Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

yemfan/helmsmart

https://github.com/yemfan/helmsmart · scanned 2026-06-16 01:06 UTC (2 months, 1 week ago)

822 raw signals (210 security + 612 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 2 months, 1 week ago · v1 · 610 actionable findings from 2 signal sources. 288 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: severity: high × excluding tests × Reset all
Corpus Intelligence Cross-corpus context (cohort percentile, top patterns, fix plan) is shown only on repositories you own. Sign up and connect your repo to view it.
Scan summary Repository scanned at 62.8/100 with 100.0% coverage. It contains 18918 nodes across 30 cross-layer flows, written primarily in mixed languages. Engine surfaced 612 findings — concentrated in quality (282), frontend (270), security (44). Risk profile is high: 2 critical, 3 high, 183 medium. Recommended next step: open the quality layer findings first — that's where the highest-impact wins live.

Showing 6 of 610 actionable findings. 898 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

high Security checks quality Practices conf 0.84 6 occurrences Foundry mined bad chains: yemfan/helmsmart
Comment chain pattern product: bad_chains Repo: yemfan/helmsmart Thread: yemfan/helmsmart#609 Outcome: claimed_resolved_with_failing_ci_signal Thread label: thread_has_human_issue_and_fix_context Source graph label: source_backed_multi_signal_graph Reasons: source_graph_has_real_artifacts, source_g…
6 occurrences
repo-level (6 hits)
high Security checks quality Quality conf 0.76 22 occurrences Foundry mined schema ui api mismatch: yemfan/helmsmart
Graph query export: Schema, UI, and API mismatch Query id: schema_ui_api_mismatch Query type: motif_query Intent: Assumption-check examples for data-path consistency across layers. Motif: schema_ui_api_mismatch Training usage: assumption_check Graph gold label: supported_by_verification_signal Repo…
22 occurrences
repo-level (22 hits)
high Security checks quality Testing conf 0.78 2 occurrences Foundry mined test ci gap after feedback: yemfan/helmsmart
Graph query export: Feedback exposes missing tests or CI Query id: test_ci_gap_after_feedback Query type: motif_query Intent: Hard negatives for feedback/fix chains without adequate guardrails. Motif: test_ci_gap_after_feedback Training usage: hard_negative Graph gold label: supported_by_verificati…
2 occurrences
repo-level (2 hits)
high System graph security security conf 1.00 Insecure pattern 'exec_used' in docs/financial-services-pitch/README.md:77
Found a known-risky pattern (exec_used). Review and replace if possible.
docs/financial-services-pitch/README.md:77 Exec used
high System graph security Secrets conf 1.00 Runtime dotenv file present in repo: apps/leadsmartai/.env.production
`apps/leadsmartai/.env.production` looks like a runtime dotenv file. No high-confidence secret value was matched, but runtime dotenv files often drift into live credentials. Move real values to a secret manager and keep only `.env.example` style templates in source control.
apps/leadsmartai/.env.production ConfigEnv fileRuntime env
high System graph security Secrets conf 1.00 Runtime dotenv file present in repo: apps/propertytoolsai/.env.production
`apps/propertytoolsai/.env.production` looks like a runtime dotenv file. No high-confidence secret value was matched, but runtime dotenv files often drift into live credentials. Move real values to a secret manager and keep only `.env.example` style templates in source control.
apps/propertytoolsai/.env.production ConfigEnv fileRuntime env
For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/0a2c56cf-eb3f-4044-af75-2be6e174d755/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/0a2c56cf-eb3f-4044-af75-2be6e174d755/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.