https://github.com/thClaws/thClaws
· scanned 2026-05-31 01:25 UTC (5 days, 7 hours ago)
· 10 languages
239 findings (93 legacy + 146 scanner) 11/13 scanners ran 54th percentile · Rust · large (100-500K LoC)
Last scanned 5 days, 7 hours ago · v2 · 177 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
20.0 | 0.20 | 4.00 |
documentation_score |
96.0 | 0.15 | 14.40 |
practices_score |
90.0 | 0.15 | 13.50 |
code_quality |
50.0 | 0.10 | 5.00 |
| Overall | 1.00 | 70.9 |
Showing 121 of 177 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/cargo-audit.yml:25
dependencylegacy
.github/workflows/cargo-audit.yml:19
dependencylegacy
.github/workflows/ci.yml:140
dependencylegacy
.github/workflows/ci.yml:100
dependencylegacy
.github/workflows/ci.yml:68
dependencylegacy
.github/workflows/ci.yml:41
dependencylegacy
.github/workflows/ci.yml:30
dependencylegacy
.github/workflows/ci.yml:150
dependencylegacy
.github/workflows/ci.yml:110
dependencylegacy
.github/workflows/ci.yml:79
dependencylegacy
.github/workflows/ci.yml:45
dependencylegacy
.github/workflows/ci.yml:56
dependencylegacy
.github/workflows/ci.yml:141
dependencylegacy
.github/workflows/ci.yml:101
dependencylegacy
.github/workflows/ci.yml:69
dependencylegacy
.github/workflows/ci.yml:31
dependencylegacy
.github/workflows/cargo-audit.yml:22
dependencylegacy
.github/workflows/ci.yml:42
dependencylegacy
.github/workflows/ci.yml:142
dependencylegacy
.github/workflows/ci.yml:102
dependencylegacy
.github/workflows/ci.yml:72
dependencylegacy
crates/core/assets/gui-shells/session-explorer/main.js:142
xsslegacy
frontend/src/components/TeamView.tsx:95
qualitylegacy
crates/core/src/research/pipeline.rs:1063
owaspeval_used
crates/core/src/workflow/runtime.rs:49
owaspeval_used
frontend/src/components/ShellPicker.tsx:179
error_handlinglegacy
user-manual-th/ch26-gui-shells.md:185
qualitylegacy
user-manual/ch26-gui-shells.md:189
qualitylegacy
docker-compose.yml:20
dockerlegacy
frontend/src/components/ModelPickerModal.tsx:33
qualitylegacy
user-manual-th/ch05-permissions.md:121
dependencylegacy
user-manual-th/ch02-installation.md:270
dependencylegacy
user-manual/ch05-permissions.md:106
dependencylegacy
user-manual-th/ch11-built-in-tools.md:35
dependencylegacy
user-manual/ch11-built-in-tools.md:35
dependencylegacy
.github/workflows/cargo-audit.yml:22
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
frontend/src/components/KmsViewerOverlay.tsx:350
owaspdangerous_innerhtml
.dockerignore
dockerlegacy
docker-compose.yml:20
dockerlegacy
docker-compose.yml:20
dockerlegacy
frontend/src/components/TodoSidebar.tsx:57
qualitylegacy
frontend/src/components/TodoSidebar.tsx:41
qualitylegacy
frontend/src/components/TelegramConnectModal.tsx:111
qualitylegacy
frontend/src/components/Sidebar.tsx:22
qualitylegacy
frontend/src/components/ResearchSidebar.tsx:143
qualitylegacy
frontend/src/components/PlanSidebar.tsx:107
qualitylegacy
frontend/src/components/MessengerConnectModal.tsx:39
qualitylegacy
frontend/src/components/KmsBrowserSidebar.tsx:91
qualitylegacy
crates/core/src/workflow/headless.rs:34
qualitylegacy
crates/core/src/telegram/topic.rs:47
qualitylegacy
crates/core/src/telegram/headless.rs:108
qualitylegacy
crates/core/src/telegram/config.rs:95
qualitylegacy
crates/core/src/telegram/client.rs:259
qualitylegacy
crates/core/src/telegram/approver.rs:108
qualitylegacy
crates/core/src/telegram/approver.rs:51
qualitylegacy
crates/core/src/messenger/config.rs:53
qualitylegacy
crates/core/src/messenger/client.rs:23
qualitylegacy
crates/core/src/messenger/bootstrap.rs:42
qualitylegacy
crates/core/src/messenger/approver.rs:9
qualitylegacy
crates/core/src/gui_shell/serve.rs:118
qualitylegacy
crates/core/src/deploy_client.rs:14
qualitylegacy
frontend/src/components/PlanSidebar.tsx:83
qualitylegacy
frontend/src/components/ModelPickerModal.tsx:179
qualitylegacy
frontend/src/components/MarkdownEditor.tsx:64
qualitylegacy
crates/core/src/tools/pptx_edit.rs:86
qualitylegacy
crates/core/src/tools/pptx_create.rs:216
qualitylegacy
crates/core/src/tools/memory.rs:133
qualitylegacy
crates/core/src/providers/openai_responses.rs:148
qualitylegacy
crates/core/src/providers/ollama_cloud.rs:24
qualitylegacy
Dockerfile:24
supply-chaindockerpinned-dependencies
Dockerfile:43
supply-chaindockerpinned-dependencies
.github/workflows/cargo-audit.yml:25
supply-chaingithub-actionspinned-dependencies
crates/core/src/messenger/config.rs:191
qualitylegacy
crates/core/src/line/config.rs:195
qualitylegacy
crates/core/src/external_url.rs:70
qualitylegacy
frontend/src/hooks/useIPC.ts:46
qualitylegacy
frontend/src/components/SettingsMenu.tsx:68
qualitylegacy
frontend/src/components/TeamView.tsx:253
qualitylegacy
crates/core/src/messenger/client.rs:300
qualitylegacy
crates/core/src/line/protocol.rs:127
qualitylegacy
crates/core/src/cancel.rs:162
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/35c0bd90-7a84-43f2-96fa-aa9e363646bc/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/35c0bd90-7a84-43f2-96fa-aa9e363646bc/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.