CRIT
curl-auth-header
Discovered a potential authorization token provided in a curl command header, which could…
uk/claude_concepts_guide.md:2041
CRIT
curl-auth-header
Discovered a potential authorization token provided in a curl command header, which could…
ja/claude_concepts_guide.md:2046
CRIT
curl-auth-header
Discovered a potential authorization token provided in a curl command header, which could…
claude_concepts_guide.md:2041
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
zh/SECURITY.md:243
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
uk/SECURITY.md:247
CRIT
curl-auth-header
Discovered a potential authorization token provided in a curl command header, which could…
ja/07-plugins/documentation/templates/a…:72
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
SECURITY.md:243
CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
ja/SECURITY.md:247
CRIT
curl-auth-header
Discovered a potential authorization token provided in a curl command header, which could…
03-skills/doc-generator/SKILL.md:57
CRIT
curl-auth-header
Discovered a potential authorization token provided in a curl command header, which could…
07-plugins/documentation/templates/api-…:68
HIGH
MINED108
`self.calculate_cyclomatic_complexity` used but never assigned in __init__
uk/03-skills/code-review-specialist/scr…:89
HIGH
MINED108
`self.calculate_cognitive_complexity` used but never assigned in __init__
uk/03-skills/code-review-specialist/scr…:74
HIGH
MINED108
`self.calculate_cyclomatic_complexity` used but never assigned in __init__
uk/03-skills/code-review-specialist/scr…:73
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
scripts/check_links.py:73
HIGH
MINED104
[MINED104] Chmod 777: chmod 777 makes a file or directory world-readable, world-writable,…
uk/06-hooks/pre-tool-check.sh:75
HIGH
MINED104
[MINED104] Chmod 777: chmod 777 makes a file or directory world-readable, world-writable,…
ja/06-hooks/pre-tool-check.sh:101
HIGH
MINED104
[MINED104] Chmod 777: chmod 777 makes a file or directory world-readable, world-writable,…
06-hooks/pre-tool-check.sh:103
HIGH
MINED001
[MINED001] Bare Except Pass: except: pass or except Exception: pass — silently swallows e…
uk/06-hooks/context-tracker-tiktoken.py:117
HIGH
MINED001
[MINED001] Bare Except Pass: except: pass or except Exception: pass — silently swallows e…
06-hooks/context-tracker.py:95
HIGH
MINED001
[MINED001] Bare Except Pass: except: pass or except Exception: pass — silently swallows e…
06-hooks/context-tracker-tiktoken.py:117
HIGH
MINED108
`self._extract_return_type` used but never assigned in __init__
uk/03-skills/doc-generator/generate-doc…:19
HIGH
MINED108
`self.generic_visit` used but never assigned in __init__
uk/03-skills/doc-generator/generate-doc…:22
HIGH
MINED108
`self._collect_folder` used but never assigned in __init__
scripts/build_epub.py:468
HIGH
MINED108
`self._render_one` used but never assigned in __init__
scripts/build_epub.py:345
HIGH
MINED108
`self._resolve_mmdc` used but never assigned in __init__
scripts/build_epub.py:338
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/release.yml:20
HIGH
MINED115
Action `actions/setup-python` pinned to mutable ref `@v4`
.github/workflows/docs-check.yml:96
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/docs-check.yml:93
HIGH
MINED115
Action `actions/setup-python` pinned to mutable ref `@v4`
.github/workflows/docs-check.yml:79
HIGH
MINED115
Action `actions/setup-node` pinned to mutable ref `@v4`
.github/workflows/docs-check.yml:71
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/docs-check.yml:68
HIGH
MINED115
Action `actions/setup-python` pinned to mutable ref `@v4`
.github/workflows/docs-check.yml:54
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/docs-check.yml:51
HIGH
MINED115
Action `actions/setup-node` pinned to mutable ref `@v4`
.github/workflows/docs-check.yml:36
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/docs-check.yml:33
HIGH
MINED115
Action `actions/download-artifact` pinned to mutable ref `@v4`
.github/workflows/test.yml:200
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v4`
.github/workflows/test.yml:185
HIGH
MINED115
Action `astral-sh/setup-uv` pinned to mutable ref `@v4`
.github/workflows/test.yml:156
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/test.yml:153
HIGH
MINED115
Action `astral-sh/setup-uv` pinned to mutable ref `@v4`
.github/workflows/test.yml:132
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/test.yml:129
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v4`
.github/workflows/test.yml:117
HIGH
MINED115
Action `astral-sh/setup-uv` pinned to mutable ref `@v4`
.github/workflows/test.yml:103
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/test.yml:100
HIGH
MINED115
Action `astral-sh/setup-uv` pinned to mutable ref `@v4`
.github/workflows/test.yml:79
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/test.yml:76
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v4`
.github/workflows/test.yml:63
HIGH
MINED115
Action `codecov/codecov-action` pinned to mutable ref `@v3`
.github/workflows/test.yml:53
HIGH
MINED115
Action `astral-sh/setup-uv` pinned to mutable ref `@v4`
.github/workflows/test.yml:38
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
.github/workflows/test.yml:35
HIGH
MINED131
pre-commit hook `https://github.com/pre-commit/mirrors-mypy` pinned to mutable rev `v1.13…
.pre-commit-config.yaml:55
HIGH
MINED131
pre-commit hook `https://github.com/pre-commit/pre-commit-hooks` pinned to mutable rev `v…
.pre-commit-config.yaml:36
HIGH
MINED131
pre-commit hook `https://github.com/PyCQA/bandit` pinned to mutable rev `1.7.10`
.pre-commit-config.yaml:24
HIGH
MINED131
pre-commit hook `https://github.com/astral-sh/ruff-pre-commit` pinned to mutable rev `v0.…
.pre-commit-config.yaml:10
HIGH
GHSA-whj4-6x5x-4v2j
pillow: GHSA-whj4-6x5x-4v2j
scripts/requirements.txt
HIGH
GHSA-pwv6-vv43-88gr
pillow: GHSA-pwv6-vv43-88gr
scripts/requirements.txt
HIGH
GHSA-cfh3-3jmp-rvhc
pillow: GHSA-cfh3-3jmp-rvhc
scripts/requirements.txt
HIGH
PYSEC-2026-165
pillow: PYSEC-2026-165
scripts/requirements.txt
HIGH
PYSEC-2026-89
markdown: PYSEC-2026-89
scripts/requirements.txt
HIGH
GHSA-whj4-6x5x-4v2j
pillow: GHSA-whj4-6x5x-4v2j
scripts/requirements-dev.txt
HIGH
GHSA-pwv6-vv43-88gr
pillow: GHSA-pwv6-vv43-88gr
scripts/requirements-dev.txt
HIGH
GHSA-cfh3-3jmp-rvhc
pillow: GHSA-cfh3-3jmp-rvhc
scripts/requirements-dev.txt
HIGH
PYSEC-2026-165
pillow: PYSEC-2026-165
scripts/requirements-dev.txt
HIGH
PYSEC-2026-89
markdown: PYSEC-2026-89
scripts/requirements-dev.txt
MED
SEC031
[SEC031] Catastrophic Backtracking Regex (ReDoS): Regex contains nested quantifiers like …
scripts/check_markdown_rendering.py:46
MED
MINED111
Bare except continues silently
03-skills/refactor/scripts/detect-smell…:646
MED
MINED111
Bare except continues silently
03-skills/refactor/scripts/analyze-comp…:479
MED
MINED111
Bare except continues silently
uk/03-skills/refactor/scripts/detect-sm…:646
MED
MINED111
Bare except continues silently
uk/03-skills/refactor/scripts/analyze-c…:479
MED
MINED111
Bare except continues silently
scripts/check_links.py:80
MED
COMP001
[COMP001] High cognitive complexity: Function `main` has cognitive complexity 19 (SonarSo…
scripts/check_cross_references.py:62
MED
COMP001
[COMP001] High cognitive complexity: Function `read_transcript` has cognitive complexity …
06-hooks/context-tracker.py:40
MED
COMP001
[COMP001] High cognitive complexity: Function `read_transcript` has cognitive complexity …
06-hooks/context-tracker-tiktoken.py:62
MED
GHSA-65pc-fj4g-8rjx
idna: GHSA-65pc-fj4g-8rjx
scripts/requirements.txt
MED
GHSA-r73j-pqj5-w3x7
pillow: GHSA-r73j-pqj5-w3x7
scripts/requirements.txt
MED
GHSA-q2x7-8rv6-6q7h
jinja2: GHSA-q2x7-8rv6-6q7h
scripts/requirements.txt
MED
GHSA-gmj6-6f8f-6699
jinja2: GHSA-gmj6-6f8f-6699
scripts/requirements.txt
MED
GHSA-cpwx-vrp4-4pq7
jinja2: GHSA-cpwx-vrp4-4pq7
scripts/requirements.txt
MED
GHSA-65pc-fj4g-8rjx
idna: GHSA-65pc-fj4g-8rjx
scripts/requirements-dev.txt
MED
GHSA-w853-jp5j-5j7f
filelock: GHSA-w853-jp5j-5j7f
scripts/requirements-dev.txt
MED
GHSA-qmgc-5h2g-mvrw
filelock: GHSA-qmgc-5h2g-mvrw
scripts/requirements-dev.txt
MED
GHSA-r73j-pqj5-w3x7
pillow: GHSA-r73j-pqj5-w3x7
scripts/requirements-dev.txt
MED
GHSA-q2x7-8rv6-6q7h
jinja2: GHSA-q2x7-8rv6-6q7h
scripts/requirements-dev.txt
MED
GHSA-gmj6-6f8f-6699
jinja2: GHSA-gmj6-6f8f-6699
scripts/requirements-dev.txt
MED
GHSA-cpwx-vrp4-4pq7
jinja2: GHSA-cpwx-vrp4-4pq7
scripts/requirements-dev.txt
MED
AGT012
Agent control bridge may listen on a network interface without visible auth
scripts/vendor_assets.py:1
MED
AGT015
Remote install command pipes network code directly to a shell
vi/09-advanced-features/README.md:393
MED
AGT015
Remote install command pipes network code directly to a shell
uk/09-advanced-features/README.md:399
MED
AGT015
Remote install command pipes network code directly to a shell
ja/09-advanced-features/README.md:461
MED
AGT013
Agent auto-approve or skip-permissions mode is easy to enable
zh/QUICK_REFERENCE.md:100
MED
AGT013
Agent auto-approve or skip-permissions mode is easy to enable
zh/INDEX.md:396
MED
AGT013
Agent auto-approve or skip-permissions mode is easy to enable
ja/QUICK_REFERENCE.md:104
MED
AGT013
Agent auto-approve or skip-permissions mode is easy to enable
ja/INDEX.md:404
LOW
DEPCUR-PY
Python package `tenacity` is minor version(s) behind (9.0.0 -> 9.1.4)
scripts/requirements.txt:7
LOW
DEPCUR-PY
Python package `beautifulsoup4` is minor version(s) behind (4.12.3 -> 4.14.3)
scripts/requirements.txt:4
LOW
DEPCUR-PY
Python package `markdown` is minor version(s) behind (3.7 -> 3.10.2)
scripts/requirements.txt:3
LOW
DEPCUR-PY
Python package `ebooklib` is minor version(s) behind (0.18 -> 0.20)
scripts/requirements.txt:2
LOW
AIC003
Duplicated implementation block across source files
uk/03-skills/code-review-specialist/scr…:1
LOW
AIC003
Duplicated implementation block across source files
uk/03-skills/code-review-specialist/scr…:1
LOW
AIC003
Duplicated implementation block across source files
vi/09-advanced-features/setup-auto-mode…:1
LOW
AIC003
Duplicated implementation block across source files
vi/07-plugins/pr-review/hooks/pre-revie…:1
LOW
AIC003
Duplicated implementation block across source files
vi/07-plugins/devops-automation/hooks/p…:1
LOW
AIC003
Duplicated implementation block across source files
vi/07-plugins/devops-automation/hooks/p…:1
LOW
AIC003
Duplicated implementation block across source files
vi/06-hooks/context-tracker.py:26
LOW
AIC003
Duplicated implementation block across source files
vi/06-hooks/context-tracker.py:1
LOW
AIC003
Duplicated implementation block across source files
vi/06-hooks/context-tracker-tiktoken.py:1
LOW
AIC003
Duplicated implementation block across source files
uk/09-advanced-features/setup-auto-mode…:1
LOW
AIC003
Duplicated implementation block across source files
scripts/build_website.py:83
LOW
AIC003
Duplicated implementation block across source files
uk/07-plugins/pr-review/hooks/pre-revie…:1
LOW
AIC003
Duplicated implementation block across source files
uk/07-plugins/devops-automation/hooks/p…:1
LOW
AIC003
Duplicated implementation block across source files
uk/07-plugins/devops-automation/hooks/p…:1
LOW
AIC003
Duplicated implementation block across source files
uk/06-hooks/context-tracker.py:26
LOW
AIC003
Duplicated implementation block across source files
uk/06-hooks/context-tracker.py:1
LOW
AIC003
Duplicated implementation block across source files
uk/06-hooks/context-tracker-tiktoken.py:1
LOW
AIC003
Duplicated implementation block across source files
uk/03-skills/refactor/scripts/detect-sm…:1
LOW
AIC003
Duplicated implementation block across source files
uk/03-skills/refactor/scripts/analyze-c…:1
LOW
AIC003
Duplicated implementation block across source files
uk/03-skills/doc-generator/generate-doc…:1
LOW
AIC003
Duplicated implementation block across source files
06-hooks/context-tracker.py:26
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
07-plugins/devops-automation/scripts/ro…:23
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
07-plugins/devops-automation/scripts/he…:10
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
07-plugins/devops-automation/scripts/de…:26
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
07-plugins/pr-review/hooks/pre-review.js:9
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
07-plugins/devops-automation/hooks/pre-…:9
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
07-plugins/devops-automation/hooks/post…:9
INFO
MINED050
[MINED050] Stub Only Function: Function declared but body is just pass, return None, rais…
scripts/sync_translations.py:163
INFO
MINED050
[MINED050] Stub Only Function: Function declared but body is just pass, return None, rais…
06-hooks/context-tracker.py:96
INFO
MINED050
[MINED050] Stub Only Function: Function declared but body is just pass, return None, rais…
06-hooks/context-tracker-tiktoken.py:118
INFO
MINED049
[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout.
uk/06-hooks/context-tracker-tiktoken.py:29
INFO
MINED049
[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout.
06-hooks/context-tracker.py:110
INFO
MINED049
[MINED049] Print Pii: Logging password/token/email/ssn directly to stdout.
06-hooks/context-tracker-tiktoken.py:29
INFO
DEPCUR-PY
Python package `jinja2` is patch version(s) behind (3.1.4 -> 3.1.6)
scripts/requirements.txt:8