https://github.com/assistant-ui/assistant-ui
· scanned 2026-05-31 01:25 UTC (5 days, 7 hours ago)
· 10 languages
743 findings (190 legacy + 553 scanner) 11/13 scanners ran 59th percentile · Typescript · large (100-500K LoC) Scanner says 60 (higher by 16)
Last scanned 5 days, 7 hours ago · v2 · last Δ +0.7 (diff) · 470 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
59.0 | 0.20 | 11.80 |
documentation_score |
84.0 | 0.15 | 12.60 |
practices_score |
70.0 | 0.15 | 10.50 |
code_quality |
72.0 | 0.10 | 7.20 |
| Overall | 1.00 | 76.1 |
Showing 334 of 470 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
examples/with-chain-of-thought/app/page.tsx:23
qualitylegacy
python/assistant-stream/src/assistant_stream/create_run.py:216
qualitylegacy
.github/workflows/claude-code-review.yml:117
dependencylegacy
.github/workflows/code-quality.yaml:120
dependencylegacy
.github/workflows/code-quality.yaml:76
dependencylegacy
apps/docs/app/(home)/blog/llms.md/[slug]/route.ts:13
authlegacy
packages/assistant-stream/src/resumable/stores/InMemoryResumableStreamStore.ts:90
qualitylegacy
python/assistant-transport-backend/setup.py:31
qualitylegacy
python/assistant-ui-sync-server-api/src/assistant_ui/client.py:388
qualitylegacy
python/assistant-ui-sync-server-api/src/assistant_ui/client.py:410
qualitylegacy
python/assistant-ui-sync-server-api/src/assistant_ui/client.py:411
qualitylegacy
python/assistant-ui-sync-server-api/src/assistant_ui/client.py:389
qualitylegacy
python/assistant-ui-sync-server-api/src/assistant_ui/client.py:451
qualitylegacy
python/assistant-ui-sync-server-api/src/assistant_ui/client.py:443
qualitylegacy
examples/with-ag-ui/server/agent.py:126
qualitylegacy
python/assistant-stream-hello-world/api/chat/completions/index.py:14
qualitylegacy
python/assistant-transport-backend/main.py:93
qualitylegacy
python/assistant-transport-backend-langgraph/main.py:302
qualitylegacy
examples/with-mcp/server/server.ts:226
qualitylegacy
.github/workflows/code-quality.yaml:94
dependencylegacy
.github/workflows/registry.yaml:39
dependencylegacy
.github/workflows/devtools-frame.yaml:39
dependencylegacy
.github/workflows/expo.yaml:42
dependencylegacy
.github/workflows/code-quality.yaml:80
dependencylegacy
.github/workflows/code-quality.yaml:64
dependencylegacy
.github/workflows/code-quality.yaml:39
dependencylegacy
.github/workflows/claude.yml:63
dependencylegacy
.github/workflows/registry.yaml:25
dependencylegacy
.github/workflows/devtools-frame.yaml:25
dependencylegacy
.github/workflows/expo.yaml:28
dependencylegacy
.github/workflows/claude-code-review.yml:109
dependencylegacy
.github/workflows/claude.yml:31
dependencylegacy
.github/workflows/code-quality.yaml:88
dependencylegacy
.github/workflows/code-quality.yaml:47
dependencylegacy
.github/workflows/registry.yaml:33
dependencylegacy
.github/workflows/devtools-frame.yaml:33
dependencylegacy
.github/workflows/expo.yaml:36
dependencylegacy
.github/workflows/claude.yml:69
dependencylegacy
.github/workflows/claude-code-review.yml:115
dependencylegacy
.github/workflows/code-quality.yaml:85
dependencylegacy
.github/workflows/code-quality.yaml:44
dependencylegacy
.github/workflows/registry.yaml:30
dependencylegacy
.github/workflows/devtools-frame.yaml:30
dependencylegacy
.github/workflows/expo.yaml:33
dependencylegacy
apps/docs/components/docs/fumadocs/install/install-command.tsx:60
xsslegacy
apps/docs/components/careers/apply-form.tsx:31
xsslegacy
apps/docs/app/tw-glass/(home)/doc-components.tsx:61
xsslegacy
packages/cli/src/commands/doctor.ts:188
qualitylegacy
examples/with-ffmpeg/app/page.tsx:82
qualitylegacy
apps/docs/components/docs/preview-code.server.tsx:88
qualitylegacy
python/assistant-transport-backend/main.py:92
authowaspauth.fastapi.unauth_mutation
python/assistant-stream-hello-world/api/chat/completions/index.py:13
authowaspauth.fastapi.unauth_mutation
python/assistant-transport-backend-langgraph/main.py:301
authowaspauth.fastapi.unauth_mutation
packages/assistant-stream/src/resumable/stores/redis.ts:22
owaspexec_used
.github/workflows/changeset-semver-check.yaml
supply-chaingithub-actionspull-request-target
apps/docs/app/(home)/blog/llms.md/[slug]/route.ts:13
authlegacy
apps/docs/app/(home)/llms-full.txt/route.ts:7
authlegacy
apps/docs/app/(home)/llms.mdx/[[...slug]]/route.ts:8
authlegacy
apps/docs/app/(home)/llms.txt/route.ts:6
authlegacy
apps/docs/app/api/chat/route.ts:39
authlegacy
apps/registry/app/api/chat/route.ts:10
authlegacy
apps/docs/app/api/doc/chat/route.ts:296
authlegacy
apps/docs/app/api/playground-chat/route.ts:137
authlegacy
packages/cloud-ai-sdk/src/core/CloudTelemetryReporter.ts:81
error_handlinglegacy
packages/cloud-ai-sdk/src/core/CloudChatCore.ts:107
error_handlinglegacy
packages/assistant-stream/src/resumable/ResumableStreamContext.ts:184
error_handlinglegacy
python/assistant-stream/src/assistant_stream/serialization/openai_stream.py:30
qualitylegacy
python/assistant-ui-sync-server-api/examples/basic_example.py:162
qualitylegacy
python/assistant-ui-sync-server-api/examples/basic_example.py:128
qualitylegacy
python/assistant-ui-sync-server-api/examples/basic_example.py:68
qualitylegacy
python/assistant-ui-sync-server-api/examples/basic_example.py:199
qualitylegacy
python/assistant-ui-sync-server-api/examples/basic_example.py:37
qualitylegacy
python/assistant-transport-backend/main.py:139
qualitylegacy
python/assistant-transport-backend/setup.py:140
qualitylegacy
python/assistant-transport-backend/setup.py:146
qualitylegacy
examples/with-ag-ui/server/agent.py:119
qualitylegacy
python/assistant-transport-backend/setup.py:31
injectionlegacy
packages/react/src/mcp-apps/McpAppRenderer.tsx:82
securitylegacy
packages/react-mcp/src/auth/createOAuthProvider.ts:128
qualitylegacy
templates/minimal/app/assistant.tsx:15
qualitylegacy
templates/mcp/app/assistant.tsx:43
qualitylegacy
templates/mcp/app/assistant.tsx:36
qualitylegacy
templates/default/app/assistant.tsx:30
qualitylegacy
templates/cloud-clerk/app/assistant.tsx:51
qualitylegacy
templates/cloud/app/assistant.tsx:36
qualitylegacy
packages/react-google-adk/src/AdkClient.ts:46
qualitylegacy
packages/react-google-adk/src/AdkClient.ts:11
qualitylegacy
apps/registry/app/ai-sdk/assistant.tsx:15
qualitylegacy
apps/docs/contexts/AssistantRuntimeProvider.tsx:169
qualitylegacy
apps/docs/components/home/star-pill.tsx:13
qualitylegacy
apps/docs/components/builder/builder-chat-sidebar.tsx:116
qualitylegacy
apps/docs/app/robots.ts:8
qualitylegacy
apps/docs/app/layout.tsx:57
qualitylegacy
apps/docs/app/layout.tsx:45
qualitylegacy
apps/docs/hooks/use-persistent-boolean.ts:62
qualitylegacy
apps/docs/components/docs/platform/context.tsx:195
qualitylegacy
.github/workflows/claude-code-review.yml:115
supply-chaingithub-actionspinned-dependencies
.github/workflows/expo.yaml:33
supply-chaingithub-actionspinned-dependencies
.github/workflows/devtools-frame.yaml:30
supply-chaingithub-actionspinned-dependencies
.github/workflows/registry.yaml:30
supply-chaingithub-actionspinned-dependencies
.github/workflows/claude.yml:69
supply-chaingithub-actionspinned-dependencies
.github/workflows/code-quality.yaml:44
supply-chaingithub-actionspinned-dependencies
.github/workflows/code-quality.yaml:85
supply-chaingithub-actionspinned-dependencies
.github/workflows/code-quality.yaml:130
supply-chaingithub-actionspinned-dependencies
.github/workflows/autofix.yaml:18
supply-chaingithub-actionspinned-dependencies
.github/workflows/npm-publish.yaml
supply-chaingithub-actionsleast-privilege
.github/workflows/pypi-publish.yaml
supply-chaingithub-actionsleast-privilege
.github/workflows/claude-code-review.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/traction.yaml
supply-chaingithub-actionsleast-privilege
.github/workflows/changeset.yaml
supply-chaingithub-actionsleast-privilege
.github/workflows/claude.yml
supply-chaingithub-actionsleast-privilege
python/assistant-transport-backend-langgraph/main.py:291
owaspcors_wildcard
apps/docs/app/layout.tsx:77
owaspdangerous_innerhtml
packages/ui/src/components/ui/chart.tsx:95
owaspdangerous_innerhtml
python/assistant-transport-backend/setup.py:31
owaspsubprocess_shell_true
packages/react-ag-ui/src/useAgUiRuntime.ts:65
qualitylegacy
packages/react-ag-ui/src/runtime/AgUiThreadRuntimeCore.ts:121
qualitylegacy
packages/core/src/types/index.ts:1
qualitylegacy
packages/core/src/store/runtime-clients/message-runtime-client.ts:110
qualitylegacy
packages/core/src/store/clients/thread-message-client.ts:31
qualitylegacy
packages/core/src/runtimes/remote-thread-list/empty-thread-core.ts:128
qualitylegacy
packages/core/src/runtimes/readonly/ReadonlyThreadRuntimeCore.ts:145
qualitylegacy
packages/core/src/react/runtimes/cloud/AssistantCloudThreadHistoryAdapter.ts:170
qualitylegacy
packages/core/src/react/primitives/message/MessageAttachments.tsx:31
qualitylegacy
packages/cli/src/codemods/v0-9/edge-package-split.ts:37
qualitylegacy
packages/assistant-stream/src/resumable/stores/redis.ts:57
qualitylegacy
packages/assistant-stream/src/core/utils/stream/SSE.ts:25
qualitylegacy
packages/assistant-stream/src/core/serialization/ui-message-stream/UIMessageStream.ts:21
qualitylegacy
apps/social-media/src/launches/react-native.tsx:241
qualitylegacy
apps/social-media/src/launches/react-native.tsx:238
qualitylegacy
apps/social-media/src/launches/react-ink.tsx:191
qualitylegacy
apps/social-media/src/launches/cloud-dashboard.tsx:9
qualitylegacy
.github/workflows/claude-code-review.yml:109
supply-chaingithub-actionspinned-dependencies
.github/workflows/expo.yaml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/expo.yaml:36
supply-chaingithub-actionspinned-dependencies
.github/workflows/expo.yaml:42
supply-chaingithub-actionspinned-dependencies
.github/workflows/devtools-frame.yaml:25
supply-chaingithub-actionspinned-dependencies
.github/workflows/devtools-frame.yaml:33
supply-chaingithub-actionspinned-dependencies
.github/workflows/devtools-frame.yaml:39
supply-chaingithub-actionspinned-dependencies
.github/workflows/registry.yaml:25
supply-chaingithub-actionspinned-dependencies
.github/workflows/registry.yaml:33
supply-chaingithub-actionspinned-dependencies
.github/workflows/registry.yaml:39
supply-chaingithub-actionspinned-dependencies
.github/workflows/claude.yml:31
supply-chaingithub-actionspinned-dependencies
.github/workflows/claude.yml:63
supply-chaingithub-actionspinned-dependencies
.github/workflows/code-quality.yaml:39
supply-chaingithub-actionspinned-dependencies
.github/workflows/code-quality.yaml:47
supply-chaingithub-actionspinned-dependencies
.github/workflows/code-quality.yaml:64
supply-chaingithub-actionspinned-dependencies
.github/workflows/code-quality.yaml:80
supply-chaingithub-actionspinned-dependencies
.github/workflows/code-quality.yaml:88
supply-chaingithub-actionspinned-dependencies
.github/workflows/code-quality.yaml:94
supply-chaingithub-actionspinned-dependencies
.github/workflows/code-quality.yaml:125
supply-chaingithub-actionspinned-dependencies
.github/workflows/code-quality.yaml:133
supply-chaingithub-actionspinned-dependencies
.github/workflows/code-quality.yaml:139
supply-chaingithub-actionspinned-dependencies
.github/workflows/changeset-semver-check.yaml:19
supply-chaingithub-actionspinned-dependencies
.github/workflows/autofix.yaml:13
supply-chaingithub-actionspinned-dependencies
.github/workflows/autofix.yaml:21
supply-chaingithub-actionspinned-dependencies
package.json
supply-chainnpminstall-scripts
apps/docs/package.json
supply-chainnpminstall-scripts
python/assistant-stream/src/assistant_stream/create_run.py:106
dead-code
python/assistant-stream/src/assistant_stream/create_run.py:116
dead-code
python/assistant-stream/src/assistant_stream/create_run.py:88
dead-code
python/assistant-transport-backend-langgraph/main.py:149
dead-code
python/assistant-ui-sync-server-api/src/assistant_ui/client.py:269
dead-code
examples/with-livekit/agent/agent.py:29
dead-code
python/assistant-stream/src/assistant_stream/state_proxy.py:334
dead-code
python/assistant-stream/src/assistant_stream/state_proxy.py:233
dead-code
python/assistant-stream/src/assistant_stream/state_proxy.py:338
dead-code
python/assistant-stream/src/assistant_stream/state_proxy.py:354
dead-code
python/assistant-stream/src/assistant_stream/state_proxy.py:344
dead-code
python/assistant-transport-backend/setup.py:125
dead-code
python/assistant-stream/src/assistant_stream/modules/tool_call.py:42
dead-code
python/assistant-transport-backend-langgraph/main.py:181
dead-code
python/assistant-transport-backend-langgraph/main.py:104
dead-code
python/assistant-transport-backend-langgraph/main.py:195
dead-code
python/assistant-stream/src/assistant_stream/create_run.py:48
dead-code
Showing first 300 of 334. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/40f38723-8cd5-46aa-827b-ef4ee31632f0/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/40f38723-8cd5-46aa-827b-ef4ee31632f0/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.