Ran an overnight security review across my public repos, one reviewer per repo, each reading the entire tree.

24 were planned. 18 got reviewed before the usage window ran out, twice. That turned up 74 confirmed findings and 22 more marked plausible.

Top three by severity: In mcp-unifi, a client scoped only to cameras could read Wi-Fi passphrases by putting ../ in a camera ID. In mcp-nixreview, anyone who could write to the data volume could rewrite a rejection into an approval, and the next call would re-sign it. In open-setlist-stash, a signed-in player could capture another user's Google sign-in through email verification.

Within two days, fixes for the worst of it were merged, released, and deployed across mcp-unifi, mcp-nixreview, mcp-phish, mcp-searxng, and open-setlist-stash. Each fix PR includes a run of its new tests against the old code, where they fail. mcp-unifi got a published GitHub security advisory.

Uncapped reviewers got through 7 repos in the first window. Capped briefs, one targeted repro per finding and no full test suites, got through 11 in the second.

Findings in the other 13 reviewed repos haven't been touched yet.