CRIT
SECR004
Password embedded in URL
tests/unit/crash-recovery-ux.test.ts:465
CRIT
SECR004
Password embedded in URL
tests/unit/crash-recovery-ux.test.ts:143
CRIT
SECR004
Password embedded in URL
tests/unit/output-privacy-router.test.ts:833
CRIT
SECR004
Password embedded in URL
tests/unit/output-privacy-router.test.ts:297
CRIT
SECR004
Password embedded in URL
tests/unit/output-privacy-router.test.ts:290
CRIT
SECR004
Password embedded in URL
tests/unit/output-privacy-router.test.ts:283
CRIT
SECR004
Password embedded in URL
tests/unit/output-privacy-router.test.ts:276
CRIT
SECR004
Password embedded in URL
tests/unit/secret-redactor.test.ts:393
CRIT
SECR004
Password embedded in URL
tests/unit/secret-redactor.test.ts:250
CRIT
SECR004
Password embedded in URL
tests/unit/secret-redactor.test.ts:193
CRIT
SECR004
Password embedded in URL
tests/unit/secret-redactor.test.ts:71
CRIT
SECR004
Password embedded in URL
tests/unit/secret-redactor.test.ts:68
CRIT
SECR004
Password embedded in URL
tests/unit/ContentClassifier.test.ts:186
CRIT
SECR004
Password embedded in URL
tests/unit/ContentClassifier.test.ts:176
CRIT
SECR001
Hardcoded secret in source
tests/e2e/security-lifecycle.test.ts:95
CRIT
SECR001
Hardcoded secret in source
tests/e2e/security-lifecycle.test.ts:81
CRIT
SECR001
Hardcoded secret in source
tests/e2e/security-pipeline-e2e.test.ts:1358
CRIT
SECR001
Hardcoded secret in source
tests/e2e/security-pipeline-e2e.test.ts:96
CRIT
SECR001
Hardcoded secret in source
tests/e2e/security-pipeline-e2e.test.ts:1423
CRIT
SECR001
Hardcoded secret in source
tests/e2e/security-pipeline-e2e.test.ts:1335
CRIT
SECR001
Hardcoded secret in source
tests/unit/PolicyEnforcementLayer.test.…:147
CRIT
SECR001
Hardcoded secret in source
tests/unit/PolicyEnforcementLayer.test.…:100
CRIT
SECR001
Hardcoded secret in source
tests/unit/PolicyEnforcementLayer.test.…:91
CRIT
SECR001
Hardcoded secret in source
tests/unit/PolicyEnforcementLayer.test.…:399
CRIT
SECR001
Hardcoded secret in source
tests/unit/PolicyEnforcementLayer.test.…:386
CRIT
SECR001
Hardcoded secret in source
tests/unit/PolicyEnforcementLayer.test.…:154
CRIT
SECR001
Hardcoded secret in source
tests/unit/PolicyEnforcementLayer.test.…:80
CRIT
SECR001
Hardcoded secret in source
tests/unit/PolicyEnforcementLayer.test.…:457
CRIT
SECR001
Hardcoded secret in source
tests/unit/PolicyEnforcementLayer.test.…:108
CRIT
SECR001
Hardcoded secret in source
tests/unit/ExecutionJournal.test.ts:545
CRIT
SECR001
Hardcoded secret in source
tests/unit/ExecutionJournal.test.ts:531
CRIT
SECR001
Hardcoded secret in source
tests/unit/CoherenceGateE2E.test.ts:483
CRIT
SECR001
Hardcoded secret in source
tests/unit/CoherenceGateE2E.test.ts:486
CRIT
SECR001
Hardcoded secret in source
tests/unit/crash-recovery-ux.test.ts:154
CRIT
SECR001
Hardcoded secret in source
tests/unit/crash-recovery-ux.test.ts:151
CRIT
SECR001
Hardcoded secret in source
tests/unit/serendipity-capture.test.ts:328
CRIT
SECR001
Hardcoded secret in source
tests/unit/serendipity-capture.test.ts:335
CRIT
SECR001
Hardcoded secret in source
tests/unit/serendipity-capture.test.ts:316
CRIT
SECR001
Hardcoded secret in source
tests/unit/serendipity-capture.test.ts:310
CRIT
SECR001
Hardcoded secret in source
tests/unit/output-privacy-router.test.ts:269
CRIT
SECR001
Hardcoded secret in source
tests/unit/output-privacy-router.test.ts:262
CRIT
SECR001
Hardcoded secret in source
tests/unit/secret-redactor.test.ts:82
CRIT
SECR001
Hardcoded secret in source
tests/unit/secret-redactor.test.ts:61
CRIT
SECR001
Hardcoded secret in source
tests/unit/secret-redactor.test.ts:105
CRIT
SECR001
Hardcoded secret in source
tests/unit/secret-redactor.test.ts:57
CRIT
SECR001
Hardcoded secret in source
tests/unit/secret-redactor.test.ts:54
CRIT
SECR001
Hardcoded secret in source
tests/unit/machine-identity.test.ts:344
CRIT
SECR001
Hardcoded secret in source
tests/unit/machine-identity.test.ts:343
CRIT
SECR001
Hardcoded secret in source
tests/unit/machine-identity.test.ts:92
CRIT
SECR001
Hardcoded secret in source
tests/unit/machine-identity.test.ts:53
CRIT
SECR001
Hardcoded secret in source
tests/unit/ContentClassifier.test.ts:452
CRIT
SECR001
Hardcoded secret in source
tests/unit/ContentClassifier.test.ts:438
CRIT
SECR001
Hardcoded secret in source
tests/unit/ContentClassifier.test.ts:356
CRIT
SECR001
Hardcoded secret in source
tests/unit/ContentClassifier.test.ts:163
CRIT
SECR001
Hardcoded secret in source
tests/unit/ContentClassifier.test.ts:154
CRIT
SECR001
Hardcoded secret in source
tests/unit/ContentClassifier.test.ts:145
CRIT
SECR001
Hardcoded secret in source
tests/unit/ContentClassifier.test.ts:135
CRIT
SECR001
Hardcoded secret in source
tests/unit/ContentClassifier.test.ts:104
CRIT
SECR001
Hardcoded secret in source
tests/unit/ContentClassifier.test.ts:85
CRIT
SECR001
Hardcoded secret in source
tests/unit/ContentClassifier.test.ts:113
CRIT
SECR001
Hardcoded secret in source
tests/integration/security-wiring.test.…:149
CRIT
SECR001
Hardcoded secret in source
tests/integration/output-privacy-routin…:243
HIGH
SUPC001
Supply chain — curl | bash anti-pattern
tests/e2e/phase4-dispatch-scope-provena…:176
HIGH
SUPC001
Supply chain — curl | bash anti-pattern
tests/e2e/file-viewer-e2e.test.ts:497
HIGH
SUPC001
Supply chain — curl | bash anti-pattern
tests/unit/crash-recovery-ux.test.ts:483
HIGH
SEC020
[SEC020] Secret Printed to Logs: Debug or diagnostic code appears to print a credential-b…
src/core/PostUpdateMigrator.ts:2638
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
src/server/routes.ts:4541
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
src/server/routes.ts:3684
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
src/server/routes.ts:2610
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
src/server/routes.ts:2486
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
src/server/routes.ts:2474
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
src/server/routes.ts:2403
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
src/server/routes.ts:2392
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
src/server/routes.ts:2157
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
src/server/routes.ts:1817
HIGH
AUC003
[AUC003] Object-level route lacks visible authorization: A route with an object id-like p…
src/moltbridge/routes.ts:73
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
src/messaging/WhatsAppAdapter.ts:329
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
src/messaging/TelegramAdapter.ts:487
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
src/core/DispatchExecutor.ts:373
MED
SEC007
[SEC007] Unsafe Deserialization: Unsafe deserialization can execute arbitrary code.
src/commands/jobMigrate.ts:110
MED
SEC007
[SEC007] Unsafe Deserialization: Unsafe deserialization can execute arbitrary code.
src/scheduler/AgentMdJobLoader.ts:715
MED
SEC007
[SEC007] Unsafe Deserialization: Unsafe deserialization can execute arbitrary code.
src/scheduler/InstallBuiltinJobs.ts:151
MED
ERR001
[ERR001] Silent Exception Swallowing: Silently swallowing all exceptions hides bugs. Even…
playbook-scripts/playbook-failsafe.py:171
MED
ERR001
[ERR001] Silent Exception Swallowing: Silently swallowing all exceptions hides bugs. Even…
playbook-scripts/playbook-retirement.py:169
MED
ERR001
[ERR001] Silent Exception Swallowing: Silently swallowing all exceptions hides bugs. Even…
playbook-scripts/build-state.py:192
MED
AUC001
[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks…
—
MED
AIC003
Duplicated implementation block across source files
src/monitoring/SessionWatchdog.ts:499
MED
AIC003
Duplicated implementation block across source files
src/monitoring/CommitmentTracker.ts:837
MED
AIC003
Duplicated implementation block across source files
src/core/reviewers/escalation-resolutio…:86
MED
AIC003
Duplicated implementation block across source files
src/core/SecretStore.ts:78
MED
AIC003
Duplicated implementation block across source files
src/core/AutoUpdater.ts:437
MED
AIC003
Duplicated implementation block across source files
playbook-scripts/playbook-offline-adapt…:186
MED
AIC003
Duplicated implementation block across source files
.instar/hooks/instar/claim-intercept.js:7
MED
QUAL003
Magic number used as default arg
tests/e2e/file-viewer-e2e.test.ts:108
MED
QUAL003
Magic number used as default arg
tests/e2e/scope-coherence-lifecycle.tes…:169
MED
QUAL003
Magic number used as default arg
tests/unit/activity-partitioner.test.ts:305
MED
QUAL003
Magic number used as default arg
tests/unit/InboundMessageGate.test.ts:66
MED
QUAL003
Magic number used as default arg
tests/unit/nonce-store-config.test.ts:49
MED
QUAL003
Magic number used as default arg
tests/unit/nonce-store-config.test.ts:42
MED
QUAL003
Magic number used as default arg
tests/unit/branch-manager.test.ts:91
MED
QUAL003
Magic number used as default arg
tests/unit/branch-manager.test.ts:81
MED
QUAL003
Magic number used as default arg
tests/unit/middleware-behavioral.test.ts:208
MED
QUAL003
Magic number used as default arg
tests/unit/CommitmentTracker.test.ts:865
MED
QUAL003
Magic number used as default arg
tests/unit/request-timeout.test.ts:43
MED
QUAL003
Magic number used as default arg
tests/unit/agent-bus-replay-protection.…:707
MED
QUAL003
Magic number used as default arg
tests/unit/agent-bus-replay-protection.…:687
MED
QUAL003
Magic number used as default arg
tests/unit/intent-reflect.test.ts:150
MED
QUAL003
Magic number used as default arg
tests/unit/ForegroundRestartWatcher.tes…:53
MED
QUAL003
Magic number used as default arg
tests/integration/quota-collection.test…:278
MED
QUAL003
Magic number used as default arg
tests/integration/drift-routes.test.ts:99
MED
LOG001
PII printed to stdout/stderr
src/cli.ts:214
MED
LOG001
PII printed to stdout/stderr
src/cli.ts:97
MED
LOG001
PII printed to stdout/stderr
src/cli.ts:57
MED
LOG001
PII printed to stdout/stderr
src/cli.ts:55
MED
LOG001
PII printed to stdout/stderr
src/cli.ts:52
MED
CORS001
CORS misconfiguration — wildcard Access-Control-Allow-Origin
tests/unit/middleware-behavioral.test.ts:16
MED
JRN002
Browser storage is used for session token material
dashboard/index.html:3325
MED
JRN002
Browser storage is used for session token material
dashboard/index.html:3305
MED
DKR001
Docker final stage has no non-root USER
Dockerfile.relay:26
MED
WEB003
Public web service has no security.txt
.well-known/security.txt
MED
JRN003
Frontend API reference is not matched by discovered backend routes
src/core/PostUpdateMigrator.ts:1604
MED
AUC002
[AUC002] Low visible authorization coverage in route inventory: Only 22.5% of discovered …
—
MED
AGT012
Agent control bridge may listen on a network interface without visible auth
src/core/FeedbackManager.ts:69
MED
AGT012
Agent control bridge may listen on a network interface without visible auth
src/core/DispatchManager.ts:135
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
src/server/routes.ts:2403
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
src/server/routes.ts:2157
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
src/server/routes.ts:2011
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
src/server/routes.ts:2006
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
src/server/routes.ts:2000
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
src/server/routes.ts:1967
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
src/server/machineRoutes.ts:150
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
src/server/AgentServer.ts:223
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
src/server/AgentServer.ts:207
MED
AUC009
[AUC009] Sensitive function route lacks elevated authorization evidence: A route appears …
src/moltbridge/routes.ts:178
MED
AGT013
Agent auto-approve or skip-permissions mode is easy to enable
skills/instar-session/SKILL.md:48
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
src/server/routes.ts:2260
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
src/server/routes.ts:2248
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
src/server/routes.ts:2225
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
src/server/routes.ts:2211
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
src/server/routes.ts:2200
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
src/server/routes.ts:2146
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
src/server/routes.ts:2136
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
src/server/routes.ts:1091
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
src/server/worktreeRoutes.ts:245
MED
AUC004
[AUC004] Admin route does not show super_admin separation: An administrative route was de…
src/server/worktreeRoutes.ts:108
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/e2e/threadline/A2AE2E.test.ts:852
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/e2e/launchd-node-boot-wrapper.tes…:444
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/e2e/phase4-dispatch-scope-provena…:176
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/e2e/discernment-layer-e2e.test.ts:674
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/e2e/messaging-lifecycle.test.ts:203
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/AdaptationValidator.test.ts:194
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/message-router-cross-machine…:112
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/ExecutionJournal.test.ts:516
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/ExecutionJournal.test.ts:99
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/ExecutionJournal.test.ts:87
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/agent-token-manager.test.ts:223
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/DiscoverySecurity.test.ts:253
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/CoherenceGate.test.ts:535
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/git-sync-transport.test.ts:390
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/git-sync-transport.test.ts:381
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/git-sync-transport.test.ts:374
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/git-sync-transport.test.ts:368
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/git-sync-transport.test.ts:362
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/git-sync-transport.test.ts:62
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/message-router.test.ts:346
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/message-router.test.ts:315
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/message-router.test.ts:280
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/messaging-types.test.ts:358
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/integration/threadline/A2AIntegra…:659
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/integration/execution-journal-lif…:210
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/integration/execution-journal-lif…:177
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/integration/execution-journal-lif…:160
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/integration/execution-journal-lif…:123
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/integration/messaging-routes.test…:393
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/integration/messaging-routes.test…:364
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/integration/messaging-routes.test…:326
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/integration/messaging-routes.test…:292
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
scripts/attachments-sync/main.go:206
LOW
QUAL004
Placeholder default username (admin/admin)
tests/e2e/sync-lifecycle.test.ts:43
LOW
QUAL004
Placeholder default username (admin/admin)
tests/e2e/sync-lifecycle.test.ts:34
LOW
QUAL004
Placeholder default username (admin/admin)
tests/e2e/sync-lifecycle.test.ts:32
LOW
QUAL004
Placeholder default username (admin/admin)
tests/e2e/branch-lifecycle.test.ts:46
LOW
QUAL004
Placeholder default username (admin/admin)
tests/e2e/branch-lifecycle.test.ts:34
LOW
QUAL004
Placeholder default username (admin/admin)
tests/e2e/branch-lifecycle.test.ts:32
LOW
QUAL004
Placeholder default username (admin/admin)
tests/e2e/handoff-lifecycle.test.ts:50
LOW
QUAL004
Placeholder default username (admin/admin)
tests/e2e/handoff-lifecycle.test.ts:36
LOW
QUAL004
Placeholder default username (admin/admin)
tests/e2e/handoff-lifecycle.test.ts:34
LOW
QUAL004
Placeholder default username (admin/admin)
tests/e2e/sync-edge-cases.test.ts:40
LOW
QUAL004
Placeholder default username (admin/admin)
tests/unit/worktree-monitor.test.ts:63
LOW
QUAL004
Placeholder default username (admin/admin)
tests/unit/git-state-manager.test.ts:52
LOW
QUAL004
Placeholder default username (admin/admin)
tests/unit/RelationshipManager.test.ts:654
LOW
QUAL004
Placeholder default username (admin/admin)
tests/unit/branch-manager.test.ts:62
LOW
QUAL004
Placeholder default username (admin/admin)
tests/unit/handoff-manager.test.ts:107
LOW
QUAL004
Placeholder default username (admin/admin)
tests/unit/user-manager-edge.test.ts:195
LOW
QUAL004
Placeholder default username (admin/admin)
tests/unit/user-manager-edge.test.ts:184
LOW
QUAL004
Placeholder default username (admin/admin)
tests/integration/branch-wiring.test.ts:81
LOW
QUAL004
Placeholder default username (admin/admin)
tests/integration/handoff-wiring.test.ts:46
LOW
WEB005
robots.txt does not advertise a sitemap
CLAUDE.md
LOW
DKR008
.dockerignore misses sensitive defaults
.dockerignore