Security scanner for AI agents, MCP servers and agent skills.
active 2026-02-12 → 2026-08-07 (UTC)
Activity over time
Daily event counts in the loaded window
Line chart, 177 days from 2026-02-12 to 2026-08-07. Pushes: 242 total, peak 11 in a day. Pull requests: 29 total, peak 3 in a day. Issues: 4 total, peak 1 in a day. Comments: 40 total, peak 5 in a day. Stars: 193 total, peak 15 in a day.
- Pushes
- Pull requests
- Issues
- Comments
- Stars
Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.
Top contributors
Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity
| Contributor | Contributions | Pushes | PRs | Comments |
|---|---|---|---|---|
| iamcristi | 99 | 97 | 1 | 1 |
| hemang-snyk | 72 | 49 | 11 | 5 |
| mmilanta | 47 | 37 | 6 | 1 |
| lbeurerkellner | 29 | 23 | 1 | 3 |
| qodo-merge-etso[bot] | 27 | 0 | 0 | 26 |
| knielsen404 | 18 | 9 | 6 | 1 |
| eugene-eko2000 | 16 | 15 | 0 | 1 |
| aarlaud | 5 | 4 | 1 | 0 |
| ebhardjan | 2 | 2 | 0 | 0 |
| VulnShade | 2 | 2 | 0 | 0 |
| xzhou-snyk | 2 | 1 | 0 | 1 |
| kam193 | 1 | 0 | 0 | 1 |
| viviresunarte | 1 | 0 | 1 | 0 |
| michael-bey | 1 | 0 | 1 | 0 |
| akudrinsky | 1 | 1 | 0 | 0 |
| zaneghosn12 | 1 | 0 | 0 | 0 |
| cursor[bot] | 1 | 1 | 0 | 0 |
| starbuck100 | 1 | 0 | 1 | 0 |
| SH4DY | 1 | 1 | 0 | 0 |
| sgaabdu4 | 1 | 0 | 0 | 0 |
Recent activity
Latest issues, pull requests and releases
- Issue#412sgaabdu42026-08-04 14:46W008 false positive: redaction marker treated as proof of a secret (v0.5.16)
- Issue comment#390qodo-merge-etso[bot]2026-07-02 09:31Fix/only allow skip servers from trusted domains
- Pull request#369iamcristi2026-06-16 05:43
- Issue comment#350qodo-merge-etso[bot]2026-06-05 05:51feat: [ADS-296] reapply VSCode family discoverers (VSCode, Cursor, Windsurf, Kiro, Antigravity)
- Issue comment#349iamcristi2026-06-05 05:50feat: [ADS-296] reapply VSCode family discoverers (VSCode, Cursor, Windsurf, Kiro, Antigravity)
- Issue comment#337qodo-merge-etso[bot]2026-05-29 05:44feat: [ADS-296] VSCode family discoverers (VSCode, Cursor, Windsurf, Kiro, Antigravity)
- Pull request#331hemang-snyk2026-05-27 06:09
- Pull request#323mmilanta2026-05-20 13:53
- Issue comment#308qodo-merge-etso[bot]2026-05-09 07:39Version bump to 0.5.2
- Pull request#307hemang-snyk2026-05-09 07:14
- Pull request#306hemang-snyk2026-05-09 07:07
- Pull request#298hemang-snyk2026-05-04 10:01
- Pull request#297hemang-snyk2026-05-04 09:53
- Issue comment#201hemang-snyk2026-05-04 08:06fix: discover Claude Code Cowork/DXT session skills via glob expansion
- Issue#125hemang-snyk2026-05-04 07:58`--local-only` flag not supported for scan command (contradicts documentation)
- Issue comment#125hemang-snyk2026-05-04 07:58`--local-only` flag not supported for scan command (contradicts documentation)
- Pull request#285hemang-snyk2026-04-25 07:56
- Pull request#280hemang-snyk2026-04-22 15:26
- Issue comment#279qodo-merge-etso[bot]2026-04-22 08:01chore: call the guard-enabled API before running installation
- Issue comment#278qodo-merge-etso[bot]2026-04-21 13:16chore: check guard install with observe-preview feature flag
- Issue#276zaneghosn122026-04-17 07:47Agent Scan cannot inspect OAuth-authenticated MCP servers (e.g. Claude Code marketplace plugins)
- Pull request#273hemang-snyk2026-04-16 08:31
- Issue comment#269qodo-merge-etso[bot]2026-04-13 13:06fix: add guard cmds on managed on top of user levels
- Issue comment#265qodo-merge-etso[bot]2026-04-10 11:52feat: allow for x86 builds on arm64
- Issue comment#262qodo-merge-etso[bot]2026-04-08 16:34fix: correct Windows vscode paths and deduplicate CLIENT_PATHS
Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 193 stars here means stars gained during the window, not the repo's star count.