Skip to content
View kapil971390's full-sized avatar
๐Ÿ 
Working from home
๐Ÿ 
Working from home

Block or report kapil971390

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please donโ€™t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this userโ€™s behavior. Learn more about reporting abuse.

Report abuse
kapil971390/README.md

Repos Analyzed Issues & PRs Opened PRs Merged by Maintainers Stars Impacted


๐Ÿ‘‹ About Me

I do deep commit-level analysis on actively maintained open source projects โ€” looking for behavioral contract changes that slip past code review: silent return value mutations, exception scope widening, broken caller assumptions, wrong entity types in API calls.

When I find something real, I report it with a reproducible description and a suggested fix.

Full writeups with code โ†’ oss-findings


๐Ÿ“‹ All Activity

Date Repo What Severity Status
Jun 18 affaan-m/ECC โญ 217K #2291 + PR #2292 โ€” find -exec rm bypass via compound commands (&& ; | ||) in gateguard security hook โ€” triggered maintainer's GHSA-4v57 security advisory ๐Ÿ”ด High โœ… Merged
Jun 18 penpot/penpot #10279 โ€” Stale MCP token shown after regeneration โ€” old token persisted in client state after server-side deletion ๐ŸŸก Medium โœ… Merged in v2.17.0
Jun 16 magento/magento2 #40882 โ€” NoSuchEntityException race in InvalidSkuProcessor bulk price API ๐Ÿ”ด High โณ PR #40883
Jun 5 codeceptjs/CodeceptJS PR #5639 โ€” --shuffle flag silently ignored after commit #5438 ๐Ÿ”ด High โœ… Merged
Jun 14 midjourney-api #294 โ€” ChannelId used as ServerId in guild API ๐Ÿ”ด High โณ Open
Jun 14 midjourney-api #295 โ€” Dead code in cacheCommand(), cache never populated ๐ŸŸก Medium โณ Open
Jun 14 bagisto/bagisto #11338 โ€” getClientOriginalName() path traversal in RMAImageRepository โ€” incomplete security fix ๐Ÿ”ด Critical โณ Open
Jun 14 bagisto/bagisto #11339 โ€” v-html XSS in Shop views โ€” product_name + datagrid columns unescaped ๐Ÿ”ด High โณ Open
Jun 13 MoneyPrinterTurbo PR #1033 โ€” CLI local source validation fix ๐ŸŸก Medium โœ… Merged
Jun 10 MoneyPrinterTurbo #1013 โ€” Groq model unvalidated on list-fetch failure ๐ŸŸก Medium โœ… Fixed PR #1014
Jun 4 medusajs/medusa Discussion #15550 โ€” Race condition in compensatePaymentIfNeededStep ๐Ÿ”ด High ๐Ÿ‘€ Watching
Jun 4 MoneyPrinterTurbo #985 โ€” >= comparison risk in duration check ๐ŸŸก Medium ๐Ÿ‘€ Community PR expected
Jun 4 MoneyPrinterTurbo #984 โ€” Qwen empty choices[] โ€” unhandled crash ๐Ÿ”ด High โœ… Fixed PR #994
Jun 4 Understand-Anything Discussion โ€” commit analysis findings ๐ŸŸก Medium ๐Ÿ‘€ Watching

๐Ÿ”ญ Repos Analyzed

Repository Language Stars Finding
affaan-m/ECC JavaScript 217K+ Security bypass in gateguard hook โ€” find -exec rm via &&/;/|/|| โ€” merged โœ…
penpot/penpot ClojureScript 50K+ Stale MCP token state โ€” merged in v2.17.0 โœ…
harry0703/MoneyPrinterTurbo Python 89K+ 3 bugs found, 3 fixed
medusajs/medusa TypeScript 28K+ Race condition in async workflow step
erictik/midjourney-api TypeScript 1.8K 2 bugs found
apify/crawlee-python Python 9K+ Silent URL filtering behavior change
tox-dev/tox Python 4K+ Config override namespace risk
gptme/gptme Python 4K+ LLM routing logic analysis
Lum1104/Understand-Anything Python โ€” Commit analysis findings
acacode/swagger-typescript-api TypeScript 4K+ Analyzed โ€” no actionable findings
bagisto/bagisto PHP 9.1K+ 2 security bugs found
aws/aws-sam-cli Python 6.7K Analyzed โ€” no actionable findings
codeceptjs/CodeceptJS JavaScript 10K+ shuffle regression โ€” PR #5639 merged โœ…
magento/magento2 PHP 14K+ NoSuchEntityException race condition in bulk price API

๐Ÿ“ˆ Stats

Issues Opened     โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘  12
PRs Submitted     โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘  5
PRs Merged        โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘  6  โ† accepted by maintainers
Discussions       โ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘  2
Repos Analyzed    โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ  14
Confirmed Bugs    โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘  8

Popular repositories Loading

  1. automationexercise automationexercise Public

    For showcasing work to the client

    TypeScript 1

  2. MoneyPrinterTurbo MoneyPrinterTurbo Public

    Forked from harry0703/MoneyPrinterTurbo

    ๅˆฉ็”จAIๅคงๆจกๅž‹๏ผŒไธ€้”ฎ็”Ÿๆˆ้ซ˜ๆธ…็Ÿญ่ง†้ข‘ Generate short videos with one click using AI LLM.

    Python 1

  3. oss-findings oss-findings Public

    Open source code analysis findings โ€” bugs confirmed and fixed

    1

  4. MediaCrawler MediaCrawler Public

    Forked from NanmiCoder/MediaCrawler

    ๅฐ็บขไนฆ็ฌ”่ฎฐ | ่ฏ„่ฎบ็ˆฌ่™ซใ€ๆŠ–้Ÿณ่ง†้ข‘ | ่ฏ„่ฎบ็ˆฌ่™ซใ€ๅฟซๆ‰‹่ง†้ข‘ | ่ฏ„่ฎบ็ˆฌ่™ซใ€B ็ซ™่ง†้ข‘ ๏ฝœ ่ฏ„่ฎบ็ˆฌ่™ซใ€ๅพฎๅšๅธ–ๅญ ๏ฝœ ่ฏ„่ฎบ็ˆฌ่™ซใ€็™พๅบฆ่ดดๅงๅธ–ๅญ ๏ฝœ ็™พๅบฆ่ดดๅง่ฏ„่ฎบๅ›žๅค็ˆฌ่™ซ | ็ŸฅไนŽ้—ฎ็ญ”ๆ–‡็ซ ๏ฝœ่ฏ„่ฎบ็ˆฌ่™ซ

    Python 1

  5. automation-project-portfolio automation-project-portfolio Public

    JavaScript

  6. ETL-Pipeline-Automation ETL-Pipeline-Automation Public

    JavaScript