https://github.com/gptme/gptme.git
· scanned 2026-05-16 01:47 UTC (2 weeks, 6 days ago)
· 10 languages
431 findings (58 legacy + 373 scanner) 14th percentile · Python · large (100-500K LoC) Scanner says 46 (higher by 13)
Last scanned 2 weeks, 6 days ago · v1 · 47 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
14.0 | 0.25 | 3.50 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
73.0 | 0.15 | 10.95 |
practices_score |
65.0 | 0.15 | 9.75 |
code_quality |
56.6 | 0.10 | 5.66 |
| Overall | 1.00 | 58.9 |
web: 1.6 ·
agent: 1.1 ·
authz: 2.1 ·
docker: 15.6 ·
threat: 46.0 ·
journey: 19.7
Showing 43 of 47 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
gptme/hooks/form_autodetect.py:157
injectionlegacy
gptme/eval/dspy/tasks.py:513
injectionlegacy
gptme/eval/suites/practical15.py:175
injectionlegacy
gptme/eval/main.py:53
injectionlegacy
webui/src/utils/taskApi.ts:214
path_traversallegacy
gptme/hooks/elicitation.py:202
llm_injectionlegacy
gptme/tools/morph.py:140
llm_injectionlegacy
scripts/Dockerfile.eval:13
dockerlegacy
scripts/Dockerfile:48
dockerlegacy
webui/src/components/settings/ServerApiKeySettings.tsx:187
authlegacy
webui/src/components/SetupWizard.tsx:760
authlegacy
gptme/tools/restart.py:146
error_handlinglegacy
gptme/tools/_browser_playwright.py:228
error_handlinglegacy
scripts/demo_capture.py:380
error_handlinglegacy
webui/src/components/ConversationContent.tsx:51
error_handlinglegacy
gptme/prompts/context_cmd.py:54
injectionlegacy
gptme/hooks/elicitation.py:202
llm_injectionlegacy
gptme/tools/morph.py:140
llm_injectionlegacy
webui/src/stores/servers.ts:71
authlegacy
gptme/hooks/workspace_agents.py:3
qualitylegacy
scripts/Dockerfile.dev:1
dockerlegacy
scripts/Dockerfile.dev:24
dockerlegacy
scripts/Dockerfile.computer:80
dockerlegacy
scripts/Dockerfile.computer:82
dockerlegacy
scripts/Dockerfile.computer:7
dockerlegacy
gptme/util/install.py:10
qualitylegacy
gptme/util/_telemetry.py:199
qualitylegacy
gptme/tools/computer_transport.py:137
qualitylegacy
gptme/tools/autocompact/scoring.py:139
qualitylegacy
gptme/server/session_step.py:535
qualitylegacy
gptme/eval/suites/behavioral/rate_limiting.py:56
qualitylegacy
gptme/cli/cmd_agents.py:60
qualitylegacy
gptme/server/static/main.js:296
qualitylegacy
gptme/server/static/main.js:219
qualitylegacy
gptme/server/static/main.js:165
qualitylegacy
gptme/server/static/main.js:5
qualitylegacy
.well-known/security.txt
qualitylegacy
.dockerignore
dockerlegacy
gptme/server/api_v2.py:1
qualitylegacy
gptme/eval/suites/behavioral/noisy_worktree_fix.py:1
qualitylegacy
gptme/eval/suites/behavioral/extract_function_refactor.py:1
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/852baae1-fabf-447b-9d40-b658b164911d/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/852baae1-fabf-447b-9d40-b658b164911d/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.