https://github.com/vivekchand/clawmetry
· scanned 2026-05-15 08:40 UTC (3 weeks ago)
· 10 languages
235 findings (53 legacy + 182 scanner) 37th percentile · Python · large (100-500K LoC) Scanner says 65 (higher by 7)
Last scanned 3 weeks ago · v1 · 49 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
75.0 | 0.15 | 11.25 |
security_score |
40.7 | 0.25 | 10.18 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
99.0 | 0.15 | 14.85 |
practices_score |
75.0 | 0.15 | 11.25 |
code_quality |
41.8 | 0.10 | 4.18 |
| Overall | 1.00 | 71.7 |
web: 1.6 ·
agent: 17.4 ·
authz: 2.1 ·
docker: 1.2 ·
threat: 12.1 ·
journey: 56.7
Showing 48 of 49 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
clawmetry/adapters/hermes.py:212
injectionlegacy
history.py:239
injectionlegacy
routes/infra.py:83
llm_injectionlegacy
routes/heartbeat.py:283
llm_injectionlegacy
routes/components.py:211
llm_injectionlegacy
clawmetry/local_store.py:772
error_handlinglegacy
clawmetry/gateway_tap.py:387
error_handlinglegacy
dashboard_claudecode.py:135
error_handlinglegacy
clawmetry/static/js/gw-setup.js:24
error_handlinglegacy
clawmetry/static/js/app.js:8880
authlegacy
clawmetry/static/js/app.js:8386
authlegacy
clawmetry/static/js/app.js:8385
authlegacy
clawmetry/static/js/app.js:8384
authlegacy
clawmetry/static/js/app.js:8094
authlegacy
clawmetry/static/js/app.js:7898
authlegacy
clawmetry/static/js/app.js:5731
authlegacy
clawmetry/static/js/app.js:3171
authlegacy
clawmetry/static/js/app.js:3170
authlegacy
clawmetry/static/js/app.js:3169
authlegacy
clawmetry/approvals.py:21
qualitylegacy
Dockerfile:4
dockerlegacy
routes/skills.py:105
qualitylegacy
clawmetry/static/js/app.js:145
qualitylegacy
clawmetry/static/js/app.js:125
qualitylegacy
clawmetry/static/js/app.js:120
qualitylegacy
clawmetry/static/js/app.js:90
qualitylegacy
clawmetry/static/js/app.js:79
qualitylegacy
clawmetry/static/js/alerts.js:444
qualitylegacy
clawmetry/static/js/alerts.js:443
qualitylegacy
clawmetry/static/js/alerts.js:285
qualitylegacy
clawmetry/static/js/alerts.js:128
qualitylegacy
clawmetry/static/js/alerts.js:112
qualitylegacy
clawmetry/static/js/alerts.js:104
qualitylegacy
clawmetry/static/js/alerts.js:92
qualitylegacy
clawmetry/static/js/alerts.js:56
qualitylegacy
clawmetry/static/js/alerts.js:54
qualitylegacy
clawhub-plugin/src/service.ts:16
qualitylegacy
clawmetry/static/js/gw-setup.js:9
qualitylegacy
.well-known/security.txt
qualitylegacy
install-clawmetry.sh:3
dependencylegacy
clawhub-plugin/uninstall.sh:96
dependencylegacy
clawhub-plugin/README.md:18
dependencylegacy
README.md:58
dependencylegacy
CHANGELOG.md:108
dependencylegacy
.dockerignore
dockerlegacy
This page is publicly accessible at:
https://repobility.com/scan/b8d6d8db-1a9e-4d5e-8189-6d0592eb62cf/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/b8d6d8db-1a9e-4d5e-8189-6d0592eb62cf/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.