Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

sunglasses-dev/sunglasses

https://github.com/sunglasses-dev/sunglasses · scanned 2026-06-16 00:26 UTC (2 months, 2 weeks ago)

37 raw signals (0 security + 37 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 2 months, 2 weeks ago · v1 · 36 actionable findings from 1 signal source. 1 repeated signal grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: excluding tests × Reset all

All 1463 nodes from the latest scan, grouped by kind. Each node is a unit the engine identified (file, function, endpoint, table…). Most users won't need this view — it's primarily for debugging the engine's graph extraction or for AI agents that want to enumerate the project structure.

LabelLayerStatusPath
pattern_forge.py software healthy pattern_forge.py
conftest.py software healthy conftest.py
README.md software healthy README.md
KNOWN_VERSION_GAPS.md software healthy KNOWN_VERSION_GAPS.md
CONTRIBUTING.md software healthy CONTRIBUTING.md
test_customer_zero.py software healthy test_customer_zero.py
fp_gate.py software healthy fp_gate.py
fp_corpus_data.py software healthy fp_corpus_data.py
setup.py software healthy setup.py
LICENSE software healthy LICENSE
SECURITY.md software healthy SECURITY.md
CHANGELOG.md software healthy CHANGELOG.md
manifest.json software healthy attack-db/manifest.json
README.md software healthy attack-db/README.md
generate_db.py software healthy attack-db/generate_db.py
search.py software healthy attack-db/search.py
GLS-PA-2-hidden-annotation-payload-policy-override.json software healthy attack-db/attacks/parasitic-injection/GLS-PA-2-hidden-annot…
GLS-PIEMN-001-hidden-comment-agent-instruction-guardrail-by… software healthy attack-db/attacks/parasitic-injection/GLS-PIEMN-001-hidden-…
GLS-PI-022-hidden-footer-instruction-scope-override.json software healthy attack-db/attacks/parasitic-injection/GLS-PI-022-hidden-foo…
GLS-PA-3-embedded-metadata-note-authority-override-execute.… software healthy attack-db/attacks/parasitic-injection/GLS-PA-3-embedded-met…
GLS-PI-023-hidden-annotation-payload-guardrail-override.json software healthy attack-db/attacks/parasitic-injection/GLS-PI-023-hidden-ann…
GLS-PA-001-parasitic-system-prompt-injection.json software healthy attack-db/attacks/parasitic-injection/GLS-PA-001-parasitic-…
GLS-SCAP-005-slsa-in-toto-provenance-attestation-metadata-p… software healthy attack-db/attacks/supply-chain-attestation-poisoning/GLS-SC…
GLS-SCAP-002-slsa-in-toto-attestation-metadata-agent-policy… software healthy attack-db/attacks/supply-chain-attestation-poisoning/GLS-SC…
GLS-SCAP-001-sarif-results-metadata-agent-policy-poisoning.… software healthy attack-db/attacks/supply-chain-attestation-poisoning/GLS-SC…
GLS-SCAP-003-status-badge-coverage-badge-metadata-agent-pol… software healthy attack-db/attacks/supply-chain-attestation-poisoning/GLS-SC…
GLS-SCAP-004-tuf-update-metadata-agent-policy-poisoning.json software healthy attack-db/attacks/supply-chain-attestation-poisoning/GLS-SC…
GLS-TOP-247-forged-checksum-log-integrity-gate-bypass.json software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-247-forged-…
GLS-TOP-325-forged-receipt-swap-report-approve-bypass.json software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-325-forged-…
GLS-TOP-237-tool-output-poisoning-trusted-output-override.j… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-237-tool-ou…
GLS-TOP-266-forged-tool-log-integrity-stamp-passed-override… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-266-forged-…
GLS-TOP-623-forged-tool-result-block-channel-spoofing.json software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-623-forged-…
GLS-TOP-637-tool-output-instruction-injection.json software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-637-tool-ou…
GLS-TOP-631-confidence-tag-inflation-fallback-parser-hijack… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-631-confide…
GLS-TOP-264-forged-function-output-provenance-bypass-rerout… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-264-forged-…
GLS-TOP-257-forged-tool-trace-pipeline-reroute-bypass.json software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-257-forged-…
GLS-TOP-252-forged-compliance-note-authorization-check-bypa… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-252-forged-…
GLS-TOP-246-confidence-banner-tamper-override-execution-pol… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-246-confide…
GLS-TOP-265-forged-scanner-report-route-execution-guardrail… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-265-forged-…
GLS-TOP-636-signed-summary-impostor-executor-identity-swap.… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-636-signed-…
GLS-TOP-621-confidence-tag-spoofing-contradiction-suppressi… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-621-confide…
GLS-TOP-626-stale-tool-output-provenance-identity-swap.json software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-626-stale-t…
GLS-TOP-259-forged-execution-result-planner-verification-by… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-259-forged-…
GLS-V03-0484-ci-output-attestation-seal-validation-gate-byp… software healthy attack-db/attacks/tool-output-poisoning/GLS-V03-0484-ci-out…
GLS-TOP-309-signed-summary-footer-policy-bypass.json software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-309-signed-…
GLS-TOP-245-verification-stamp-tamper-override-guardrails.j… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-245-verific…
GLS-TOP-332-forged-evaluation-trace-execution-policy-evade.… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-332-forged-…
GLS-TOP-633-tool-result-role-shadow-error-recovery-injectio… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-633-tool-re…
GLS-TOP-263-forged-rollback-certificate-compliance-bypass.j… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-263-forged-…
GLS-TOP-634-first-row-authority-hijack-chronology-inversion… software healthy attack-db/attacks/tool-output-poisoning/GLS-TOP-634-first-r…

Showing first 50 of this kind. Full payload available via the JSON button at the top of the page.

LabelLayerStatusPath
cid software healthy pattern_forge.py:37
ccat software healthy pattern_forge.py:38
creg software healthy pattern_forge.py:39
_prefix_data software healthy pattern_forge.py:48
valid_categories software healthy pattern_forge.py:54
category_prefix_map software healthy pattern_forge.py:63
engine_denylist software healthy pattern_forge.py:72
live_ids software healthy pattern_forge.py:80
clean_corpus_raw software healthy pattern_forge.py:84
clean_corpus_text software healthy pattern_forge.py:94
engine_ok software healthy pattern_forge.py:100
fail software healthy pattern_forge.py:110
env_check software healthy pattern_forge.py:117
s1_schema software dead pattern_forge.py:133
s2_keywords software dead pattern_forge.py:181
s3_fpgate software dead pattern_forge.py:208
_sig software healthy pattern_forge.py:249
_known_ids_and_sigs software healthy pattern_forge.py:252
s4_dedup software dead pattern_forge.py:277
s5_idnorm software dead pattern_forge.py:297
check_card software healthy pattern_forge.py:312
load_cards software healthy pattern_forge.py:325
_print_env software healthy pattern_forge.py:333
cmd_check software healthy pattern_forge.py:342
cmd_regrade software healthy pattern_forge.py:364
engine software healthy conftest.py:8
run_tests software healthy test_customer_zero.py:30
check software healthy test_customer_zero.py:34
test_negation_context software healthy test_customer_zero.py:164
check_negation software healthy test_customer_zero.py:169
test_real_files software healthy test_customer_zero.py:245
performance_test software healthy test_customer_zero.py:273
main software healthy test_customer_zero.py:301
clean_samples software healthy fp_gate.py:23
_fid_sev software healthy fp_gate.py:43
fp_offenders software healthy fp_gate.py:49
clean_files software healthy fp_corpus_data.py:122
main software healthy attack-db/generate_db.py:83
load_all software healthy attack-db/search.py:31
print_pattern software healthy attack-db/search.py:45
cmd_search software healthy attack-db/search.py:60
cmd_list software healthy attack-db/search.py:84
cmd_stats software healthy attack-db/search.py:93
main software healthy attack-db/search.py:120
test_vietnamese_prompt_injection_pattern_blocks_instruction… software healthy tests/test_vietnamese_multilingual_patterns.py:5
test_vietnamese_exfiltration_pattern_blocks_credential_requ… software healthy tests/test_vietnamese_multilingual_patterns.py:13
test_vietnamese_patterns_are_not_missing_from_catalog software healthy tests/test_vietnamese_multilingual_patterns.py:21
engine software healthy tests/test_ui_injection_social_gym.py:53
test_gym_miss_now_caught software healthy tests/test_ui_injection_social_gym.py:62
test_new_ui_injection_patterns_exist software healthy tests/test_ui_injection_social_gym.py:75

Showing first 50 of this kind. Full payload available via the JSON button at the top of the page.

LabelLayerStatusPath
attack-db software healthy attack-db
attacks software healthy attack-db/attacks
parasitic-injection software healthy attack-db/attacks/parasitic-injection
supply-chain-attestation-poisoning software healthy attack-db/attacks/supply-chain-attestation-poisoning
tool-output-poisoning software healthy attack-db/attacks/tool-output-poisoning
path-traversal software healthy attack-db/attacks/path-traversal
secret-detection software healthy attack-db/attacks/secret-detection
dns-tunneling software healthy attack-db/attacks/dns-tunneling
build-metadata-poisoning software healthy attack-db/attacks/build-metadata-poisoning
ssrf software healthy attack-db/attacks/ssrf
approval-graph-poisoning software healthy attack-db/attacks/approval-graph-poisoning
jailbreak-evasion software healthy attack-db/attacks/jailbreak-evasion
unicode-evasion software healthy attack-db/attacks/unicode-evasion
provenance-chain-fracture software healthy attack-db/attacks/provenance-chain-fracture
ui-injection software healthy attack-db/attacks/ui-injection
prompt-leak software healthy attack-db/attacks/prompt-leak
rtl-obfuscation software healthy attack-db/attacks/rtl-obfuscation
auth-bypass software healthy attack-db/attacks/auth-bypass
data-exfiltration software healthy attack-db/attacks/data-exfiltration
state-sync-poisoning software healthy attack-db/attacks/state-sync-poisoning
tool-chain-race software healthy attack-db/attacks/tool-chain-race
repo-metadata-poisoning software healthy attack-db/attacks/repo-metadata-poisoning
discovery-file-poisoning software healthy attack-db/attacks/discovery-file-poisoning
agent-workflow-security software healthy attack-db/attacks/agent-workflow-security
cross-agent-injection software healthy attack-db/attacks/cross-agent-injection
token-smuggling software healthy attack-db/attacks/token-smuggling
mcp-threat software healthy attack-db/attacks/mcp-threat
memory-poisoning software healthy attack-db/attacks/memory-poisoning
encoding-evasion software healthy attack-db/attacks/encoding-evasion
model-routing-confusion software healthy attack-db/attacks/model-routing-confusion
tool-poisoning software healthy attack-db/attacks/tool-poisoning
code-switching software healthy attack-db/attacks/code-switching
deserialization software healthy attack-db/attacks/deserialization
supply-chain software healthy attack-db/attacks/supply-chain
cicd-metadata-poisoning software healthy attack-db/attacks/cicd-metadata-poisoning
structured-metadata-poisoning software healthy attack-db/attacks/structured-metadata-poisoning
command-injection software healthy attack-db/attacks/command-injection
agent-instruction-file-poisoning software healthy attack-db/attacks/agent-instruction-file-poisoning
social-engineering-ui software healthy attack-db/attacks/social-engineering-ui
indirect-prompt-injection software healthy attack-db/attacks/indirect-prompt-injection
invisible-unicode software healthy attack-db/attacks/invisible-unicode
sandbox-escape software healthy attack-db/attacks/sandbox-escape
authorization-bypass software healthy attack-db/attacks/authorization-bypass
api-descriptor-poisoning software healthy attack-db/attacks/api-descriptor-poisoning
identity-discovery-poisoning software healthy attack-db/attacks/identity-discovery-poisoning
policy-scope-redefinition software healthy attack-db/attacks/policy-scope-redefinition
tool-metadata-smuggling software healthy attack-db/attacks/tool-metadata-smuggling
identity-federation software healthy attack-db/attacks/identity-federation
agent-workflow software healthy attack-db/attacks/agent-workflow
privilege-escalation software healthy attack-db/attacks/privilege-escalation

Showing first 50 of this kind. Full payload available via the JSON button at the top of the page.

LabelLayerStatusPath
auth::attack-db/attacks/identity-federation/GLS-IDF-001-for… security healthy attack-db/attacks/identity-federation/GLS-IDF-001-forged-oi…
auth::attack-db/attacks/identity-discovery-poisoning/GLS-ID… security healthy attack-db/attacks/identity-discovery-poisoning/GLS-IDP-011-…
auth::attack-db/attacks/mcp-threat/GLS-MCP-015-mcp-oauth-sc… security healthy attack-db/attacks/mcp-threat/GLS-MCP-015-mcp-oauth-scope-co…
auth::attack-db/attacks/secret-detection/GLS-SD-005-jwt-tok… security healthy attack-db/attacks/secret-detection/GLS-SD-005-jwt-token.json
auth::attack-db/attacks/privilege-escalation/GLS-PE-004-exc… security healthy attack-db/attacks/privilege-escalation/GLS-PE-004-excessive…
auth::attack-db/attacks/agent-workflow-security/GLS-AW-088-… security healthy attack-db/attacks/agent-workflow-security/GLS-AW-088-permis…
auth::attack-db/attacks/identity-phishing/GLS-ID-001-oauth-… security healthy attack-db/attacks/identity-phishing/GLS-ID-001-oauth-pkce-d…
auth::attack-db/attacks/identity-federation/GLS-IDF-002-for… security healthy attack-db/attacks/identity-federation/GLS-IDF-002-forged-se…
auth::attack-db/attacks/identity-federation/GLS-IDF-004-for… security healthy attack-db/attacks/identity-federation/GLS-IDF-004-forged-fe…
auth::attack-db/attacks/discovery-file-poisoning/GLS-DFP-02… security healthy attack-db/attacks/discovery-file-poisoning/GLS-DFP-021-mail…
auth::attack-db/attacks/identity-discovery-poisoning/GLS-ID… security healthy attack-db/attacks/identity-discovery-poisoning/GLS-IDP-008-…
auth::attack-db/attacks/auth-bypass/GLS-AB-006-jwt-algorith… security healthy attack-db/attacks/auth-bypass/GLS-AB-006-jwt-algorithm-none…
auth::attack-db/attacks/identity-discovery-poisoning/GLS-ID… security healthy attack-db/attacks/identity-discovery-poisoning/GLS-IDP-015-…
auth::attack-db/attacks/supply-chain-attestation-poisoning/… security healthy attack-db/attacks/supply-chain-attestation-poisoning/GLS-SC…
auth::fp_corpus_data.py security healthy fp_corpus_data.py
auth::README.md security healthy README.md
auth::attack-db/attacks/mcp-threat/GLS-MCP-003-mcp-capabili… security healthy attack-db/attacks/mcp-threat/GLS-MCP-003-mcp-capability-exp…

LabelLayerStatusPath
ProtectedEngine software healthy sunglasses/reporter.py:43
SunglassesScanner software healthy sunglasses/scanner.py:50
ScanResult software healthy sunglasses/engine.py:28
SunglassesEngine software healthy sunglasses/engine.py:83
SunglassesScanInput software healthy sunglasses/integrations/langchain.py:62
_SunglassesScanTool software healthy sunglasses/integrations/langchain.py:68
Config software healthy sunglasses/integrations/langchain.py:84
SunglassesScanTool software healthy sunglasses/integrations/langchain.py:106
PDFExtractor software healthy sunglasses/extractors/pdf.py:32
AudioExtractor software healthy sunglasses/extractors/audio.py:46
VideoExtractor software healthy sunglasses/extractors/video.py:43
ImageExtractor software healthy sunglasses/extractors/image.py:49
QRExtractor software healthy sunglasses/extractors/qr.py:43

LabelLayerStatusPath
mysql data healthy attack-db/attacks/mcp-tool-injection/GLS-MTI-001-mcp-databa…
postgres data healthy attack-db/attacks/mcp-tool-injection/GLS-MTI-001-mcp-databa…
sqlite data healthy attack-db/attacks/mcp-tool-injection/GLS-MTI-001-mcp-databa…

LabelLayerStatusPath
port:01 network healthy stats/verified-sources.yml
port:2025 network healthy stats/verified-sources.yml
port:03 network healthy stats/verified-sources.yml

LabelLayerStatusPath
vps::azure hardware healthy README.md
vps::aws hardware healthy attack-db/generate_db.py
vps::gcp hardware healthy attack-db/attacks/discovery-file-poisoning/GLS-DFP-056-terr…

LabelLayerStatusPath
repobility-clone-61k_9utu software healthy /tmp/repobility-clone-61k_9utu

LabelLayerStatusPath
10.0.0.1 network healthy test_customer_zero.py

LabelLayerStatusPath
gpu (detected) hardware healthy README.md

LabelLayerStatusPath
gha::pattern-integrity cicd healthy .github/workflows/pattern-integrity.yml

LabelLayerStatusPath
integrity cicd healthy .github/workflows/pattern-integrity.yml
For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/1f506e91-e3ed-4ed3-8b5b-d06c716ea151/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/1f506e91-e3ed-4ed3-8b5b-d06c716ea151/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.