Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

rohitg00/ai-engineering-from-scratch

https://github.com/rohitg00/ai-engineering-from-scratch · scanned 2026-07-23 10:39 UTC (5 days, 4 hours ago)

291 raw signals (0 security + 291 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 5 days, 4 hours ago · v5 · last Δ +7.6 (diff) · 291 actionable findings from 1 signal source. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: severity: critical × excluding tests × Reset all
Scan summary Repository scanned at 48.6/100 with 100.0% coverage. It contains 13609 nodes across 24 cross-layer flows, written primarily in mixed languages. Engine surfaced 291 findings — concentrated in dependencies (94), security (62), quality (59). Risk profile is high: 2 critical, 35 high, 116 medium. Recommended next step: open the dependencies layer findings first — that's where the highest-impact wins live.

Showing 2 of 291 actionable findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

critical System graph security Secrets conf 0.95 Possible secret in phases/15-autonomous-systems/18-llama-guard/code/main.py
Detected 1 occurrence(s) matching openai_or_anthropic_key. Rotate real credentials and move them to a secret manager.
phases/15-autonomous-systems/18-llama-guard/code/main.py:154 Openai or anthropic keyHigh confidence secret
critical System graph security Semgrep conf 1.00 subprocess shell true — phases/19-capstone-projects/01-terminal-native-coding-agent/code/main.py:116
Found 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead. Rule: py…
SecurityPython
For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/4748f4ec-5421-4960-963a-7ccdcd14ecf4/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/4748f4ec-5421-4960-963a-7ccdcd14ecf4/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.