https://github.com/volcengine/OpenViking.git
· scanned 2026-05-16 08:27 UTC (2 weeks, 5 days ago)
· 10 languages
556 findings (121 legacy + 435 scanner) 16th percentile · Python · large (100-500K LoC) Scanner says 55 (higher by 6)
Last scanned 2 weeks, 5 days ago · v1 · 113 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Showing 105 of 113 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
bot/deploy/docker/langfuse/docker-compose.yml:145
dockerlegacy
bot/deploy/docker/langfuse/docker-compose.yml:108
dockerlegacy
bot/deploy/docker/langfuse/docker-compose.yml:87
dockerlegacy
bot/deploy/docker/langfuse/docker-compose.yml:68
dockerlegacy
bot/deploy/docker/langfuse/docker-compose.yml:6
dockerlegacy
openviking/console/app.py:338
authlegacy
openviking/console/app.py:358
authlegacy
openviking/console/app.py:245
authlegacy
openviking/console/app.py:238
authlegacy
openviking/server/routers/tasks.py:23
authlegacy
openviking/console/app.py:348
authlegacy
openviking/console/app.py:389
authlegacy
openviking/console/app.py:373
authlegacy
benchmark/locomo/claudecode/import_to_ov.py:421
path_traversallegacy
benchmark/locomo/claudecode/stat_judge_result.py:38
path_traversallegacy
benchmark/locomo/claudecode/judge.py:123
path_traversallegacy
benchmark/RAG/src/adapters/qasper_adapter.py:379
llm_injectionlegacy
benchmark/RAG/src/adapters/syllabusqa_adapter.py:464
llm_injectionlegacy
bot/deploy/docker/langfuse/docker-compose.yml:108
dockerlegacy
bot/deploy/docker/Dockerfile:7
dockerlegacy
bot/deploy/Dockerfile:4
dockerlegacy
openviking/message/message.py:167
llm_injectionlegacy
benchmark/tau2/scripts/run_memory_v2_eval.py:35
llm_injectionlegacy
benchmark/locomo/vikingbot/import_to_ov.py:37
llm_injectionlegacy
benchmark/locomo/openclaw/import_to_ov.py:37
llm_injectionlegacy
benchmark/locomo/openclaw/eval.py:54
llm_injectionlegacy
benchmark/locomo/claudecode/import_to_ov.py:37
llm_injectionlegacy
examples/openclaw-plugin/context-engine.ts:7
llm_injectionlegacy
bot/vikingbot/channels/openapi.py:387
authlegacy
openviking/console/app.py:234
authlegacy
openviking/console/app.py:245
authlegacy
openviking/console/app.py:238
authlegacy
openviking/console/app.py:268
authlegacy
openviking/console/app.py:264
authlegacy
openviking/console/app.py:256
authlegacy
openviking/console/app.py:260
authlegacy
openviking/console/app.py:230
authlegacy
openviking/console/app.py:252
authlegacy
openviking/server/routers/relations.py:67
authlegacy
openviking/console/app.py:324
authlegacy
openviking/server/routers/sessions.py:219
authlegacy
openviking/server/routers/sessions.py:197
authlegacy
openviking/server/routers/sessions.py:176
authlegacy
openviking/server/oauth/router.py:407
authlegacy
bot/vikingbot/channels/openapi.py:401
authlegacy
openviking/server/routers/sessions.py:252
authlegacy
bot/demo/werewolf/werewolf_server.py:358
error_handlinglegacy
openviking_cli/setup_wizard.py:802
error_handlinglegacy
openviking_cli/rust_cli.py:63
error_handlinglegacy
bot/workspace/skills/opencode/opencode_utils.py:16
injectionlegacy
benchmark/RAG/scripts/download_dataset.py:121
path_traversallegacy
benchmark/RAG/src/adapters/qasper_adapter.py:379
llm_injectionlegacy
benchmark/RAG/src/adapters/syllabusqa_adapter.py:464
llm_injectionlegacy
bot/workspace/skills/tmux/SKILL.md:81
qualitylegacy
docker/pending_health_server.py:26
qualitylegacy
bot/demo/werewolf/werewolf_server.py:8
qualitylegacy
openviking/models/vlm/backends/codex_auth.py:84
qualitylegacy
docker-compose.yml:15
dockerlegacy
examples/grafana/docker-compose.yml:13
dockerlegacy
.dockerignore
dockerlegacy
bot/deploy/docker/Dockerfile:4
dockerlegacy
bot/deploy/Dockerfile:1
dockerlegacy
Dockerfile:86
dockerlegacy
openviking/eval/ragas/play_recorder.py:175
qualitylegacy
crates/ragfs/src/plugins/sqlfs/mod.rs:23
qualitylegacy
crates/ragfs/src/plugins/sqlfs/cache.rs:139
qualitylegacy
crates/ragfs/src/plugins/serverinfofs/mod.rs:249
qualitylegacy
crates/ragfs/src/core/plugin.rs:81
qualitylegacy
crates/ragfs/src/core/mountable.rs:245
qualitylegacy
bot/vikingbot/providers/openai_compatible_provider.py:48
qualitylegacy
bot/vikingbot/openviking_mount/viking_fuse.py:68
qualitylegacy
bot/vikingbot/openviking_mount/viking_fuse.py:67
qualitylegacy
bot/vikingbot/openviking_mount/fuse_simple_debug.py:9
qualitylegacy
bot/vikingbot/openviking_mount/fuse_simple.py:9
qualitylegacy
bot/vikingbot/openviking_mount/fuse_proxy.py:9
qualitylegacy
openviking/console/static/app.js:161
qualitylegacy
openviking/session/compressor_v2.py:1
qualitylegacy
.well-known/security.txt
qualitylegacy
npm/cli/README.md:19
dependencylegacy
examples/cloud/GUIDE.md:616
dependencylegacy
docs/zh/getting-started/03-quickstart-server.md:227
dependencylegacy
bot/README_CN.md:31
dependencylegacy
CONTRIBUTING_JA.md:51
dependencylegacy
CONTRIBUTING_CN.md:51
dependencylegacy
examples/grafana/docker-compose.yml:13
dockerlegacy
examples/grafana/docker-compose.yml:1
dockerlegacy
docker-compose.yml:15
dockerlegacy
bot/deploy/docker/langfuse/docker-compose.yml:68
dockerlegacy
bot/deploy/docker/langfuse/docker-compose.yml:6
dockerlegacy
examples/grafana/docker-compose.yml:13
dockerlegacy
examples/grafana/docker-compose.yml:1
dockerlegacy
docker-compose.yml:15
dockerlegacy
bot/deploy/docker/langfuse/docker-compose.yml:87
dockerlegacy
bot/deploy/docker/langfuse/docker-compose.yml:68
dockerlegacy
bot/deploy/docker/langfuse/docker-compose.yml:6
dockerlegacy
bot/deploy/docker/langfuse/docker-compose.yml:145
dockerlegacy
bot/deploy/docker/langfuse/docker-compose.yml:129
dockerlegacy
bot/deploy/docker/langfuse/docker-compose.yml:87
dockerlegacy
bot/deploy/docker/Dockerfile:48
dockerlegacy
bot/deploy/docker/Dockerfile:28
dockerlegacy
bot/deploy/Dockerfile:56
dockerlegacy
bot/deploy/Dockerfile:37
dockerlegacy
This page is publicly accessible at:
https://repobility.com/scan/12056a6a-d5b1-4a95-9bc1-27d844e39785/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/12056a6a-d5b1-4a95-9bc1-27d844e39785/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.