Scan timing: clone 23.93s · analysis 12.82s · 36.1 MB · GitHub API rate-limit (preflight)
https://github.com/holaboss-ai/holaOS
· scanned 2026-05-31 01:26 UTC (1 week, 6 days ago)
· 10 languages
915 raw signals (167 security + 748 graph) 11/13 scanners ran 41st percentile · Typescript · large (100-500K LoC) System graph score 67 (higher by 6)
Last scanned 1 week, 6 days ago · v2 · last Δ +4.9 (diff) · 461 actionable findings from 2 signal sources. 148 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
58.0 | 0.20 | 11.60 |
documentation_score |
65.0 | 0.15 | 9.75 |
practices_score |
70.0 | 0.15 | 10.50 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 72.8 |
Showing 270 of 461 actionable findings. 609 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/ci.yml:222, 266, 267, 268, 269, 270, 294, 302, +17 more (25 hits)runtime/api-server/src/app.ts:5430
runtime/api-server/src/app.ts:5342
runtime/api-server/src/app.ts:5557
runtime/api-server/src/app.ts:5264
runtime/api-server/src/app.ts:4892
runtime/api-server/src/app.ts:5832
runtime/api-server/src/app.ts:5811
runtime/api-server/src/app.ts:5490
runtime/api-server/src/app.ts:5471
runtime/api-server/src/app.ts:5577
runtime/api-server/src/app.ts:5238
runtime/api-server/src/app.ts:5316
runtime/api-server/src/app.ts:5647
runtime/api-server/src/app.ts:5688
runtime/api-server/src/app.ts:5563
runtime/api-server/src/app.ts:4858
runtime/api-server/src/app.ts:4958
runtime/api-server/src/app.ts:5117
runtime/api-server/src/app.ts:5047
runtime/api-server/src/app.ts:5070
runtime/api-server/src/app.ts:5094
runtime/api-server/src/app.ts:5372
runtime/api-server/src/app.ts:5532
runtime/api-server/src/app.ts:4818
runtime/api-server/src/app.ts:4839
runtime/api-server/src/memory-recall-index.ts:39
.github/workflows/ci.yml:55, 63, 78, 86, 110, 118, 139, 147, +10 more (32 hits).github/workflows/publish-sdk.yml:42, 75, 78, 108, 111, 191, 204, 207 (8 hits).github/workflows/publish-linux-runtime.yml:67, 118, 173 (4 hits).github/workflows/publish-macos-intel-desktop.yml:77, 128, 355 (3 hits).github/workflows/ci.yml:58, 81, 113, 142, 278, 579 (12 hits).github/workflows/publish-sdk.yml:85, 117, 213 (3 hits).github/workflows/publish-linux-runtime.yml:113.github/workflows/publish-macos-intel-desktop.yml:123runtime/api-server/src/memory-writeback-extractor.ts:57
runtime/api-server/src/evolve-skill-review.ts:446
apps/desktop/src/components/auth/AuthPanel.tsx:3420, 3828 (2 hits)website/docs/worker-configuration.d.ts:3004
Exec used
runtime/api-server/src/session-scratchpad.ts:147
runtime/api-server/src/composio-tool-registry.ts:48
sdk/app-builder-sdk/src/runtime/state.ts:103
runtime/harnesses/src/embedded-skills/app-builder-sdk/sdk-package/src/runtime/state.ts:103
runtime/api-server/src/runner-worker.ts:219
runtime/deploy/bootstrap/shared.sh:57
.dockerignore
CI/CD securitycontainers
runtime/deploy/Dockerfile.toolchain:1
CI/CD securitycontainers
runtime/deploy/Dockerfile:2
CI/CD securitycontainers
apps/desktop/src/components/layout/AppShell.tsx:1441apps/desktop/src/components/layout/SettingsScreenRoot.tsx:915apps/desktop/src/components/layout/new-shell/useSettingsState.ts:97apps/desktop/src/components/panes/ChatPane/index.tsx:5320apps/desktop/src/components/publish/usePublishDraft.ts:97apps/desktop/src/features/workspace-onboarding/preferences.ts:30apps/desktop/src/lib/chat/useChatComposerModelSelection.ts:197apps/desktop/src/lib/workspaceSelection.tsx:26.github/workflows/ci.yml.github/workflows/publish-linux-runtime.yml.github/workflows/publish-macos-intel-desktop.yml.github/workflows/publish-sdk.ymlapps/desktop/src/components/auth/AuthPanel.tsx:1434
Dangerous innerhtml
apps/desktop/src/components/marketplace/CodeBlock.tsx:236
Dangerous innerhtml
apps/desktop/src/lib/providerBrandIcon.tsx:156
Dangerous innerhtml
sdk/ui/src/primitives/chart.tsx:93
Dangerous innerhtml
website/docs/app/root.tsx:60
Dangerous innerhtml
apps/desktop/src/components/panes/ChatPane/IssueThreadControls.tsx:36, 42 (2 hits)runtime/harness-host/src/contracts.ts:6, 93 (2 hits)apps/desktop/src/components/layout/new-shell/NewAppShell.tsx:220apps/desktop/src/components/layout/new-shell/SearchDialog.tsx:230apps/desktop/src/components/layout/new-shell/WorkspaceDashboardPane.tsx:21apps/desktop/src/components/onboarding/IntegrationsList.tsx:67apps/desktop/src/components/panes/AppSurfacePane.tsx:453apps/desktop/src/components/panes/BrowserProfileImportButton.tsx:473website/docs/package.json
CI/CD securitySupply chainNpm
runtime/harness-host/package.json
CI/CD securitySupply chainNpm
This page is publicly accessible at:
https://repobility.com/scan/2bb252b3-baf7-4896-a58a-4c45dc20c51c/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/2bb252b3-baf7-4896-a58a-4c45dc20c51c/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.