https://github.com/multica-ai/multica
· scanned 2026-05-17 02:50 UTC (13 hours, 30 minutes ago)
· 10 languages
761 findings (52 legacy + 709 scanner) 2nd percentile · Typescript · large (100-500K LoC) Scanner says 63 (lower by 6)
Last scanned 13 hours, 30 minutes ago · v2 · 407 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Showing 406 of 407 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
scripts/ensure-postgres.sh:19
credential_exposurelegacy
server/cmd/backfill_task_usage_daily/main.go:49
credential_exposurelegacy
scripts/screenshot-pr-cards.mjs:14
credential_exposurelegacy
scripts/init-worktree-env.sh:31
credential_exposurelegacy
docker-compose.yml:3
dockerlegacy
apps/desktop/src/main/index.ts:69
authlegacy
packages/views/auth/login-page.tsx:70
authlegacy
apps/web/app/(auth)/login/page.tsx:174
authlegacy
apps/web/app/(auth)/login/page.tsx:75
authlegacy
apps/desktop/src/renderer/src/App.tsx:51
authlegacy
apps/web/app/auth/callback/page.tsx:127
authlegacy
apps/web/app/auth/callback/page.tsx:44
authlegacy
packages/views/issues/components/issue-detail.tsx:1333
path_traversallegacy
server/internal/daemon/daemon.go:683
credential_exposurelegacy
apps/desktop/src/main/external-url.ts:6
ssrflegacy
apps/desktop/src/main/daemon-manager.ts:113
ssrflegacy
apps/desktop/scripts/package.mjs:427
ssrflegacy
server/internal/handler/skill_create.go:37
resource_exhaustionlegacy
server/internal/handler/skill.go:1708
resource_exhaustionlegacy
packages/views/common/task-transcript/agent-transcript-dialog.tsx:215
error_handlinglegacy
packages/core/auth/store.ts:119
error_handlinglegacy
apps/desktop/src/main/daemon-manager.ts:201
error_handlinglegacy
packages/views/auth/login-page.tsx:252
authlegacy
packages/views/auth/login-page.tsx:201
authlegacy
packages/views/auth/login-page.tsx:140
authlegacy
apps/web/components/web-providers.tsx:24
authlegacy
apps/desktop/src/renderer/src/App.tsx:84
authlegacy
e2e/helpers.ts:26
authlegacy
apps/web/features/landing/i18n/zh.ts:528
qualitylegacy
apps/web/features/landing/i18n/en.ts:528
qualitylegacy
Dockerfile:23
dockerlegacy
apps/desktop/src/renderer/src/platform/i18n-adapter.ts:25
qualitylegacy
server/internal/handler/runtime_update.go:1
qualitylegacy
README.zh-CN.md:79
dependencylegacy
apps/web/features/landing/components/download/cli-section.tsx:8
dependencylegacy
apps/docs/content/docs/cloud-quickstart.zh.mdx:29
dependencylegacy
SELF_HOSTING_AI.md:15
dependencylegacy
.github/workflows/desktop-smoke.yml:37
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:21
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:79
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:113
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:121
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:124
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:132
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:175
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:179
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:190
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:230
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:238
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:241
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:249
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
apps/docs/components/mermaid.tsx:153
owaspdangerous_innerhtml
apps/web/app/(landing)/layout.tsx:69
owaspdangerous_innerhtml
packages/ui/components/ui/chart.tsx:95
owaspdangerous_innerhtml
packages/ui/markdown/CodeBlock.tsx:167
owaspdangerous_innerhtml
packages/views/editor/attachment-preview-modal.tsx:471
owaspdangerous_innerhtml
packages/views/editor/extensions/math.tsx:27
owaspdangerous_innerhtml
packages/views/editor/readonly-content.tsx:383
owaspdangerous_innerhtml
server/internal/auth/cloudfront.go:148
owaspweak_hash
.dockerignore
dockerlegacy
server/cmd/server/health.go:160
error_handlinglegacy
server/cmd/multica/cmd_daemon.go:446
error_handlinglegacy
server/cmd/multica/cmd_agent.go:886
error_handlinglegacy
docker-compose.yml:3
dockerlegacy
docker-compose.yml:3
dockerlegacy
packages/views/agents/components/agent-profile-card.tsx:30
qualitylegacy
packages/views/autopilots/components/trigger-config.tsx:29
qualitylegacy
packages/views/agents/components/tabs/env-tab.tsx:208
qualitylegacy
packages/views/agents/components/model-dropdown.tsx:27
qualitylegacy
apps/desktop/src/renderer/src/components/daemon-runtime-card.tsx:129
qualitylegacy
server/internal/daemon/auto_update.go:1
qualitylegacy
packages/views/editor/extensions/markdown-copy.ts:1
qualitylegacy
server/cmd/multica/cmd_update.go:1
qualitylegacy
Dockerfile:23
supply-chaindockerpinned-dependencies
Dockerfile:2
supply-chaindockerpinned-dependencies
.github/workflows/desktop-smoke.yml:22
supply-chaingithub-actionspinned-dependencies
.github/workflows/desktop-smoke.yml:31
supply-chaingithub-actionspinned-dependencies
.github/workflows/desktop-smoke.yml:40
supply-chaingithub-actionspinned-dependencies
.github/workflows/desktop-smoke.yml:55
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:18
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:78
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:81
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:23
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:49
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:68
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:73
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:109
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:153
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:168
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:226
supply-chaingithub-actionspinned-dependencies
apps/docs/package.json
supply-chainnpminstall-scripts
apps/desktop/package.json
supply-chainnpminstall-scripts
Showing first 300 of 406. Refine filters or use the legacy findings page for deep search.
{# ── 2026-05-17 Round 14: AI-agent bridge footer ────────────────────── Discoverability: the /agents/voting/ guide + MCP manifest exist but aren't linked from anywhere users actually land. Small, opt-in footer. #}
This page is publicly accessible at:
https://repobility.com/scan/a3a23df1-c446-4e56-a160-ed8bb6252f50/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/a3a23df1-c446-4e56-a160-ed8bb6252f50/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.