https://github.com/code-yeongyu/oh-my-openagent
· scanned 2026-06-05 09:31 UTC (5 days, 16 hours ago)
· 10 languages
701 raw signals (151 security + 550 graph) 11/13 scanners ran 99th percentile · Typescript · large (100-500K LoC) System graph score 58 (higher by 33)
Last scanned 5 days, 16 hours ago · v2 · 289 actionable findings from 2 signal sources. 137 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
97.0 | 0.15 | 14.55 |
practices_score |
76.0 | 0.15 | 11.40 |
code_quality |
74.0 | 0.10 | 7.40 |
| Overall | 1.00 | 91.1 |
Showing 198 of 289 actionable findings. 426 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/plugin/ultrawork-db-model-override.ts:19
src/shared/posthog.ts:44
packages/omo-codex/plugin/components/telemetry/src/product-identity.ts:9
packages/omo-codex/plugin/components/telemetry/src/product-identity.ts:9
packages/omo-codex/src/telemetry/product-identity.ts:9
src/shared/posthog.ts:44
src/cli/config-manager/bun-install.ts:143
packages/boulder-state/src/storage/session.ts:33packages/omo-codex/plugin/components/rules/src/rules/engine.ts:107src/features/skill-mcp-manager/cleanup.ts:38packages/omo-codex/plugin/components/lsp/package.json:1
packages/omo-codex/plugin/package.json:1
packages/boulder-state/src/storage/task.ts:29
src/cli/sparkshell-appserver-websocket.ts:34
src/hooks/webfetch-redirect-guard/hook.ts:92
src/hooks/hashline-edit-diff-enhancer/hook.ts:64
packages/omo-codex/plugin/components/ulw-loop/src/codex-goal-snapshot.ts:34
.agents/skills/work-with-pr-workspace/iteration-1/review.html:717
.github/workflows/publish-platform.yml:48, 179, 252, 273 (6 hits)packages/omo-codex/plugin/components/comment-checker/.github/workflows/ci.yml:29, 32 (4 hits)packages/omo-codex/plugin/components/comment-checker/.github/workflows/publish.yml:22, 25 (4 hits)packages/omo-codex/plugin/components/lsp/.github/workflows/ci.yml:29, 34 (4 hits)packages/omo-codex/plugin/components/lsp/.github/workflows/publish.yml:22, 27 (4 hits)packages/omo-codex/plugin/components/rules/.github/workflows/ci.yml:29, 32 (4 hits)packages/omo-codex/plugin/components/rules/.github/workflows/publish.yml:22, 25 (4 hits).github/workflows/cla.yml:22 (2 hits)src/cli/sparkshell-appserver.ts:23
Exec used
packages/web/app/api/npm-downloads/route.ts:23
packages/web/app/api/stats/route.ts:11
packages/ast-grep-mcp/src/cli-binary-path-resolution.ts:34src/agents/dynamic-agent-policy-sections.ts:25src/cli/config-manager/opencode-binary.ts:45packages/utils/src/frontmatter.ts:25src/features/opencode-skill-loader/async-loader.ts:39src/features/opencode-skill-loader/skill-mcp-config.ts:11.agents/skills/opencode-qa/references/cli-commands.md:35
CI/CD securityagent runtimepermissions
packages/omo-codex/plugin/components/start-work-continuation/src/boulder-reader.ts:81
src/agents/metis.ts:257
packages/web/components/landing/live-stats.tsx:19
.opencode/skills/work-with-pr-workspace/iteration-1/review.html:736
.agents/skills/work-with-pr-workspace/iteration-1/review.html:736
packages/omo-codex/plugin/skills/programming/references/python/one-liners.md:37
.github/workflows/publish-platform.yml:49, 137 (3 hits).github/workflows/refresh-model-capabilities.yml:18, 35 (3 hits).github/workflows/web-deploy.yml:35, 51 (3 hits).github/workflows/cla.yml:135.github/workflows/sisyphus-agent.yml:60.github/workflows/ci.yml.github/workflows/cla.yml.github/workflows/publish-platform.yml.github/workflows/publish.yml.github/workflows/refresh-model-capabilities.ymlpackages/omo-codex/plugin/components/comment-checker/.github/workflows/publish.ymlpackages/omo-codex/plugin/components/lsp/.github/workflows/publish.ymlpackages/omo-codex/plugin/components/rules/.github/workflows/publish.ymlpackages/web/app/[locale]/docs/page.tsx:22
Dangerous innerhtml
packages/web/app/layout.tsx:120
Dangerous innerhtml
src/agents/sisyphus/default.ts:8, 10, 80, 87 (4 hits)src/agents/sisyphus-junior/kimi-k2-6.ts:36, 65, 69 (3 hits)src/agents/sisyphus/claude-opus-4-7.ts:7, 28, 35 (3 hits)src/agents/sisyphus-dynamic-prompt.ts:36, 43 (2 hits)src/agents/sisyphus-junior/gpt.ts:14, 15 (2 hits)src/agents/sisyphus/gpt-5-4.ts:2, 8 (2 hits)packages/model-core/src/category-model-requirements.ts:26packages/model-core/src/model-resolution-types.ts:20src/tools/task/task-update.ts:1
src/hooks/auto-update-checker/checker/check-for-update.ts:1
repo-level (20 hits)package.json
CI/CD securitySupply chainNpm
packages/web/package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/25b0c6bc-02cf-4dad-b4e9-900d6feab85f/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/25b0c6bc-02cf-4dad-b4e9-900d6feab85f/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.