Scan timing: clone 2.29s · analysis 33.51s · 22.7 MB · GitHub preflight 494ms
https://github.com/Gitlawb/openclaude
· scanned 2026-05-31 01:22 UTC (5 days, 7 hours ago)
· 10 languages
1461 findings (76 legacy + 1385 scanner) 10/13 scanners ran 59th percentile · Typescript · huge (>500K LoC) Scanner says 68 (higher by 18)
Last scanned 5 days, 7 hours ago · v2 · 776 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
74.0 | 0.20 | 14.80 |
documentation_score |
100.0 | 0.15 | 15.00 |
practices_score |
80.0 | 0.15 | 12.00 |
code_quality |
69.0 | 0.10 | 6.90 |
| Overall | 1.00 | 86.5 |
Showing 241 of 776 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/services/api/openaiShim.ts:226
secrets
src/utils/powershell/parser.ts:1343
secrets
src/utils/providerProfile.ts:1709
secrets
src/utils/providerProfile.ts:1756
secrets
src/utils/urlRedaction.ts:36
secrets
src/services/settingsSync/types.ts:30
qualitylegacy
python/smart_router.py:361
qualitylegacy
python/smart_router.py:171
qualitylegacy
python/smart_router.py:354
qualitylegacy
python/smart_router.py:341
qualitylegacy
python/smart_router.py:62
qualitylegacy
python/smart_router.py:80
qualitylegacy
python/smart_router.py:305
qualitylegacy
python/smart_router.py:288
qualitylegacy
python/smart_router.py:75
qualitylegacy
python/smart_router.py:291
qualitylegacy
Dockerfile:31
dependencylegacy
Dockerfile:2
dependencylegacy
src/utils/secureStorage/macOsKeychainStorage.ts:40
credential_exposurelegacy
src/components/permissions/hooks.ts:80
xsslegacy
src/components/LogoPicker.tsx:26
xsslegacy
scripts/render-coverage-heatmap.ts:197
xsslegacy
src/tools/BashTool/sedEditParser.ts:314
qualitylegacy
src/services/teamMemorySync/secretScanner.ts:233
qualitylegacy
scripts/no-telemetry-plugin.ts:130
qualitylegacy
src/components/GlobalSearchDialog.tsx:332
qualitylegacy
src/buddy/useBuddyNotification.tsx:90
qualitylegacy
scripts/pr-intent-scan.ts:123
qualitylegacy
src/screens/REPL.tsx:3251
authlegacy
src/utils/auth.ts:678
owaspexec_used
src/components/Onboarding.tsx:167
error_handlinglegacy
src/commands/rename/rename.ts:71
error_handlinglegacy
src/bridge/replBridgeHandle.ts:22
error_handlinglegacy
python/atomic_chat_provider.py:35
qualitylegacy
python/ollama_provider.py:30
qualitylegacy
src/tools/shared/gitOperationTracking.ts:23
redoslegacy
src/utils/mcp/elicitationValidation.ts:24
qualitylegacy
src/utils/storage/SQLiteProvider.ts:257
qualitylegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
src/cli/print.ts:549
qualitylegacy
src/components/Spinner/useShimmerAnimation.ts:13
qualitylegacy
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
src/commands/security-review.ts:169
owaspdangerous_innerhtml
src/services/settingsSync/types.ts:30
owaspweak_hash
src/tools/BashTool/pathValidation.ts:549
owaspweak_hash
.dockerignore
dockerlegacy
src/cli/handlers/autoMode.ts:125
qualitylegacy
llms.txt
qualitylegacy
humans.txt
qualitylegacy
robots.txt
qualitylegacy
sitemap.xml
qualitylegacy
Dockerfile:2
supply-chaindockerpinned-dependencies
Dockerfile:31
supply-chaindockerpinned-dependencies
python/atomic_chat_provider.py:94
dead-code
python/ollama_provider.py:130
dead-code
src/services/api/codexOAuthShared.ts:67
qualitylegacy
src/commands/plugin/parseArgs.ts:46
qualitylegacy
src/commands/mcp/addCommand.ts:129
qualitylegacy
src/bridge/bridgeEnabled.ts:81
qualitylegacy
scripts/provider-launch.ts:196
qualitylegacy
scripts/grpc-cli.ts:107
qualitylegacy
scripts/provider-recommend.ts:254
qualitylegacy
src/grpc/server.ts:22
qualitylegacy
src/entrypoints/mcp.ts:226
qualitylegacy
scripts/grpc-cli.ts:16
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/a75ab839-80fb-497b-bd17-48a725fff0cb/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/a75ab839-80fb-497b-bd17-48a725fff0cb/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.