Scan timing: clone 2.89s · analysis 16.71s · 12.3 MB · GitHub API rate-limit (preflight)
https://github.com/agentforce314/clawcodex
· scanned 2026-05-31 01:23 UTC (5 days, 7 hours ago)
· 10 languages
597 findings (163 legacy + 434 scanner) 60th percentile · Python · large (100-500K LoC) Scanner says 93 (lower by 18)
Last scanned 5 days, 7 hours ago · v2 · last Δ +1.1 (diff) · 415 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
70.0 | 0.25 | 17.50 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
44.0 | 0.15 | 6.60 |
code_quality |
38.1 | 0.10 | 3.81 |
| Overall | 1.00 | 75.7 |
Showing 191 of 415 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/tool_system/tools/grep.py:59
qualitylegacy
src/plugins/dependency.py:74
qualitylegacy
src/tool_system/tools/read.py:327
qualitylegacy
src/memdir/memory_scan.py:148
qualitylegacy
src/tool_system/context.py:237
qualitylegacy
src/services/mcp/doctor.py:122
qualitylegacy
src/permissions/setup.py:154
qualitylegacy
src/services/session_resume.py:77
qualitylegacy
src/auth/auth.py:85
qualitylegacy
src/agent/foreground_promotion.py:194
qualitylegacy
src/agent/agent_tool_utils.py:292
qualitylegacy
src/tool_system/registry.py:169
qualitylegacy
src/entrypoints/tui.py:149
qualitylegacy
scripts/diagnose_keys.py:96
qualitylegacy
src/tool_system/tools/notebook_edit.py:99
injectionlegacy
src/utils/git.py:200
injectionlegacy
src/services/api/errors.py:97
injectionlegacy
src/task_registry.py:114
qualitylegacy
src/config.py:216
qualitylegacy
src/config.py:219
qualitylegacy
src/config.py:188
qualitylegacy
src/config.py:190
qualitylegacy
src/config.py:224
qualitylegacy
src/config.py:189
qualitylegacy
src/config.py:221
qualitylegacy
src/config.py:226
qualitylegacy
src/services/mcp/xaa_idp_login.py:1
llm_injectionlegacy
src/providers/deepseek_provider.py:56
owasptls_verify_false
src/providers/openai_provider.py:43
owasptls_verify_false
src/providers/openrouter_provider.py:65
owasptls_verify_false
src/auth/gemini.py:28
error_handlinglegacy
src/auth/aws.py:55
error_handlinglegacy
src/auth/auth.py:85
error_handlinglegacy
src/providers/openrouter_provider.py:65
cryptolegacy
src/providers/openai_provider.py:43
cryptolegacy
src/providers/deepseek_provider.py:56
cryptolegacy
src/tool_system/tools/worktree.py:12
redoslegacy
demos/minecraft-app/src/utils/terrain.js:86
qualitylegacy
demos/adopt-me-app/src/pages/Trade.jsx:31
qualitylegacy
demos/crm-app/src/context/CRMContext.jsx:7
qualitylegacy
src/services/mcp/xaa_idp_login.py:142
qualitylegacy
src/services/compact/post_compact_attachments.py:252
qualitylegacy
src/config.py:246
qualitylegacy
src/entrypoints/headless.py:18
qualitylegacy
src/permissions/modes.py:93
qualitylegacy
src/entrypoints/tui.py:38
qualitylegacy
src/tool_system/renderers.py:95
qualitylegacy
src/tool_system/renderers.py:71
qualitylegacy
src/tool_system/registry.py:169
qualitylegacy
src/skills/loader.py:1174
qualitylegacy
src/skills/loader.py:563
qualitylegacy
src/skills/loader.py:1168
qualitylegacy
src/skills/loader.py:273
qualitylegacy
src/skills/loader.py:168
qualitylegacy
src/skills/argument_substitution.py:13
qualitylegacy
src/bridge/session_runner.py:810
qualitylegacy
src/bridge/session_runner.py:739
qualitylegacy
src/bridge/session_runner.py:795
qualitylegacy
src/bridge/debug_utils.py:109
qualitylegacy
src/plugins/loader.py:46
qualitylegacy
eval/run_compare.py:324
qualitylegacy
eval/run_compare.py:254
qualitylegacy
src/cli.py:537
qualitylegacy
src/token_estimation.py:252
qualitylegacy
src/token_estimation.py:394
qualitylegacy
src/token_estimation.py:36
qualitylegacy
src/config.py:255
qualitylegacy
src/config.py:137
qualitylegacy
src/__init__.py:10
qualitylegacy
src/services/session_storage.py:1
qualitylegacy
claude-code-wiki/raw/claude-code-sourcemap-learning-notebook/en/03_permission_security.md:21
dependencylegacy
src/tool_system/tools/grep.py:11
qualitylegacy
src/providers/minimax_provider.py:46
qualitylegacy
src/providers/base.py:43
qualitylegacy
src/providers/anthropic_provider.py:305
qualitylegacy
src/providers/openrouter_provider.py:60
qualitylegacy
src/providers/openai_provider.py:41
qualitylegacy
src/memdir/team_mem_prompts.py:109
qualitylegacy
src/hooks/registry.py:125
qualitylegacy
src/entrypoints/tui.py:49
qualitylegacy
src/costHook.py:6
dead-code
src/replLauncher.py:44
dead-code
eval/run_compare.py:775
dead-code
eval/run_compare.py:344
dead-code
eval/run_compare.py:648
dead-code
scripts/audit/commands.py:51
dead-code
src/context_system/context_analyzer.py:104
dead-code
src/token_estimation.py:335
dead-code
src/auth/oauth.py:87
dead-code
scripts/audit/command_graph.py:15
dead-code
src/tui/vim_state.py:922
dead-code
src/replLauncher.py:53
dead-code
src/auth/oauth.py:103
dead-code
src/auth/oauth.py:149
dead-code
scripts/audit/query_engine.py:134
dead-code
src/config.py:206
dead-code
src/config.py:223
dead-code
scripts/audit/tools.py:45
dead-code
src/services/mcp/oauth_callback_server.py:73
qualitylegacy
src/services/mcp/doctor.py:148
qualitylegacy
src/bridge/work_secret.py:109
qualitylegacy
src/agent/agent_definitions.py:16
qualitylegacy
scripts/audit/architecture_stats.py:56
qualitylegacy
eval/compare_results.py:29
qualitylegacy
src/tool_system/tools/mcp.py:48
qualitylegacy
src/command_system/engine.py:109
qualitylegacy
scripts/audit/legacy_cli_repl.py:246
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/a323da9b-bb32-4324-b9e5-662ea243eca9/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/a323da9b-bb32-4324-b9e5-662ea243eca9/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.