Scan timing: clone 21.7s · analysis 14.02s · 80.3 MB · GitHub API rate-limit (preflight)
https://github.com/modu-ai/moai-adk
· scanned 2026-05-31 01:24 UTC (5 days, 6 hours ago)
· 10 languages
265 findings (90 legacy + 175 scanner) 11/13 scanners ran 73rd percentile · Go · large (100-500K LoC) Scanner says 77 (higher by 11)
Last scanned 5 days, 6 hours ago · v2 · 194 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
85.0 | 0.20 | 17.00 |
documentation_score |
90.0 | 0.15 | 13.50 |
practices_score |
84.0 | 0.15 | 12.60 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 87.8 |
Showing 148 of 194 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
internal/hook/security/rules.go:199
qualitylegacy
.github/workflows/claude-code-review.yml:48
dependencylegacy
.github/workflows/ci.yml:133
dependencylegacy
docs-site/themes/hugo-geekdoc/static/js/2130-d110bcb1.chunk.min.js:1
dependencylegacy
internal/hook/security/rules.go:200
qualitylegacy
internal/hook/security/rules.go:199
qualitylegacy
internal/hook/security/rules.go:200
deserializationlegacy
internal/update/updater.go:299
qualitylegacy
internal/hook/trace/writer.go:66
qualitylegacy
.github/workflows/docs-i18n-check.yml:53
dependencylegacy
.github/workflows/claude-code-review.yml:19
dependencylegacy
.github/workflows/label-sync.yml:42
dependencylegacy
.github/workflows/ci.yml:172
dependencylegacy
.github/workflows/ci.yml:80
dependencylegacy
.github/workflows/ci.yml:39
dependencylegacy
.github/workflows/release-pr-multi-os.yml:52
dependencylegacy
.github/workflows/codeql.yml:80
dependencylegacy
.github/workflows/codeql.yml:30
dependencylegacy
.github/workflows/docs-i18n-check.yml:99
dependencylegacy
.github/workflows/ci.yml:177
dependencylegacy
.github/workflows/ci.yml:85
dependencylegacy
.github/workflows/release-pr-multi-os.yml:57
dependencylegacy
.github/workflows/codeql.yml:83
dependencylegacy
.github/workflows/docs-i18n-check.yml:165
dependencylegacy
.github/workflows/ci.yml:129
dependencylegacy
.github/workflows/label-sync.yml:45
dependencylegacy
.github/workflows/codeql.yml:97
dependencylegacy
.github/workflows/codeql.yml:94
dependencylegacy
.github/workflows/codeql.yml:89
dependencylegacy
internal/github/issue_closer.go:124
qualitylegacy
internal/cli/cg.go:27
qualitylegacy
internal/cli/cc.go:27
qualitylegacy
internal/cli/worktree/guard.go:285
qualitylegacy
internal/cli/branch_protection.go:69
qualitylegacy
internal/cli/astgrep.go:214
qualitylegacy
internal/hook/instructions_loaded.go:46
path_traversallegacy
internal/hook/security/rules.go:169
owaspeval_used
internal/cli/cc.go:27
owaspexec_used
internal/cli/cg.go:27
owaspexec_used
internal/cli/glm.go:37
owaspexec_used
internal/github/gh.go:165
owaspexec_used
internal/github/issue_parser.go:87
owaspexec_used
internal/hook/security/rules.go:172
owaspexec_used
internal/hook/security/rules.go:181
injectionlegacy
internal/hook/security/rules.go:199
deserializationlegacy
.moai/brain/IDEA-002/claude-design-handoff/project/overlays.jsx:152
qualitylegacy
internal/cli/doctor_sandbox.go:141
xsslegacy
internal/cli/doctor_hook.go:102
xsslegacy
internal/cli/astgrep.go:164
xsslegacy
internal/update/updater.go:138
securitylegacy
internal/update/rollback.go:53
securitylegacy
internal/hook/security/rules.go:208
qualitylegacy
.moai/marketing/blog-posts/velog-ko.md:59
dependencylegacy
.moai/marketing/blog-posts/okky-ko.md:158
dependencylegacy
.github/workflows/codeql.yml:89
supply-chaingithub-actionspinned-dependencies
.github/workflows/codeql.yml:94
supply-chaingithub-actionspinned-dependencies
.github/workflows/codeql.yml:97
supply-chaingithub-actionspinned-dependencies
.github/workflows/label-sync.yml:45
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:129
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-drafter.yml:32
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:35
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-drafter.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/claude.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/release-drafter-cleanup.yml
supply-chaingithub-actionsleast-privilege
.github/workflows/auto-merge.yml
supply-chaingithub-actionsleast-privilege
internal/hook/security/rules.go:218
owaspcors_wildcard
internal/hook/security/rules.go:181
owaspsubprocess_shell_true
internal/cli/astgrep.go:130
error_handlinglegacy
internal/ciwatch/state.go:57
error_handlinglegacy
internal/astgrep/rules.go:36
error_handlinglegacy
internal/harness/tier/tier.go:7
qualitylegacy
.moai/scripts/status-drift-cleanup.go:110
qualitylegacy
internal/lsp/hook/tracker.go:123
qualitylegacy
internal/lsp/aggregator/aggregator.go:173
qualitylegacy
internal/loop/storage.go:68
qualitylegacy
internal/hook/user_prompt_submit.go:69
qualitylegacy
internal/harness/retention.go:63
qualitylegacy
internal/design/dtcg/categories/typography.go:10
qualitylegacy
internal/cli/migrate_agency_disk_windows.go:30
qualitylegacy
internal/hook/auto_update.go:1
qualitylegacy
.github/workflows/codeql.yml:80
supply-chaingithub-actionspinned-dependencies
.github/workflows/codeql.yml:83
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-pr-multi-os.yml:52
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-pr-multi-os.yml:57
supply-chaingithub-actionspinned-dependencies
.github/workflows/label-sync.yml:42
supply-chaingithub-actionspinned-dependencies
.github/workflows/docs-i18n-check.yml:53
supply-chaingithub-actionspinned-dependencies
.github/workflows/docs-i18n-check.yml:99
supply-chaingithub-actionspinned-dependencies
.github/workflows/docs-i18n-check.yml:165
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:80
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:85
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:172
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:177
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:198
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:203
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:243
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:248
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:267
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:285
supply-chaingithub-actionspinned-dependencies
.github/workflows/ci.yml:290
supply-chaingithub-actionspinned-dependencies
.github/workflows/template-neutrality-check.yaml:50
supply-chaingithub-actionspinned-dependencies
.github/workflows/community.yml:27
supply-chaingithub-actionspinned-dependencies
.github/workflows/community.yml:62
supply-chaingithub-actionspinned-dependencies
.github/workflows/community.yml:94
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:24
supply-chaingithub-actionspinned-dependencies
.github/workflows/release.yml:29
supply-chaingithub-actionspinned-dependencies
.github/workflows/release-drafter-cleanup.yml:35
supply-chaingithub-actionspinned-dependencies
.github/workflows/auto-merge.yml:51
supply-chaingithub-actionspinned-dependencies
internal/hook/security/rules.go:210
owaspdebug_true
internal/hook/security/rules.go:142
owaspdocument_write
This page is publicly accessible at:
https://repobility.com/scan/b17cb6f7-f398-498c-b7bc-c52164018838/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/b17cb6f7-f398-498c-b7bc-c52164018838/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.