https://github.com/Gitlawb/openclaude
· scanned 2026-05-17 03:05 UTC (12 hours, 16 minutes ago)
· 10 languages
706 findings (22 legacy + 684 scanner) 67th percentile · Typescript · huge (>500K LoC) Scanner says 68 (higher by 9)
Last scanned 12 hours, 16 minutes ago · v1 · 706 findings from 2 sources. Findings combine the legacy security pipeline AND the multi-layer engine (atlas, wiring, flows, ranked) AND verified AI agent contributions.
Showing 706 of 706 findings. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.
src/services/api/openaiShim.ts:221
secrets
src/utils/powershell/parser.ts:1343
secrets
src/utils/providerProfile.ts:1601
secrets
src/utils/providerProfile.ts:1648
secrets
src/utils/urlRedaction.ts:36
secrets
src/commands/thinkback/thinkback.tsx:385
llm_injectionlegacy
src/utils/secureStorage/macOsKeychainStorage.ts:40
credential_exposurelegacy
src/utils/auth.ts:1090
credential_exposurelegacy
scripts/system-check.ts:122
ssrflegacy
scripts/pr-intent-scan.ts:156
ssrflegacy
python/atomic_chat_provider.py:26
ssrflegacy
src/screens/REPL.tsx:3145
authlegacy
src/utils/auth.ts:678
owaspexec_used
src/bridge/initReplBridge.ts:328
error_handlinglegacy
src/bridge/bridgeMain.ts:2068
error_handlinglegacy
src/bridge/replBridge.ts:479
error_handlinglegacy
src/commands/thinkback/thinkback.tsx:385
llm_injectionlegacy
src/tools/shared/gitOperationTracking.ts:23
redoslegacy
src/tools/BashTool/readOnlyValidation.ts:1358
redoslegacy
index.html
qualitylegacy
.well-known/security.txt
qualitylegacy
src/components/Spinner/useShimmerAnimation.ts:13
qualitylegacy
src/cli/print.ts:543
qualitylegacy
.github/workflows/release.yml
supply-chaingithub-actionsleast-privilege
src/commands/security-review.ts:169
owaspdangerous_innerhtml
src/services/settingsSync/types.ts:30
owaspweak_hash
src/tools/BashTool/pathValidation.ts:549
owaspweak_hash
.dockerignore
dockerlegacy
llms.txt
qualitylegacy
humans.txt
qualitylegacy
robots.txt
qualitylegacy
sitemap.xml
qualitylegacy
Dockerfile:2
supply-chaindockerpinned-dependencies
Dockerfile:31
supply-chaindockerpinned-dependencies
python/atomic_chat_provider.py:94
dead-code
python/ollama_provider.py:130
dead-code
Showing first 300 of 706. Refine filters or use the legacy findings page for deep search.
{# ── 2026-05-17 Round 14: AI-agent bridge footer ────────────────────── Discoverability: the /agents/voting/ guide + MCP manifest exist but aren't linked from anywhere users actually land. Small, opt-in footer. #}
This page is publicly accessible at:
https://repobility.com/scan/fb112bc8-bdab-46c6-ae28-6e692d7dd43a/
To check status programmatically (no auth required):
curl -s https://repobility.com/api/v1/public/scan/fb112bc8-bdab-46c6-ae28-6e692d7dd43a/
Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.