https://github.com/vercel/ai
· scanned 2026-05-31 01:27 UTC (5 days, 14 hours ago)
· 10 languages
3198 findings (95 legacy + 3103 scanner) 11/13 scanners ran 50th percentile · Typescript · large (100-500K LoC) Scanner says 69 (higher by 7)
Last scanned 5 days, 14 hours ago · v2 · last Δ +5.8 (diff) · 1649 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
79.0 | 0.20 | 15.80 |
documentation_score |
45.0 | 0.15 | 6.75 |
practices_score |
74.0 | 0.15 | 11.10 |
code_quality |
79.0 | 0.10 | 7.90 |
| Overall | 1.00 | 75.6 |
Showing 1518 of 1649 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
examples/ai-functions/src/generate-text/openai/tool-call-with-tools-context.ts:42
qualitylegacy
examples/ai-functions/src/generate-text/openai/reasoning-tools.ts:21
qualitylegacy
examples/ai-functions/src/generate-text/amazon-bedrock/anthropic-multiple-tools.ts:40
qualitylegacy
examples/next-workflow/workflow/agent-chat.ts:57
qualitylegacy
.github/workflows/auto-merge-release-prs.yml:29
dependencylegacy
.github/workflows/slack-team-review-notification.yml:34
dependencylegacy
.github/workflows/ci.yml:225
dependencylegacy
packages/google-vertex/src/edge/google-vertex-auth-edge.ts:59
owaspprivate_key_in_repo
packages/openai/src/responses/__fixtures__/openai-compaction.1.json:36
secrets
examples/next-fastapi/api/index.py:129
qualitylegacy
packages/devtools/src/viewer/server.ts:164
qualitylegacy
packages/devtools/src/viewer/server.ts:232
qualitylegacy
examples/mcp/src/mcp-with-auth/client.ts:48
qualitylegacy
examples/ai-e2e-next/app/chat/mcp-with-auth/page.tsx:15
securitylegacy
examples/ai-e2e-next/app/chat/mcp-apps/page.tsx:54
securitylegacy
examples/ai-e2e-next/app/chat/custom-sources/page.tsx:31
securitylegacy
examples/ai-functions/src/agent/openai/generate-tools-context.ts:18
qualitylegacy
examples/ai-functions/src/agent/openai/generate-tools-context-call-options.ts:18
qualitylegacy
examples/ai-e2e-next/app/chat/tools/page.tsx:33
qualitylegacy
examples/ai-functions/src/generate-text/amazon-bedrock/api-key.ts:38
qualitylegacy
examples/ai-functions/src/generate-video/klingai/motion-control-v3.ts:21
qualitylegacy
examples/ai-functions/src/generate-video/klingai/motion-control-pro.ts:21
qualitylegacy
examples/ai-e2e-next/app/api/chat/custom-sources/route.ts:22
qualitylegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/update-model-settings.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/backport.yml
supply-chaingithub-actionsleast-privilege
packages/assemblyai/tsup.config.ts:1
qualitylegacy
packages/anthropic/tsup.config.ts:1
qualitylegacy
packages/anthropic/src/tool/web-search_20260209.ts:8
qualitylegacy
packages/anthropic/src/tool/web-fetch-20260209.ts:19
qualitylegacy
packages/anthropic/src/tool/text-editor_20250728.ts:15
qualitylegacy
packages/anthropic/src/tool/text-editor_20250124.ts:8
qualitylegacy
packages/anthropic/src/tool/computer_20251124.ts:8
qualitylegacy
packages/anthropic/src/tool/code-execution_20260120.ts:10
qualitylegacy
packages/anthropic/src/tool/code-execution_20260120.ts:8
qualitylegacy
packages/anthropic/src/tool/code-execution_20250825.ts:10
qualitylegacy
packages/anthropic/src/tool/bash_20250124.ts:66
qualitylegacy
packages/anthropic/src/anthropic-provider.ts:106
qualitylegacy
packages/anthropic-aws/tsup.config.ts:1
qualitylegacy
packages/anthropic-aws/src/anthropic-aws-provider.ts:85
qualitylegacy
packages/anthropic-aws/src/anthropic-aws-provider.ts:56
qualitylegacy
packages/anthropic-aws/src/anthropic-aws-fetch.ts:21
qualitylegacy
packages/amazon-bedrock/src/mantle/bedrock-mantle-provider.ts:86
qualitylegacy
packages/amazon-bedrock/src/mantle/bedrock-mantle-provider.ts:60
qualitylegacy
packages/ai/src/generate-text/step-result.ts:69
qualitylegacy
packages/anthropic/src/anthropic-provider.ts:102
qualitylegacy
packages/amazon-bedrock/src/anthropic/amazon-bedrock-anthropic-provider.ts:76
qualitylegacy
packages/amazon-bedrock/src/amazon-bedrock-image-model.ts:205
qualitylegacy
packages/ai/src/ui/last-assistant-message-is-complete-with-tool-calls.ts:3
qualitylegacy
packages/ai/src/generate-object/stream-object.ts:81
qualitylegacy
packages/ai/src/embed/embed.ts:48
qualitylegacy
humans.txt
qualitylegacy
robots.txt
qualitylegacy
sitemap.xml
qualitylegacy
package.json
supply-chainnpminstall-scripts
packages/svelte/package.json
supply-chainnpminstall-scripts
examples/nuxt-openai/package.json
supply-chainnpminstall-scripts
examples/sveltekit-openai/package.json
supply-chainnpminstall-scripts
Showing first 300 of 1518. Refine filters or use the legacy findings page for deep search.
This page is publicly accessible at:
https://repobility.com/scan/9a1ae60a-ba5d-47ea-833b-bdc487805b97/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/9a1ae60a-ba5d-47ea-833b-bdc487805b97/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.