Scan timing: clone 24.55s · analysis 2.66s · 26.7 MB · GitHub preflight 419ms
https://github.com/openclaw/mcporter
· scanned 2026-05-31 01:22 UTC (5 days, 14 hours ago)
· 10 languages
243 findings (55 legacy + 188 scanner) 11/13 scanners ran 97th percentile · Typescript · medium (20-100K LoC) Scanner says 79 (higher by 10)
Last scanned 5 days, 14 hours ago · v2 · 149 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
100.0 | 0.15 | 15.00 |
security_score |
100.0 | 0.25 | 25.00 |
testing_score |
100.0 | 0.20 | 20.00 |
documentation_score |
70.0 | 0.15 | 10.50 |
practices_score |
74.0 | 0.15 | 11.10 |
code_quality |
80.0 | 0.10 | 8.00 |
| Overall | 1.00 | 89.6 |
Showing 133 of 149 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/generated-daemon-runtime.ts:50
qualitylegacy
scripts/release.sh:31
qualitylegacy
.github/workflows/ci.yml:40
dependencylegacy
.github/workflows/pages.yml:33
dependencylegacy
.github/workflows/ci.yml:27
dependencylegacy
.github/workflows/crabbox-hydrate.yml:42
dependencylegacy
.github/workflows/pages.yml:44
dependencylegacy
.github/workflows/pages.yml:53
dependencylegacy
.github/workflows/pages.yml:36
dependencylegacy
.github/workflows/ci.yml:28
dependencylegacy
.github/workflows/crabbox-hydrate.yml:49
dependencylegacy
.github/workflows/pages.yml:47
dependencylegacy
.github/workflows/crabbox-hydrate.yml:45
dependencylegacy
src/cli/help-output.ts:160
xsslegacy
src/cli/emit-ts-templates.ts:127
xsslegacy
src/env.ts:29
qualitylegacy
src/env.ts:18
path_traversallegacy
src/config/imports/paths-utils.ts:8
path_traversallegacy
src/config-normalize.ts:194
path_traversallegacy
src/cli/serve-command.ts:37
error_handlinglegacy
src/cli/emit-ts-templates.ts:92
error_handlinglegacy
src/cli/daemon-command.ts:92
error_handlinglegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
.github/workflows/pages.yml
supply-chaingithub-actionsleast-privilege
src/cli/list-command.ts:444
qualitylegacy
src/sdk-patches.ts:115
qualitylegacy
src/runtime/utils.ts:33
qualitylegacy
src/cli/generate/name-utils.ts:77
qualitylegacy
src/cli/config/render.ts:35
qualitylegacy
src/chrome-devtools-compat.ts:11
qualitylegacy
llms.txt
qualitylegacy
humans.txt
qualitylegacy
robots.txt
qualitylegacy
sitemap.xml
qualitylegacy
.github/workflows/pages.yml:33
supply-chaingithub-actionspinned-dependencies
.github/workflows/pages.yml:36
supply-chaingithub-actionspinned-dependencies
.github/workflows/pages.yml:44
supply-chaingithub-actionspinned-dependencies
.github/workflows/pages.yml:47
supply-chaingithub-actionspinned-dependencies
.github/workflows/pages.yml:53
supply-chaingithub-actionspinned-dependencies
src/cli/config/add.ts:336
qualitylegacy
src/cli/call-help.ts:20
qualitylegacy
src/cli/auth-command.ts:248
qualitylegacy
src/config/imports/external.ts:18
qualitylegacy
src/cli/runtime-debug.ts:46
qualitylegacy
src/cli/call-expression-parser.ts:183
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/eec2b134-807a-40f4-9651-147730667e94/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/eec2b134-807a-40f4-9651-147730667e94/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.