Scan timing: clone 18.0s · analysis 105.19s · 24.4 MB · GitHub API rate-limit (preflight)
https://github.com/Open-LLM-VTuber/Open-LLM-VTuber
· scanned 2026-06-04 03:23 UTC (1 day, 11 hours ago)
· 10 languages
463 findings (287 legacy + 176 scanner) 13th percentile · Python · small (2-20K LoC) Scanner says 81 (lower by 35)
Last scanned 1 day, 11 hours ago · v2 · 375 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
100.0 | 0.15 | 15.00 |
security_score |
0.0 | 0.25 | 0.00 |
testing_score |
0.0 | 0.20 | 0.00 |
documentation_score |
95.0 | 0.15 | 14.25 |
practices_score |
78.0 | 0.15 | 11.70 |
code_quality |
57.4 | 0.10 | 5.74 |
| Overall | 1.00 | 46.7 |
Showing 81 of 375 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/open_llm_vtuber/routes.py:141
authowaspauth.fastapi.unauth_mutation
.github/workflows/update-requirements.yml:19
supply-chaingithub-actionspinned-dependencies
.github/workflows/update-requirements.yml:25
supply-chaingithub-actionspinned-dependencies
.github/workflows/codeql.yml:62
supply-chaingithub-actionspinned-dependencies
.github/workflows/codeql.yml:90
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-blacksmith.yml:54
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-blacksmith.yml:85
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-blacksmith.yml:140
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-blacksmith.yml:191
supply-chaingithub-actionspinned-dependencies
.github/workflows/update-requirements.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/docker-blacksmith.yml
supply-chaingithub-actionsleast-privilege
src/open_llm_vtuber/utils/install_utils.py:116
owaspsubprocess_shell_true
upgrade_codes/upgrade_core/upgrade_utils.py:22
owaspsubprocess_shell_true
.github/workflows/update-requirements.yml:15
supply-chaingithub-actionspinned-dependencies
.github/workflows/codeql.yml:58
supply-chaingithub-actionspinned-dependencies
.github/workflows/docker-blacksmith.yml:82
supply-chaingithub-actionspinned-dependencies
.github/workflows/create_release.yml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/create_release.yml:40
supply-chaingithub-actionspinned-dependencies
.github/workflows/create_release.yml:60
supply-chaingithub-actionspinned-dependencies
.github/workflows/create_release.yml:132
supply-chaingithub-actionspinned-dependencies
.github/workflows/create_release.yml:140
supply-chaingithub-actionspinned-dependencies
.github/workflows/create_release.yml:148
supply-chaingithub-actionspinned-dependencies
.github/workflows/create_release.yml:156
supply-chaingithub-actionspinned-dependencies
.github/workflows/create_release.yml:227
supply-chaingithub-actionspinned-dependencies
src/open_llm_vtuber/chat_group.py:138
dead-code
upgrade_codes/upgrade_core/comment_diff_fn.py:41
dead-code
src/open_llm_vtuber/chat_group.py:20
dead-code
src/open_llm_vtuber/agent/transformers.py:165
dead-code
upgrade_codes/config_sync.py:242
dead-code
src/open_llm_vtuber/proxy_handler.py:296
dead-code
src/open_llm_vtuber/utils/sentence_divider.py:144
dead-code
src/open_llm_vtuber/conversations/group_conversation.py:156
dead-code
prompts/prompt_loader.py:57
dead-code
src/open_llm_vtuber/chat_history_manager.py:311
dead-code
src/open_llm_vtuber/asr/asr_interface.py:36
dead-code
src/open_llm_vtuber/live2d_model.py:174
dead-code
src/open_llm_vtuber/mcpp/server_registry.py:93
dead-code
src/open_llm_vtuber/chat_history_manager.py:354
dead-code
src/open_llm_vtuber/config_manager/utils.py:42
dead-code
src/open_llm_vtuber/live/bilibili_live.py:141
dead-code
src/open_llm_vtuber/utils/install_utils.py:133
dead-code
src/open_llm_vtuber/asr/fun_asr.py:103
dead-code
src/open_llm_vtuber/asr/sherpa_onnx_asr.py:215
dead-code
src/open_llm_vtuber/asr/openai_whisper_asr.py:21
dead-code
src/open_llm_vtuber/asr/azure_asr.py:127
dead-code
src/open_llm_vtuber/asr/faster_whisper_asr.py:29
dead-code
src/open_llm_vtuber/asr/groq_whisper_asr.py:20
dead-code
src/open_llm_vtuber/asr/whisper_cpp_asr.py:27
dead-code
src/open_llm_vtuber/tts/pyttsx3_tts.py:46
dead-code
This page is publicly accessible at:
https://repobility.com/scan/42006152-1d92-47d5-9b25-d33bc637259d/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/42006152-1d92-47d5-9b25-d33bc637259d/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.