Scan timing: clone 4.28s · analysis 5.74s · 8.5 MB · GitHub preflight 459ms
https://github.com/mxyxyz9/Tabs-ide.git
· scanned 2026-05-22 12:46 UTC (2 weeks ago)
· 10 languages
353 findings (69 legacy + 284 scanner) 56th percentile · Typescript · large (100-500K LoC)
Last scanned 2 weeks ago · v2 · 211 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
87.9 | 0.25 | 21.98 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
79.0 | 0.15 | 11.85 |
practices_score |
67.0 | 0.15 | 10.05 |
code_quality |
59.9 | 0.10 | 5.99 |
| Overall | 1.00 | 77.9 |
Showing 175 of 211 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
apps/server/src/git/Prompts.ts:123
xsslegacy
apps/desktop/scripts/dev-electron.mjs:24
xsslegacy
apps/desktop/resources/code-oss-extensions/tabs-workbench-integration/extension.js:309
xsslegacy
apps/web/src/components/chat/userMessageTerminalContexts.ts:19
qualitylegacy
apps/server/src/provider/codexCliVersion.ts:121
qualitylegacy
apps/server/src/imageMime.ts:35
qualitylegacy
apps/server/src/attachmentPaths.ts:22
path_traversallegacy
.github/workflows/ci.yml:38
dependencylegacy
.github/workflows/ci.yml:28
dependencylegacy
.github/workflows/release.yml:265
dependencylegacy
.github/workflows/release.yml:232
dependencylegacy
.github/workflows/release.yml:110
dependencylegacy
.github/workflows/release.yml:30
dependencylegacy
.github/workflows/ci.yml:81
dependencylegacy
.github/workflows/ci.yml:15
dependencylegacy
.github/workflows/release.yml:275
dependencylegacy
.github/workflows/pr-vouch.yml:88
dependencylegacy
.github/workflows/pr-vouch.yml:28
dependencylegacy
.github/workflows/release.yml:270
dependencylegacy
.github/workflows/release.yml:242
dependencylegacy
.github/workflows/release.yml:121
dependencylegacy
.github/workflows/release.yml:64
dependencylegacy
.github/workflows/ci.yml:89
dependencylegacy
.github/workflows/ci.yml:23
dependencylegacy
.github/workflows/release.yml:220
dependencylegacy
.github/workflows/pr-vouch.yml:80
dependencylegacy
.github/workflows/release.yml:237
dependencylegacy
.github/workflows/release.yml:116
dependencylegacy
.github/workflows/release.yml:59
dependencylegacy
.github/workflows/ci.yml:84
dependencylegacy
.github/workflows/ci.yml:18
dependencylegacy
.github/workflows/release.yml:289
dependencylegacy
apps/web/src/components/KeybindingsToast.browser.tsx:385
error_handlinglegacy
apps/web/src/wsNativeApi.ts:177
securitylegacy
apps/server/src/provider/Layers/CodexAdapter.ts:2
qualitylegacy
apps/web/src/store.ts:76
qualitylegacy
.github/workflows/pr-vouch.yml:80
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:18
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:84
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:59
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:116
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:237
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:289
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:338
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
apps/web/src/components/ChatMarkdown.tsx:203
owaspdangerous_innerhtml
apps/web/src/providerModels.ts:88
qualitylegacy
apps/web/src/lib/patchParsing.ts:7
qualitylegacy
apps/web/src/hooks/useSettings.ts:37
qualitylegacy
apps/web/src/components/ui/combobox.tsx:59
qualitylegacy
apps/web/src/components/chat/TraitsPicker.browser.tsx:61
qualitylegacy
apps/web/src/components/chat/TraitsPicker.browser.tsx:36
qualitylegacy
apps/web/src/components/chat/CompactComposerControlsMenu.browser.tsx:45
qualitylegacy
apps/web/src/components/PatchViewer.tsx:13
qualitylegacy
apps/server/src/provider/Layers/CodexProvider.ts:14
qualitylegacy
apps/server/src/persistence/Layers/ProjectionTurns.ts:46
qualitylegacy
apps/server/src/persistence/Layers/ProjectionThreads.ts:73
qualitylegacy
apps/server/src/persistence/Layers/ProjectionThreadMessages.ts:76
qualitylegacy
apps/server/src/persistence/Layers/ProjectionThreadActivities.ts:69
qualitylegacy
apps/server/src/persistence/Layers/ProjectionProjects.ts:78
qualitylegacy
apps/server/src/git/Layers/CodexTextGeneration.ts:185
qualitylegacy
.github/workflows/pr-vouch.yml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/pr-vouch.yml:88
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:15
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:23
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:38
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:81
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:89
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:30
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:64
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:110
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:121
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:220
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:232
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:242
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:265
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:270
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:275
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:313
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:320
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:343
supply-chaingithub-actionspinned-dependencies
.github/workflows/issue-labels.yml:21
supply-chaingithub-actionspinned-dependencies
.github/workflows/pr-size.yml:19
supply-chaingithub-actionspinned-dependencies
.github/workflows/pr-size.yml:67
supply-chaingithub-actionspinned-dependencies
.github/workflows/pr-size.yml:128
supply-chaingithub-actionspinned-dependencies
apps/web/package.json
supply-chainnpminstall-scripts
apps/server/package.json
supply-chainnpminstall-scripts
scripts/package.json
supply-chainnpminstall-scripts
packages/shared/package.json
supply-chainnpminstall-scripts
packages/contracts/package.json
supply-chainnpminstall-scripts
apps/server/src/persistence/Layers/OrchestrationEventStore.ts:252
qualitylegacy
apps/server/src/imageMime.ts:73
qualitylegacy
apps/server/scripts/cli.ts:102
qualitylegacy
apps/web/src/routeTree.gen.ts:20
qualitylegacy
apps/server/src/persistence/NodeSqliteClient.ts:125
qualitylegacy
apps/web/src/components/ChatMarkdown.tsx:203
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/2d30d258-c4ca-4367-b881-7293cf182d4d/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/2d30d258-c4ca-4367-b881-7293cf182d4d/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.