https://github.com/snapotter-hq/SnapOtter
· scanned 2026-05-17 01:37 UTC (13 hours, 45 minutes ago)
· 10 languages
708 findings (58 legacy + 650 scanner) 8/10 scanners ran 98th percentile · Typescript · large (100-500K LoC) Scanner says 53 (higher by 34)
Last scanned 13 hours, 44 minutes ago · v2 · 383 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Showing 376 of 383 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
docker/entrypoint.sh:8
credential_exposurelegacy
docker/docker-compose.yml:7
dockerlegacy
packages/shared/src/i18n/ar.ts:1667
secrets
packages/shared/src/i18n/ar.ts:1686
secrets
packages/shared/src/i18n/de.ts:1692
secrets
packages/shared/src/i18n/de.ts:1714
secrets
packages/shared/src/i18n/en.ts:1626
secrets
packages/shared/src/i18n/en.ts:1646
secrets
packages/shared/src/i18n/es.ts:1671
secrets
packages/shared/src/i18n/es.ts:1692
secrets
packages/shared/src/i18n/fr.ts:1690
secrets
packages/shared/src/i18n/fr.ts:1712
secrets
packages/shared/src/i18n/hi.ts:1663
secrets
packages/shared/src/i18n/hi.ts:1683
secrets
packages/shared/src/i18n/id.ts:1679
secrets
packages/shared/src/i18n/id.ts:1699
secrets
packages/shared/src/i18n/it.ts:1684
secrets
packages/shared/src/i18n/it.ts:1705
secrets
packages/shared/src/i18n/ja.ts:1656
secrets
packages/shared/src/i18n/ko.ts:1641
secrets
packages/shared/src/i18n/nl.ts:1682
secrets
packages/shared/src/i18n/nl.ts:1702
secrets
packages/shared/src/i18n/pl.ts:1709
secrets
packages/shared/src/i18n/pt-BR.ts:1703
secrets
packages/shared/src/i18n/ru.ts:1681
secrets
packages/shared/src/i18n/ru.ts:1701
secrets
packages/shared/src/i18n/sv.ts:1677
secrets
packages/shared/src/i18n/sv.ts:1697
secrets
packages/shared/src/i18n/th.ts:1655
secrets
packages/shared/src/i18n/th.ts:1674
secrets
packages/shared/src/i18n/tr.ts:1685
secrets
packages/shared/src/i18n/tr.ts:1706
secrets
packages/shared/src/i18n/uk.ts:1681
secrets
packages/shared/src/i18n/uk.ts:1702
secrets
packages/shared/src/i18n/vi.ts:1677
secrets
packages/shared/src/i18n/vi.ts:1697
secrets
packages/ai/python/enhance_faces.py:247
path_traversallegacy
packages/ai/python/detect_faces.py:236
path_traversallegacy
packages/ai/python/colorize.py:177
path_traversallegacy
apps/web/src/components/common/dropzone.tsx:131
ssrflegacy
apps/api/src/routes/fetch-urls.ts:101
ssrflegacy
apps/api/src/plugins/oidc.ts:30
ssrflegacy
apps/web/src/pages/login-page.tsx:212
authlegacy
packages/ai/python/noise_removal.py:328
owaspeval_used
packages/ai/python/dispatcher.py:235
owaspexec_used
apps/api/src/routes/user-files.ts:449
error_handlinglegacy
apps/api/src/routes/tools/info.ts:170
error_handlinglegacy
apps/api/src/routes/tools/convert.ts:125
error_handlinglegacy
apps/api/src/routes/docs.ts:147
deserializationlegacy
apps/web/src/lib/api.ts:160
authlegacy
apps/web/src/lib/api.ts:49
authlegacy
docker/docker-compose.yml:7
dockerlegacy
docker/docker-compose.yml:7
dockerlegacy
docker/Dockerfile:125
dockerlegacy
docker/Dockerfile:125
supply-chaindockerpinned-dependencies
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
apps/landing/src/components/json-ld.tsx:6
owaspdangerous_innerhtml
.dockerignore
dockerlegacy
docker/docker-compose.yml:7
dockerlegacy
docker/docker-compose.yml:7
dockerlegacy
docker/Dockerfile:199
dockerlegacy
apps/api/src/routes/tools/edit-metadata.ts:119
qualitylegacy
apps/api/src/routes/tools/edit-metadata.ts:107
qualitylegacy
apps/api/src/routes/tools/edit-metadata.ts:104
qualitylegacy
apps/api/src/routes/tools/edit-metadata.ts:69
qualitylegacy
apps/api/src/routes/tools/convert.ts:22
qualitylegacy
apps/api/src/routes/tools/convert.ts:21
qualitylegacy
apps/api/src/routes/tools/content-aware-resize.ts:43
qualitylegacy
apps/api/src/routes/tools/content-aware-resize.ts:31
qualitylegacy
apps/api/src/routes/tools/content-aware-resize.ts:28
qualitylegacy
apps/api/src/routes/tools/compose.ts:89
qualitylegacy
apps/api/src/routes/tools/compose.ts:72
qualitylegacy
apps/api/src/routes/tools/colorize.ts:72
qualitylegacy
apps/api/src/routes/tools/colorize.ts:62
qualitylegacy
apps/api/src/routes/tools/colorize.ts:58
qualitylegacy
apps/api/src/routes/tools/colorize.ts:27
qualitylegacy
apps/api/src/routes/tools/color-palette.ts:64
qualitylegacy
apps/api/src/routes/tools/collage.ts:472
qualitylegacy
apps/api/src/routes/tools/collage.ts:399
qualitylegacy
apps/api/src/routes/tools/bulk-rename.ts:43
qualitylegacy
apps/api/src/routes/tools/border.ts:82
qualitylegacy
apps/api/src/routes/tools/blur-faces.ts:72
qualitylegacy
apps/api/src/routes/tools/blur-faces.ts:58
qualitylegacy
apps/api/src/routes/tools/blur-faces.ts:27
qualitylegacy
apps/api/src/routes/tools/beautify.ts:247
qualitylegacy
apps/api/src/routes/tools/barcode-read.ts:77
qualitylegacy
apps/api/src/routes/tools/barcode-read.ts:65
qualitylegacy
apps/api/src/routes/tools/ai-canvas-expand.ts:82
qualitylegacy
apps/api/src/routes/roles.ts:10
qualitylegacy
apps/api/src/routes/pipeline.ts:337
qualitylegacy
apps/api/src/lib/format-decoders.ts:18
qualitylegacy
docker/Dockerfile:50
supply-chaindockerpinned-dependencies
docker/Dockerfile:13
supply-chaindockerpinned-dependencies
docker/Dockerfile:113
supply-chaindockerpinned-dependencies
docker/Dockerfile:118
supply-chaindockerpinned-dependencies
docker/Dockerfile:114
supply-chaindockerpinned-dependencies
package.json
supply-chainnpminstall-scripts
docker/download_models.py:336
dead-code
docker/download_models.py:381
dead-code
docker/download_models.py:350
dead-code
docker/download_models.py:469
dead-code
docker/download_models.py:322
dead-code
docker/download_models.py:300
dead-code
docker/download_models.py:525
dead-code
docker/download_models.py:456
dead-code
docker/download_models.py:495
dead-code
docker/download_models.py:410
dead-code
docker/download_models.py:432
dead-code
docker/download_models.py:308
dead-code
docker/download_models.py:285
dead-code
docker/download_models.py:444
dead-code
Showing first 300 of 376. Refine filters or use the legacy findings page for deep search.
{# ── 2026-05-17 Round 14: AI-agent bridge footer ────────────────────── Discoverability: the /agents/voting/ guide + MCP manifest exist but aren't linked from anywhere users actually land. Small, opt-in footer. #}
This page is publicly accessible at:
https://repobility.com/scan/74b4c143-ebfb-420c-bd4a-ca532718732c/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/74b4c143-ebfb-420c-bd4a-ca532718732c/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.