REPOGEO REPORT · LITE
Phelaine/SinkFinder
Default branch llm · commit 3fd38eff · scanned 6/1/2026, 4:07:17 AM
GitHub: 509 stars · 24 forks
Action plan is what to do next — copy-pasteable changes prioritized by impact. Category visibility is the real GEO test: when a user asks an AI a brand-free question that should surface Phelaine/SinkFinder, does the AI actually recommend you — or your competitors? Objective checks verify the metadata signals AI engines weight first. Self-mention check detects whether AI even knows you exist by name.
Action plan — copy-paste fixes
3 prioritized changes generated by gemini-2.5-flash. Mark items done after you ship the fix.
- highreadme#1Reposition README H1 and first sentence to specify Java/JVM target
Why:
CURRENT# SinkFinder + LLM ### 功能说明 闭源系统半自动漏洞挖掘工具,针对 jar/war/zip 进行静态代码分析,增加 LLM 大模型能力验证路径可达性,LLM根据上下文代码环境判断该路径可信分数。
COPY-PASTE FIX# SinkFinder + LLM: AI-Powered Static Analysis for Java (JAR/WAR/ZIP) Vulnerabilities ### 功能说明 SinkFinder是一款闭源系统半自动漏洞挖掘工具,专门针对 Java 应用的 jar/war/zip 包进行静态代码分析,增加 LLM 大模型能力验证路径可达性,LLM根据上下文代码环境判断该路径可信分数。
- hightopics#2Add relevant topics to the repository
Why:
CURRENT(none)
COPY-PASTE FIXjava, static-analysis, sast, vulnerability-scanning, llm, security, jar-analysis, war-analysis, taint-analysis, code-security
- highlicense#3Add a LICENSE file to the repository
Why:
CURRENT(no LICENSE file detected — the repo has no recognizable license)
COPY-PASTE FIXCreate a LICENSE file in the repository root. Choose a standard open-source license (e.g., Apache-2.0, MIT, GPL-3.0) that best suits your project's distribution and usage intentions.
Category GEO backends resolved for this scan: google/gemini-2.5-flash, deepseek/deepseek-v4-flash
Category visibility — the real GEO test
Brand-free queries asked to google/gemini-2.5-flash. Did AI recommend you, or someone else?
Same questions for every model — switch tabs to compare answers and rankings.
- Veracode Static Analysis · recommended 2×
- Checkmarx SAST · recommended 1×
- Fortify Static Code Analyzer · recommended 1×
- SonarQube · recommended 1×
- Snyk Code · recommended 1×
- CATEGORY QUERYHow can I find vulnerabilities in compiled Java applications using static analysis and AI verification?you: not recommendedAI recommended (in order):
- Checkmarx SAST
- Fortify Static Code Analyzer
- SonarQube
- Snyk Code
- Veracode Static Analysis
- CodeQL (github/codeql)
- DeepCode AI
AI recommended 7 alternatives but never named Phelaine/SinkFinder. This is the gap to close.
Show full AI answer
- CATEGORY QUERYWhat tools analyze JAR/WAR files for potential security flaws and trace data flows?you: not recommendedAI recommended (in order):
- OWASP Dependency-Check (jeremylong/DependencyCheck)
- Snyk
- Checkmarx SAST (CxSAST)
- Veracode Static Analysis
- Fortify Static Code Analyzer (SCA)
- SonarQube (with SonarJava plugin) (SonarSource/sonarqube)
- Contrast Security
AI recommended 7 alternatives but never named Phelaine/SinkFinder. This is the gap to close.
Show full AI answer
Objective checks
Rule-based audits of metadata signals AI engines weight most.
- Metadata completenesswarn
Suggestion:
- README presencepass
Self-mention check
Does AI even know your repo exists when asked about it directly?
- Compared to common alternatives in this category, what is the core differentiator of Phelaine/SinkFinder?passAI named Phelaine/SinkFinder explicitly
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
- If a team adopts Phelaine/SinkFinder in production, what risks or prerequisites should they evaluate first?passAI named Phelaine/SinkFinder explicitly
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
- In one sentence, what problem does the repo Phelaine/SinkFinder solve, and who is the primary audience?passAI named Phelaine/SinkFinder explicitly
AI answers can be confidently wrong. Read for accuracy: does it match your actual tech stack, audience, and differentiator?
Embed your GEO score
Drop this badge into the README of Phelaine/SinkFinder. It auto-updates whenever the report is rescanned and links back to the latest report — easy public proof that you care about AI discoverability.
[](https://repogeo.com/en/r/Phelaine/SinkFinder)<a href="https://repogeo.com/en/r/Phelaine/SinkFinder"><img src="https://repogeo.com/badge/Phelaine/SinkFinder.svg" alt="RepoGEO" /></a>Subscribe to Pro for deep diagnoses
Phelaine/SinkFinder — Lite scans stay free; this card itemizes Pro deep limits vs Lite.
- Deep reports10 / month
- Brand-free category queries5 vs 2 in Lite
- Prioritized action items8 vs 3 in Lite