Scan timing: clone 7.18s · analysis 78.79s · 20.3 MB · GitHub API rate-limit (preflight)
https://github.com/smith-horn/skillsmith
· scanned 2026-06-06 00:04 UTC (4 days, 2 hours ago)
· 10 languages
1245 raw signals (183 security + 1062 graph) 40th percentile · Typescript · large (100-500K LoC) System graph score 65 (higher by 8)
Last scanned 4 days, 2 hours ago · v2 · 617 actionable findings from 2 signal sources. 96 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
42.7 | 0.25 | 10.68 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
98.1 | 0.15 | 14.71 |
practices_score |
83.0 | 0.15 | 12.45 |
code_quality |
58.8 | 0.10 | 5.88 |
| Overall | 1.00 | 72.7 |
Showing 430 of 617 actionable findings. 713 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
scripts/apply-075-audit-logs-index.sh:83
packages/core/src/telemetry/tracer-imports.ts:14
packages/core/src/telemetry/metric-helpers.ts:16
packages/enterprise/tests/audit/scheduled-scan.test.ts:233, 430 (2 hits)packages/enterprise/src/audit/scheduled-scan.ts:24package-lock.json
packages/core/CHANGELOG.md:10, 53, 98, 101, 118, 122 (6 hits)packages/mcp-server/src/tools/get-skill.ts:204, 287 (2 hits)packages/website/src/middleware.ts:27, 53 (2 hits).claude/development/deployment-guide.md:493.github/workflows/ci.yml:1343CLAUDE.md:279.github/workflows/e2e-tests.yml:63, 66, 190, 193, 271, 274, 350, 353, +4 more (12 hits).github/workflows/ci.yml:488, 491, 590, 734, 737, 1006, 1009, 1058, +3 more (11 hits).github/workflows/concurrency-audit-pr.yml:80, 101 (2 hits)package-lock.json
scripts/phase4-orchestrator/orchestrator.ts:223
packages/mcp-server/src/suggestions/suggestion-engine.ts:327
packages/mcp-server/src/suggestions/suggestion-engine.ts:309
packages/core/src/sync/BackgroundSyncService.ts:98
packages/core/src/api/utils.ts:115
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
packages/core/src/services/quarantine/QuarantineService.ts:15
Dockerfile:20
package-lock.json
package-lock.json
scripts/phase4-orchestrator/code-reviewer.ts:43
Eval used
packages/core/src/db/database-interface.ts:86
Exec used
packages/core/src/db/drivers/betterSqlite3Driver.ts:62
Exec used
packages/core/src/db/drivers/sqljsDriver.ts:240
Exec used
packages/mcp-server/src/index.ts:233
Exec used
packages/core/src/services/skill-installation.feedback.ts:31packages/core/src/services/skill-installation.io.ts:129packages/core/src/services/skill-manifest.ts:53packages/core/src/api/utils.ts:87packages/core/src/benchmarks/cacheBenchmark.ts:280packages/enterprise/src/quota/QuotaEnforcementService.ts:357packages/mcp-server/src/middleware/errorFormatter.builders.ts:218
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package.json
scripts/phase4-orchestrator/package.json
packages/core/package.json (2 hits)packages/vscode-extension/package.json
package.json
package.json
package.json
package.json
packages/vscode-extension/package.json
package.json
package.json
.well-known/security.txt
package-lock.json
package-lock.json
package-lock.json
package-lock.json
package-lock.json
.github/workflows/analytics-report.yml.github/workflows/ci.yml.github/workflows/detect-release-drift.yml.github/workflows/e2e-tests.yml.github/workflows/ghcr-cache-prune.yml.github/workflows/publish.yml.github/workflows/release-cadence-pr-staleness.yml.github/workflows/release-cadence.ymlscripts/phase4-orchestrator/code-reviewer.ts:46
Dangerous innerhtml
.github/workflows/chronic-red-monitor.yml
Ports
scripts/phases/phase-7-enterprise.sh
Ports
scripts/phases/phase-7-enterprise.sh
Ports
.dockerignore
CI/CD securitycontainers
package-lock.json
docker-compose.yml:1, 41, 64 (3 hits)packages/core/src/services/SearchService.types.ts:3, 5 (2 hits)packages/core/src/db/migration.ts:93packages/core/src/embeddings/index.ts:214packages/core/src/repositories/SkillRepository.ts:5packages/core/src/scripts/import-github-skills.ts:33packages/core/src/scripts/sync-to-supabase.ts:5packages/core/src/scripts/validation/index.ts:9packages/core/src/security/AuditLogger.ts:89packages/core/package.json
packages/core/package.json
packages/vscode-extension/package.json
package.jsonpackages/vscode-extension/package.jsonpackage.json
package.json
package.jsonscripts/phase4-orchestrator/package.jsonllms.txt
humans.txt
sitemap.xml
supabase/functions/stripe-webhook/handlers/subscription-updated.ts:1
packages/website/src/lib/complete-profile-copy.ts:1
package-lock.json
Dockerfile:20
containersPinned dependencies
package.json
CI/CD securitySupply chainNpm
Showing first 300 of 430. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/72a3ffa5-cbcd-4a9e-8c7c-015f5f1e3595/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/72a3ffa5-cbcd-4a9e-8c7c-015f5f1e3595/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.