Scan timing: clone 3.86s · analysis 6.76s · 3.4 MB · GitHub preflight 670ms
https://github.com/nicobailon/pi-subagents.git
· scanned 2026-06-01 04:21 UTC (4 days, 4 hours ago)
· 10 languages
102 findings (34 legacy + 68 scanner) 69th percentile · Typescript · medium (20-100K LoC) Scanner says 94 (lower by 14)
Last scanned 4 days, 4 hours ago · v2 · 68 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
100.0 | 0.15 | 15.00 |
security_score |
85.0 | 0.25 | 21.25 |
testing_score |
90.0 | 0.20 | 18.00 |
documentation_score |
52.0 | 0.15 | 7.80 |
practices_score |
72.0 | 0.15 | 10.80 |
code_quality |
67.4 | 0.10 | 6.74 |
| Overall | 1.00 | 79.6 |
Showing 56 of 68 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/runs/shared/long-running-guard.ts:162
qualitylegacy
src/runs/background/run-id-resolver.ts:80
xsslegacy
src/extension/doctor.ts:102
xsslegacy
src/agents/agent-serializer.ts:41
xsslegacy
src/shared/artifacts.ts:20
path_traversallegacy
src/runs/shared/single-output.ts:29
path_traversallegacy
src/extension/doctor.ts:109
path_traversallegacy
.github/workflows/release.yml:18
dependencylegacy
.github/workflows/release.yml:19
dependencylegacy
.github/workflows/release.yml:18
dependencylegacy
.github/workflows/release.yml:19
dependencylegacy
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
src/slash/slash-bridge.ts:142
qualitylegacy
src/runs/shared/nested-events.ts:726
qualitylegacy
src/intercom/intercom-bridge.ts:120
qualitylegacy
src/extension/index.ts:188
qualitylegacy
package.json
dependencylegacy
package.json
dependencylegacy
package.json
dependencylegacy
package.json
dependencylegacy
src/runs/background/top-level-async.ts:11
qualitylegacy
src/runs/background/result-watcher.ts:193
qualitylegacy
src/agents/chain-serializer.ts:97
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/5767aa70-e926-4344-8830-617ecf01445e/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/5767aa70-e926-4344-8830-617ecf01445e/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.