Scan timing: clone 23.93s · analysis 12.82s · 36.1 MB · GitHub API rate-limit (preflight)
https://github.com/holaboss-ai/holaOS
· scanned 2026-05-31 01:26 UTC (5 days, 6 hours ago)
· 10 languages
915 findings (167 legacy + 748 scanner) 11/13 scanners ran 37th percentile · Typescript · large (100-500K LoC) Scanner says 67 (higher by 6)
Last scanned 5 days, 6 hours ago · v2 · last Δ +4.9 (diff) · 609 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
58.0 | 0.20 | 11.60 |
documentation_score |
65.0 | 0.15 | 9.75 |
practices_score |
70.0 | 0.15 | 10.50 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 72.8 |
Showing 418 of 609 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
runtime/api-server/src/composio-tool-registry.ts:48
qualitylegacy
.github/workflows/ci.yml:269
dependencylegacy
.github/workflows/ci.yml:268
dependencylegacy
.github/workflows/ci.yml:270
dependencylegacy
.github/workflows/ci.yml:751
dependencylegacy
.github/workflows/ci.yml:663
dependencylegacy
.github/workflows/ci.yml:601
dependencylegacy
.github/workflows/ci.yml:752
dependencylegacy
.github/workflows/ci.yml:664
dependencylegacy
.github/workflows/ci.yml:602
dependencylegacy
.github/workflows/ci.yml:750
dependencylegacy
.github/workflows/ci.yml:662
dependencylegacy
.github/workflows/ci.yml:600
dependencylegacy
.github/workflows/ci.yml:943
dependencylegacy
.github/workflows/ci.yml:222
dependencylegacy
.github/workflows/ci.yml:267
dependencylegacy
.github/workflows/ci.yml:266
dependencylegacy
.github/workflows/ci.yml:1079
dependencylegacy
.github/workflows/ci.yml:1085
dependencylegacy
.github/workflows/ci.yml:1080
dependencylegacy
.github/workflows/ci.yml:845
dependencylegacy
.github/workflows/ci.yml:364
dependencylegacy
.github/workflows/ci.yml:302
dependencylegacy
.github/workflows/ci.yml:753
dependencylegacy
.github/workflows/ci.yml:340
dependencylegacy
.github/workflows/ci.yml:294
dependencylegacy
runtime/api-server/src/composio-tool-registry.ts:48
qualitylegacy
runtime/api-server/src/composio-tool-registry.ts:48
deserializationlegacy
runtime/api-server/src/app.ts:5430
qualitylegacy
runtime/api-server/src/app.ts:5342
qualitylegacy
runtime/api-server/src/app.ts:5557
qualitylegacy
runtime/api-server/src/app.ts:5264
qualitylegacy
runtime/api-server/src/app.ts:4892
qualitylegacy
runtime/api-server/src/app.ts:5832
qualitylegacy
runtime/api-server/src/app.ts:5811
qualitylegacy
runtime/api-server/src/app.ts:5490
qualitylegacy
runtime/api-server/src/app.ts:5471
qualitylegacy
runtime/api-server/src/app.ts:5577
qualitylegacy
runtime/api-server/src/app.ts:5238
qualitylegacy
runtime/api-server/src/app.ts:5316
qualitylegacy
runtime/api-server/src/app.ts:5647
qualitylegacy
runtime/api-server/src/app.ts:5688
qualitylegacy
runtime/api-server/src/app.ts:5563
qualitylegacy
runtime/api-server/src/app.ts:4858
qualitylegacy
runtime/api-server/src/app.ts:4958
qualitylegacy
runtime/api-server/src/app.ts:5117
qualitylegacy
runtime/api-server/src/app.ts:5047
qualitylegacy
runtime/api-server/src/app.ts:5070
qualitylegacy
runtime/api-server/src/app.ts:5094
qualitylegacy
runtime/api-server/src/app.ts:5372
qualitylegacy
runtime/api-server/src/app.ts:5532
qualitylegacy
runtime/api-server/src/app.ts:4818
qualitylegacy
runtime/api-server/src/app.ts:4839
qualitylegacy
.github/workflows/publish-linux-runtime.yml:67
dependencylegacy
.github/workflows/ci.yml:574
dependencylegacy
.github/workflows/ci.yml:273
dependencylegacy
.github/workflows/ci.yml:179
dependencylegacy
.github/workflows/ci.yml:139
dependencylegacy
.github/workflows/ci.yml:110
dependencylegacy
.github/workflows/ci.yml:78
dependencylegacy
.github/workflows/ci.yml:55
dependencylegacy
.github/workflows/ci.yml:936
dependencylegacy
.github/workflows/ci.yml:930
dependencylegacy
.github/workflows/ci.yml:924
dependencylegacy
.github/workflows/ci.yml:584
dependencylegacy
.github/workflows/ci.yml:283
dependencylegacy
.github/workflows/ci.yml:147
dependencylegacy
.github/workflows/ci.yml:118
dependencylegacy
.github/workflows/ci.yml:86
dependencylegacy
.github/workflows/ci.yml:63
dependencylegacy
.github/workflows/ci.yml:884
dependencylegacy
.github/workflows/ci.yml:552
dependencylegacy
.github/workflows/ci.yml:579
dependencylegacy
.github/workflows/ci.yml:278
dependencylegacy
.github/workflows/ci.yml:142
dependencylegacy
.github/workflows/ci.yml:113
dependencylegacy
.github/workflows/ci.yml:81
dependencylegacy
.github/workflows/ci.yml:58
dependencylegacy
runtime/api-server/src/composio-tool-registry.ts:80
xsslegacy
runtime/api-server/src/apply-app-schema.ts:171
xsslegacy
apps/desktop/src/components/panes/ChatPane/Composer/ThinkingValueSelect.tsx:35
xsslegacy
apps/desktop/src/components/panes/ChatPane/skeletons.tsx:303
qualitylegacy
apps/desktop/src/components/panes/ChatPane/helpers.ts:82
qualitylegacy
apps/desktop/src/components/marketplace/markdownFenceNormalization.mjs:5
qualitylegacy
runtime/api-server/src/session-scratchpad.ts:71
path_traversallegacy
runtime/api-server/src/runner-prep.ts:73
path_traversallegacy
apps/desktop/scripts/runtime-bundle-state.mjs:170
path_traversallegacy
runtime/api-server/src/memory-recall-index.ts:39
authlegacy
runtime/api-server/src/memory-writeback-extractor.ts:57
llm_injectionlegacy
runtime/api-server/src/evolve-skill-review.ts:446
llm_injectionlegacy
apps/desktop/src/components/auth/AuthPanel.tsx:3828
authlegacy
apps/desktop/src/components/auth/AuthPanel.tsx:3420
authlegacy
website/docs/worker-configuration.d.ts:3004
owaspexec_used
runtime/api-server/src/session-scratchpad.ts:147
error_handlinglegacy
runtime/api-server/src/composio-tool-registry.ts:48
deserializationlegacy
sdk/app-builder-sdk/src/runtime/state.ts:103
qualitylegacy
runtime/harnesses/src/embedded-skills/app-builder-sdk/sdk-package/src/runtime/state.ts:103
qualitylegacy
runtime/api-server/src/runner-worker.ts:219
qualitylegacy
runtime/deploy/bootstrap/shared.sh:57
qualitylegacy
.dockerignore
dockerlegacy
runtime/deploy/Dockerfile.toolchain:1
dockerlegacy
runtime/deploy/Dockerfile:2
dockerlegacy
apps/desktop/src/lib/workspaceSelection.tsx:26
qualitylegacy
apps/desktop/src/lib/chat/useChatComposerModelSelection.ts:197
qualitylegacy
apps/desktop/src/features/workspace-onboarding/preferences.ts:30
qualitylegacy
apps/desktop/src/components/publish/usePublishDraft.ts:97
qualitylegacy
apps/desktop/src/components/panes/ChatPane/index.tsx:5320
qualitylegacy
apps/desktop/src/components/layout/new-shell/useSettingsState.ts:97
qualitylegacy
apps/desktop/src/components/layout/SettingsScreenRoot.tsx:915
qualitylegacy
apps/desktop/src/components/layout/AppShell.tsx:1441
qualitylegacy
.github/workflows/ci.yml:58
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:81
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:113
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:142
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:278
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:579
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-linux-runtime.yml:113
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-sdk.yml:85
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-sdk.yml:117
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-sdk.yml:213
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-macos-intel-desktop.yml:123
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/publish-linux-runtime.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/publish-sdk.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/publish-macos-intel-desktop.yml
supply-chaingithub-actionsleast-privilege
apps/desktop/src/components/auth/AuthPanel.tsx:1434
owaspdangerous_innerhtml
apps/desktop/src/components/marketplace/CodeBlock.tsx:236
owaspdangerous_innerhtml
apps/desktop/src/lib/providerBrandIcon.tsx:156
owaspdangerous_innerhtml
sdk/ui/src/primitives/chart.tsx:93
owaspdangerous_innerhtml
website/docs/app/root.tsx:60
owaspdangerous_innerhtml
runtime/harnesses/src/desktop-browser-tools.ts:188
qualitylegacy
runtime/harness-host/src/harness-ai-monitoring.ts:49
qualitylegacy
runtime/harness-host/src/contracts.ts:93
qualitylegacy
runtime/harness-host/src/contracts.ts:6
qualitylegacy
runtime/api-server/src/workspace-mcp-host.ts:45
qualitylegacy
runtime/api-server/src/workspace-app-ui-lint.ts:39
qualitylegacy
runtime/api-server/src/teammate-skill-files.ts:106
qualitylegacy
runtime/api-server/src/runtime-sentry.ts:6
qualitylegacy
runtime/api-server/src/resolved-app-bootstrap-shared.ts:40
qualitylegacy
runtime/api-server/src/recall-embedding-model.ts:37
qualitylegacy
runtime/api-server/src/recall-embedding-backfill-worker.ts:159
qualitylegacy
runtime/api-server/src/queue-worker.ts:140
qualitylegacy
runtime/api-server/src/memory.ts:64
qualitylegacy
runtime/api-server/src/memory-writeback-extractor.ts:63
qualitylegacy
runtime/api-server/src/main-session-event-worker.ts:466
qualitylegacy
runtime/api-server/src/integration-types.ts:25
qualitylegacy
runtime/api-server/src/cron-worker.ts:605
qualitylegacy
apps/desktop/src/components/panes/useWorkspaceBrowser.ts:14
qualitylegacy
apps/desktop/src/components/panes/SpaceBrowserExplorerPane.tsx:143
qualitylegacy
apps/desktop/src/components/panes/MarketplacePane.tsx:20
qualitylegacy
apps/desktop/src/components/panes/HtmlPreviewFrame.tsx:112
qualitylegacy
apps/desktop/src/components/panes/ChatPane/IssueThreadControls.tsx:42
qualitylegacy
apps/desktop/src/components/panes/ChatPane/IssueThreadControls.tsx:36
qualitylegacy
apps/desktop/src/components/panes/BrowserProfileImportButton.tsx:473
qualitylegacy
apps/desktop/src/components/panes/AppSurfacePane.tsx:453
qualitylegacy
apps/desktop/src/components/onboarding/IntegrationsList.tsx:67
qualitylegacy
apps/desktop/src/components/layout/new-shell/WorkspaceDashboardPane.tsx:21
qualitylegacy
apps/desktop/src/components/layout/new-shell/SearchDialog.tsx:230
qualitylegacy
apps/desktop/src/components/layout/new-shell/NewAppShell.tsx:220
qualitylegacy
runtime/api-server/src/image-generation-model.ts:79
qualitylegacy
.github/workflows/ci.yml:55
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:63
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:78
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:86
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:110
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:118
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:139
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:147
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:179
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:273
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:283
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:552
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:574
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:584
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-linux-runtime.yml:67
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-linux-runtime.yml:118
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-linux-runtime.yml:173
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-sdk.yml:42
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-sdk.yml:75
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-sdk.yml:78
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-sdk.yml:108
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-sdk.yml:111
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-sdk.yml:191
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-sdk.yml:204
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-sdk.yml:207
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-macos-intel-desktop.yml:77
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-macos-intel-desktop.yml:128
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish-macos-intel-desktop.yml:355
supply-chaingithub-actionspinned-dependencies
website/docs/package.json
supply-chainnpminstall-scripts
runtime/harness-host/package.json
supply-chainnpminstall-scripts
Showing first 300 of 418. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/2bb252b3-baf7-4896-a58a-4c45dc20c51c/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/2bb252b3-baf7-4896-a58a-4c45dc20c51c/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.