https://github.com/tailcallhq/forgecode
· scanned 2026-05-15 23:19 UTC (2 weeks, 6 days ago)
· 10 languages
83 findings (18 legacy + 65 scanner) 8th percentile · Rust · large (100-500K LoC) Scanner says 85 (lower by 28)
Last scanned 2 weeks, 6 days ago · v1 · 18 findings from 1 source. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
| Component | Sub-score | Weight | Contribution |
|---|---|---|---|
structure_score |
60.0 | 0.15 | 9.00 |
security_score |
86.8 | 0.25 | 21.70 |
testing_score |
16.0 | 0.20 | 3.20 |
documentation_score |
60.0 | 0.15 | 9.00 |
practices_score |
65.0 | 0.15 | 9.75 |
code_quality |
46.9 | 0.10 | 4.69 |
| Overall | 1.00 | 57.3 |
agent: 3.2 ·
threat: 10.0
Showing 18 of 18 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
.github/scripts/bounty/src/sync-issue.ts:27
credential_exposurelegacy
.github/scripts/bounty/src/sync-pr.ts:60
credential_exposurelegacy
crates/forge_repo/src/provider/bedrock_cache.rs:93
qualitylegacy
crates/forge_repo/src/provider/anthropic.rs:384
qualitylegacy
crates/forge_repo/src/forge_repo.rs:558
qualitylegacy
crates/forge_infra/src/http.rs:35
qualitylegacy
crates/forge_infra/src/auth/http/standard.rs:74
qualitylegacy
crates/forge_domain/src/transformer/transform_tool_calls.rs:102
qualitylegacy
crates/forge_domain/src/transformer/transform_tool_calls.rs:72
qualitylegacy
crates/forge_domain/src/compact/compact_config.rs:49
qualitylegacy
crates/forge_app/src/user_prompt.rs:208
qualitylegacy
crates/forge_app/src/dto/openai/transformers/reasoning_content.rs:51
qualitylegacy
crates/forge_app/src/dto/anthropic/transforms/set_cache.rs:65
qualitylegacy
.github/scripts/bounty/src/sync-pr.ts:34
qualitylegacy
shell-plugin/doctor.zsh:143
dependencylegacy
README.md:4
dependencylegacy
.github/ISSUE_TEMPLATE/bug_report.yml:105
dependencylegacy
crates/forge_ci/src/jobs/release_draft.rs:1
qualitylegacy
This page is publicly accessible at:
https://repobility.com/scan/f3936e4f-3dd3-4cb7-ad33-e59891b846af/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/f3936e4f-3dd3-4cb7-ad33-e59891b846af/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.