https://github.com/zts212653/clowder-ai
· scanned 2026-06-05 19:55 UTC (4 days, 14 hours ago)
· 10 languages
1462 raw signals (174 security + 1288 graph) 11/13 scanners ran 68th percentile · Typescript · huge (>500K LoC) System graph score 59 (higher by 28)
Last scanned 4 days, 14 hours ago · v2 · 712 actionable findings from 2 signal sources. 106 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
84.0 | 0.15 | 12.60 |
code_quality |
69.0 | 0.10 | 6.90 |
| Overall | 1.00 | 87.5 |
Showing 368 of 712 actionable findings. 818 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
packages/api/src/domains/cats/services/runtime-session/RedisRuntimeSessionStore.ts:105packages/api/src/domains/cats/services/stores/redis/RedisCommunityIssueStore.ts:96packages/api/src/domains/cats/services/stores/redis/RedisPendingRequestStore.ts:116packages/api/src/utils/cli-resolve.ts:172
packages/api/src/domains/cats/services/agents/providers/catagent/catagent-stream-parser.ts:120packages/api/src/domains/health/ActivityTracker.ts:172packages/api/src/infrastructure/websocket/BroadcastRateMonitor.ts:168scripts/services/tts-api.py:311, 323 (2 hits)scripts/services/tts-api.py:481
scripts/services/qwen3-asr-api.py:96
scripts/services/whisper-api.py:82
scripts/services/embed-api.py:128
scripts/services/llm-postprocess-api.py:141
packages/api/src/routes/threads.ts:538
packages/api/src/routes/config.ts:162
packages/api/src/routes/config.ts:260
packages/api/src/routes/config.ts:294
packages/api/src/routes/config.ts:263
packages/api/src/routes/threads.ts:461
packages/api/src/routes/backlog.ts:327
packages/api/src/routes/backlog.ts:301
packages/api/src/routes/callback-guide-routes.ts:161
packages/api/src/routes/callback-guide-routes.ts:188
packages/api/src/routes/callback-guide-routes.ts:164
packages/api/src/routes/callback-guide-routes.ts:136
packages/api/src/routes/callback-guide-routes.ts:101
packages/api/src/routes/cats.ts:479
packages/api/src/routes/memory-publish.ts:34
packages/api/src/routes/projects-mkdir.ts:17
packages/api/src/routes/session-hooks.ts:81
packages/api/src/routes/session-hooks.ts:267
packages/api/src/routes/task-outcome.ts:89
packages/api/src/routes/task-outcome.ts:69
packages/api/src/routes/task-outcome.ts:79
packages/api/src/routes/task-outcome.ts:99
packages/api/src/routes/threads.ts:253
packages/api/src/routes/threads.ts:683
packages/api/src/routes/config.ts:419
packages/web/package.json:1
packages/mcp-server/src/tools/hub-action-tools.ts:73
packages/api/src/domains/cats/services/agents/providers/antigravity/antigravity-cascade-health.ts:140
packages/api/src/routes/connector-hub.ts:720
.github/workflows/build-windows-desktop.yml:41, 59, 95, 103 (7 hits).github/workflows/ci.yml:28, 30, 41, 43, 56, 58, 70 (7 hits).github/workflows/build-mac-dmg.yml:58, 76, 100 (5 hits).github/workflows/windows-smoke.yml:28, 30 (2 hits).github/workflows/build-mac-dmg.yml:74, 93 (3 hits).github/workflows/build-windows-desktop.yml:57, 86 (3 hits).github/workflows/ci.yml:29, 42, 57 (3 hits).github/workflows/windows-smoke.yml:29packages/web/src/components/UnifiedAuthModal.tsx:313packages/web/src/components/WeComBotSetupPanel.tsx:124packages/web/src/components/hub-accounts.sections.tsx:81scripts/services/embed-api.py:127
securityAuth fastapi unauth mutation
scripts/services/llm-postprocess-api.py:140
securityAuth fastapi unauth mutation
scripts/services/tts-api.py:480
securityAuth fastapi unauth mutation
scripts/services/qwen3-asr-api.py:95
securityAuth fastapi unauth mutation
scripts/services/whisper-api.py:81
securityAuth fastapi unauth mutation
packages/api/src/domains/cats/services/agents/invocation/RedisAuthInvocationBackend.ts:200
Eval used
packages/api/src/domains/cats/services/stores/redis/RedisBacklogStore.ts:693
Eval used
packages/api/src/domains/cats/services/stores/redis/RedisCommunityIssueStore.ts:96
Eval used
packages/api/src/domains/cats/services/stores/redis/RedisPendingRequestStore.ts:116
Eval used
packages/api/src/domains/cats/services/stores/redis/RedisProposalStore.ts:133
Eval used
packages/api/src/domains/cats/services/stores/redis/RedisTaskStore.ts:166
Eval used
packages/api/src/domains/cats/services/stores/redis/RedisThreadStore.ts:347
Eval used
packages/api/src/domains/cats/services/stores/redis/RedisWorkflowSopStore.ts:133
Eval used
packages/api/src/infrastructure/connectors/RedisConnectorThreadBindingStore.ts:106
Eval used
packages/api/src/infrastructure/email/RedisPrTrackingStore.ts:73
Eval used
packages/api/src/services/ApiInstanceLease.ts:142
Eval used
packages/shared/src/utils/redis.ts:110
Eval used
packages/api/src/domains/terminal/tmux-gateway.ts:79
Exec used
scripts/services/whisper-api.py:143
packages/api/src/domains/cats/services/agents/providers/acp/AcpProcessPool.ts:195packages/api/src/domains/cats/services/agents/providers/antigravity/executors/McpToolExecutor.ts:207packages/api/src/domains/cats/services/game/GameNarratorDriver.ts:70cat-cafe-skills/refs/requirements-checklist-template.md:31
cat-cafe-skills/refs/requirements-checklist-template.md:3, 15, 16, 17, 18, 19, 29, 30 (8 hits)cat-cafe-skills/refs/requirements-checklist-template.md:25
cat-cafe-skills/refs/requirements-checklist-template.md:12
packages/mcp-server/src/tools/shell-tools.ts:204
packages/api/src/routes/callback-bootcamp-routes.ts:236
packages/api/src/infrastructure/connectors/adapters/weixin-cdn.ts:220
desktop/service-manager.js:186packages/api/src/domains/cats/services/agents/providers/JobEventConsumer.ts:6packages/api/src/domains/cats/services/agents/providers/codex-session-context-snapshot.ts:2.github/workflows/build-mac-dmg.yml.github/workflows/build-windows-desktop.yml.github/workflows/release-desktop.ymlpackages/web/src/components/MermaidDiagram.tsx:78
Dangerous innerhtml
cat-cafe-skills/hyperfocus-brake/state.sh
Ports
packages/api/src/domains/cats/services/agents/providers/OpenCodeAgentService.ts:131, 193, 260 (3 hits)packages/api/src/domains/cats/services/agents/providers/DareAgentService.ts:113, 174 (2 hits)packages/api/src/domains/cats/services/runtime-session/RuntimeSessionMetadata.ts:256, 258 (2 hits)packages/api/src/domains/memory/FlatScanner.ts:5, 133 (2 hits)packages/api/src/domains/memory/GenericRepoScanner.ts:5, 6 (2 hits)packages/api/src/config/governance/skills-state.ts:67packages/api/src/domains/cats/services/agents/providers/CodexAgentService.ts:499packages/api/src/domains/cats/services/agents/providers/KimiAgentService.ts:108AGENTS.md:1
repo-level (2 hits)package.jsonpackages/finance/package.jsonpackages/shared/package.jsonscripts/services/embed-api.py:270scripts/services/llm-postprocess-api.py:273scripts/services/tts-api.py:559scripts/services/whisper-api.py:200Showing first 300 of 368. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/5b66fd59-9503-4ef3-990f-ff5ca22a2c7d/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/5b66fd59-9503-4ef3-990f-ff5ca22a2c7d/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.