Scan timing: clone 24.24s · analysis 28.88s · 47.1 MB · GitHub API rate-limit (preflight)
https://github.com/cline/cline
· scanned 2026-06-05 09:25 UTC (5 days, 17 hours ago)
· 10 languages
1030 raw signals (196 security + 834 graph) 11/13 scanners ran 93rd percentile · Typescript · large (100-500K LoC) System graph score 72 (higher by 15)
Last scanned 5 days, 17 hours ago · v2 · 437 actionable findings from 2 signal sources. 152 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
88.0 | 0.20 | 17.60 |
documentation_score |
96.0 | 0.15 | 14.40 |
practices_score |
88.0 | 0.15 | 13.20 |
code_quality |
79.0 | 0.10 | 7.90 |
| Overall | 1.00 | 87.1 |
Showing 245 of 437 actionable findings. 589 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/scripts/coverage_check/workflow.py:226
sdk/packages/core/src/runtime/turn-queue/pending-prompt-service.ts:100
apps/vscode/src/core/task/tools/utils/ToolHookUtils.ts:159
apps/vscode/src/integrations/terminal/standalone/StandaloneTerminal.ts:104
.github/scripts/coverage_check/util.py:190
sdk/packages/core/src/session/services/file-session-service.ts:208
apps/cli/src/connectors/base.ts:149
apps/vscode/scripts/download-ripgrep.mjs:110
apps/cli/src/connectors/chat-runtime.ts:33apps/cli/src/connectors/runtime-turn.ts:337apps/cli/src/index.ts:53.github/scripts/coverage_check/util.py:190apps/cli/src/tui/commands/slash-command-registry.ts:264apps/cli/src/utils/team-command.ts:14evals/analysis/src/classifier.ts:46
apps/vscode/src/core/context/instructions/user-instructions/frontmatter.ts:47
apps/cline-hub/src/server.ts:88apps/vscode/src/dev/commands/tasks.ts:125sdk/packages/core/src/session/stores/conversation-store.ts:16apps/vscode/src/core/api/providers/claude-code.ts:212apps/vscode/src/services/browser/BrowserDiscovery.ts:50apps/vscode/src/utils/git-worktree.ts:84apps/cli/src/commands/program.ts:11apps/cli/src/main.ts:24apps/cli/src/runtime/tool-policies.ts:30apps/cline-hub/src/server/sessions.ts:88apps/examples/cline-core-cli-agent/src/index.ts:140apps/cline-hub/src/webview/src/vscode.ts:100
.github/workflows/cli-publish.yml:62, 217, 236, 301 (4 hits).github/workflows/ext-vscode-publish-stable.yml:197, 210 (4 hits).github/workflows/ext-vscode-test.yml:32, 331, 341, 361 (4 hits).github/workflows/sdk-test.yml:35, 70 (2 hits).github/workflows/ext-vscode-test-e2e.yml:32.github/workflows/sdk-publish.yml:111.github/workflows/cli-publish.yml.github/workflows/ext-vscode-publish-nightly.yml.github/workflows/ext-vscode-publish-stable.yml.github/workflows/ext-vscode-test-e2e.yml.github/workflows/sdk-publish.ymlapps/cline-hub/src/webview/src/components/ai-elements/schema-display.tsx:111
Dangerous innerhtml
apps/vscode/webview-ui/src/components/settings/ClineModelPicker.tsx:497
Dangerous innerhtml
apps/vscode/webview-ui/src/components/settings/common/ModelAutocomplete.tsx:232
Dangerous innerhtml
apps/vscode/webview-ui/src/components/settings/GroqModelPicker.tsx:240
Dangerous innerhtml
apps/vscode/webview-ui/src/components/settings/HicapModelPicker.tsx:223
Dangerous innerhtml
apps/vscode/webview-ui/src/components/settings/HuggingFaceModelPicker.tsx:226
Dangerous innerhtml
apps/vscode/webview-ui/src/components/settings/OllamaModelPicker.tsx:180
Dangerous innerhtml
apps/vscode/webview-ui/src/components/settings/OpenRouterModelPicker.tsx:308
Dangerous innerhtml
apps/vscode/webview-ui/src/components/settings/providers/OcaModelPicker.tsx:253
Dangerous innerhtml
apps/vscode/webview-ui/src/components/settings/RequestyModelPicker.tsx:231
Dangerous innerhtml
apps/vscode/webview-ui/src/components/settings/VercelModelPicker.tsx:263
Dangerous innerhtml
apps/vscode/src/shared/storage/adapters.ts:124
Weak hash
apps/cline-hub/src/webview/src/components/views/settings/channels-view.tsx:38, 70, 142 (3 hits)apps/cli/src/connectors/adapters/whatsapp.ts:14, 278 (2 hits)apps/cli/src/tui/views/config-view.tsx:56, 57 (2 hits)apps/cli/src/commands/hub.ts:31apps/cli/src/commands/schedule/import-export.ts:60apps/cli/src/connectors/adapters/linear.ts:10apps/cli/src/connectors/stores/memory-state.ts:84apps/cli/src/tui/components/model-selector/cline-model-selector.tsx:13apps/cli/src/tui/utils/selection-copy.ts:1
.github/workflows/ext-vscode-test.yml:29, 83, 86, 124, 127, 153, 207, 225, +5 more (20 hits).github/workflows/ext-vscode-test-e2e.yml:29, 86, 88, 94, 102, 110, 120, 156 (13 hits).github/workflows/cli-publish.yml:55, 67, 276, 307 (4 hits).github/workflows/ext-vscode-publish-nightly.yml:40, 54 (4 hits).github/workflows/ext-vscode-publish-stable.yml:44, 113 (3 hits).github/workflows/sdk-test.yml:32, 67, 75 (3 hits).github/workflows/sdk-publish.yml:58, 117 (2 hits).github/workflows/ext-jb-test-integration.yml:30package.json
CI/CD securitySupply chainNpm
apps/vscode/package.json
CI/CD securitySupply chainNpm
.github/scripts/coverage_check/util.py:203
.github/scripts/coverage_check/util.py:235
.github/scripts/coverage_check/util.py:122
.github/scripts/coverage_check/util.py:144
This page is publicly accessible at:
https://repobility.com/scan/225c1628-8aa6-4e9a-8b28-2acec03cadf0/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/225c1628-8aa6-4e9a-8b28-2acec03cadf0/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.