Security: Tradingagents Improved
316
Vulnerabilities
13
Credential Leaks
FAIL
Quality Gate
B
OWASP Grade
225.8h
Tech Debt (E)
High
DORA Rating
⚡
View AI Prompts
AI Fix Prompts
Auto-generated prompts to fix every issue — copy into Claude, GPT, or any AI coder
About: code-quality intelligence by Repobility · https://repobility.com
Quality Gate: Default Gate
| Metric | Condition | |
|---|---|---|
| ✗ | overall_score | 0.0 >= 50 |
| ✗ | security_score | 0.0 >= 40 |
| ✗ | critical_vulnerabilities | 29.0 <= 0 |
| ✓ | critical_credentials | 0.0 <= 0 |
| ✗ | duplication_pct | 32.4 <= 20 |
DORA Metrics
| Deploy Frequency | unknown (0.0/week) |
| Lead Time | 2.6 hours |
| MTTR | 0.0 hours |
| Change Failure Rate | 0.0% |
| Total Commits | 53 |
| Overall Rating | HIGH |
Vulnerabilities (316)
| Severity | ID | Package | Version | Summary |
|---|---|---|---|---|
| critical | GHSA-cgcg-p68q-3w7v | langchain-experimental | - | |
| critical | GHSA-x32c-59v5-h7fg | langchain | - | |
| critical | GHSA-p2qj-r53j-h3xj | langchain-experimental | - | |
| critical | GHSA-3pqx-4fqf-j49f | pyyaml | - | |
| critical | GHSA-6757-jp84-gxfx | pyyaml | - | |
| critical | GHSA-8q59-q68h-6hv4 | pyyaml | - | |
| critical | GHSA-rprw-h62v-c2w7 | pyyaml | - | |
| critical | GHSA-v8vj-cv27-hjv8 | langchain-experimental | - | |
| critical | GHSA-887w-45rq-vxgf | sqlalchemy | - | |
| critical | GHSA-fj32-q626-pjjc | langchain | - | |
| critical | GHSA-57fc-8q82-gfp3 | langchain | - | |
| critical | GHSA-fff8-4w9p-7v76 | pygments | - | |
| critical | GHSA-www2-v7xj-xrc6 | urllib3 | - | |
| critical | GHSA-vqfr-h8mv-ghfj | h11 | - | |
| critical | GHSA-6643-h7h5-x9wh | langchain | - | |
| critical | GHSA-2qmj-7962-cjq8 | langchain | - | |
| critical | GHSA-9fq2-x9r6-wfmf | numpy | - | |
| critical | GHSA-h8pj-cxx2-jfg2 | httpx | - | |
| critical | GHSA-fprp-p869-w6q2 | langchain | - | |
| critical | GHSA-38fc-9xqv-7f7q | sqlalchemy | - | |
| critical | GHSA-8h5w-f6q9-wg35 | langchain | - | |
| critical | GHSA-gwqq-6vq7-5j86 | langchain | - | |
| critical | GHSA-gjjr-63x4-v8cq | langchain-experimental | - | |
| critical | GHSA-hfg2-wf6j-x53p | sqlalchemy | - | |
| critical | GHSA-92j5-3459-qgp4 | langchain | - | |
| critical | GHSA-c67j-w6g6-q2cm | langchain-core | - | |
| critical | GHSA-f73w-4m7g-ch9x | langchain | - | |
| critical | GHSA-prgp-w7vf-ch62 | langchain | - | |
| critical | GHSA-7gfq-f96f-g85j | langchain | - | |
| high | GHSA-jrwr-5x3p-hvc3 | markdown-it-py | - | |
| high | GHSA-vrjv-mxr7-vjf8 | markdown-it-py | - | |
| high | GHSA-5rv5-6h4r-h22v | opentelemetry-instrumentation | - | |
| high | GHSA-7gcm-g887-7qv7 | protobuf | - | |
| high | GHSA-8gq9-2x98-w8hf | protobuf | - | |
| high | GHSA-8qvm-5x2c-j2w7 | protobuf | - | |
| high | GHSA-jwvw-v7c5-m82h | protobuf | - | |
| high | GHSA-3qhf-m339-9g5v | mcp | - | |
| high | GHSA-9h52-p55h-vw2f | mcp | - | |
| high | GHSA-63vm-454h-vhhq | pyasn1 | - | |
| high | GHSA-jr27-m4p2-rc6r | pyasn1 | - | |
| high | GHSA-j975-95f5-7wqh | mcp | - | |
| high | GHSA-2fc2-6r4j-p65h | numpy | - | |
| high | GHSA-5545-2q6w-2gh6 | numpy | - | |
| high | GHSA-27x4-j476-jp5f | setuptools | - | |
| high | GHSA-9w8r-397f-prfh | pygments | - | |
| high | GHSA-496j-2rq6-j6cc | grpcio | - | |
| high | GHSA-pq64-v7f5-gqh8 | pygments | - | |
| high | GHSA-cw6w-4rcx-xphc | numpy | - | |
| high | GHSA-33c7-2mpw-hg34 | uvicorn | - | |
| high | GHSA-752w-5fwx-jx9f | pyjwt | - |
Credential Findings (13)
| Severity | Pattern | File | Line |
|---|---|---|---|
| high | [sast:aljefra/ssrf-requests] SSRF via HTTP Client with Variable URL | tradingagents/dataflows/alpha_vantage_common.py | 68 |
| high | [sast:aljefra/info-debug-prod] Debug Mode Enabled in Production Config | cli/main.py | 926 |
| high | [sast:aljefra/info-debug-prod] Debug Mode Enabled in Production Config | crypto_main.py | 30 |
| high | [sast:aljefra/info-debug-prod] Debug Mode Enabled in Production Config | main.py | 24 |
| high | [sast:aljefra/info-debug-prod] Debug Mode Enabled in Production Config | scripts/dashboard.py | 872 |
| high | [sast:aljefra/taint-path-traversal] Path Traversal via Tainted Data | scripts/fetch_all_data.py | 102 |
| high | [sast:aljefra/taint-path-traversal] Path Traversal via Tainted Data | scripts/fetch_all_data.py | 103 |
| high | [sast:aljefra/ssrf-requests] SSRF via HTTP Client with Variable URL | scripts/polymarket/latency_measure.py | 26 |
| high | [sast:aljefra/ssrf-requests] SSRF via HTTP Client with Variable URL | scripts/polymarket/latency_measure_v2.py | 43 |
| high | [sast:aljefra/ssrf-requests] SSRF via HTTP Client with Variable URL | scripts/polymarket/penny_scanner.py | 35 |
| high | [sast:aljefra/ssrf-requests] SSRF via HTTP Client with Variable URL | cli/announcements.py | 16 |
| medium | Ethereum Address | scripts/polymarket/latency_scalper.py | 33 |
| medium | Ethereum Address | scripts/polymarket/negrisk_arb.py | 26 |