Scan timing: clone 20.15s · analysis 31.93s · 50.6 MB · GitHub API rate-limit (preflight)
https://github.com/tinyhumansai/openhuman
· scanned 2026-05-24 01:21 UTC (1 week, 5 days ago)
· 10 languages
2754 findings (188 legacy + 2566 scanner) 11/13 scanners ran 100th percentile · Rust · huge (>500K LoC) Scanner says 76 (higher by 14)
Last scanned 1 week, 5 days ago · v8 · last Δ -10.3 (diff) · 780 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
98.0 | 0.20 | 19.60 |
documentation_score |
81.0 | 0.15 | 12.15 |
practices_score |
92.0 | 0.15 | 13.80 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 90.3 |
Showing 547 of 780 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/openhuman/integrations/twilio.rs:198
qualitylegacy
src/openhuman/wallet/rpc.rs:195
qualitylegacy
src/openhuman/memory/tree/util/redact.rs:96
qualitylegacy
src/openhuman/memory/tree/jobs/redact.rs:186
qualitylegacy
src/openhuman/memory/tree/jobs/redact.rs:164
credential_exposurelegacy
src/openhuman/agent_experience/types.rs:128
credential_exposurelegacy
src/openhuman/memory/tree/jobs/redact.rs:137
credential_exposurelegacy
app/src/components/oauth/OAuthProviderButton.tsx:251
authlegacy
scripts/mock-api/socket/websocket.mjs:84
qualitylegacy
app/src/store/notificationSlice.ts:80
qualitylegacy
app/src/store/accountsSlice.ts:49
qualitylegacy
src/openhuman/memory/tree/jobs/redact.rs:164
qualitylegacy
src/openhuman/agent_experience/types.rs:128
qualitylegacy
.github/workflows/e2e-reusable.yml:108
dependencylegacy
.github/workflows/e2e-reusable.yml:99
dependencylegacy
.github/workflows/e2e-reusable.yml:79
dependencylegacy
.github/workflows/typecheck.yml:26
dependencylegacy
.github/workflows/coverage.yml:123
dependencylegacy
.github/workflows/coverage.yml:33
dependencylegacy
.github/workflows/e2e-reusable.yml:72
dependencylegacy
.github/workflows/typecheck.yml:53
dependencylegacy
.github/workflows/typecheck.yml:22
dependencylegacy
.github/workflows/coverage.yml:148
dependencylegacy
.github/workflows/coverage.yml:110
dependencylegacy
.github/workflows/coverage.yml:79
dependencylegacy
.github/workflows/coverage.yml:29
dependencylegacy
.github/workflows/coverage.yml:161
dependencylegacy
.github/workflows/contributor-rewards.yml:33
dependencylegacy
.github/workflows/coverage.yml:155
dependencylegacy
.github/workflows/e2e-reusable.yml:165
dependencylegacy
.github/workflows/coverage.yml:191
dependencylegacy
.github/workflows/coverage.yml:134
dependencylegacy
.github/workflows/coverage.yml:94
dependencylegacy
.github/workflows/coverage.yml:56
dependencylegacy
.github/workflows/e2e-reusable.yml:87
dependencylegacy
.github/workflows/typecheck.yml:57
dependencylegacy
.github/workflows/coverage.yml:115
dependencylegacy
.github/workflows/coverage.yml:84
dependencylegacy
Dockerfile:65
dependencylegacy
Dockerfile:12
dependencylegacy
.github/Dockerfile:1
dependencylegacy
e2e/Dockerfile:14
dependencylegacy
.github/workflows/e2e-reusable.yml:195
dependencylegacy
.github/workflows/e2e-reusable.yml:68
dependencylegacy
.github/workflows/build.yml:21
dependencylegacy
.github/workflows/pr-quality.yml:36
dependencylegacy
.github/workflows/pr-quality.yml:20
dependencylegacy
.github/workflows/weekly-code-review.yml:30
dependencylegacy
.github/workflows/typecheck.yml:50
dependencylegacy
.github/workflows/typecheck.yml:19
dependencylegacy
.github/workflows/coverage.yml:105
dependencylegacy
.github/workflows/coverage.yml:72
dependencylegacy
.github/workflows/coverage.yml:26
dependencylegacy
scripts/act-staging.sh:127
credential_exposurelegacy
scripts/act-build-desktop.sh:72
credential_exposurelegacy
scripts/mock-api/routes/llm/dynamic.mjs:123
xsslegacy
scripts/act-staging.sh:61
xsslegacy
scripts/mock-api/server.mjs:128
qualitylegacy
scripts/cancel-stale-pr-ci.mjs:106
qualitylegacy
scripts/agent-batch/lib.mjs:116
qualitylegacy
app/src/pages/conversations/utils/workerThreadRef.ts:34
qualitylegacy
app/src/pages/conversations/utils/format.ts:111
qualitylegacy
scripts/build-apt-repo.sh:35
injectionlegacy
Dockerfile:108
dockerlegacy
e2e/Dockerfile:35
dockerlegacy
e2e/Dockerfile:30
dockerlegacy
.github/Dockerfile:52
dockerlegacy
.github/Dockerfile:46
dockerlegacy
app/src/components/settings/panels/ComposioPanel.tsx:295
authlegacy
app/src/components/settings/panels/AIPanel.tsx:2741
authlegacy
.github/Dockerfile:46
supply-chaindockerremote-installer
.github/Dockerfile:52
supply-chaindockerremote-installer
e2e/Dockerfile:35
supply-chaindockerremote-installer
src/openhuman/mcp_server/http.rs:449
authlegacy
src/openhuman/mcp_server/http.rs:351
authlegacy
src/openhuman/mcp_server/http.rs:73
authlegacy
app/src-tauri/src/meet_audio/captions_bridge.js:158
error_handlinglegacy
app/src-tauri/src/meet_audio/audio_bridge.js:209
error_handlinglegacy
app/src-tauri/src/meet_video/camera_bridge.js:138
error_handlinglegacy
app/src/pages/conversations/utils/workerThreadRef.ts:34
injectionlegacy
app/src/utils/openUrl.ts:70
securitylegacy
app/src/utils/deviceFingerprint.ts:13
qualitylegacy
src/openhuman/tools/impl/network/mcp.rs:300
qualitylegacy
src/openhuman/redirect_links/store.rs:301
qualitylegacy
app/src/utils/configPersistence.ts:256
authlegacy
app/src/utils/configPersistence.ts:239
authlegacy
app/src/store/coreModeSlice.ts:67
authlegacy
e2e/Dockerfile:14
dockerlegacy
.github/Dockerfile:1
dockerlegacy
app/src/utils/tauriCommands/localAi.ts:199
qualitylegacy
app/src/pages/onboarding/components/BetaBanner.tsx:22
qualitylegacy
app/src/overlay/OverlayApp.tsx:486
qualitylegacy
app/src/components/settings/panels/AgentChatPanel.tsx:48
qualitylegacy
app/src/pages/Conversations.tsx:664
qualitylegacy
src/openhuman/memory/tree/canonicalize/email_clean.rs:1
qualitylegacy
remotion/src/Mascot/mascot-yellow-wave-alt.tsx:1
qualitylegacy
README.zh-CN.md:54
dependencylegacy
README.ko.md:56
dependencylegacy
README.ja-JP.md:55
dependencylegacy
README.de.md:55
dependencylegacy
.github/workflows/coverage.yml:84
supply-chaingithub-actionspinned-dependencies
.github/workflows/coverage.yml:90
supply-chaingithub-actionspinned-dependencies
.github/workflows/coverage.yml:115
supply-chaingithub-actionspinned-dependencies
.github/workflows/coverage.yml:130
supply-chaingithub-actionspinned-dependencies
.github/workflows/typecheck.yml:57
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-reusable.yml:87
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-reusable.yml:217
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-reusable.yml:252
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-reusable.yml:261
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-reusable.yml:275
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-reusable.yml:355
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-reusable.yml:364
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-staging.yml:102
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-staging.yml:286
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-staging.yml:288
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-ci-image.yml:27
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-ci-image.yml:33
supply-chaingithub-actionspinned-dependencies
.github/workflows/ios-compile.yml:45
supply-chaingithub-actionspinned-dependencies
.github/workflows/ios-compile.yml:51
supply-chaingithub-actionspinned-dependencies
.github/workflows/ios-compile.yml:60
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-production.yml:122
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-production.yml:459
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-production.yml:461
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-production.yml:483
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-production.yml:536
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-production.yml:538
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-production.yml:725
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-production.yml:727
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-windows.yml:30
supply-chaingithub-actionspinned-dependencies
.github/workflows/pr-quality.yml:57
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-desktop.yml:149
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-desktop.yml:153
supply-chaingithub-actionspinned-dependencies
.github/workflows/build-desktop.yml:161
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-agent-review.yml:40
supply-chaingithub-actionspinned-dependencies
.github/workflows/e2e-agent-review.yml:50
supply-chaingithub-actionspinned-dependencies
.github/workflows/deploy-smoke.yml:52
supply-chaingithub-actionspinned-dependencies
.github/workflows/deploy-smoke.yml:55
supply-chaingithub-actionspinned-dependencies
.github/workflows/deploy-smoke.yml:151
supply-chaingithub-actionspinned-dependencies
.github/workflows/deploy-smoke.yml:154
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-packages.yml:43
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-packages.yml:45
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-packages.yml:172
supply-chaingithub-actionspinned-dependencies
.github/workflows/android-compile.yml:37
supply-chaingithub-actionspinned-dependencies
.github/workflows/android-compile.yml:43
supply-chaingithub-actionspinned-dependencies
.github/workflows/android-compile.yml:51
supply-chaingithub-actionspinned-dependencies
.github/workflows/build.yml:29
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-staging.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/docker-ci-image.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release-production.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release-packages.yml
supply-chaingithub-actionsleast-privilege
app/src-tauri/src/loopback_oauth.rs
securityports
app/src-tauri/src/lib.rs
securityports
.dockerignore
dockerlegacy
app/src-tauri/src/meet_audio/audio_bridge.js:71
qualitylegacy
docker-compose.yml:17
dockerlegacy
e2e/Dockerfile:35
dockerlegacy
e2e/Dockerfile:19
dockerlegacy
app/src/components/settings/panels/TeamMembersPanel.tsx:120
qualitylegacy
app/src/components/settings/panels/TeamMembersPanel.tsx:118
qualitylegacy
app/src/components/settings/panels/TeamInvitesPanel.tsx:115
qualitylegacy
app/src/components/settings/panels/TeamInvitesPanel.tsx:114
qualitylegacy
app/src/components/settings/panels/ScreenIntelligencePanel.tsx:128
qualitylegacy
app/src/components/settings/panels/RecoveryPhrasePanel.tsx:397
qualitylegacy
app/src/components/settings/panels/DevicesPanel.tsx:227
qualitylegacy
app/src/components/settings/panels/AutocompletePanel.tsx:7
qualitylegacy
app/src/components/ios/MobileTabBar.tsx:46
qualitylegacy
app/src/components/intelligence/MemoryWorkspace.tsx:420
qualitylegacy
app/src/components/intelligence/MemorySyncConnections.tsx:33
qualitylegacy
app/src/components/intelligence/IntelligenceSubconsciousTab.tsx:381
qualitylegacy
app/src/components/channels/TelegramConfig.tsx:5
qualitylegacy
app/src-tauri/src/whatsapp_scanner/idb.rs:99
qualitylegacy
app/src-tauri/src/whatsapp_scanner/idb.rs:85
qualitylegacy
app/src-tauri/src/wechat_scanner/dom_snapshot.rs:227
qualitylegacy
app/src-tauri/src/telegram_scanner/mod.rs:418
qualitylegacy
app/src-tauri/src/telegram_scanner/mod.rs:381
qualitylegacy
app/src-tauri/src/telegram_scanner/mod.rs:1
qualitylegacy
app/src-tauri/src/telegram_scanner/idb.rs:147
qualitylegacy
app/src-tauri/src/deep_link_ipc_windows.rs:89
qualitylegacy
app/src-tauri/src/telegram_scanner/idb.rs:14
qualitylegacy
app/src-tauri/src/telegram_scanner/dom_snapshot.rs:37
qualitylegacy
app/src-tauri/src/slack_scanner/mod.rs:505
qualitylegacy
app/src-tauri/src/slack_scanner/mod.rs:468
qualitylegacy
app/src-tauri/src/slack_scanner/idb.rs:144
qualitylegacy
app/src-tauri/src/slack_scanner/dom_snapshot.rs:1
qualitylegacy
app/src-tauri/src/meet_video/inject.rs:39
qualitylegacy
app/src-tauri/src/meet_scanner/mod.rs:55
qualitylegacy
app/src-tauri/src/imessage_scanner/mod.rs:321
qualitylegacy
Dockerfile:65
supply-chaindockerpinned-dependencies
Dockerfile:12
supply-chaindockerpinned-dependencies
.github/Dockerfile:1
supply-chaindockerpinned-dependencies
e2e/Dockerfile:14
supply-chaindockerpinned-dependencies
.github/workflows/coverage.yml:29
supply-chaingithub-actionspinned-dependencies
Showing first 300 of 547. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/3117d5b4-46cd-4383-9f7a-e2577ccdb176/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/3117d5b4-46cd-4383-9f7a-e2577ccdb176/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.