Scan timing: clone 1.44s · analysis 3.35s · 4.2 MB · GitHub API rate-limit (preflight)
https://github.com/modelcontextprotocol/typescript-sdk
· scanned 2026-05-24 01:20 UTC (1 week, 5 days ago)
· 10 languages
1278 findings (101 legacy + 1177 scanner) 56th percentile · Typescript · medium (20-100K LoC) Scanner says 66 (higher by 10)
Last scanned 1 week, 5 days ago · v7 · 281 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
80.4 | 0.25 | 20.10 |
testing_score |
90.0 | 0.20 | 18.00 |
documentation_score |
81.6 | 0.15 | 12.24 |
practices_score |
74.0 | 0.15 | 11.10 |
code_quality |
57.1 | 0.10 | 5.71 |
| Overall | 1.00 | 76.1 |
Showing 229 of 281 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
packages/core/src/types/guards.ts:105
qualitylegacy
packages/codemod/scripts/generateVersions.ts:24
xsslegacy
packages/client/src/client/middleware.ts:170
xsslegacy
packages/core/src/shared/uriTemplate.ts:274
qualitylegacy
.github/workflows/publish.yml:19
dependencylegacy
.github/workflows/deploy-docs.yml:28
dependencylegacy
.github/workflows/release.yml:53
dependencylegacy
.github/workflows/release.yml:20
dependencylegacy
.github/workflows/claude.yml:30
dependencylegacy
.github/workflows/main.yml:70
dependencylegacy
.github/workflows/main.yml:42
dependencylegacy
.github/workflows/main.yml:17
dependencylegacy
.github/workflows/conformance.yml:39
dependencylegacy
.github/workflows/conformance.yml:21
dependencylegacy
.github/workflows/deploy-docs.yml:44
dependencylegacy
.github/workflows/deploy-docs.yml:53
dependencylegacy
.github/workflows/publish.yml:27
dependencylegacy
.github/workflows/deploy-docs.yml:34
dependencylegacy
.github/workflows/release.yml:61
dependencylegacy
.github/workflows/release.yml:28
dependencylegacy
.github/workflows/main.yml:75
dependencylegacy
.github/workflows/main.yml:49
dependencylegacy
.github/workflows/main.yml:24
dependencylegacy
.github/workflows/conformance.yml:44
dependencylegacy
.github/workflows/conformance.yml:26
dependencylegacy
.github/workflows/deploy-docs.yml:47
dependencylegacy
.github/workflows/claude.yml:36
dependencylegacy
examples/server/src/simpleStatelessStreamableHttp.ts:141
qualitylegacy
examples/server/src/resourceServerOnly.ts:76
qualitylegacy
examples/server/src/simpleStatelessStreamableHttp.ts:99
qualitylegacy
examples/server/src/standaloneSseWithGetStreamableHttp.ts:50
qualitylegacy
examples/server/src/jsonResponseStreamableHttp.ts:85
qualitylegacy
packages/middleware/node/src/streamableHttp.examples.ts:52
qualitylegacy
packages/middleware/node/src/streamableHttp.ts:62
qualitylegacy
scripts/cli.ts:84
qualitylegacy
packages/middleware/express/src/auth/metadataRouter.ts:56
authlegacy
packages/middleware/node/src/streamableHttp.ts:62
authlegacy
packages/middleware/hono/src/hono.ts:19
qualitylegacy
packages/middleware/fastify/src/fastify.ts:1
qualitylegacy
packages/middleware/fastify/src/fastify.examples.ts:2
qualitylegacy
packages/middleware/express/src/express.ts:1
qualitylegacy
packages/middleware/express/src/express.examples.ts:2
qualitylegacy
examples/server/src/serverGuide.examples.ts:13
qualitylegacy
packages/core/src/shared/authUtils.ts:50
qualitylegacy
packages/core/src/shared/authUtils.ts:49
qualitylegacy
.github/workflows/claude.yml:36
supply-chaingithub-actionspinned-dependencies
.github/workflows/claude.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/deploy-docs.yml
supply-chaingithub-actionsleast-privilege
packages/client/src/client/streamableHttp.ts:117
qualitylegacy
packages/server/tsdown.config.ts:5
qualitylegacy
packages/server/src/server/stdio.ts:38
qualitylegacy
packages/server/src/server/server.ts:356
qualitylegacy
packages/server/src/server/server.ts:166
qualitylegacy
packages/server/src/experimental/tasks/server.ts:24
qualitylegacy
packages/middleware/node/tsdown.config.ts:5
qualitylegacy
packages/middleware/hono/tsdown.config.ts:1
qualitylegacy
packages/middleware/fastify/tsdown.config.ts:1
qualitylegacy
pnpm-lock.yaml
qualitylegacy
.github/workflows/claude.yml:30
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:28
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:61
supply-chaingithub-actionspinned-dependencies
.github/workflows/deploy-docs.yml:44
supply-chaingithub-actionspinned-dependencies
.github/workflows/deploy-docs.yml:47
supply-chaingithub-actionspinned-dependencies
.github/workflows/deploy-docs.yml:53
supply-chaingithub-actionspinned-dependencies
.github/workflows/publish.yml:27
supply-chaingithub-actionspinned-dependencies
package.json
supply-chainnpminstall-scripts
packages/server/src/server/middleware/hostHeaderValidation.ts:25
qualitylegacy
examples/server/src/standaloneSseWithGetStreamableHttp.ts:159
qualitylegacy
examples/server/src/honoWebStandardStreamableHttp.ts:33
qualitylegacy
examples/client/src/ssePollingClient.ts:85
qualitylegacy
examples/client/src/simpleClientCredentials.ts:52
qualitylegacy
examples/client-quickstart/src/index.ts:170
qualitylegacy
examples/shared/src/auth.ts:218
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/941e20b9-d91f-4609-a0f4-1b7fa3f6e58f/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/941e20b9-d91f-4609-a0f4-1b7fa3f6e58f/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.