https://github.com/HKUDS/nanobot
· scanned 2026-05-15 05:01 UTC (3 weeks ago)
· 10 languages
152 findings (34 legacy + 118 scanner) 44th percentile · Python · large (100-500K LoC) Scanner says 78 (lower by 5)
Last scanned 3 weeks ago · v1 · 27 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
54.4 | 0.25 | 13.60 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
85.0 | 0.15 | 12.75 |
practices_score |
75.0 | 0.15 | 11.25 |
code_quality |
59.0 | 0.10 | 5.90 |
| Overall | 1.00 | 72.5 |
web: 1.6 ·
agent: 5.8 ·
docker: 9.5 ·
threat: 28.8
Bug-class explainers. Each card groups findings of the same shape — these are the patterns most likely to ship to prod and reappear in future scans unless you systematically fix the cause, not just the instance.
.well-known/security.txt
webui/src/lib/bootstrap.ts:18
webui/src/i18n/config.ts:80
webui/src/hooks/useTheme.ts:36
webui/src/App.tsx:259
nanobot/skills/tmux/SKILL.md:81
nanobot/providers/bedrock_provider.py:620
nanobot/providers/bedrock_provider.py:619
nanobot/providers/azure_openai_provider.py:117
This page is publicly accessible at:
https://repobility.com/scan/9cb48be6-42ed-41b5-8e46-4312e8f96321/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/9cb48be6-42ed-41b5-8e46-4312e8f96321/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.