Scan timing: clone 14.27s · analysis 20.51s · 85.4 MB · GitHub preflight 454ms
https://github.com/google-gemini/gemini-cli
· scanned 2026-06-05 05:53 UTC (8 hours, 51 minutes ago)
· 10 languages
881 findings (97 legacy + 784 scanner) 11/13 scanners ran 74th percentile · Typescript · huge (>500K LoC) Scanner says 58 (higher by 29)
Last scanned 8 hours, 51 minutes ago · v2 · 489 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
95.0 | 0.20 | 19.00 |
documentation_score |
89.0 | 0.15 | 13.35 |
practices_score |
94.0 | 0.15 | 14.10 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 87.5 |
Showing 325 of 489 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/ci.yml:443
dependencylegacy
.github/workflows/ci.yml:47
dependencylegacy
.github/actions/push-docker/action.yml:50
secrets
.github/actions/push-sandbox/action.yml:56
secrets
.github/workflows/eval.yml:25
secrets
.github/workflows/gemini-automated-issue-dedup.yml:59
secrets
.github/workflows/gemini-scheduled-issue-dedup.yml:39
secrets
packages/vscode-ide-companion/src/ide-server.ts:213
qualitylegacy
evals/update_topic.eval.ts:200
qualitylegacy
.gcp/Dockerfile.gemini-code-builder:3
dependencylegacy
.gcp/Dockerfile.development:2
dependencylegacy
Dockerfile:42
dependencylegacy
Dockerfile:2
dependencylegacy
packages/a2a-server/package.json:1
dependencylegacy
packages/cli/package.json:1
dependencylegacy
packages/sdk/package.json:1
dependencylegacy
packages/cli/package.json:1
dependencylegacy
packages/core/package.json:1
dependencylegacy
packages/cli/src/services/McpPromptLoader.ts:69
xsslegacy
packages/cli/src/commands/extensions/update.ts:61
xsslegacy
packages/core/src/policy/utils.ts:21
qualitylegacy
packages/core/src/hooks/hookPlanner.ts:107
qualitylegacy
packages/cli/src/services/McpPromptLoader.ts:196
qualitylegacy
packages/cli/src/acp/commands/about.ts:32
qualitylegacy
.github/scripts/sync-maintainer-labels.cjs:57
qualitylegacy
.gemini/skills/ci/scripts/ci.mjs:41
qualitylegacy
packages/core/src/tools/get-internal-docs.ts:124
path_traversallegacy
packages/core/src/safety/built-in.ts:83
path_traversallegacy
packages/cli/src/commands/extensions/validate.ts:54
path_traversallegacy
packages/cli/src/acp/commands/about.ts:32
owaspexec_used
packages/cli/src/ui/commands/aboutCommand.ts:33
owaspexec_used
packages/cli/src/ui/commands/bugCommand.ts:46
owaspexec_used
packages/sdk/src/shell.ts:34
owaspexec_used
packages/sdk/src/types.ts:183
owaspexec_used
.github/workflows/eval-pr.yml
supply-chaingithub-actionspull-request-target
packages/cli/src/ui/utils/directoryUtils.ts:128
error_handlinglegacy
packages/cli/src/ui/hooks/useLogger.ts:27
error_handlinglegacy
packages/cli/src/ui/components/Notifications.tsx:109
error_handlinglegacy
packages/core/src/utils/agent-sanitization-utils.ts:120
redoslegacy
packages/core/src/policy/utils.ts:21
redoslegacy
.gemini/skills/ci/scripts/ci.mjs:33
qualitylegacy
packages/cli/src/config/settingsSchema.ts:236
qualitylegacy
packages/cli/src/config/config.ts:258
qualitylegacy
docs/reference/configuration.md:128
qualitylegacy
docs/cli/settings.md:30
qualitylegacy
docs/cli/cli-reference.md:58
qualitylegacy
.gcp/Dockerfile.gemini-code-builder:3
dockerlegacy
.gcp/Dockerfile.development:20
dockerlegacy
.gcp/Dockerfile.development:21
dockerlegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
manifest.json
qualitylegacy
.dockerignore
dockerlegacy
.gcp/Dockerfile.gemini-code-builder:81
dockerlegacy
.gcp/Dockerfile.gemini-code-builder:81
dockerlegacy
packages/cli/src/ui/components/messages/ToolMessage.tsx:71
qualitylegacy
packages/cli/src/ui/components/messages/GeminiMessageContent.tsx:22
qualitylegacy
packages/cli/src/ui/components/PolicyUpdateDialog.tsx:78
qualitylegacy
packages/cli/src/ui/components/OverageMenuDialog.tsx:38
qualitylegacy
packages/cli/src/ui/components/NewAgentsNotification.tsx:46
qualitylegacy
packages/cli/src/ui/components/BackgroundTaskDisplay.tsx:346
qualitylegacy
packages/cli/src/nonInteractiveCliAgentSession.ts:59
qualitylegacy
packages/cli/src/config/extensions/update.ts:69
qualitylegacy
packages/cli/src/commands/extensions/enable.ts:72
qualitylegacy
packages/cli/src/acp/commands/restore.ts:1
qualitylegacy
packages/cli/src/acp/commands/memory.ts:5
qualitylegacy
packages/cli/src/acp/commands/extensions.ts:32
qualitylegacy
packages/cli/src/acp/commands/commandRegistry.ts:5
qualitylegacy
evals/validation_fidelity_pre_existing_errors.eval.ts:22
qualitylegacy
evals/tool_output_masking.eval.ts:6
qualitylegacy
evals/skill_extraction.eval.ts:117
qualitylegacy
llms.txt
qualitylegacy
humans.txt
qualitylegacy
sitemap.xml
qualitylegacy
docs/cli/telemetry.md
qualitylegacy
Dockerfile:2
supply-chaindockerpinned-dependencies
Dockerfile:42
supply-chaindockerpinned-dependencies
package.json
supply-chainnpminstall-scripts
packages/vscode-ide-companion/package.json
supply-chainnpminstall-scripts
third_party/get-ripgrep/package.json
supply-chainnpminstall-scripts
Showing first 300 of 325. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/99c256b4-7e59-4244-ad4e-e01584eb41f3/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/99c256b4-7e59-4244-ad4e-e01584eb41f3/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.