Scan timing: clone 11.56s · analysis 6.71s · 13.6 MB · GitHub API rate-limit (preflight)
https://github.com/ultraworkers/claw-code
· scanned 2026-06-05 04:30 UTC (3 hours, 21 minutes ago)
· 10 languages
179 findings (91 legacy + 88 scanner) 8th percentile · Rust · large (100-500K LoC) Scanner says 72 (lower by 13)
Last scanned 3 hours, 21 minutes ago · v2 · 135 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
65.0 | 0.15 | 9.75 |
security_score |
35.8 | 0.25 | 8.95 |
testing_score |
51.0 | 0.20 | 10.20 |
documentation_score |
84.0 | 0.15 | 12.60 |
practices_score |
85.0 | 0.15 | 12.75 |
code_quality |
38.9 | 0.10 | 3.89 |
| Overall | 1.00 | 58.1 |
Showing 113 of 135 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
ROADMAP.md:1816
credential_exposurelegacy
ROADMAP.md:1810
credential_exposurelegacy
USAGE.md:271
credential_exposurelegacy
docs/windows-install-release.md:131
credential_exposurelegacy
rust/crates/api/src/providers/anthropic.rs:1748
secrets
install.sh:139
qualitylegacy
src/runtime.py:95
qualitylegacy
src/runtime.py:94
qualitylegacy
src/path_scope.py:67
qualitylegacy
src/runtime.py:91
qualitylegacy
src/query_engine.py:87
qualitylegacy
src/runtime.py:148
qualitylegacy
src/query_engine.py:165
qualitylegacy
src/runtime.py:206
qualitylegacy
src/path_scope.py:62
qualitylegacy
src/query_engine.py:96
qualitylegacy
src/query_engine.py:148
qualitylegacy
src/runtime.py:184
qualitylegacy
src/runtime.py:144
qualitylegacy
scripts/dogfood-probe.py:36
qualitylegacy
scripts/dogfood-probe.py:35
qualitylegacy
src/query_engine.py:127
qualitylegacy
src/path_scope.py:54
qualitylegacy
src/path_scope.py:50
qualitylegacy
.github/workflows/rust-ci.yml:132
dependencylegacy
.github/workflows/rust-ci.yml:114
dependencylegacy
.github/workflows/rust-ci.yml:102
dependencylegacy
.github/workflows/rust-ci.yml:88
dependencylegacy
.github/workflows/rust-ci.yml:71
dependencylegacy
.github/workflows/release.yml:43
dependencylegacy
.github/workflows/rust.yml:21
dependencylegacy
.github/workflows/rust-ci.yml:72
dependencylegacy
.github/workflows/release.yml:63
dependencylegacy
.github/workflows/rust-ci.yml:133
dependencylegacy
.github/workflows/rust-ci.yml:115
dependencylegacy
.github/workflows/rust-ci.yml:103
dependencylegacy
.github/workflows/rust-ci.yml:89
dependencylegacy
.github/workflows/release.yml:44
dependencylegacy
.github/workflows/release.yml:72
dependencylegacy
.github/workflows/rust-ci.yml:134
dependencylegacy
.github/workflows/rust-ci.yml:118
dependencylegacy
.github/workflows/rust-ci.yml:104
dependencylegacy
.github/workflows/rust-ci.yml:92
dependencylegacy
.github/workflows/release.yml:46
dependencylegacy
rust/Cargo.lock
dependencylegacy
rust/crates/claw-rag-service/Dockerfile:13
dependencylegacy
rust/crates/claw-rag-service/Dockerfile:3
dependencylegacy
rust/Cargo.lock
dependencylegacy
rust/Cargo.lock
dependencylegacy
rust/Cargo.lock
dependencylegacy
rust/Cargo.lock
dependencylegacy
rust/README.md:128
qualitylegacy
rust/.claude/sessions/session-1775009841982.json:1
qualitylegacy
scripts/generate_cc2_board.py:102
qualitylegacy
docker-compose.yml:1
dockerlegacy
rust/crates/claw-rag-service/Dockerfile:14
dockerlegacy
rust/crates/claw-rag-service/Dockerfile:6
dockerlegacy
rust/crates/claw-rag-service/Dockerfile:12
dockerlegacy
.github/workflows/release.yml:72
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
.dockerignore
dockerlegacy
docker-compose.yml:30
dockerlegacy
docker-compose.yml:11
dockerlegacy
docker-compose.yml:1
dockerlegacy
docker-compose.yml:30
dockerlegacy
docker-compose.yml:11
dockerlegacy
docker-compose.yml:1
dockerlegacy
rust/crates/claw-rag-service/Dockerfile:13
supply-chaindockerpinned-dependencies
rust/crates/claw-rag-service/Dockerfile:3
supply-chaindockerpinned-dependencies
.github/workflows/release.yml:63
supply-chaingithub-actionspinned-dependencies
src/costHook.py:6
dead-code
src/replLauncher.py:4
dead-code
src/interactiveHelpers.py:4
dead-code
src/commands.py:53
dead-code
src/command_graph.py:15
dead-code
src/ink.py:4
dead-code
src/query_engine.py:141
dead-code
src/tools.py:44
dead-code
rust/crates/claw-rag-service/src/main.rs:127
qualitylegacy
docker-compose.yml:22
qualitylegacy
src/path_scope.py:24
qualitylegacy
rust/crates/runtime/src/mcp_client.rs:173
qualitylegacy
rust/crates/runtime/src/git_context.rs:320
qualitylegacy
rust/crates/api/src/client.rs:244
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/8cfe9283-d3dd-47e9-97dc-f9c53760eeed/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/8cfe9283-d3dd-47e9-97dc-f9c53760eeed/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.