Scan timing: clone 3.7s · analysis 11.28s · 12.4 MB · GitHub API rate-limit (preflight)
https://github.com/generalaction/emdash
· scanned 2026-05-31 01:25 UTC (5 days, 6 hours ago)
· 10 languages
481 findings (115 legacy + 366 scanner) 28th percentile · Typescript · large (100-500K LoC) Scanner says 57 (higher by 13)
Last scanned 5 days, 6 hours ago · v2 · last Δ +0.1 (diff) · 305 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
54.5 | 0.25 | 13.62 |
testing_score |
81.0 | 0.20 | 16.20 |
documentation_score |
74.7 | 0.15 | 11.21 |
practices_score |
69.0 | 0.15 | 10.35 |
code_quality |
60.1 | 0.10 | 6.01 |
| Overall | 1.00 | 70.1 |
Showing 225 of 305 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/renderer/lib/components/feedback-modal/use-feedback-submit.ts:7
dependencylegacy
src/renderer/features/tasks/create-task-modal/workspace-settings-section.tsx:34
qualitylegacy
src/main/core/pty/persist-dropped-blob.ts:107
resource_exhaustionlegacy
src/main/core/jira/jira-issue-provider.ts:152
xsslegacy
src/main/core/execution-context/ssh-execution-context.ts:14
xsslegacy
scripts/release/verify-linux.ts:108
xsslegacy
src/main/core/agent-hooks/classifiers/codebuff.ts:23
qualitylegacy
src/main/core/app/utils.ts:14
qualitylegacy
scripts/release/verify-linux.ts:16
qualitylegacy
scripts/release/build.ts:51
qualitylegacy
src/main/core/projects/worktrees/hosts/local-worktree-host.ts:64
path_traversallegacy
.github/workflows/release-canary.yml:141
dependencylegacy
.github/workflows/release-canary.yml:76
dependencylegacy
.github/workflows/release-canary.yml:40
dependencylegacy
.github/workflows/release-prod.yml:136
dependencylegacy
.github/workflows/release-prod.yml:74
dependencylegacy
.github/workflows/release-prod.yml:41
dependencylegacy
.github/workflows/nix-build.yml:15
dependencylegacy
.github/workflows/windows-beta-build.yml:19
dependencylegacy
.github/workflows/code-consistency-check.yml:16
dependencylegacy
.github/workflows/windows-beta-build.yml:49
dependencylegacy
.github/workflows/code-consistency-check.yml:24
dependencylegacy
.github/workflows/windows-beta-build.yml:55
dependencylegacy
.github/workflows/nix-build.yml:38
dependencylegacy
.github/workflows/windows-beta-build.yml:92
dependencylegacy
.github/workflows/release-canary.yml:149
dependencylegacy
.github/workflows/release-prod.yml:143
dependencylegacy
.github/workflows/nix-build.yml:23
dependencylegacy
.github/workflows/nix-build.yml:18
dependencylegacy
.github/workflows/windows-beta-build.yml:44
dependencylegacy
.github/workflows/code-consistency-check.yml:19
dependencylegacy
tooling/docker-ssh/dockerfile:124
dockerlegacy
tooling/byoi/Dockerfile:87
dockerlegacy
tooling/byoi/Dockerfile:1
dependencylegacy
tooling/docker-ssh/dockerfile:13
dependencylegacy
tooling/docker-ssh/dockerfile:54
dockerlegacy
tooling/byoi/Dockerfile:37
dockerlegacy
src/renderer/features/integrations/AsanaSetupForm.tsx:14
authlegacy
.github/workflows/release-canary.yml:17
dependencylegacy
.github/workflows/release-prod.yml:18
dependencylegacy
tooling/byoi/Dockerfile:37
supply-chaindockerremote-installer
scripts/release/build.ts:35
owaspexec_used
scripts/release/notarize-mac.ts:54
owaspexec_used
scripts/release/rebuild-native.ts:18
owaspexec_used
scripts/release/verify-mac.ts:88
owaspexec_used
scripts/release/verify-win.ts:28
owaspexec_used
src/main/core/app/service.ts:461
owaspexec_used
src/main/core/app/utils.ts:14
owaspexec_used
src/main/core/execution-context/local-execution-context.ts:40
owaspexec_used
src/main/core/execution-context/ssh-execution-context.ts:50
owaspexec_used
src/main/core/execution-context/types.ts:28
owaspexec_used
src/main/core/fs/impl/ssh-fs.ts:95
owaspexec_used
src/main/core/ssh/lifecycle/remote-shell-profile.ts:38
owaspexec_used
src/main/core/ssh/lifecycle/ssh-client-proxy.ts:84
owaspexec_used
src/main/core/workspaces/byoi/provision-byoi-task.ts:150
error_handlinglegacy
src/main/core/tasks/task-builder.ts:131
error_handlinglegacy
src/main/core/ssh/credentials/ssh-credential-service.ts:106
error_handlinglegacy
src/renderer/features/mcp/components/McpCard.tsx:99
securitylegacy
src/renderer/features/tasks/create-task-modal/use-branch-name.ts:27
qualitylegacy
.dockerignore
dockerlegacy
.dockerignore
dockerlegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
.github/workflows/code-consistency-check.yml:19
supply-chaingithub-actionspinned-dependencies
.github/workflows/windows-beta-build.yml:44
supply-chaingithub-actionspinned-dependencies
.github/workflows/nix-build.yml:18
supply-chaingithub-actionspinned-dependencies
.github/workflows/nix-build.yml:23
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-prod.yml:143
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-canary.yml:149
supply-chaingithub-actionspinned-dependencies
src/renderer/features/settings/components/IntegrationRow.tsx:111
owaspdangerous_innerhtml
src/renderer/features/skills/components/SkillIconRenderer.tsx:52
owaspdangerous_innerhtml
src/renderer/lib/components/agent-logo.tsx:37
owaspdangerous_innerhtml
src/renderer/lib/components/terminal-shell-option-label.tsx:26
owaspdangerous_innerhtml
src/renderer/lib/ui/mermaid-diagram-dialog.tsx:27
owaspdangerous_innerhtml
src/renderer/lib/ui/mermaid-diagram-preview.tsx:39
owaspdangerous_innerhtml
src/renderer/utils/mcpIcons.tsx:36
owaspdangerous_innerhtml
docker-compose.yaml:11
dockerlegacy
docker-compose.yaml:11
dockerlegacy
tooling/docker-ssh/dockerfile:54
dockerlegacy
tooling/docker-ssh/dockerfile:44
dockerlegacy
tooling/byoi/Dockerfile:37
dockerlegacy
tooling/byoi/Dockerfile:27
dockerlegacy
src/main/core/agent-hooks/classifiers/pi.ts:12
qualitylegacy
src/main/core/agent-hooks/classifiers/pi.ts:6
qualitylegacy
src/main/core/agent-hooks/classifiers/pi.ts:3
qualitylegacy
src/main/core/agent-hooks/classifiers/opencode.ts:12
qualitylegacy
src/main/core/agent-hooks/classifiers/mistral.ts:48
qualitylegacy
src/main/core/agent-hooks/classifiers/letta.ts:24
qualitylegacy
src/main/core/agent-hooks/classifiers/kiro.ts:12
qualitylegacy
src/main/core/agent-hooks/classifiers/kimi.ts:30
qualitylegacy
src/main/core/agent-hooks/classifiers/kimi.ts:18
qualitylegacy
src/main/core/agent-hooks/classifiers/kilocode.ts:36
qualitylegacy
src/main/core/agent-hooks/classifiers/junie.ts:18
qualitylegacy
src/main/core/agent-hooks/classifiers/jules.ts:18
qualitylegacy
src/main/core/agent-hooks/classifiers/grok.ts:18
qualitylegacy
src/main/core/agent-hooks/classifiers/goose.ts:36
qualitylegacy
src/main/core/agent-hooks/classifiers/generic.ts:36
qualitylegacy
src/main/core/agent-hooks/classifiers/droid.ts:18
qualitylegacy
src/main/core/agent-hooks/classifiers/droid.ts:3
qualitylegacy
src/main/core/agent-hooks/classifiers/devin.ts:24
qualitylegacy
src/main/core/agent-hooks/classifiers/cursor.ts:18
qualitylegacy
src/main/core/agent-hooks/classifiers/copilot.ts:16
qualitylegacy
src/main/core/agent-hooks/classifiers/continue.ts:30
qualitylegacy
src/main/core/agent-hooks/classifiers/continue.ts:3
qualitylegacy
src/main/core/agent-hooks/classifiers/codebuff.ts:30
qualitylegacy
src/main/core/agent-hooks/classifiers/codebuff.ts:3
qualitylegacy
src/main/core/agent-hooks/classifiers/cline.ts:36
qualitylegacy
src/main/core/agent-hooks/classifiers/charm.ts:30
qualitylegacy
src/main/core/agent-hooks/classifiers/autohand.ts:12
qualitylegacy
src/main/core/agent-hooks/classifiers/autohand.ts:3
qualitylegacy
src/main/core/agent-hooks/classifiers/auggie.ts:30
qualitylegacy
electron-builder.config.ts:9
qualitylegacy
build:1
qualitylegacy
llms.txt
qualitylegacy
humans.txt
qualitylegacy
sitemap.xml
qualitylegacy
pnpm-lock.yaml
qualitylegacy
tooling/byoi/Dockerfile:1
supply-chaindockerpinned-dependencies
.github/workflows/code-consistency-check.yml:16
supply-chaingithub-actionspinned-dependencies
.github/workflows/code-consistency-check.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/windows-beta-build.yml:19
supply-chaingithub-actionspinned-dependencies
.github/workflows/windows-beta-build.yml:49
supply-chaingithub-actionspinned-dependencies
.github/workflows/windows-beta-build.yml:55
supply-chaingithub-actionspinned-dependencies
.github/workflows/windows-beta-build.yml:92
supply-chaingithub-actionspinned-dependencies
.github/workflows/nix-build.yml:15
supply-chaingithub-actionspinned-dependencies
.github/workflows/nix-build.yml:38
supply-chaingithub-actionspinned-dependencies
package.json
supply-chainnpminstall-scripts
src/shared/repository-ref.ts:80
qualitylegacy
src/main/core/shared/oauth-flow.ts:86
qualitylegacy
src/main/core/agent-hooks/classifier-wiring.ts:104
qualitylegacy
scripts/release/rebuild-native.ts:14
qualitylegacy
scripts/release/build.ts:16
qualitylegacy
src/renderer/features/tasks/diff-view/comments/monaco-comment-manager.ts:59
qualitylegacy
src/renderer/utils/mcpIcons.tsx:36
qualitylegacy
src/renderer/features/skills/components/SkillIconRenderer.tsx:52
qualitylegacy
src/renderer/features/settings/components/IntegrationRow.tsx:111
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/8612bc46-7d0e-47c7-8171-c5618ca2d4f1/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/8612bc46-7d0e-47c7-8171-c5618ca2d4f1/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.