CRIT
MINED107
Missing import: `html` used but not imported
.agents/skills/skill-creator/eval-viewe…:343
CRIT
MINED107
Missing import: `html` used but not imported
skills/skill-creator/eval-viewer/genera…:343
HIGH
SEC135
[SEC135] Auth/permission check missing on AI-generated endpoint: Mutating HTTP endpoint g…
workers/line-bot/src/presentation/http/…:40
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
workers/line-bot/src/presentation/http/…:61
HIGH
SEC040
[SEC040] innerHTML XSS — template literal with server-supplied data: Setting .innerHTML w…
workers/line-bot/src/infrastructure/con…:65
HIGH
SEC040
[SEC040] innerHTML XSS — template literal with server-supplied data: Setting .innerHTML w…
workers/line-bot/src/domain/line/issue-…:45
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
templates/codex-gemini-api/.agents/skil…:45
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
skills/gemini-image-describer/src/descr…:45
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
skills/gemini-audio-transcriber/src/tra…:45
HIGH
MINED108
`self.send_response` used but never assigned in __init__
.agents/skills/skill-creator/eval-viewe…:344
HIGH
MINED108
`self.path` used but never assigned in __init__
.agents/skills/skill-creator/eval-viewe…:333
HIGH
MINED108
`self.send_response` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:374
HIGH
MINED108
`self.headers` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:363
HIGH
MINED108
`self.wfile` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:378
HIGH
MINED108
`self.send_response` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:371
HIGH
MINED108
`self.rfile` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:364
HIGH
MINED108
`self.send_error` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:380
HIGH
MINED108
`self.end_headers` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:377
HIGH
MINED108
`self.send_header` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:376
HIGH
MINED108
`self.send_header` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:375
HIGH
MINED108
`self.path` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:362
HIGH
MINED108
`self.wfile` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:357
HIGH
MINED108
`self.send_error` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:359
HIGH
MINED108
`self.end_headers` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:356
HIGH
MINED108
`self.send_header` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:355
HIGH
MINED108
`self.send_header` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:354
HIGH
MINED108
`self.send_response` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:353
HIGH
MINED108
`self.wfile` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:348
HIGH
MINED108
`self.path` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:349
HIGH
MINED108
`self.end_headers` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:347
HIGH
MINED108
`self.send_header` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:346
HIGH
MINED108
`self.send_header` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:345
HIGH
MINED108
`self.send_response` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:344
HIGH
MINED108
`self.path` used but never assigned in __init__
skills/skill-creator/eval-viewer/genera…:333
HIGH
COMP001
[COMP001] High cognitive complexity: Function `validate_skill` has cognitive complexity 2…
.agents/skills/skill-creator/scripts/qu…:12
HIGH
COMP001
[COMP001] High cognitive complexity: Function `improve_description` has cognitive complex…
.agents/skills/skill-creator/scripts/im…:50
HIGH
MINED115
Action `duotify/GitHubClawToolkit/actions/update-comment-action` pinned to mutable ref `@…
templates/default/.github/workflows/iss…:186
HIGH
MINED115
Action `duotify/GitHubClawToolkit/actions/error-handler-action` pinned to mutable ref `@v…
templates/default/.github/workflows/iss…:178
HIGH
MINED115
Action `actions/setup-node` pinned to mutable ref `@v6`
templates/default/.github/workflows/iss…:87
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
templates/default/.github/workflows/iss…:80
HIGH
MINED115
Action `duotify/GitHubClawToolkit/actions/update-comment-action` pinned to mutable ref `@…
templates/codex-default/.github/workflo…:183
HIGH
MINED115
Action `duotify/GitHubClawToolkit/actions/error-handler-action` pinned to mutable ref `@v…
templates/codex-default/.github/workflo…:176
HIGH
MINED115
Action `duotify/GitHubClawToolkit/actions/commit-push-issue-branch-action` pinned to muta…
templates/codex-default/.github/workflo…:170
HIGH
MINED115
Action `actions/setup-node` pinned to mutable ref `@v6`
templates/codex-default/.github/workflo…:84
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
templates/codex-default/.github/workflo…:77
HIGH
MINED115
Action `duotify/GitHubClawToolkit/actions/update-comment-action` pinned to mutable ref `@…
templates/gemini-nanobanana/.github/wor…:166
HIGH
MINED115
Action `duotify/GitHubClawToolkit/actions/error-handler-action` pinned to mutable ref `@v…
templates/gemini-nanobanana/.github/wor…:159
HIGH
MINED115
Action `duotify/GitHubClawToolkit/actions/commit-push-issue-branch-action` pinned to muta…
templates/gemini-nanobanana/.github/wor…:153
HIGH
MINED115
Action `oven-sh/setup-bun` pinned to mutable ref `@v2`
templates/gemini-nanobanana/.github/wor…:76
HIGH
MINED115
Action `actions/setup-node` pinned to mutable ref `@v6`
templates/gemini-nanobanana/.github/wor…:73
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
templates/gemini-nanobanana/.github/wor…:66
HIGH
MINED115
Action `duotify/GitHubClawToolkit/actions/update-comment-action` pinned to mutable ref `@…
templates/copilot-gemini-api/.github/wo…:192
HIGH
MINED115
Action `duotify/GitHubClawToolkit/actions/error-handler-action` pinned to mutable ref `@v…
templates/copilot-gemini-api/.github/wo…:184
HIGH
MINED115
Action `duotify/GitHubClawToolkit/actions/commit-push-issue-branch-action` pinned to muta…
templates/copilot-gemini-api/.github/wo…:178
HIGH
MINED115
Action `actions/setup-node` pinned to mutable ref `@v6`
templates/copilot-gemini-api/.github/wo…:88
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
templates/copilot-gemini-api/.github/wo…:81
HIGH
MINED115
Action `duotify/GitHubClawToolkit/actions/update-comment-action` pinned to mutable ref `@…
templates/copilot-felo/.github/workflow…:192
HIGH
MINED115
Action `duotify/GitHubClawToolkit/actions/error-handler-action` pinned to mutable ref `@v…
templates/copilot-felo/.github/workflow…:184
HIGH
MINED115
Action `duotify/GitHubClawToolkit/actions/commit-push-issue-branch-action` pinned to muta…
templates/copilot-felo/.github/workflow…:178
HIGH
MINED115
Action `actions/setup-node` pinned to mutable ref `@v6`
templates/copilot-felo/.github/workflow…:88
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v4`
templates/copilot-felo/.github/workflow…:81
HIGH
GHSA-c2c7-rcm5-vvqj
picomatch: GHSA-c2c7-rcm5-vvqj
workers/line-bot/bun.lock
HIGH
MINED113
Express POST /line/webhook has no auth
workers/line-bot/src/presentation/http/…:40
MED
SEC125
[SEC125] AI placeholder credential left in source (your-api-key-here style): AI coding as…
skills/felo-superAgent/scripts/run_styl…:146
MED
MINED111
Bare except continues silently
.agents/skills/skill-creator/scripts/ru…:223
MED
MINED111
Bare except continues silently
.agents/skills/skill-creator/scripts/pa…:106
MED
MINED111
Bare except continues silently
skills/skill-creator/scripts/run_eval.py:223
MED
MINED111
Bare except continues silently
skills/skill-creator/scripts/package_sk…:106
MED
DEPCUR-NPM
npm package `@google/genai` is 1 major version(s) behind (>=1.33.0 -> 2.8.0)
skills/gemini-audio-transcriber/package…
MED
DEPCUR-NPM
npm package `@google/genai` is 1 major version(s) behind (>=1.33.0 -> 2.8.0)
skills/gemini-image-describer/package.j…
MED
DEPCUR-NPM
npm package `@google/genai` is 1 major version(s) behind (>=1.33.0 -> 2.8.0)
skills/gemini-deep-researcher/package.j…
MED
DEPCUR-NPM
npm package `@google/genai` is 1 major version(s) behind (>=1.33.0 -> 2.8.0)
skills/gemini-summary/package.json
MED
DEPCUR-NPM
npm package `@google/genai` is 1 major version(s) behind (>=1.33.0 -> 2.8.0)
templates/codex-gemini-api/.agents/skil…
MED
DEPCUR-NPM
npm package `@google/genai` is 1 major version(s) behind (>=1.33.0 -> 2.8.0)
templates/codex-gemini-api/.agents/skil…
MED
DEPCUR-NPM
npm package `@google/genai` is 1 major version(s) behind (>=1.33.0 -> 2.8.0)
templates/codex-gemini-api/.agents/skil…
MED
DEPCUR-NPM
npm package `@google/genai` is 1 major version(s) behind (>=1.33.0 -> 2.8.0)
templates/codex-gemini-api/.agents/skil…
MED
DEPCUR-NPM
npm package `@google/genai` is 1 major version(s) behind (>=1.33.0 -> 2.8.0)
templates/copilot-gemini-api/.agents/sk…
MED
DEPCUR-NPM
npm package `@google/genai` is 1 major version(s) behind (>=1.33.0 -> 2.8.0)
templates/copilot-gemini-api/.agents/sk…
MED
DEPCUR-NPM
npm package `@google/genai` is 1 major version(s) behind (>=1.33.0 -> 2.8.0)
templates/copilot-gemini-api/.agents/sk…
MED
DEPCUR-NPM
npm package `@google/genai` is 1 major version(s) behind (>=1.33.0 -> 2.8.0)
templates/copilot-gemini-api/.agents/sk…
MED
GHSA-58qx-3vcg-4xpx
ws: GHSA-58qx-3vcg-4xpx
workers/line-bot/bun.lock
MED
GHSA-3v7f-55p6-f55p
picomatch: GHSA-3v7f-55p6-f55p
workers/line-bot/bun.lock
MED
GHSA-v2v4-37r5-5v8g
ip-address: GHSA-v2v4-37r5-5v8g
workers/line-bot/bun.lock
MED
GHSA-xrhx-7g5j-rcj5
hono: GHSA-xrhx-7g5j-rcj5
workers/line-bot/bun.lock
MED
GHSA-xpcf-pg52-r92g
hono: GHSA-xpcf-pg52-r92g
workers/line-bot/bun.lock
MED
GHSA-xf4j-xp2r-rqqx
hono: GHSA-xf4j-xp2r-rqqx
workers/line-bot/bun.lock
MED
GHSA-wmmm-f939-6g9c
hono: GHSA-wmmm-f939-6g9c
workers/line-bot/bun.lock
MED
GHSA-r5rp-j6wh-rvv4
hono: GHSA-r5rp-j6wh-rvv4
workers/line-bot/bun.lock
MED
GHSA-qp7p-654g-cw7p
hono: GHSA-qp7p-654g-cw7p
workers/line-bot/bun.lock
MED
GHSA-p77w-8qqv-26rm
hono: GHSA-p77w-8qqv-26rm
workers/line-bot/bun.lock
MED
GHSA-f577-qrjj-4474
hono: GHSA-f577-qrjj-4474
workers/line-bot/bun.lock
MED
GHSA-9vqf-7f2p-gf9v
hono: GHSA-9vqf-7f2p-gf9v
workers/line-bot/bun.lock
MED
GHSA-69xw-7hcm-h432
hono: GHSA-69xw-7hcm-h432
workers/line-bot/bun.lock
MED
GHSA-458j-xx4x-4375
hono: GHSA-458j-xx4x-4375
workers/line-bot/bun.lock
MED
GHSA-3hrh-pfw6-9m5x
hono: GHSA-3hrh-pfw6-9m5x
workers/line-bot/bun.lock
MED
GHSA-2gcr-mfcq-wcc3
hono: GHSA-2gcr-mfcq-wcc3
workers/line-bot/bun.lock
MED
GHSA-26pp-8wgv-hjvm
hono: GHSA-26pp-8wgv-hjvm
workers/line-bot/bun.lock
MED
GHSA-jxxr-4gwj-5jf2
brace-expansion: GHSA-jxxr-4gwj-5jf2
workers/line-bot/bun.lock
MED
GHSA-f886-m6hf-6m8v
brace-expansion: GHSA-f886-m6hf-6m8v
workers/line-bot/bun.lock
MED
AGT015
Remote install command pipes network code directly to a shell
templates/antigravity-gcp/.github/workf…:127
MED
AGT013
Agent auto-approve or skip-permissions mode is easy to enable
templates/copilot-gemini-api/.github/wo…:162
MED
AGT013
Agent auto-approve or skip-permissions mode is easy to enable
templates/copilot-felo/.github/workflow…:162
MED
AGT013
Agent auto-approve or skip-permissions mode is easy to enable
templates/codex-gemini-api/.github/work…:158
MED
AGT013
Agent auto-approve or skip-permissions mode is easy to enable
templates/codex-felo/.github/workflows/…:158
MED
AGT013
Agent auto-approve or skip-permissions mode is easy to enable
templates/codex-default/.github/workflo…:154
MED
CORE_LARGE_FILES
Average file size is 663 lines (recommend <300)
—
MED
CORE_NO_CI
No CI/CD configuration found
—
MED
CORE_NO_README
No README file found
—
LOW
COMP001
[COMP001] High cognitive complexity: Function `package_skill` has cognitive complexity 14…
.agents/skills/skill-creator/scripts/pa…:42
LOW
DEPCUR-NPM
npm package `node-gyp` is minor version(s) behind (^12.2.0 -> 12.4.0)
workers/line-bot/package.json
LOW
DEPCUR-NPM
npm package `node-addon-api` is minor version(s) behind (^8.6.0 -> 8.8.0)
workers/line-bot/package.json
LOW
GHSA-hm8q-7f3q-5f36
hono: GHSA-hm8q-7f3q-5f36
workers/line-bot/bun.lock
LOW
AIC003
Duplicated implementation block across source files
workers/line-bot/src/infrastructure/lin…:2
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
skills/felo-web-fetch/scripts/run_web_f…:27
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
skills/felo-superAgent/scripts/run_styl…:9
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
skills/felo-slides/scripts/run_ppt_task…:11
INFO
MINED055
[MINED055] Npm Install No Lockfile: Production image runs npm install (resolves new versi…
skills/agent-browser/install.sh:6
INFO
DEPCUR-NPM
npm package `linkedom` is patch version(s) behind (^0.18.0 -> 0.18.12)
skills/gemini-summary/package.json
INFO
DEPCUR-NPM
npm package `linkedom` is patch version(s) behind (^0.18.0 -> 0.18.12)
templates/codex-gemini-api/.agents/skil…
INFO
DEPCUR-NPM
npm package `linkedom` is patch version(s) behind (^0.18.0 -> 0.18.12)
templates/copilot-gemini-api/.agents/sk…