Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

srgplus/srgplus-mcp

https://github.com/srgplus/srgplus-mcp · scanned 2026-06-16 00:20 UTC (2 months, 2 weeks ago)

75 raw signals (34 security + 41 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 2 months, 2 weeks ago · v1 · 45 actionable findings from 2 signal sources. 61 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: excluding tests × Reset all
Corpus Intelligence Cross-corpus context (cohort percentile, top patterns, fix plan) is shown only on repositories you own. Sign up and connect your repo to view it.
Scan summary Repository scanned at 94.6/100 with 88.9% coverage. It contains 350 nodes across 0 cross-layer flows, written primarily in mixed languages. Engine surfaced 41 findings — concentrated in quality (24), software (13), hardware (2). Risk profile is low: 0 critical, 0 high, 2 medium. Recommended next step: open the quality layer findings first — that's where the highest-impact wins live.

Showing 36 of 45 actionable findings. 106 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

critical Security checks quality Practices conf 0.82 2 occurrences Foundry mined mock as real or placeholder: srgplus/srgplus-mcp
Graph query export: Mock, sample, placeholder, or self-attested behavior treated as real Query id: mock_as_real_or_placeholder Query type: motif_query Intent: Hard negatives for fake completeness and missing real data paths. Motif: mock_as_real_or_placeholder Training usage: hard_negative Graph gol…
2 occurrences
repo-level (2 hits)
critical Security checks security auth conf 0.78 6 occurrences Foundry mined security auth guardrail gaps: srgplus/srgplus-mcp
Graph query export: Security/auth changes without enough guardrails Query id: security_auth_guardrail_gaps Query type: motif_query Intent: Assumption-check security/auth examples requiring stronger tests or CI. Motif: security_auth_without_guardrails Training usage: assumption_check Graph gold labe…
6 occurrences
repo-level (6 hits)
high Security checks quality Practices conf 0.84 2 occurrences Foundry mined bad chains: srgplus/srgplus-mcp
Comment chain pattern product: bad_chains Repo: srgplus/srgplus-mcp Thread: srgplus/srgplus-mcp#13 Outcome: claimed_resolved_unverified Thread label: thread_has_human_issue_and_fix_context Source graph label: source_backed_multi_signal_graph Reasons: source_graph_has_real_artifacts, source_graph_ha…
2 occurrences
repo-level (2 hits)
high Security checks quality Quality conf 0.76 3 occurrences Foundry mined schema ui api mismatch: srgplus/srgplus-mcp
Graph query export: Schema, UI, and API mismatch Query id: schema_ui_api_mismatch Query type: motif_query Intent: Assumption-check examples for data-path consistency across layers. Motif: schema_ui_api_mismatch Training usage: assumption_check Graph gold label: supported_by_verification_signal Repo…
3 occurrences
repo-level (3 hits)
high Security checks quality Testing conf 0.78 11 occurrences Foundry mined test ci gap after feedback: srgplus/srgplus-mcp
Graph query export: Feedback exposes missing tests or CI Query id: test_ci_gap_after_feedback Query type: motif_query Intent: Hard negatives for feedback/fix chains without adequate guardrails. Motif: test_ci_gap_after_feedback Training usage: hard_negative Graph gold label: supported_by_verificati…
11 occurrences
repo-level (11 hits)
medium Security checks quality Practices conf 0.62 20 occurrences Foundry mined assumption checks: srgplus/srgplus-mcp
Comment chain pattern product: assumption_checks Repo: srgplus/srgplus-mcp Thread: srgplus/srgplus-mcp#8 Outcome: claimed_resolved_unverified Thread label: thread_has_human_issue_and_fix_context Source graph label: source_backed_multi_signal_graph Reasons: source_graph_has_real_artifacts, source_gr…
20 occurrences
repo-level (20 hits)
medium Security checks quality maintenance conf 0.70 21 occurrences Foundry mined blueprint gap alignment: srgplus/srgplus-mcp
Graph query export: Human feedback aligned with blueprint or architecture gaps Query id: blueprint_gap_alignment Query type: motif_query Intent: Curriculum-gap examples connecting issue threads to helicopter-view gaps. Motif: blueprint_gap_alignment Training usage: curriculum_gap Graph gold label: …
21 occurrences
repo-level (21 hits)
medium System graph quality Placeholder conf 1.00 Critical user flow still appears backed by mock or placeholder data
A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded.
Mock dataCritical flowGenerated repo pattern
medium System graph cicd CI/CD security conf 1.00 No CI/CD pipelines detected
No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints.
CI/CD securityCoverage
low System graph quality Production readiness conf 1.00 Composite production-readiness gap
Multiple low-cost hardening controls are missing together: license, ci. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation.
Repo hardeningGenerated repo pattern
low System graph hardware Coverage conf 1.00 Containers defined but no K8s/orchestration manifest found
Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo.
Deployment
low System graph hardware Supply chain conf 1.00 Docker base image is tag-pinned but not digest-pinned: python:3.12-slim
Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter.
Dockerfile:1 containersPinned dependencies
low System graph quality Integrity conf 1.00 4 occurrences Near-duplicate function bodies in 2 places
Functions with the same first-5-line body hash: srg_mcp/contents.py:list_contents, srg_mcp/assets.py:list_assets This is *the* AI-coder failure mode (4× more duplication in vibe-coded repos — see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate.
4 occurrences
repo-level (4 hits)
duplicatesduplication
low System graph quality License conf 1.00 No license file detected
No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake.
Repo hardeningGenerated repo pattern
low System graph quality Integrity conf 1.00 Old/deprecated-named symbol `get_category_v2` in srg_mcp/channels.py:451
Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version.
old markerDead code
low System graph quality Integrity conf 1.00 Old/deprecated-named symbol `get_content_v2` in srg_mcp/_app.py:33
Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version.
old markerDead code
low System graph quality Integrity conf 1.00 Old/deprecated-named symbol `get_content_v2` in srg_mcp/contents.py:121
Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version.
old markerDead code
low System graph quality Integrity conf 1.00 Old/deprecated-named symbol `get_content_v2` in srg_mcp/guide.py:35
Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version.
old markerDead code
low System graph quality Integrity conf 1.00 Old/deprecated-named symbol `get_content_v2` in srg_mcp/serve/profiles.py:37
Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version.
old markerDead code
low System graph quality Integrity conf 1.00 Old/deprecated-named symbol `get_content_v2` in tests/test_core_profile.py:19
Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version.
old markerDead code
low System graph quality Integrity conf 1.00 Old/deprecated-named symbol `get_content_v2` in tests/test_instructions.py:17
Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version.
old markerDead code
low System graph quality Integrity conf 1.00 Old/deprecated-named symbol `srgplus_old` in tests/test_stability.py:61
Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version.
old markerDead code
low System graph software Dead code conf 1.00 Possibly dead Python function: authorization_server_metadata
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
srg_mcp/serve/oauth/discovery.py:43
low System graph software Dead code conf 1.00 Possibly dead Python function: authorize_get
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
srg_mcp/serve/oauth/authorize.py:194
low System graph software Dead code conf 1.00 Possibly dead Python function: authorize_post
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
srg_mcp/serve/oauth/authorize.py:221
low System graph software Dead code conf 1.00 Possibly dead Python function: favicon
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
srg_mcp/serve/main.py:358
low System graph software Dead code conf 1.00 Possibly dead Python function: handler
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
srg_mcp/serve/main.py:415
low System graph software Dead code conf 1.00 Possibly dead Python function: health
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
srg_mcp/serve/main.py:147
low System graph software Dead code conf 1.00 Possibly dead Python function: openai_apps_challenge
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
srg_mcp/serve/main.py:380
low System graph software Dead code conf 1.00 Possibly dead Python function: protected_resource_metadata
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
srg_mcp/serve/oauth/discovery.py:80
low System graph software Dead code conf 1.00 Possibly dead Python function: register
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
srg_mcp/serve/oauth/dcr.py:51
low System graph software Dead code conf 1.00 Possibly dead Python function: revoke
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
srg_mcp/serve/oauth/token.py:256
low System graph software Dead code conf 1.00 Possibly dead Python function: root_index
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
srg_mcp/serve/main.py:457
low System graph software Dead code conf 1.00 Possibly dead Python function: static_asset
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
srg_mcp/serve/main.py:362
low System graph software Dead code conf 1.00 Possibly dead Python function: verify
No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler.
srg_mcp/serve/oauth/pkce.py:24
low System graph quality Provenance conf 1.00 Shallow git history limits provenance confidence
The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence.
Git historyGenerated repo pattern
For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/f4eba3d5-3dfa-4a92-96d0-f0ef06d96b10/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/f4eba3d5-3dfa-4a92-96d0-f0ef06d96b10/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.