https://github.com/multica-ai/multica
· scanned 2026-05-17 02:50 UTC (13 hours, 31 minutes ago)
· 10 languages
761 findings (52 legacy + 709 scanner) 2nd percentile · Typescript · large (100-500K LoC) Scanner says 63 (lower by 6)
Last scanned 13 hours, 31 minutes ago · v2 · 407 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Showing 354 of 407 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/desktop-smoke.yml:37
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:21
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:79
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:113
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:121
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:124
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:132
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:175
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:179
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:190
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:230
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:238
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:241
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:249
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
apps/docs/components/mermaid.tsx:153
owaspdangerous_innerhtml
apps/web/app/(landing)/layout.tsx:69
owaspdangerous_innerhtml
packages/ui/components/ui/chart.tsx:95
owaspdangerous_innerhtml
packages/ui/markdown/CodeBlock.tsx:167
owaspdangerous_innerhtml
packages/views/editor/attachment-preview-modal.tsx:471
owaspdangerous_innerhtml
packages/views/editor/extensions/math.tsx:27
owaspdangerous_innerhtml
packages/views/editor/readonly-content.tsx:383
owaspdangerous_innerhtml
server/internal/auth/cloudfront.go:148
owaspweak_hash
Dockerfile:23
supply-chaindockerpinned-dependencies
Dockerfile:2
supply-chaindockerpinned-dependencies
.github/workflows/desktop-smoke.yml:22
supply-chaingithub-actionspinned-dependencies
.github/workflows/desktop-smoke.yml:31
supply-chaingithub-actionspinned-dependencies
.github/workflows/desktop-smoke.yml:40
supply-chaingithub-actionspinned-dependencies
.github/workflows/desktop-smoke.yml:55
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:18
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:78
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:81
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:23
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:49
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:68
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:73
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:109
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:153
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:168
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:226
supply-chaingithub-actionspinned-dependencies
apps/docs/package.json
supply-chainnpminstall-scripts
apps/desktop/package.json
supply-chainnpminstall-scripts
Showing first 300 of 354. Refine filters or use the legacy findings page for deep search.
{# ── 2026-05-17 Round 14: AI-agent bridge footer ────────────────────── Discoverability: the /agents/voting/ guide + MCP manifest exist but aren't linked from anywhere users actually land. Small, opt-in footer. #}
This page is publicly accessible at:
https://repobility.com/scan/a3a23df1-c446-4e56-a160-ed8bb6252f50/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/a3a23df1-c446-4e56-a160-ed8bb6252f50/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.