Scan timing: clone 28.3s · analysis 28.44s · 54.0 MB · GitHub API rate-limit (preflight)
https://github.com/trpc-group/trpc-agent-go
· scanned 2026-05-31 01:26 UTC (5 days, 6 hours ago)
· 10 languages
462 findings (187 legacy + 275 scanner) 11/13 scanners ran 83rd percentile · Go · huge (>500K LoC) Scanner says 66 (higher by 23)
Last scanned 5 days, 6 hours ago · v2 · last Δ -0.4 (diff) · 329 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
95.0 | 0.15 | 14.25 |
practices_score |
95.0 | 0.15 | 14.25 |
code_quality |
64.0 | 0.10 | 6.40 |
| Overall | 1.00 | 89.7 |
Showing 291 of 329 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/workflows/prc.yml:145
dependencylegacy
openclaw/internal/gateway/stream.go:123
secrets
knowledge/source/source.go:91
qualitylegacy
knowledge/source/repo/graph_source.go:15
qualitylegacy
examples/tool/codeexec/main.go:372
qualitylegacy
graph/emitter.go:232
qualitylegacy
evaluation/internal/callback/callbacks.go:52
qualitylegacy
agent/extension/extension.go:109
qualitylegacy
examples/knowledge/reranker/infinity/deploy_infinity.py:68
qualitylegacy
.github/workflows/prc.yml:115
dependencylegacy
.github/workflows/prc.yml:100
dependencylegacy
.github/workflows/prc.yml:58
dependencylegacy
.github/workflows/prc.yml:29
dependencylegacy
.github/workflows/prc.yml:17
dependencylegacy
.github/workflows/module-sum-check.yml:11
dependencylegacy
.github/workflows/openclaw-release.yml:103
dependencylegacy
.github/workflows/openclaw-release.yml:63
dependencylegacy
.github/workflows/deploy.yml:17
dependencylegacy
.github/workflows/prc.yml:117
dependencylegacy
.github/workflows/openclaw-release.yml:105
dependencylegacy
.github/workflows/prc.yml:150
dependencylegacy
.github/workflows/prc.yml:101
dependencylegacy
.github/workflows/prc.yml:59
dependencylegacy
.github/workflows/prc.yml:18
dependencylegacy
.github/workflows/module-sum-check.yml:14
dependencylegacy
.github/workflows/openclaw-release.yml:64
dependencylegacy
.github/workflows/deploy.yml:24
dependencylegacy
.github/workflows/prc.yml:136
dependencylegacy
.github/workflows/prc.yml:91
dependencylegacy
.github/workflows/openclaw-release.yml:91
dependencylegacy
.github/workflows/prc.yml:141
dependencylegacy
.github/workflows/cla.yml:21
dependencylegacy
.github/workflows/deploy.yml:35
dependencylegacy
.github/workflows/openclaw-release.yml:117
dependencylegacy
examples/a2ui/go.mod:4
dependencylegacy
examples/graph/go.mod:4
dependencylegacy
examples/knowledge/go.mod:4
dependencylegacy
memory/redis/go.mod:4
dependencylegacy
examples/skill/go.mod:4
dependencylegacy
examples/tailor/go.mod:6
dependencylegacy
examples/session/go.mod:4
dependencylegacy
memory/mysqlvec/go.mod:4
dependencylegacy
memory/mysql/go.mod:4
dependencylegacy
memory/pgvector/go.mod:4
dependencylegacy
memory/postgres/go.mod:4
dependencylegacy
openclaw/go.mod:4
dependencylegacy
evaluation/go.mod:4
dependencylegacy
examples/go.mod:4
dependencylegacy
openclaw/go.mod:30
dependencylegacy
agent/extension/toolpipe/go.mod:4
dependencylegacy
memory/sqlitevec/go.mod:6
dependencylegacy
memory/sqlite/go.mod:4
dependencylegacy
codeexecutor/container/go.mod:4
dependencylegacy
codeexecutor/jupyter/go.mod:4
dependencylegacy
agent/weknora/go.mod:4
dependencylegacy
agent/n8n/go.mod:4
dependencylegacy
agent/dify/go.mod:4
dependencylegacy
openclaw/skills/model-usage/scripts/model_usage.py:83
path_traversallegacy
internal/toolretry/runner.go:156
resource_exhaustionlegacy
openclaw/browser-extension/popup.js:16
xsslegacy
evaluation/metric/mysql/mysql.go:145
qualitylegacy
evaluation/internal/mysqldb/schema.go:160
qualitylegacy
evaluation/evalresult/mysql/mysql.go:114
qualitylegacy
openclaw/internal/channel/telegram/audio_input.go:129
qualitylegacy
graph/visualize.go:323
qualitylegacy
agent/claudecode/command.go:45
qualitylegacy
openclaw/internal/channel/telegram/audio_input.go:119
path_traversallegacy
internal/workspaceinput/stager.go:242
path_traversallegacy
internal/skillstage/stager.go:310
path_traversallegacy
.github/workflows/prc.yml:366
supply-chaingithub-actionspinned-dependencies
evaluation/service/local/local.go:655
owaspeval_used
tool/hostexec/manager.go:78
owaspexec_used
examples/skill/skills/ocr/scripts/ocr_url.py:73
qualitylegacy
examples/skill/skills/ocr/scripts/ocr.py:89
qualitylegacy
examples/skill/scripts/download_gaia_2023_level1_validation.py:99
qualitylegacy
examples/skill/scripts/download_gaia_2023_level1_validation.py:76
qualitylegacy
examples/skill/scripts/download_gaia_2023_level1_validation.py:342
qualitylegacy
examples/skillrun/skills/python_math/scripts/fib.py:14
qualitylegacy
examples/a2aadk/adk/adk_server.py:66
qualitylegacy
examples/a2aadk/adk/adk_server.py:48
qualitylegacy
openclaw/skills/nano-banana-pro/scripts/generate_image.py:106
qualitylegacy
openclaw/skills/nano-banana-pro/scripts/generate_image.py:179
qualitylegacy
openclaw/skills/skill-creator/scripts/package_skill.py:109
qualitylegacy
openclaw/skills/skill-creator/scripts/init_skill.py:300
qualitylegacy
openclaw/skills/skill-creator/scripts/init_skill.py:292
qualitylegacy
openclaw/skills/skill-creator/scripts/init_skill.py:280
qualitylegacy
openclaw/skills/model-usage/scripts/model_usage.py:287
qualitylegacy
openclaw/skills/model-usage/scripts/model_usage.py:119
qualitylegacy
examples/a2aadk/adk/requirements.txt:3
dependencylegacy
examples/a2aadk/adk/requirements.txt:2
dependencylegacy
examples/openapitool/mockserver/main.go:66
qualitylegacy
examples/mcptool/http_headers/mcpserver/main.go:51
qualitylegacy
examples/a2ui/server/sbti/main.go:68
qualitylegacy
examples/a2ui/server/default/main.go:54
qualitylegacy
examples/a2amultipath/server/main.go:114
qualitylegacy
codeexecutor/e2b/internal/codeinterpreter/client.go:82
qualitylegacy
openclaw/skills/model-usage/scripts/model_usage.py:117
qualitylegacy
examples/agui/client/tdesign-chat/src/App.tsx:149
qualitylegacy
.github/workflows/cla.yml:21
supply-chaingithub-actionspinned-dependencies
.github/workflows/deploy.yml:35
supply-chaingithub-actionspinned-dependencies
.github/workflows/openclaw-release.yml:117
supply-chaingithub-actionspinned-dependencies
.github/workflows/prc.yml:141
supply-chaingithub-actionspinned-dependencies
.github/workflows/prc.yml:155
supply-chaingithub-actionspinned-dependencies
.github/workflows/cla.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/deploy.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/openclaw-release.yml
supply-chaingithub-actionsleast-privilege
codeexecutor/metadata.go:385
error_handlinglegacy
codeexecutor/e2b/internal/codeinterpreter/example/main.go:50
error_handlinglegacy
.github/scripts/check-current-module-sums.go:78
error_handlinglegacy
examples/summary/toolcalls/main.go:130
qualitylegacy
examples/skill/scripts/download_gaia_2023_level1_validation.py:249
qualitylegacy
examples/graph/io_conventions/main.go:231
qualitylegacy
examples/telemetry/jaeger-prometheus/docker-compose.yaml:17
dockerlegacy
examples/telemetry/jaeger-prometheus/docker-compose.yaml:10
dockerlegacy
examples/telemetry/jaeger-prometheus/docker-compose.yaml:1
dockerlegacy
examples/callbacks/timer/docker-compose.yaml:16
dockerlegacy
examples/callbacks/timer/docker-compose.yaml:9
dockerlegacy
examples/callbacks/timer/docker-compose.yaml:1
dockerlegacy
examples/telemetry/jaeger-prometheus/docker-compose.yaml:17
dockerlegacy
examples/telemetry/jaeger-prometheus/docker-compose.yaml:10
dockerlegacy
examples/telemetry/jaeger-prometheus/docker-compose.yaml:1
dockerlegacy
examples/callbacks/timer/docker-compose.yaml:16
dockerlegacy
examples/callbacks/timer/docker-compose.yaml:9
dockerlegacy
examples/callbacks/timer/docker-compose.yaml:1
dockerlegacy
evaluation/evaluator/llm/rubriccritic/rubriccritic.go:2
qualitylegacy
evaluation/evaluator/llm/rubriccritic/options.go:22
qualitylegacy
evaluation/evaluator/llm/operator/messagesconstructor/rubricresponse/rubricresponse.go:67
qualitylegacy
evaluation/evaluator/llm/operator/messagesconstructor/rubricresponse/rubricresponse.go:2
qualitylegacy
evaluation/evaluator/llm/operator/messagesconstructor/rubricreferencecritic/rubricreferencecritic.go:2
qualitylegacy
evaluation/evaluator/llm/operator/messagesconstructor/rubricknowledgerecall/rubricknowledgerecall.go:2
qualitylegacy
evaluation/evaluator/llm/operator/internal/rubrics/rubrics.go:78
qualitylegacy
evaluation/evaluator/llm/hallucination/options.go:22
qualitylegacy
evaluation/evaluator/llm/hallucination/hallucination.go:2
qualitylegacy
evaluation/evalset/mysql/options.go:1
qualitylegacy
evaluation/evalset/mysql/mysql.go:229
qualitylegacy
evaluation/evalset/mysql/mysql.go:23
qualitylegacy
evaluation/evalset/locator.go:17
qualitylegacy
evaluation/evalset/local/local.go:267
qualitylegacy
evaluation/evalset/local/local.go:82
qualitylegacy
evaluation/evalresult/mysql/mysql.go:51
qualitylegacy
evaluation/evalresult/local/local.go:33
qualitylegacy
artifact/s3/service.go:54
qualitylegacy
agent/parallelagent/structure_export.go:25
qualitylegacy
agent/llmagent/option.go:36
qualitylegacy
agent/llmagent/extension.go:109
qualitylegacy
agent/parallelagent/structure_export.go:8
qualitylegacy
agent/parallelagent/parallel_agent.go:165
qualitylegacy
agent/parallelagent/parallel_agent.go:79
qualitylegacy
agent/llmagent/structure_export.go:98
qualitylegacy
agent/llmagent/structure_export.go:78
qualitylegacy
agent/graphagent/graph_agent.go:528
qualitylegacy
agent/dify/dify_agent.go:242
qualitylegacy
agent/cycleagent/structure_export.go:8
qualitylegacy
agent/cycleagent/cycle_agent.go:37
qualitylegacy
.github/workflows/deploy.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/openclaw-release.yml:91
supply-chaingithub-actionspinned-dependencies
.github/workflows/openclaw-release.yml:105
supply-chaingithub-actionspinned-dependencies
.github/workflows/prc.yml:91
supply-chaingithub-actionspinned-dependencies
.github/workflows/prc.yml:117
supply-chaingithub-actionspinned-dependencies
.github/workflows/prc.yml:136
supply-chaingithub-actionspinned-dependencies
examples/a2aadk/adk/adk_server.py:27
dead-code
examples/a2aadk/adk/adk_server.py:143
dead-code
examples/a2aadk/adk/adk_codeexec_server.py:124
dead-code
examples/a2aadk/adk/adk_server.py:52
dead-code
examples/evaluation/promptiter/server/client.py:165
dead-code
examples/a2aadk/adk/adk_codeexec_server.py:143
dead-code
examples/a2aadk/adk/adk_server.py:115
dead-code
examples/a2aadk/adk/adk_codeexec_server.py:96
dead-code
openclaw/skills/model-usage/scripts/model_usage.py:20
dead-code
examples/a2aadk/adk/adk_server.py:178
dead-code
examples/a2aadk/adk/adk_codeexec_server.py:201
dead-code
examples/a2amultipath/server/main.go:41
qualitylegacy
examples/a2aagent/error_handling/main.go:67
qualitylegacy
codeexecutor/jupyter/jupyter_client.go:81
qualitylegacy
openclaw/skills/nano-banana-pro/scripts/generate_image.py:72
qualitylegacy
examples/a2aadk/adk/adk_server.py:81
qualitylegacy
examples/a2aadk/adk/adk_codeexec_server.py:42
qualitylegacy
examples/agui/client/tdesign-chat/src/agui/format.ts:29
qualitylegacy
examples/agui/client/copilotkit/app/api/copilotkit/route.ts:24
qualitylegacy
examples/skill/skills/ocr/scripts/ocr_url.py:37
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/a403e5be-55bf-4133-b7a5-6bc687c43c3b/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/a403e5be-55bf-4133-b7a5-6bc687c43c3b/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.