https://github.com/vellum-ai/vellum-assistant
· scanned 2026-06-05 19:05 UTC (4 days, 17 hours ago)
· 10 languages
3754 raw signals (178 security + 3576 graph) 11/13 scanners ran 46th percentile · Typescript · huge (>500K LoC) System graph score 52 (higher by 32)
Last scanned 4 days, 17 hours ago · v2 · 1835 actionable findings from 2 signal sources. 106 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
40.0 | 0.15 | 6.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
98.0 | 0.15 | 14.70 |
practices_score |
78.0 | 0.15 | 11.70 |
code_quality |
69.0 | 0.10 | 6.90 |
| Overall | 1.00 | 83.3 |
Showing 738 of 1835 actionable findings. 1941 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/pr-macos.yaml:139, 140, 258, 259 (4 hits).github/workflows/cherry-pick-to-release.yml:25, 26 (2 hits).github/workflows/pr-assistant.yaml:179, 180 (2 hits)assistant/src/runtime/assistant-stream-state.ts:156
assistant/src/memory/context-search/search.ts:260
evals/src/lib/egress/recording/Dockerfile:17
evals/src/lib/egress/connection-telemetry/Dockerfile:16
assistant/package.json:1 (10 hits)gateway/package.json:1 (6 hits)credential-executor/package.json:1 (3 hits)apps/macos/package.json:1 (2 hits)apps/web/package.json:1 (2 hits)cli/package.json:1 (2 hits)assistant/src/config/bundled-skills/document-editor/tools/document-open.ts:11
assistant/src/notifications/preference-summary.ts:71
evals/src/lib/egress/recording/Dockerfile:19
CI/CD securitycontainers
assistant/Dockerfile:234
CI/CD securitycontainers
credential-executor/Dockerfile:13
CI/CD securitycontainers
assistant/Dockerfile:16
CI/CD securitycontainers
apps/web/src/domains/onboarding/pages/api-key-screen.tsx:96
credential-executor/Dockerfile:13
containersRemote installer
assistant/Dockerfile:16
containersRemote installer
assistant/src/bundler/bundle-scanner.ts:376
Eval used
skills/watch-together/scripts/process-chunk.sh:13
Eval used
assistant/src/memory/app-git-service.ts:326
Exec used
cli/src/commands/recover.ts:102
Exec used
cli/src/commands/retire.ts:62
Exec used
cli/src/commands/upgrade.ts:337
Exec used
cli/src/lib/aws.ts:97
Exec used
cli/src/lib/docker.ts:124
Exec used
cli/src/lib/gcp.ts:127
Exec used
cli/src/lib/upgrade-lifecycle.ts:653
Exec used
apps/web/src/domains/chat/components/surfaces/table-surface.tsx:163apps/web/src/domains/chat/streaming/sse-event-consumer.ts:154apps/web/src/domains/chat/voice/live-voice/pcm-capture.ts:245assistant/src/cli/utils/parse-duration.ts:25
apps/web/src/domains/chat/api/managed-oauth.ts:377apps/web/src/domains/chat/components/preferences-menu.tsx:240apps/web/src/domains/settings/ai/chatgpt-oauth-section.tsx:62apps/web/src/domains/chat/components/activity-run-card/activity-run-card.stories.tsx:18apps/web/src/domains/chat/components/inline-activity-link/inline-tool-link.stories.tsx:18apps/web/src/domains/chat/components/tool-progress-card/phase-grouped-step-list.stories.tsx:20assistant/src/security/secret-scanner.ts:115
assistant/src/security/secret-ingress.ts:29
evals/src/lib/egress/recording/usage_parser.py:124
Error handlingquality
apps/web/src/lib/auth/gateway-session.ts:39, 40, 73, 75, 89, 90 (6 hits)skills/meet-join/bot/Dockerfile:35
CI/CD securitycontainers
evals/src/lib/egress/connection-telemetry/Dockerfile:17
CI/CD securitycontainers
apps/web/src/domains/account/pages/oauth-popup-complete-page.tsx:247
.github/workflows/ci-main-storybook.yaml.github/workflows/ci-main-web.yaml.github/workflows/deploy-web-spa.yaml.github/workflows/dev-release.yaml.github/workflows/release.yml.github/workflows/socket-autofix.yml.github/workflows/upload-skill-assets.yamlapps/web/src/components/avatar-renderer.tsx:40
Dangerous innerhtml
apps/web/src/domains/account/pages/oauth-complete-page.tsx:257
Dangerous innerhtml
apps/web/src/domains/account/pages/oauth-popup-complete-page.tsx:261
Dangerous innerhtml
apps/web/src/domains/chat/components/chat-attachments/text-preview.tsx:195
Dangerous innerhtml
evals/src/lib/report-html.tsx:1280
Dangerous innerhtml
clients/macos/build.sh:365
Weak hash
gateway/src/schema.ts:4657
Weak hash
Showing first 300 of 738. Refine filters or use the findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/87dd9975-69d1-4959-b9b8-94465869ab20/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/87dd9975-69d1-4959-b9b8-94465869ab20/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.