https://github.com/nexu-io/open-design
· scanned 2026-06-05 09:50 UTC (5 days, 16 hours ago)
· 10 languages
2828 raw signals (212 security + 2616 graph) 11/13 scanners ran 51st percentile · Typescript · huge (>500K LoC) System graph score 60 (higher by 25)
Last scanned 5 days, 16 hours ago · v2 · 1232 actionable findings from 2 signal sources. 278 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
81.0 | 0.15 | 12.15 |
code_quality |
45.0 | 0.10 | 4.50 |
| Overall | 1.00 | 84.7 |
Showing 569 of 1232 actionable findings. 1510 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
design-templates/last30days/scripts/lib/pipeline.py:545
skills/hatch-pet/scripts/validate_atlas.py:105
.github/workflows/landing-page-ci.yml:203, 204 (2 hits)apps/landing-page/scripts/blog-indexing/render-status.ts:170
design-templates/last30days/scripts/lib/providers.py:47, 88 (2 hits)design-templates/last30days/scripts/lib/ui.py:250apps/daemon/src/project-routes.ts:1420
apps/daemon/src/project-routes.ts:1583
apps/daemon/src/project-routes.ts:1677
apps/daemon/src/project-routes.ts:2075
apps/daemon/src/terminal-routes.ts:108
apps/daemon/src/project-routes.ts:1809
apps/daemon/src/project-routes.ts:1313
apps/daemon/src/project-routes.ts:1574
apps/daemon/src/project-routes.ts:1652
apps/daemon/src/project-routes.ts:1863
apps/daemon/src/project-routes.ts:1837
apps/daemon/src/project-routes.ts:946
apps/daemon/src/project-routes.ts:1056
apps/daemon/src/project-routes.ts:1487
apps/daemon/src/project-routes.ts:1633
apps/daemon/src/project-routes.ts:2051
apps/daemon/src/terminal-routes.ts:49
apps/daemon/src/terminal-routes.ts:107
apps/daemon/src/terminal-routes.ts:90
apps/daemon/src/terminal-routes.ts:79
apps/daemon/src/project-routes.ts:1745
apps/daemon/src/project-routes.ts:1823
apps/daemon/src/project-routes.ts:915
apps/daemon/src/project-routes.ts:1602
apps/daemon/src/project-routes.ts:1705
tools/pack/resources/win/7zip/7z.dll:1
tools/pack/resources/win/7zip/7z.exe:1
.github/scripts/agent-pr-explore-local.sh:53
.claude/skills/od-contribute/scripts/check-prereqs.sh:87
apps/daemon/src/plugins/snapshot-diff.ts:77
apps/daemon/src/server.ts:5484
apps/web/src/components/SettingsDialog.tsx:4824
.github/workflows/metrics.yml:31
CI/CD securitySupply chainGithub actions
apps/desktop/src/main/index.ts:496
Eval used
apps/desktop/src/main/runtime.ts:314
Eval used
apps/daemon/src/critique/artifact-handler.ts:208apps/daemon/src/critique/artifact-writer.ts:121apps/daemon/src/document-preview.ts:99apps/web/src/components/SocialShareGrid.tsx:82
design-templates/html-ppt/assets/animations/fx/knowledge-graph.js:20
apps/web/src/components/PrivacySection.tsx:19
apps/daemon/src/runtimes/defs/trae-cli.ts:19
CI/CD securityagent runtimepermissions
apps/daemon/src/runtimes/defs/gemini.ts:23
CI/CD securityagent runtimepermissions
design-templates/last30days/scripts/lib/pipeline.py:287, 307, 365, 389, 670, 697, 823, 867, +2 more (10 hits)design-templates/last30days/scripts/lib/env.py:342, 574 (2 hits)design-templates/last30days/scripts/lib/quality_nudge.py:39, 93 (2 hits)design-templates/last30days/scripts/lib/reddit_public.py:278, 286 (2 hits)design-templates/last30days/scripts/last30days.py:784design-templates/last30days/scripts/lib/bird_x.py:188design-templates/last30days/scripts/lib/fanout.py:60design-templates/last30days/scripts/lib/polymarket.py:358.github/scripts/provision-agent-pr-explore-runner.sh:28
design-templates/web-prototype-taste-soft/example.html:529
apps/daemon/src/design-system-showcase.ts:369
apps/daemon/src/prompts/deck-framework.ts:287
.well-known/security.txt
.claude/skills/od-contribute/install.sh:10README.md:302apps/daemon/src/runtimes/defs/grok-build.ts:5.github/workflows/docker-image.yml:24, 29, 33, 41, 56 (5 hits).github/workflows/landing-page-production.yml:56, 152 (4 hits).github/workflows/release-beta.yml:195, 370, 440, 614 (4 hits).github/workflows/release-preview.yml:87, 123, 331, 402 (4 hits).github/workflows/release-stable.yml:188, 242, 457, 531 (4 hits).github/workflows/blog-3day-report.yml:54, 176 (2 hits).github/workflows/blog-indexing-monitor.yml:52, 275 (2 hits).github/workflows/blog-indexing-on-deploy.yml:70, 265 (2 hits).github/workflows/blog-indexing-on-deploy.yml.github/workflows/docker-image.yml.github/workflows/notify-release-feishu.yml.github/workflows/release-stable.ymlapps/web/app/layout.tsx:36
Dangerous innerhtml
apps/web/src/components/FileViewer.tsx:10052
Dangerous innerhtml
apps/web/src/components/IframeKeepAlivePool.tsx:323
Dangerous innerhtml
tools/pack/src/win/sign.ts:149
Weak hash
.github/workflows/e2e-coverage-reminder.yml
Ports
.github/workflows/e2e-coverage-reminder.yml
Ports
.dockerignore
CI/CD securitycontainers
tools/pack/docker-compose.yml:20
CI/CD securitycontainers
tools/pack/docker-compose.yml:20
CI/CD securitycontainers
apps/daemon/src/tools-live-artifacts-cli.ts:33, 146 (2 hits)apps/web/sidecar/server.ts:290, 553 (2 hits).github/scripts/release/r2/publish-platform.ts:11.github/scripts/release/r2/verify-beta-metadata.ts:1apps/daemon/src/copilot-stream.ts:8apps/daemon/src/critique/interrupt-handler.ts:17apps/daemon/src/design-system-showcase.ts:574apps/daemon/src/live-artifacts/schema.ts:160llms.txt
humans.txt
sitemap.xml
apps/landing-page/app/_lib/home-copy.ts:1
.github/workflows/release-beta.yml:127, 133, 190, 200, 291, 317, 353, 365, +8 more (18 hits).github/workflows/release-preview.yml:50, 55, 82, 92, 118, 128, 270, 296, +8 more (16 hits).github/workflows/release-stable.yml:128, 134, 182, 193, 236, 247, 394, 420, +8 more (16 hits).github/workflows/ci.yml:144, 216, 227, 266, 325, 371, 399, 419, +2 more (10 hits).github/workflows/landing-page-production.yml:47, 61, 77, 85 (8 hits).github/workflows/landing-page-ci.yml:79, 88, 214 (6 hits).github/workflows/ui-extended-main.yml:76, 101, 130, 155, 174, 199 (6 hits).github/workflows/visual-pr-comment.yml:40, 52, 58, 247, 261, 373 (6 hits)apps/web/src/runtime/srcdoc.ts:109
Document write
repo-level (9 hits)repo-level (2 hits)repo-level (2 hits)Showing first 300 of 569. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/4f01aef0-39c8-44fa-a798-a497d4fe9632/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/4f01aef0-39c8-44fa-a798-a497d4fe9632/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.