Scan timing: clone 1.95s · analysis 4.58s · 1.4 MB · GitHub preflight 673ms
https://github.com/NVIDIA/SkillSpector.git
· scanned 2026-06-18 08:45 UTC (18 hours, 39 minutes ago)
· 10 languages
95 raw signals (60 security + 35 graph) 12th percentile · Python · small (2-20K LoC)
Last scanned 18 hours, 39 minutes ago · v1 · 92 actionable findings from 2 signal sources. 3 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
50.1 | 0.25 | 12.53 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
52.0 | 0.15 | 7.80 |
code_quality |
60.5 | 0.10 | 6.05 |
| Overall | 1.00 | 74.1 |
Showing 51 of 92 actionable findings. 95 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
docs/plans/2026-04-03-skilltrap-integration.md:418
0 TP
·
1 FP
uv.lock
1 TP
·
0 FP
uv.lock
1 TP
·
0 FP
uv.lock
1 TP
·
0 FP
Dockerfile:1, 8 (2 hits)uv.lock
1 TP
·
0 FP
uv.lock
uv.lock
1 TP
·
0 FP
uv.lock
1 TP
·
0 FP
uv.lock
1 TP
·
0 FP
uv.lock
1 TP
·
0 FP
.pre-commit-config.yaml:2
1 TP
·
0 FP
uv.lock
uv.lock
uv.lock
uv.lock
uv.lock
uv.lock
uv.lock
uv.lock
uv.lock
uv.lock
uv.lock
README.md:287
Eval used
README.md:286
Exec used
Dockerfile:9
CI/CD securitycontainers
uv.lock
uv.lock
uv.lock
uv.lock
uv.lock
uv.lock
docs/B.3.2-mcp-tool-poisoning.md:199
uv.lock
uv.lock
.dockerignore
CI/CD securitycontainers
1 TP
·
0 FP
uv.lock
uv.lock
uv.lock
uv.lock
Dockerfile:1, 8 (2 hits)repo-level (2 hits)
This page is publicly accessible at:
https://repobility.com/scan/5af0a74e-3409-4ffe-985d-4356097a0e01/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/5af0a74e-3409-4ffe-985d-4356097a0e01/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.