Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

ibelick/ui-skills

https://github.com/ibelick/ui-skills · scanned 2026-07-23 19:41 UTC (4 days, 19 hours ago)

49 raw signals (0 security + 49 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 4 days, 19 hours ago · v7 · 49 actionable findings from 1 signal source. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: layer: dependencies × excluding tests × Reset all
Scan summary Repository scanned at 70.4/100 with 90.0% coverage. It contains 174 nodes across 9 cross-layer flows, written primarily in mixed languages. Engine surfaced 49 findings — concentrated in security (26), dependencies (15), quality (6). Risk profile is high: 0 critical, 11 high, 25 medium. Recommended next step: open the security layer findings first — that's where the highest-impact wins live.

Showing 15 of 49 actionable findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

high System graph dependencies dependencies conf 1.00 Vulnerable dependency astro 5.18.2: GHSA-2pvr-wf23-7pc7
OSV.dev reports `astro` at version `5.18.2` (resolved in `package-lock.json`) is affected by GHSA-2pvr-wf23-7pc7 (aka CVE-2026-54299). Astro: Host header SSRF in prerendered error page fetch Aliases: CVE-2026-54299 Advisory: https://osv.dev/vulnerability/GHSA-2pvr-wf23-7pc7 Fix: upgrade `astro` p…
package.json ScaOsvGhsa 2pvr wf23 7pc7
high System graph dependencies dependencies conf 1.00 Vulnerable dependency astro 5.18.2: GHSA-8hv8-536x-4wqp
OSV.dev reports `astro` at version `5.18.2` (resolved in `package-lock.json`) is affected by GHSA-8hv8-536x-4wqp (aka CVE-2026-50146). Astro: Reflected XSS via unescaped slot name Aliases: CVE-2026-50146 Advisory: https://osv.dev/vulnerability/GHSA-8hv8-536x-4wqp Fix: upgrade `astro` past the aff…
package.json ScaOsvGhsa 8hv8 536x 4wqp
high System graph dependencies dependencies conf 0.90 Vulnerable dependency sharp 0.34.5: GHSA-f88m-g3jw-g9cj
OSV.dev reports `sharp` at version `0.34.5` (resolved in `package-lock.json`) is affected by GHSA-f88m-g3jw-g9cj. Note: `sharp` is a transitive dependency — pulled in by another package, not declared directly in a manifest. sharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328…
package-lock.json ScaOsvGhsa f88m g3jw g9cj
medium System graph dependencies dependencies conf 0.90 Dependency @astrojs/cloudflare is two or more major versions behind
`@astrojs/cloudflare` is pinned at `12.6.13` in `package.json` while the latest release on the npm registry is `14.1.4` — 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@astrojs/cloudfla…
package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency @astrojs/react is two or more major versions behind
`@astrojs/react` is pinned at `4.4.2` in `package.json` while the latest release on the npm registry is `6.0.1` — 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `@astrojs/react` to `6.0.1…
package.json FreshnessOutdated
medium System graph dependencies dependencies conf 0.90 Dependency astro is two or more major versions behind
`astro` is pinned at `5.16.7` in `package.json` while the latest release on the npm registry is `7.1.3` — 2 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `astro` to `7.1.3`.
package.json FreshnessOutdated
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency astro 5.18.2: GHSA-4g3v-8h47-v7g6
OSV.dev reports `astro` at version `5.18.2` (resolved in `package-lock.json`) is affected by GHSA-4g3v-8h47-v7g6. Astro: Reflected XSS via unescaped View Transition animation properties Advisory: https://osv.dev/vulnerability/GHSA-4g3v-8h47-v7g6 Fix: upgrade `astro` past the affected range per th…
package.json ScaOsvGhsa 4g3v 8h47 v7g6
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency astro 5.18.2: GHSA-f48w-9m4c-m7f5
OSV.dev reports `astro` at version `5.18.2` (resolved in `package-lock.json`) is affected by GHSA-f48w-9m4c-m7f5 (aka CVE-2026-59729). Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298) Aliases: CVE-2026-59729 Advisory: https://osv.dev/vulnera…
package.json ScaOsvGhsa f48w 9m4c m7f5
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency astro 5.18.2: GHSA-j687-52p2-xcff
OSV.dev reports `astro` at version `5.18.2` (resolved in `package-lock.json`) is affected by GHSA-j687-52p2-xcff (aka CVE-2026-41067). Astro: XSS in define:vars via incomplete </script> tag sanitization Aliases: CVE-2026-41067 Advisory: https://osv.dev/vulnerability/GHSA-j687-52p2-xcff Fix: upgra…
package.json ScaOsvGhsa j687 52p2 xcff
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency astro 5.18.2: GHSA-jrpj-wcv7-9fh9
OSV.dev reports `astro` at version `5.18.2` (resolved in `package-lock.json`) is affected by GHSA-jrpj-wcv7-9fh9 (aka CVE-2026-54298). Astro: XSS via Unescaped Attribute Names in Spread Props Aliases: CVE-2026-54298 Advisory: https://osv.dev/vulnerability/GHSA-jrpj-wcv7-9fh9 Fix: upgrade `astro` …
package.json ScaOsvGhsa jrpj wcv7 9fh9
medium System graph dependencies dependencies conf 1.00 Vulnerable dependency astro 5.18.2: GHSA-xr5h-phrj-8vxv
OSV.dev reports `astro` at version `5.18.2` (resolved in `package-lock.json`) is affected by GHSA-xr5h-phrj-8vxv (aka CVE-2026-45028). Astro: Server island encrypted parameters vulnerable to cross-component replay Aliases: CVE-2026-45028 Advisory: https://osv.dev/vulnerability/GHSA-xr5h-phrj-8vxv…
package.json ScaOsvGhsa xr5h phrj 8vxv
low System graph dependencies dependencies conf 0.90 Dependency marked is a major version behind
`marked` is pinned at `17.0.1` in `package.json` while the latest release on the npm registry is `18.0.7` — 1 major version(s) behind. Old majors stop receiving security backports and accumulate known CVEs. Review the upstream changelog / migration guide and upgrade `marked` to `18.0.7`.
package.json FreshnessOutdated
low System graph dependencies dependencies conf 1.00 Vulnerable dependency @astrojs/cloudflare 12.6.13: GHSA-88gm-j2wx-58h6
OSV.dev reports `@astrojs/cloudflare` at version `12.6.13` (resolved in `package-lock.json`) is affected by GHSA-88gm-j2wx-58h6 (aka CVE-2026-41321). Cloudflare has SSRF via redirect following through its image-binding-transform endpoint (incomplete fix for GHSA-qpr4) Aliases: CVE-2026-41321 Advi…
package.json ScaOsvGhsa 88gm j2wx 58h6
low System graph dependencies dependencies conf 1.00 Vulnerable dependency astro 5.18.2: GHSA-7pw4-f3q4-r2p2
OSV.dev reports `astro` at version `5.18.2` (resolved in `package-lock.json`) is affected by GHSA-7pw4-f3q4-r2p2 (aka CVE-2026-59727). Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands Aliases: CVE-2026-59727 Advisory: https://osv.dev/vulnerability/GHSA-7…
package.json ScaOsvGhsa 7pw4 f3q4 r2p2
low System graph dependencies dependencies conf 0.90 Vulnerable dependency esbuild 0.27.7: GHSA-g7r4-m6w7-qqqr
OSV.dev reports `esbuild` at version `0.27.7` (resolved in `package-lock.json`) is affected by GHSA-g7r4-m6w7-qqqr. Note: `esbuild` is a transitive dependency — pulled in by another package, not declared directly in a manifest. esbuild allows arbitrary file read when running the development server…
package-lock.json ScaOsvGhsa g7r4 m6w7 qqqr
For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/1c46d1ef-57dc-49b4-876a-2ca5bfba906d/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/1c46d1ef-57dc-49b4-876a-2ca5bfba906d/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.