Scan timing: clone 4.83s · analysis 8.99s · 14.7 MB · GitHub API rate-limit (preflight)
https://github.com/cloudflare/agents
· scanned 2026-05-24 01:20 UTC (1 week, 5 days ago)
· 10 languages
3663 findings (99 legacy + 3564 scanner) 38th percentile · Typescript · large (100-500K LoC) Scanner says 55 (higher by 18)
Last scanned 1 week, 5 days ago · v7 · 628 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
80.1 | 0.25 | 20.02 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
62.1 | 0.15 | 9.31 |
practices_score |
71.0 | 0.15 | 10.65 |
code_quality |
49.5 | 0.10 | 4.95 |
| Overall | 1.00 | 72.9 |
Showing 504 of 628 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
packages/codemode/src/iframe-runtime.ts:131
qualitylegacy
packages/ai-chat/e2e/worker.ts:156
secrets
packages/shell/src/git/index.ts:74
secrets
packages/shell/src/git/index.ts:258
secrets
packages/shell/src/git/index.ts:294
secrets
packages/shell/src/git/index.ts:323
secrets
packages/shell/src/prompt.ts:34
qualitylegacy
packages/shell/src/backend.ts:151
qualitylegacy
openai-sdk/chess-app/src/chess.tsx:84
qualitylegacy
packages/agents/src/experimental/memory/session/search.ts:114
xsslegacy
packages/agents/src/experimental/memory/session/providers/postgres-search.ts:67
xsslegacy
experimental/gadgets-subagents/src/server.ts:285
xsslegacy
experimental/gadgets-gatekeeper/src/server.ts:87
qualitylegacy
examples/playground/src/demos/core/sql-agent.ts:56
qualitylegacy
examples/codemode/src/tools.ts:158
qualitylegacy
.github/workflows/release.yml:43
dependencylegacy
.github/workflows/nightly.yml:33
dependencylegacy
.github/workflows/pullrequest.yml:49
dependencylegacy
.github/workflows/pullrequest.yml:33
dependencylegacy
.github/workflows/semgrep.yml:51
dependencylegacy
.github/workflows/release.yml:27
dependencylegacy
.github/workflows/nightly.yml:55
dependencylegacy
.github/workflows/nightly.yml:20
dependencylegacy
.github/workflows/bonk.yml:24
dependencylegacy
.github/workflows/pullrequest.yml:23
dependencylegacy
.github/workflows/semgrep.yml:47
dependencylegacy
.github/workflows/bonk.yml:27
dependencylegacy
.github/workflows/release.yml:56
dependencylegacy
.github/workflows/pullrequest.yml:29
dependencylegacy
examples/mcp-worker-authenticated/src/auth-handler.ts:128
qualitylegacy
.github/workflows/bonk.yml:27
supply-chaingithub-actionspinned-dependencies
examples/playground/src/demos/core/ConnectionsDemo.tsx:133
securitylegacy
examples/mcp-worker-authenticated/src/auth-handler.ts:97
securitylegacy
site/agents/src/components/agent-visual.tsx:186
qualitylegacy
packages/agents/src/browser/shared.ts:244
qualitylegacy
site/ai-playground/src/components/McpServers.tsx:342
authlegacy
site/ai-playground/src/components/McpServers.tsx:70
authlegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
examples/playground/src/demos/core/ScheduleDemo.tsx:98
qualitylegacy
.github/workflows/release.yml:56
supply-chaingithub-actionspinned-dependencies
.github/workflows/bonk.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
packages/agents/src/mcp/utils.ts:791
owaspcors_wildcard
guides/human-in-the-loop/vite.config.ts:8
qualitylegacy
experimental/session-skills/src/server.ts:41
qualitylegacy
experimental/session-skills/src/client.tsx:82
qualitylegacy
experimental/session-skills/src/client.tsx:81
qualitylegacy
Showing first 300 of 504. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/3b58000f-bd23-4495-babe-c5bc135de534/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/3b58000f-bd23-4495-babe-c5bc135de534/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.