
qualitylegacy
scripts/install.sh:122
qualitylegacy
packages/providers/src/claude/binary-resolver.ts:101
qualitylegacy
packages/web/src/experiments/console/components/RunGraphPanel.tsx:98
xsslegacy
packages/core/src/utils/credential-sanitizer.ts:18
qualitylegacy
packages/web/src/experiments/console/components/ProjectRail.tsx:21
qualitylegacy
packages/web/src/components/chat/MessageBubble.tsx:19
qualitylegacy
.archon/scripts/maintainer-standup-gh-data.ts:17
qualitylegacy
.github/workflows/release.yml:223
dependencylegacy
.github/workflows/release.yml:41
dependencylegacy
.github/workflows/marketplace-auto-review.yml:17
dependencylegacy
.github/workflows/e2e-smoke.yml:98
dependencylegacy
.github/workflows/e2e-smoke.yml:68
dependencylegacy
.github/workflows/e2e-smoke.yml:38
dependencylegacy
.github/workflows/e2e-smoke.yml:17
dependencylegacy
.github/workflows/marketplace-lint.yml:13
dependencylegacy
.github/workflows/release.yml:226
dependencylegacy
.github/workflows/e2e-smoke.yml:106
dependencylegacy
.github/workflows/e2e-smoke.yml:76
dependencylegacy
.github/workflows/release.yml:211
dependencylegacy
.github/workflows/e2e-smoke.yml:25
dependencylegacy
.github/workflows/release.yml:232
dependencylegacy
.github/workflows/release.yml:44
dependencylegacy
.github/workflows/marketplace-auto-review.yml:18
dependencylegacy
.github/workflows/e2e-smoke.yml:101
dependencylegacy
.github/workflows/e2e-smoke.yml:71
dependencylegacy
.github/workflows/e2e-smoke.yml:41
dependencylegacy
.github/workflows/e2e-smoke.yml:20
dependencylegacy
.github/workflows/marketplace-lint.yml:14
dependencylegacy
.github/workflows/release.yml:262
dependencylegacy
docker-compose.yml:68
dockerlegacy
deploy/Dockerfile.user.example:7
dependencylegacy
auth-service/Dockerfile:1
dependencylegacy
Dockerfile:54
dependencylegacy
Dockerfile:9
dependencylegacy
packages/server/src/index.ts:637
qualitylegacy
packages/server/src/index.ts:663
qualitylegacy
packages/server/src/index.ts:591
qualitylegacy
packages/server/src/index.ts:691
qualitylegacy
packages/web/src/components/layout/Header.tsx:32
securitylegacy
packages/providers/src/community/pi/provider.ts:230
qualitylegacy
packages/server/src/scripts/setup-auth.ts:4
qualitylegacy
packages/providers/src/community/pi/provider.ts:325
qualitylegacy
packages/providers/src/community/pi/session-resolver.ts:13
qualitylegacy
deploy/docker-compose.yml:13
dockerlegacy
Dockerfile:54
dockerlegacy
deploy/Dockerfile.user.example:8
dockerlegacy
Dockerfile:44
dockerlegacy
packages/web/src/experiments/console/components/DraftRunCard.tsx:48
qualitylegacy
packages/web/src/contexts/ProjectContext.tsx:41
qualitylegacy
packages/web/src/components/workflows/WorkflowBuilder.tsx:84
qualitylegacy
packages/web/src/components/layout/Sidebar.tsx:96
qualitylegacy
packages/docs-web/src/content/docs/guides/script-nodes.md:258
dependencylegacy
packages/docs-web/src/content/docs/index.mdx:33
dependencylegacy
packages/docs-web/src/content/docs/getting-started/ai-assistants.md:27
dependencylegacy
deploy/cloud-init.yml:62
dependencylegacy
README.md:113
dependencylegacy
.github/workflows/e2e-smoke.yml:47
dependencylegacy
.claude/skills/archon/references/troubleshooting.md:71
dependencylegacy
.github/workflows/e2e-smoke.yml:20
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-smoke.yml:25
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-smoke.yml:41
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-smoke.yml:71
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-smoke.yml:101
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:44
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:232
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:262
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:26
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:29
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:32
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:40
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:55
supply-chaingithub-actionspinned-dependencies
.github/workflows/marketplace-auto-review.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/deploy-docs.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/publish.yml
supply-chaingithub-actionsleast-privilege
packages/server/src/routes/api.ts:914
owaspcors_wildcard
.dockerignore
dockerlegacy
docker-compose.yml:118
dockerlegacy
docker-compose.yml:38
dockerlegacy
deploy/docker-compose.yml:13
dockerlegacy
docker-compose.yml:118
dockerlegacy
docker-compose.yml:38
dockerlegacy
deploy/docker-compose.yml:13
dockerlegacy
docker-compose.yml:68
dockerlegacy
Dockerfile:80
dockerlegacy
Dockerfile:67
dockerlegacy
packages/workflows/src/executor.ts:34
qualitylegacy
packages/providers/src/community/pi/event-bridge.ts:8
qualitylegacy
packages/providers/src/community/opencode/session.ts:81
qualitylegacy
packages/providers/src/codex/provider.ts:188
qualitylegacy
packages/adapters/src/forge/github/adapter.ts:151
qualitylegacy
packages/paths/src/archon-paths.ts:104
qualitylegacy
packages/web/src/routes/ChatPage.tsx:85
qualitylegacy
packages/web/src/routes/ChatPage.tsx:43
qualitylegacy
packages/web/src/lib/api.ts:68
qualitylegacy
Showing first 300 of 427. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/03f8e180-87b4-4749-b483-9718dabd5226/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/03f8e180-87b4-4749-b483-9718dabd5226/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.