Scan timing: clone 8.85s · analysis 43.23s · 121.6 MB · GitHub API rate-limit (preflight)
https://github.com/CopilotKit/CopilotKit
· scanned 2026-06-06 00:02 UTC (4 days, 1 hour ago)
· 10 languages
6546 raw signals (438 security + 6108 graph) 10/13 scanners ran 37th percentile · Typescript · huge (>500K LoC) System graph score 52 (higher by 30)
Last scanned 4 days, 1 hour ago · v2 · 3044 actionable findings from 2 signal sources. 448 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
78.0 | 0.20 | 15.60 |
documentation_score |
95.0 | 0.15 | 14.25 |
practices_score |
78.0 | 0.15 | 11.70 |
code_quality |
61.0 | 0.10 | 6.10 |
| Overall | 1.00 | 81.6 |
Showing 916 of 3044 actionable findings. 3492 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
examples/integrations/mcp-apps/threejs-server/src/threejs-app.tsx:152examples/showcases/generative-ui-playground/mcp-server/src/calculator.ts:79examples/showcases/open-mcp-client/apps/threejs-server/src/threejs-app.tsx:152.github/workflows/publish-release.yml:698
examples/integrations/agentcore/agents/utils/auth.py:64
.github/workflows/test_e2e-dojo.yml:298, 299, 311, 312, 313 (5 hits).github/workflows/showcase_validate.yml:43, 511, 686, 709 (4 hits).github/workflows/publish-release.yml:669, 802, 845 (3 hits).github/workflows/test_smoke-starter.yml:43, 77, 185 (3 hits).github/workflows/showcase_eval_check.yml:25, 108 (2 hits).github/workflows/showcase_lint_prod.yml:54.github/workflows/social_copy-generator.yml:264packages/react-core/src/hooks/use-copilot-chat-headless_c.ts:30
showcase/harness/src/cli/config.ts:47
showcase/harness/src/http/probes.ts:237
showcase/harness/src/http/probes.ts:293
examples/integrations/agentcore/infra-cdk/lambdas/oauth2-provider/index.py:69
examples/showcases/generative-ui-playground/mcp-server/src/calculator.ts:131
showcase/integrations/crewai-crews/src/agents/subagents.py:342, 351, 355, 370, 405, 420, 429, 451, +3 more (11 hits)showcase/integrations/crewai-crews/src/agents/shared_state_read_write.py:157, 164, 180, 185, 198, 221, 241, 244, +1 more (9 hits)showcase/integrations/crewai-crews/src/agents/tool_rendering.py:100, 105, 118, 138, 147 (5 hits)showcase/integrations/claude-sdk-python/src/agents/agent.py:880
showcase/integrations/langroid/src/agent_server.py:74
showcase/integrations/claude-sdk-python/src/agent_server.py:367
showcase/integrations/langroid/src/agent_server.py:158
showcase/integrations/claude-sdk-python/src/agent_server.py:170
examples/showcases/deep-agents-job-search/agent/main.py:47
showcase/integrations/claude-sdk-python/src/agent_server.py:147
showcase/integrations/langroid/src/agent_server.py:137
showcase/integrations/claude-sdk-python/src/agent_server.py:136
showcase/integrations/langroid/src/agent_server.py:148
showcase/integrations/claude-sdk-python/src/agent_server.py:347
showcase/integrations/langroid/src/agent_server.py:101
showcase/integrations/claude-sdk-python/src/agent_server.py:304
showcase/integrations/claude-sdk-python/src/agent_server.py:324
showcase/integrations/claude-sdk-python/src/agent_server.py:257
showcase/integrations/langroid/src/agent_server.py:174
showcase/integrations/claude-sdk-python/src/agent_server.py:158
showcase/integrations/langroid/src/agent_server.py:126
showcase/integrations/claude-sdk-python/src/agent_server.py:210
showcase/integrations/langroid/src/agent_server.py:89
showcase/integrations/claude-sdk-python/src/agent_server.py:185
showcase/integrations/langroid/src/agent_server.py:114
showcase/integrations/claude-sdk-python/src/agent_server.py:284
showcase/integrations/claude-sdk-python/src/agent_server.py:235
showcase/integrations/claude-sdk-typescript/src/agent/index.ts:141
showcase/integrations/claude-sdk-typescript/src/agent_server.ts:1089
showcase/integrations/claude-sdk-typescript/src/agent_server.ts:1192
showcase/integrations/claude-sdk-typescript/src/agent_server.ts:1116
showcase/integrations/claude-sdk-typescript/src/agent_server.ts:1097
showcase/integrations/claude-sdk-typescript/src/agent_server.ts:1093
showcase/integrations/claude-sdk-typescript/src/agent_server.ts:1207
showcase/integrations/claude-sdk-typescript/src/agent_server.ts:1103
showcase/integrations/claude-sdk-typescript/src/agent_server.ts:1136
showcase/integrations/claude-sdk-typescript/src/agent_server.ts:1149
showcase/integrations/claude-sdk-typescript/src/agent_server.ts:1173
showcase/integrations/langgraph-fastapi/Dockerfile:2, 16, 28 (3 hits)showcase/integrations/pydantic-ai/Dockerfile:2, 18, 30 (3 hits)showcase/integrations/strands/Dockerfile:4, 20, 32 (3 hits)showcase/shell-dashboard/Dockerfile:1, 45, 52 (3 hits)showcase/eval-webhook/Dockerfile:1, 11 (2 hits)showcase/harness/Dockerfile:1, 65 (2 hits)showcase/pocketbase/Dockerfile:7, 34 (2 hits)showcase/shell-docs/Dockerfile:1, 31 (2 hits)examples/v1/_legacy/copilot-openai-mongodb-atlas-vector-search/package.json:1examples/v2/angular/demo/package.json:1showcase/integrations/built-in-agent/package.json:1showcase/integrations/built-in-agent/package-lock.json:1
examples/v2/react-native/demo/android/gradle/wrapper/gradle-wrapper.jar:1
examples/integrations/ms-agent-framework-dotnet/agent/Program.cs:58
examples/integrations/agentcore/deploy-strands.sh:53
examples/integrations/agentcore/deploy-langgraph.sh:54
examples/integrations/_intelligence/docker-compose.yml:65, 125 (2 hits)examples/integrations/_intelligence/docker-compose.yml:19, 41 (2 hits)examples/showcases/deep-agents-finance-erp/docker-compose.yml:1examples/integrations/adk/Dockerfile:19examples/integrations/agno/Dockerfile:26examples/integrations/crewai-crews/Dockerfile:19examples/integrations/langgraph-fastapi/Dockerfile:29examples/integrations/langgraph-python/Dockerfile:29examples/integrations/llamaindex/Dockerfile:26examples/integrations/ms-agent-framework-dotnet/Dockerfile:33examples/integrations/ms-agent-framework-python/Dockerfile:23showcase/shell-dashboard/src/components/pb-auth-prompt.tsx:100
showcase/integrations/claude-sdk-python/src/agent_server.py:366
securityAuth fastapi unauth mutation
showcase/integrations/claude-sdk-python/src/agent_server.py:169
securityAuth fastapi unauth mutation
showcase/integrations/claude-sdk-python/src/agent_server.py:146
securityAuth fastapi unauth mutation
showcase/integrations/claude-sdk-python/src/agent_server.py:135
securityAuth fastapi unauth mutation
showcase/integrations/claude-sdk-python/src/agent_server.py:346
securityAuth fastapi unauth mutation
showcase/integrations/claude-sdk-python/src/agent_server.py:303
securityAuth fastapi unauth mutation
showcase/integrations/claude-sdk-python/src/agent_server.py:323
securityAuth fastapi unauth mutation
showcase/integrations/claude-sdk-python/src/agent_server.py:256
securityAuth fastapi unauth mutation
showcase/integrations/claude-sdk-python/src/agent_server.py:157
securityAuth fastapi unauth mutation
showcase/integrations/claude-sdk-python/src/agent_server.py:209
securityAuth fastapi unauth mutation
showcase/integrations/langroid/src/agent_server.py:157
securityAuth fastapi unauth mutation
showcase/integrations/claude-sdk-python/src/agents/agent.py:879
securityAuth fastapi unauth mutation
showcase/integrations/langroid/src/agent_server.py:73
securityAuth fastapi unauth mutation
showcase/integrations/langroid/src/agent_server.py:136
securityAuth fastapi unauth mutation
showcase/integrations/langroid/src/agent_server.py:147
securityAuth fastapi unauth mutation
showcase/integrations/langroid/src/agent_server.py:100
securityAuth fastapi unauth mutation
showcase/integrations/langroid/src/agent_server.py:173
securityAuth fastapi unauth mutation
showcase/integrations/langroid/src/agent_server.py:125
securityAuth fastapi unauth mutation
showcase/integrations/langroid/src/agent_server.py:88
securityAuth fastapi unauth mutation
showcase/integrations/langroid/src/agent_server.py:113
securityAuth fastapi unauth mutation
showcase/integrations/claude-sdk-python/src/agent_server.py:184
securityAuth fastapi unauth mutation
showcase/integrations/claude-sdk-python/src/agent_server.py:283
securityAuth fastapi unauth mutation
showcase/integrations/claude-sdk-python/src/agent_server.py:234
securityAuth fastapi unauth mutation
showcase/aimock/d6/ag2/recorded.json:96
Eval used
showcase/aimock/d6/agno/gen-ui-open.json:47
Eval used
showcase/aimock/d6/agno/recorded.json:97
Eval used
showcase/aimock/d6/built-in-agent/gen-ui-open.json:48
Eval used
showcase/aimock/d6/built-in-agent/recorded.json:97
Eval used
showcase/aimock/d6/claude-sdk-python/recorded.json:97
Eval used
showcase/aimock/d6/claude-sdk-typescript/recorded.json:97
Eval used
showcase/aimock/d6/crewai-crews/recorded.json:97
Eval used
showcase/aimock/d6/google-adk/recorded.json:96
Eval used
showcase/aimock/d6/langgraph-fastapi/recorded.json:97
Eval used
showcase/aimock/d6/langgraph-python/recorded.json:96
Eval used
showcase/aimock/d6/langgraph-typescript/recorded.json:97
Eval used
showcase/aimock/d6/langroid/gen-ui-open.json:48
Eval used
showcase/aimock/d6/langroid/recorded.json:97
Eval used
showcase/aimock/d6/llamaindex/recorded.json:97
Eval used
showcase/aimock/d6/mastra/recorded.json:97
Eval used
showcase/aimock/d6/ms-agent-dotnet/recorded.json:97
Eval used
showcase/aimock/d6/ms-agent-python/recorded.json:97
Eval used
showcase/aimock/d6/pydantic-ai/recorded.json:97
Eval used
showcase/aimock/d6/spring-ai/gen-ui-open.json:48
Eval used
showcase/aimock/d6/spring-ai/recorded.json:97
Eval used
showcase/aimock/d6/strands/recorded.json:97
Eval used
showcase/harness/src/http/probes.ts:293
showcase/integrations/claude-sdk-typescript/src/app/api/debug/route.ts:3
examples/showcases/research-canvas/agent/requirements.txt:1, 2, 3, 4, 6, 7, 8, 9, +2 more (10 hits)scripts/qa/lib/langserve/requirements.txt:1, 2, 3, 4, 5, 6, 7, 8 (8 hits)showcase/integrations/google-adk/requirements.txt:3, 4, 5 (3 hits)examples/integrations/a2a-middleware/agents/requirements.txt:19examples/showcases/research-canvas/final/agent/requirements.txt:1showcase/integrations/ms-agent-python/requirements.txt:9showcase/integrations/pydantic-ai/requirements.txt:7examples/integrations/a2a-middleware/agents/orchestrator.py:80examples/integrations/a2a-middleware/agents/research_agent.py:158examples/integrations/adk/agent/main.py:202showcase/integrations/agno/src/agent_server.py:230, 337, 350, 437, 622 (5 hits)showcase/integrations/agno/src/agents/multimodal_agent.py:60, 77 (2 hits)showcase/integrations/claude-sdk-python/src/agents/multimodal_agent.py:64, 83 (2 hits)showcase/integrations/ms-agent-python/src/agents/multimodal_agent.py:68, 87 (2 hits)showcase/integrations/claude-sdk-python/src/agents/a2ui_dynamic.py:235showcase/integrations/claude-sdk-python/src/agents/a2ui_fixed.py:239showcase/integrations/claude-sdk-python/src/agents/agent.py:755showcase/integrations/claude-sdk-python/src/agents/hitl_in_chat_agent.py:299examples/integrations/_intelligence/docker-compose.yml:19, 65, 125, 149 (4 hits)examples/integrations/agentcore/docker/docker-compose.yml:12examples/showcases/deep-agents-finance-erp/docker-compose.yml:1examples/integrations/_intelligence/docker-compose.yml:65, 125 (2 hits)examples/showcases/deep-agents-finance-erp/docker-compose.yml:1examples/integrations/adk/Dockerfile:16examples/integrations/adk/docker/Dockerfile.agent:1examples/integrations/agentcore/docker/Dockerfile.bridge.dev:1examples/integrations/agentcore/docker/Dockerfile.frontend.dev:4examples/integrations/agno/Dockerfile:23examples/integrations/agno/docker/Dockerfile.agent:1examples/integrations/crewai-crews/Dockerfile:16examples/integrations/crewai-crews/docker/Dockerfile.agent:1showcase/aimock/Dockerfile:1
CI/CD securitycontainers
examples/integrations/adk/docker/Dockerfile.app:12examples/integrations/agentcore/docker/Dockerfile.bridge.dev:5examples/integrations/agentcore/docker/Dockerfile.frontend.dev:15examples/integrations/agno/docker/Dockerfile.app:12examples/integrations/crewai-crews/docker/Dockerfile.app:12examples/integrations/langgraph-fastapi/docker/Dockerfile.app:24examples/integrations/langgraph-js/docker/Dockerfile.app:24examples/integrations/langgraph-python/docker/Dockerfile.app:24packages/runtime/src/v2/runtime/intelligence-platform/client.ts:542, 550, 596 (3 hits)showcase/harness/src/fleet/job-claim.ts:206, 215 (2 hits)scripts/qa/lib/css/page.tsx:62scripts/qa/lib/langchain/page.tsx:62scripts/qa/lib/langchain/route.ts:41scripts/qa/lib/langserve/next/page.tsx:62scripts/qa/lib/langserve/next/route.ts:85scripts/qa/lib/next/page.tsx:62Showing first 300 of 916. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/5c865d8d-bd31-4274-81bf-8558cfd5f077/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/5c865d8d-bd31-4274-81bf-8558cfd5f077/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.