https://github.com/multica-ai/multica
· scanned 2026-05-17 02:50 UTC (17 hours, 35 minutes ago)
· 10 languages
761 findings (52 legacy + 709 scanner) 2nd percentile · Typescript · large (100-500K LoC) Scanner says 63 (lower by 8)
Last scanned 17 hours, 35 minutes ago · v2 · 407 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
2.3 | 0.25 | 0.57 |
testing_score |
90.0 | 0.20 | 18.00 |
documentation_score |
75.0 | 0.15 | 11.25 |
practices_score |
75.0 | 0.15 | 11.25 |
code_quality |
51.7 | 0.10 | 5.17 |
| Overall | 1.00 | 55.2 |
agent: 7.6 ·
authz: 1.2 ·
docker: 8.9 ·
threat: 55.1 ·
journey: 62.8
Showing 52 of 407 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
scripts/ensure-postgres.sh:19
credential_exposurelegacy
server/cmd/backfill_task_usage_daily/main.go:49
credential_exposurelegacy
scripts/screenshot-pr-cards.mjs:14
credential_exposurelegacy
scripts/init-worktree-env.sh:31
credential_exposurelegacy
docker-compose.yml:3
dockerlegacy
apps/desktop/src/main/index.ts:69
authlegacy
packages/views/auth/login-page.tsx:70
authlegacy
apps/web/app/(auth)/login/page.tsx:174
authlegacy
apps/web/app/(auth)/login/page.tsx:75
authlegacy
apps/desktop/src/renderer/src/App.tsx:51
authlegacy
apps/web/app/auth/callback/page.tsx:127
authlegacy
apps/web/app/auth/callback/page.tsx:44
authlegacy
packages/views/issues/components/issue-detail.tsx:1333
path_traversallegacy
server/internal/daemon/daemon.go:683
credential_exposurelegacy
apps/desktop/src/main/external-url.ts:6
ssrflegacy
apps/desktop/src/main/daemon-manager.ts:113
ssrflegacy
apps/desktop/scripts/package.mjs:427
ssrflegacy
server/internal/handler/skill_create.go:37
resource_exhaustionlegacy
server/internal/handler/skill.go:1708
resource_exhaustionlegacy
packages/views/common/task-transcript/agent-transcript-dialog.tsx:215
error_handlinglegacy
packages/core/auth/store.ts:119
error_handlinglegacy
apps/desktop/src/main/daemon-manager.ts:201
error_handlinglegacy
packages/views/auth/login-page.tsx:252
authlegacy
packages/views/auth/login-page.tsx:201
authlegacy
packages/views/auth/login-page.tsx:140
authlegacy
apps/web/components/web-providers.tsx:24
authlegacy
apps/desktop/src/renderer/src/App.tsx:84
authlegacy
e2e/helpers.ts:26
authlegacy
apps/web/features/landing/i18n/zh.ts:528
qualitylegacy
apps/web/features/landing/i18n/en.ts:528
qualitylegacy
Dockerfile:23
dockerlegacy
apps/desktop/src/renderer/src/platform/i18n-adapter.ts:25
qualitylegacy
server/internal/handler/runtime_update.go:1
qualitylegacy
README.zh-CN.md:79
dependencylegacy
apps/web/features/landing/components/download/cli-section.tsx:8
dependencylegacy
apps/docs/content/docs/cloud-quickstart.zh.mdx:29
dependencylegacy
SELF_HOSTING_AI.md:15
dependencylegacy
.dockerignore
dockerlegacy
server/cmd/server/health.go:160
error_handlinglegacy
server/cmd/multica/cmd_daemon.go:446
error_handlinglegacy
server/cmd/multica/cmd_agent.go:886
error_handlinglegacy
docker-compose.yml:3
dockerlegacy
docker-compose.yml:3
dockerlegacy
packages/views/agents/components/agent-profile-card.tsx:30
qualitylegacy
packages/views/autopilots/components/trigger-config.tsx:29
qualitylegacy
packages/views/agents/components/tabs/env-tab.tsx:208
qualitylegacy
packages/views/agents/components/model-dropdown.tsx:27
qualitylegacy
apps/desktop/src/renderer/src/components/daemon-runtime-card.tsx:129
qualitylegacy
server/internal/daemon/auto_update.go:1
qualitylegacy
packages/views/editor/extensions/markdown-copy.ts:1
qualitylegacy
server/cmd/multica/cmd_update.go:1
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/a3a23df1-c446-4e56-a160-ed8bb6252f50/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/a3a23df1-c446-4e56-a160-ed8bb6252f50/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.