https://github.com/thesongzhu/Friday
· scanned 2026-06-05 18:16 UTC (4 days, 19 hours ago)
· 10 languages
972 raw signals (78 security + 894 graph) 11/13 scanners ran 42nd percentile · Typescript · large (100-500K LoC) System graph score 67 (higher by 6)
Last scanned 4 days, 19 hours ago · v2 · 446 actionable findings from 2 signal sources. 79 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
85.0 | 0.15 | 12.75 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
42.0 | 0.20 | 8.40 |
documentation_score |
65.0 | 0.15 | 9.75 |
practices_score |
68.0 | 0.15 | 10.20 |
code_quality |
70.0 | 0.10 | 7.00 |
| Overall | 1.00 | 73.1 |
Showing 288 of 446 actionable findings. 525 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/agent/tools/friday-agent-canvas-tool.ts:42
src/cloud-workers/services/friday-cloud-worker-package.ts:124, 127 (2 hits)src/agent/runtime/friday-agent-tool-risk.ts:51
.github/workflows/real-green-gate.yml:105, 108, 164, 186, 189, 206, 224, 227, +14 more (28 hits).github/workflows/release.yml:265, 347, 386, 394, 402, 410, 418, 426, +4 more (12 hits).github/workflows/nightly-heavy.yml:122, 143, 164, 228, 274 (10 hits).github/workflows/cloud-e2e.yml:122, 184 (4 hits).github/workflows/telegram-live-proof.yml:66src/agent/runtime/friday-agent-system-prompt-builder.ts:17
src/agent/tools/friday-agent-canvas-tool.ts:42
Eval used
rust-core/crates/friday-storage/src/offline.rs:147
Exec used
src/desktop/engine/friday-desktop-adapters.ts:176
Exec used
src/workflows/engine/friday-workflow-expression-evaluator.ts:528
Exec used
src/workflows/model/friday-workflow-expression.types.ts:77
Exec used
src/agent/tools/friday-agent-gateway-validation.ts:13
src/agent/security/friday-agent-ssrf-guard.ts:1
index.html
.well-known/security.txt
.github/workflows/release.yml:675
CI/CD securitySupply chainGithub actions
.github/workflows/release.yml
CI/CD securitySupply chainGithub actions
src/agent/persistence/friday-agent-run-repository.ts:124src/agent/persistence/friday-subagent-run-repository.ts:176src/agent/tools/friday-agent-sessions-tool.ts:38src/agent/tools/friday-agent-skill-tool.ts:113src/agent/tools/friday-agent-workflow-generator-tool.ts:27src/api/auth/friday-auth-service.types.ts:4src/api/http/friday-default-public-principal.ts:4llms.txt
humans.txt
robots.txt
sitemap.xml
docker/Dockerfile:2
containersPinned dependencies
docker/Dockerfile:26
containersPinned dependencies
This page is publicly accessible at:
https://repobility.com/scan/c5fba84f-b81a-4bdf-84b5-d36dbead92d4/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/c5fba84f-b81a-4bdf-84b5-d36dbead92d4/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.