Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions docs/fixed.md
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
---
layout: default
title: Findings a maintainer fixed
description: "The 25 scans in the AI PatchLab series where the maintainer shipped a fix — what was reported, and what landed upstream."
description: "The 26 scans in the AI PatchLab series where the maintainer shipped a fix — what was reported, and what landed upstream."
---

# Findings a maintainer fixed

Of 109 scans, **25** ended with a maintainer shipping a fix. This page is the
Of 111 scans, **26** ended with a maintainer shipping a fix. This page is the
short version of the argument: a report is only worth writing if someone can act on it.

The fastest turnaround in the series was about six hours from filing to a merged pull
Expand All @@ -20,6 +20,7 @@ release notes.
| 2026-09-14 | [superlinked/sie](scans/superlinked-sie.html) | 156 | 1 real |
| 2026-09-03 | [samuelgursky/davinci-resolve-mcp](scans/samuelgursky-davinci-resolve-mcp.html) | 97 | 1 real |
| 2026-08-31 | [shy3130/tick-stock-panel](scans/shy3130-tick-stock-panel.html) | 77 | 1 real |
| 2026-08-29 | [ginlix-ai/LangAlpha](scans/ginlix-ai-langalpha.html) | 372 | 1 real |
| 2026-08-27 | [Zleap-AI/SAG](scans/zleap-ai-sag.html) | 60 | 1 real |
| 2026-08-20 | [whiteguo233/OpenBiliClaw](scans/whiteguo233-openbiliclaw.html) | 373 | 1 real |
| 2026-08-17 | [zilliztech/memsearch](scans/zilliztech-memsearch.html) | 90 | 1 real |
Expand Down
8 changes: 4 additions & 4 deletions docs/index.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
layout: default
title: AI PatchLab Scans
description: "111 curated security scans of open-source AI agents, MCP servers and LLM apps - 25 confirmed fixes, run local-first with Semgrep, Gitleaks, Trivy and pip-audit."
description: "111 curated security scans of open-source AI agents, MCP servers and LLM apps - 26 confirmed fixes, run local-first with Semgrep, Gitleaks, Trivy and pip-audit."
---

# AI PatchLab Scans
Expand All @@ -20,7 +20,7 @@ remediation and confidence rules to normalize the findings.

> **Want this run privately against your own codebase?** I do independent
> security review of AI agents, MCP servers, and LLM apps —
> [**work with me →**]({{ '/work-with-me' | relative_url }}). 111 scans, 25 confirmed fixes, methodology in the open.
> [**work with me →**]({{ '/work-with-me' | relative_url }}). 111 scans, 26 confirmed fixes, methodology in the open.

> **OpenAI just launched [Daybreak](https://openai.com/index/daybreak-securing-the-world/) and Patch the Planet.**
> Same remediation loop, opposite trade-off: their path is a cloud frontier model;
Expand All @@ -35,7 +35,7 @@ remediation and confidence rules to normalize the findings.

## Two shorter ways in

- [**Findings a maintainer fixed**]({{ '/fixed' | relative_url }}) — the 25 that resolved
- [**Findings a maintainer fixed**]({{ '/fixed' | relative_url }}) — the 26 that resolved
upstream. The shortest version of the argument: a report is only worth writing if someone
can act on it.
- [**Scans that found nothing**]({{ '/clean' | relative_url }}) — 40 of them, published as
Expand Down Expand Up @@ -141,7 +141,7 @@ filed, which is the usual outcome of a clean scan.
| 2026-09-01 | [future-agi/future-agi](scans/future-agi-future-agi.html) | 1227 | 1 real — withheld | private |
| 2026-08-31 | [shy3130/tick-stock-panel](scans/shy3130-tick-stock-panel.html) | 77 | 1 real | **fixed** |
| 2026-08-30 | [SenteLabsAI/OpenExecutive](scans/sentelabsai-openexecutive.html) | 124 | 1 real — withheld | private |
| 2026-08-29 | [ginlix-ai/LangAlpha](scans/ginlix-ai-langalpha.html) | 372 | 1 real | open |
| 2026-08-29 | [ginlix-ai/LangAlpha](scans/ginlix-ai-langalpha.html) | 372 | 1 real | **fixed** |
| 2026-08-28 | [Ontos-AI/knowhere](scans/ontos-ai-knowhere.html) | 129 | 1 real — withheld | private |
| 2026-08-27 | [Zleap-AI/SAG](scans/zleap-ai-sag.html) | 60 | 1 real | **fixed** |
| 2026-08-26 | [ascending-llc/jarvis-registry](scans/ascending-llc-jarvis-registry.html) | 235 | 1 real — withheld | private |
Expand Down
4 changes: 2 additions & 2 deletions docs/scan-log.md

Large diffs are not rendered by default.

45 changes: 39 additions & 6 deletions docs/scans/ginlix-ai-langalpha.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,12 +9,16 @@ date: 2026-08-29
**Repository:** [ginlix-ai/LangAlpha](https://github.com/ginlix-ai/LangAlpha)
**Commit scanned:** `f5232fa2` (main at scan time)
**Scan date:** 2026-08-29
**Disclosure status:** disclosed — one real finding filed as a single focused
public issue. No `SECURITY.md` at the repository root, in `.github/`, in
`docs/`, or at the organisation level, and private vulnerability reporting is
disabled (confirmed with an empty-payload control request, which returned
`403 Repository does not have private vulnerability reporting enabled` — it
files nothing). A public issue is the only channel the project offers.
**Disclosure status:** ✅ **resolved** — one real finding, filed as a single
focused public issue on the day of the scan and fixed by the maintainer 27 days
later in [ginlix-ai/LangAlpha#425](https://github.com/ginlix-ai/LangAlpha/pull/425),
which closed the issue as completed. The fix went further than the one proposed
here: it retired the design the finding took as given. No `SECURITY.md` at the
repository root, in `.github/`, in `docs/`, or at the organisation level, and
private vulnerability reporting is disabled (confirmed with an empty-payload
control request, which returned `403 Repository does not have private
vulnerability reporting enabled` — it files nothing). A public issue is the
only channel the project offers.

## Summary

Expand Down Expand Up @@ -181,6 +185,35 @@ high-severity findings automatically instead of by hand.
[issue #378](https://github.com/ginlix-ai/LangAlpha/issues/378). One finding,
not a grouped review. No PR opened: the fix is one file, but choosing 404 vs
503 for a sleeping sandbox is a product decision the maintainer should make.
- **2026-09-25** — **fixed** in [#425](https://github.com/ginlix-ai/LangAlpha/pull/425)
(`2eab033f`) and the issue closed as completed, 27 days after filing. The
maintainer did not adopt the accessor swap proposed above; the fix removes
the premise instead. The old `/api/v1/preview/{workspace_id}/{port}` route no
longer resolves a signed URL or touches a session at all: it reads the
registered preview command from the database, gets or creates the app's one
link, and redirects to it. That link opens for the signed-in workspace owner
alone, and the owner's path is now the only one that resolves a preview — in
the new docstring's words, "a stopped sandbox is started for the owner and for
nobody else." This page described the workspace UUID as the route's bearer
credential, by design. #425 retired that design: report frames now load under
an HMAC-signed grant that expires, and running apps open through the owner's
private link. A regression test names #378 — with the workspace manager and
the sandbox lookup both patched to raise, the redirect still answers `302`
and the manager is never called.
- **2026-09-26** — re-verified at `2eab033f`, starting with the differential
that found the bug. At the scanned commit, five unauthenticated routes touched
a workspace session and one called the waking accessor; at the fix, none do,
and every remaining caller of `get_session_for_workspace` sits behind an
authenticated owner. The redirect was then probed as a new check, because it
still answers anyone who holds a UUID. What it hands back is an app link
code, and an app link cannot be shared — the migration's `share_links_app_shape`
constraint requires `shared_at IS NULL` on every app row — so for anyone but
the owner the code opens nothing and returns the same `404` as an unknown one.
The public page that does resolve a preview reaches the waking path only past
two independent ownership checks (`resolve_link`, then `require_workspace_owner`
inside `_get_sandbox`). Nor can the redirect be used to rewrite the owner's
link: its insert is `ON CONFLICT DO NOTHING`, and an old URL's page rides along
as `?path=` rather than being stored.

## Reproduce

Expand Down
16 changes: 14 additions & 2 deletions docs/scans/superdesigndev-treg.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,8 +14,9 @@ date: 2026-09-24
project's `SECURITY.md` (which asks that vulnerabilities not be opened as public
issues; GitHub private vulnerability reporting is disabled on the repo, and the
policy names an email address, so email is the channel). Detail below is kept at
class level until the maintainer has had a chance to respond. **The private send
is the operator's step and had not gone out when this page was published.**
class level until the maintainer has had a chance to respond. The private send
was the operator's step and had not gone out when this page was published; it
went out ten minutes later (see the timeline below).

## Summary

Expand Down Expand Up @@ -161,6 +162,17 @@ curated by hand; scanner output alone is not a vulnerability report. This page w
updated with full technical detail once the maintainer has responded and a fix has
shipped.*

## Disclosure timeline

- 2026-09-24 — scan run at `240c595`; finding verified by running treg's own two host
guards side by side
- 2026-09-24 — channel probed: `SECURITY.md` asks that vulnerabilities not be opened as
public issues and names an email address; GitHub private vulnerability reporting is
disabled (`{"enabled":false}`)
- 2026-09-24 13:31 UTC — this page published, finding withheld at class level
- 2026-09-24 13:41 UTC — reported privately by email to the address in `SECURITY.md`
- 2026-09-26 — no reply yet, no bounce; none of the reported files has changed upstream

## Reproduce

```bash
Expand Down
4 changes: 2 additions & 2 deletions docs/work-with-me.md
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
---
layout: default
title: Work with me — AI agent & LLM security review
description: "Independent security review of AI agents, MCP servers and LLM applications. 109 public scans and 25 confirmed fixes as the proof; first-look engagements from $750."
description: "Independent security review of AI agents, MCP servers and LLM applications. 111 public scans and 26 confirmed fixes as the proof; first-look engagements from $750."
---

# Work with me
Expand All @@ -12,7 +12,7 @@ If you're shipping an agent framework, an MCP server, a RAG pipeline, or anythin

## The proof is public

Everything I'd do for you, I've done in the open — [109 curated scans]({{ '/' | relative_url }}) of well-known AI/agent projects, with **25 confirmed fixes** where maintainers acted on the findings, and a documented methodology behind each one.
Everything I'd do for you, I've done in the open — [111 curated scans]({{ '/' | relative_url }}) of well-known AI/agent projects, with **26 confirmed fixes** where maintainers acted on the findings, and a documented methodology behind each one.

- **Real findings, not scanner noise.** A typical scan starts at hundreds of raw findings and ends at a handful that matter — because the rest are false positives, by-design patterns, or vendored third-party code. The curation is the value.
- **Reachability over rule-count.** A `subprocess(shell=True)` that's safe under operator trust can become a multi-tenant sandbox escape once you trace who reaches it — and a scary-looking SQL string can be fully gated by a five-character allowlist. The verdict goes wherever the *code* goes, which means reading the code, not the rule.
Expand Down
Loading