Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
221 changes: 221 additions & 0 deletions auditor/audits/hoangsonww-Claude-Code-Agent-Monitor.findings.jsonl

Large diffs are not rendered by default.

252 changes: 252 additions & 0 deletions auditor/audits/hoangsonww-Claude-Code-Agent-Monitor.md

Large diffs are not rendered by default.

2 changes: 2 additions & 0 deletions auditor/disagreements.jsonl
Original file line number Diff line number Diff line change
Expand Up @@ -228,3 +228,5 @@
{"event":"maintainer_rejected","pr":"laolaoshiren/claude-code-skills-zh#16","fingerprints":["sha256:c949f71c4d1fa09e8c29690639cfb7dab79feca91ef138b5b9ad7628b062a60c","sha256:fa5e9803f2ff3c1a834b85059c9727fc819a7d7316103668c27e40df2e83e529"],"rule_ids":["SEC-temp-file-write","SEC-temp-file-write"],"dissent_type":"context_missed","quote":"We did not adopt the repository .tmp scheme because new directory might still be 0755 under common POSIX umask.","commenter_role":"maintainer","classifier_model":"haiku-4-5","classifier_confidence":"medium","comments_hash":"sha256:021cf038186b23b9ec71e4fb392a3cc2909e331a4dbdc68aaefdb954c966f75f","timestamp":"2026-08-01T04:40:35Z"}
{"event": "downstream_suppression", "timestamp": "2026-08-02T00:22:26Z", "repo": "xiaolai/cc-suite", "commit_sha": "6d02d7540acba055eda79c8355e85275a0451a3d", "rule_id": "R31", "suppression_type": "threshold_adjustment", "fingerprint": "sha256:479c2103b7d8dd2532b6af6c514e5d3b95f364db6503416633bba4b838612fde", "file_fingerprint": "sha256:0973eb2098961d7d60ac66c4217a6974abac61cd366b713ee9f4ac626fe6fb59", "path": ".claude/nlpm.local.md", "override_value": {"threshold": 900}, "reason_given": ""}
{"event": "downstream_suppression", "timestamp": "2026-08-02T00:22:26Z", "repo": "xiaolai/cc-suite", "commit_sha": "6d02d7540acba055eda79c8355e85275a0451a3d", "rule_id": "R51", "suppression_type": "rule_override", "fingerprint": "sha256:6eb255100e953a537daab93747608eb544524e9e41b5c095b0cafe48079486a2", "file_fingerprint": "sha256:0973eb2098961d7d60ac66c4217a6974abac61cd366b713ee9f4ac626fe6fb59", "path": ".claude/nlpm.local.md", "override_value": {"enabled": true, "vocabulary_skill": "skills/cc-suite/vocabulary/"}, "reason_given": ""}
{"event":"self_false_positive","timestamp":"2026-08-05T12:55:57Z","repo":"hoangsonww/Claude-Code-Agent-Monitor","fingerprint":"sha256:021a7ba0a1cdd92dea374bea8829d0026a5920d9dd89ada4f03d00039fdfe820","rule_id":"SEC-shell-true","reason":"Argument list to spawnSync is a fixed literal array (\"npm\",[\"install\"]) with no interpolation of external input; shell:true is required only for Windows .cmd shim resolution per the inline comment, and the equivalent calls in desktop/scripts/install.js and prebuild.js explicitly gate it to process.platform === \"win32\".","rule_gap":"The security scanner's HIGH pattern for shell=True/shell:true should distinguish fixed-argument spawn calls from calls that interpolate external/user input into the command or args."}
{"event":"self_false_positive","timestamp":"2026-08-05T12:55:57Z","repo":"hoangsonww/Claude-Code-Agent-Monitor","fingerprint":"sha256:1e78a18687daca55f79179c6306894e05d4c89789d13c09351de7c89e750dc71","rule_id":"CC-orphan-component","reason":"mcp/build/ is a standard gitignored TypeScript compilation output regenerated by npm run mcp:build; absence in a fresh git checkout is expected, not a bug.","rule_gap":"Broken-reference checks for .mcp.json server paths should first check the nearest .gitignore before flagging a missing build-output path as broken."}
221 changes: 221 additions & 0 deletions auditor/findings.jsonl

Large diffs are not rendered by default.

4 changes: 4 additions & 0 deletions auditor/logs/events.jsonl
Original file line number Diff line number Diff line change
Expand Up @@ -3767,6 +3767,10 @@
{"timestamp":"2026-08-05T07:03:42Z","workflow":"audit","event":"audit_complete","run_id":"30983032406","run_number":744,"data":{"repo":"Shubhamsaboo/awesome-llm-apps","score":96,"artifacts":11,"strategy":"single"}}
{"timestamp":"2026-08-05T07:03:59Z","workflow":"audit","event":"manual_disclosure_pending","run_id":"30983032406","run_number":744,"data":{"repo":"Shubhamsaboo/awesome-llm-apps","queue_path":"auditor/disclosures-pending/Shubhamsaboo-awesome-llm-apps.md","gh_error":"GraphQL: Resource not accessible by integration (createIssue)"}}
{"timestamp":"2026-08-05T09:09:12Z","workflow":"track","event":"status_check","run_id":"30991292365","run_number":654,"data":{"contributed":57,"tracked":37,"case_study_ready":42,"rule_adopted":2}}
{"timestamp":"2026-08-05T12:55:57Z","workflow":"audit","event":"scorer_drift_check","run_id":"31006432913","run_number":750,"data":{"repo":"hoangsonww/Claude-Code-Agent-Monitor","sidecar":"auditor/audits/hoangsonww-Claude-Code-Agent-Monitor.findings.jsonl","drifts":83,"exit_code":1,"total_findings":221,"missing_confidence":0}}
{"timestamp":"2026-08-05T12:56:02Z","workflow":"audit","event":"findings_aggregated","run_id":"31006432913","run_number":750,"data":{"repo":"hoangsonww/Claude-Code-Agent-Monitor","findings":221,"invalid_lines":0,"self_false_positives":2}}
{"timestamp":"2026-08-05T12:56:03Z","workflow":"audit","event":"repo_report_rendered","run_id":"31006432913","run_number":750,"data":{"repo":"hoangsonww/Claude-Code-Agent-Monitor","html":"auditor/reports/hoangsonww-Claude-Code-Agent-Monitor.html"}}
{"timestamp":"2026-08-05T12:56:03Z","workflow":"audit","event":"audit_complete","run_id":"31006432913","run_number":750,"data":{"repo":"hoangsonww/Claude-Code-Agent-Monitor","score":72,"artifacts":126,"strategy":"progressive"}}
{"timestamp":"2026-08-05T12:51:30Z","workflow":"track","event":"status_check","run_id":"31006646628","run_number":655,"data":{"contributed":57,"tracked":37,"case_study_ready":42,"rule_adopted":2}}
{"timestamp":"2026-08-05T16:46:30Z","workflow":"track","event":"status_check","run_id":"31025995346","run_number":656,"data":{"contributed":57,"tracked":37,"case_study_ready":42,"rule_adopted":2}}
{"timestamp":"2026-08-05T20:41:36Z","workflow":"track","event":"status_check","run_id":"31044548240","run_number":657,"data":{"contributed":57,"tracked":37,"case_study_ready":42,"rule_adopted":2}}
Expand Down
9 changes: 6 additions & 3 deletions auditor/registry/repos.json
Original file line number Diff line number Diff line change
Expand Up @@ -9736,10 +9736,13 @@
"stars": 870,
"artifacts": 131,
"description": "🚀 A real-time monitoring dashboard for Claude Code & Codex, built with SQLite3, Node.js, Express, React, Vite, TailwindCSS, & WebSockets. It tracks sessions, agent activity, tool usage, and subagent orchestration, providing live analytics, a Kanban status board, status notifications, a cute buddy, & an interactive web UI/MacOS/Windows native app.",
"status": "discovered",
"score": null,
"status": "audited",
"score": 72,
"audit_issue": 759,
"prs": []
"prs": [],
"strategy": "progressive",
"security": "REVIEW",
"commit_sha_at_audit": "10d6b2ef6304017c93b31bfa817e31caa7de1403"
},
"indranilbanerjee/digital-marketing-pro": {
"discovered": "2026-08-05T02:07:37Z",
Expand Down
104 changes: 104 additions & 0 deletions auditor/reports/hoangsonww-Claude-Code-Agent-Monitor.html

Large diffs are not rendered by default.

Loading
Loading