Security: Claudeclaw
22
Vulnerabilities
4
Credential Leaks
FAIL
Quality Gate
C
OWASP Grade
17.5h
Tech Debt (D)
High
DORA Rating
⚡
View AI Prompts
AI Fix Prompts
Auto-generated prompts to fix every issue — copy into Claude, GPT, or any AI coder
Want this analysis on your repo? https://repobility.com/scan/
Quality Gate: Default Gate
| Metric | Condition | |
|---|---|---|
| ✗ | overall_score | 0.0 >= 50 |
| ✗ | security_score | 0.0 >= 40 |
| ✗ | critical_vulnerabilities | 4.0 <= 0 |
| ✓ | critical_credentials | 0.0 <= 0 |
| ✓ | duplication_pct | 0.9 <= 20 |
DORA Metrics
| Deploy Frequency | unknown (0.0/week) |
| Lead Time | 1.1 hours |
| MTTR | 0.0 hours |
| Change Failure Rate | 0.0% |
| Total Commits | 29 |
| Overall Rating | HIGH |
Vulnerabilities (22)
| Severity | ID | Package | Version | Summary |
|---|---|---|---|---|
| critical | GHSA-hr2v-3952-633q | deep-extend | - | |
| critical | GHSA-g2q5-5433-rhrf | rc | - | |
| critical | GHSA-wc9v-mj63-m9g5 | pg | - | |
| critical | GHSA-xvch-5gv4-984h | minimist | - | |
| high | GHSA-6663-c963-2gqg | ws | - | |
| high | GHSA-qqgx-2p2h-9c37 | ini | - | |
| high | GHSA-wpg7-2c88-r8xv | simple-get | - | |
| high | GHSA-8cj5-5rvv-wf4v | tar-fs | - | |
| high | GHSA-pq67-2wwv-3xjx | tar-fs | - | |
| high | GHSA-vj76-c3g6-qr5v | tar-fs | - | |
| high | GHSA-x2mc-8fgj-3wmr | tar-fs | - | |
| high | GHSA-3h5v-q93c-6h6q | ws | - | |
| high | GHSA-5v72-xg48-5rpm | ws | - | |
| high | GHSA-c2qf-rxjj-qqgw | semver | - | |
| high | GHSA-x6fg-f45m-jf5q | semver | - | |
| medium | GHSA-pp7h-53gx-mx7r | bl | - | |
| medium | GHSA-6fc8-4gx4-v693 | ws | - | |
| medium | GHSA-xc7v-wxcw-j472 | tunnel-agent | - | |
| medium | GHSA-wrw9-m778-g6mc | bl | - | |
| medium | GHSA-vh95-rmgr-6w4m | minimist | - | |
| low | GHSA-c6rq-rjc2-86v2 | chownr | - | |
| low | GHSA-2mhh-w6q8-5hxw | ws | - |
Credential Findings (4)
| Severity | Pattern | File | Line |
|---|---|---|---|
| high | [sast:aljefra/taint-path-traversal] Path Traversal via Tainted Data | Opus46/lib/files.js | 90 |
| high | [sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URL | Opus46/public/sw.js | 24 |
| high | [sast:aljefra/ssrf-http-client] SSRF via HTTP Client with Dynamic URL | Opus46/public/sw.js | 30 |
| high | Telegram Bot Token | telegram-claude-bridge.js | 11 |