SlopCop

Sample only

Repository review with a visible evidence trail.

This is a synthetic example of a completed quick review. The repository, code, and findings are illustrative—not customer data or measured results from a real scan.

Repository analysis

example/acme-service

Analysis completeCommit 7b4e2a1Quick analysis
Your results

3 patterns need review

3 analyzer matches at 3 code locations across 3 files.

3Code locations
3Files with findings
3Checks with findings
20/20Checks completed
  • Critical 1
  • Error 1
  • Warning 1

Quick review is a fast first pass built mostly from pattern and linter-style checks. These heuristics can be noisy, so treat matches as candidates to verify.

Deep review adds data-flow analysis for security-sensitive and correctness issues. Both reviews cover the checked-out revision and supported source semantics.

Findings to review

SecurityAnalyzer flag

Unchecked authentication result

Highest analyzer severity: Critical

1 location · 1 file · 1 match

The session is created without checking valid. A failed password verification can therefore reach the success path in this synthetic example.

What to do: Return an authentication failure when valid is false, and add a regression test that proves no session is created.

Source example

src/auth/login.ts:15

Session creation ignores the authentication result

valid is assigned but never read before the session is created.

src/auth/login.ts:12–16
export async function login(username: string, password: string) {  const valid = await verifyCredentials(username, password);  audit.record("login-attempt", { username });  return database.createSession(username);}
CorrectnessAnalyzer flag

Dry run falls through to the real operation

Highest analyzer severity: Error

1 location · 1 file · 1 match

The dry-run branch records intent but does not return. Execution continues to the real deletion call.

What to do: Return after the preview or make the destructive call the explicit non-dry-run branch.

Source example

src/accounts/delete-account.ts:22-23

Dry-run mode still reaches the destructive operation

The dry-run branch logs and continues to the deletion call on the next line.

src/accounts/delete-account.ts:21–25
export async function deleteAccount(username: string, dryRun = false) {  if (dryRun) console.log(`Would delete ${username}`);  await database.deleteAccount(username);  await audit.record("account-deleted", { username });}
PerformanceAnalyzer flag

Remote call inside a loop

Highest analyzer severity: Warning

1 location · 1 file · 1 match

The loop performs one remote request per repository. This is a review lead: actual impact depends on list size, provider limits, and whether the client batches internally.

What to do: Measure the production path, then use a bounded bulk request or controlled concurrency if repeated latency is material.

Source example

src/repositories/summarize.ts:11

Repository metadata is fetched once per item

One awaited request per repository in the list.

src/repositories/summarize.ts:8–14
export async function summarize(repositories: Repository[]) {  const summaries = [];  for (const repository of repositories) {    summaries.push(await api.fetchMetadata(repository.id));  }  return summaries;}

Sample only

What the result does—and does not—say.

This synthetic example shows all 20 sample quick-review check families as complete. A real report records incomplete, unavailable, failed, or unselected work separately; those outcomes are not passes.

A clean report does not guarantee defect-free code. Findings are candidates to verify against runtime behavior, intended contracts, and repository context.

Review your own repository.

Start with a public repository URL or connect selected private GitHub repositories.

Talk to the SlopCop team

Build your team’s rulebook.

Talk with us about custom checks, CI setup, or anything else you’d like to know about SlopCop.

We’ll use your email to respond. No scan or report is needed.