MED
QUAL003
Magic number used as default arg
tests/unit/servers/mcpgw/test_intellige…:150
MED
QUAL003
Magic number used as default arg
registry/core/config.py:299
MED
QUAL003
Magic number used as default arg
registry/core/config.py:292
MED
QUAL003
Magic number used as default arg
registry/api/federation_export_routes.py:604
MED
QUAL003
Magic number used as default arg
registry/api/federation_export_routes.py:495
MED
QUAL003
Magic number used as default arg
registry/api/federation_export_routes.py:382
MED
QUAL003
Magic number used as default arg
registry/audit/routes.py:406
MED
QUAL003
Magic number used as default arg
terraform/aws-ecs/scripts/run-documentd…:51
MED
QUAL003
Magic number used as default arg
terraform/aws-ecs/scripts/run-documentd…:11
MED
TEST002
Function is stub-only (pass/raise NotImplementedError)
metrics-service/tests/test_migrations.py:37
MED
TEST002
Function is stub-only (pass/raise NotImplementedError)
metrics-service/tests/test_migrations.py:34
MED
TEST002
Function is stub-only (pass/raise NotImplementedError)
registry/metrics/client.py:362
MED
TEST002
Function is stub-only (pass/raise NotImplementedError)
registry/metrics/client.py:359
MED
TEST002
Function is stub-only (pass/raise NotImplementedError)
registry/metrics/client.py:356
MED
TEST002
Function is stub-only (pass/raise NotImplementedError)
registry/metrics/client.py:353
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:182
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:203
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:522
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:502
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:442
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:352
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:319
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:283
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:247
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:690
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:684
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:638
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:574
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:551
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:531
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:511
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:454
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:364
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:331
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:295
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:259
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:844
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:587
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:561
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:544
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:418
MED
ERRH002
Bare except — overly broad
/tank0/claude-archive/community/agentic…:151
MED
LOG001
PII printed to stdout/stderr
cli/agent_mgmt.py:705
MED
LOG001
PII printed to stdout/stderr
cli/agent_mgmt.py:704
MED
LOG001
PII printed to stdout/stderr
cli/agent_mgmt.py:703
MED
LOG001
PII printed to stdout/stderr
cli/agent_mgmt.py:702
MED
LOG001
PII printed to stdout/stderr
cli/agent_mgmt.py:374
MED
LOG001
PII printed to stdout/stderr
cli/test_asor_complete.py:158
MED
LOG001
PII printed to stdout/stderr
cli/test_asor_complete.py:156
MED
LOG001
PII printed to stdout/stderr
cli/test_asor_complete.py:136
MED
LOG001
PII printed to stdout/stderr
cli/test_asor_complete.py:55
MED
LOG001
PII printed to stdout/stderr
cli/service_mgmt.sh:629
MED
LOG001
PII printed to stdout/stderr
cli/mcp_client.py:247
MED
LOG001
PII printed to stdout/stderr
cli/mcp_client.py:245
MED
LOG001
PII printed to stdout/stderr
cli/mcp_client.py:171
MED
LOG001
PII printed to stdout/stderr
cli/mcp_client.py:134
MED
LOG001
PII printed to stdout/stderr
cli/mcp_client.py:92
MED
LOG001
PII printed to stdout/stderr
cli/mcp_client.py:74
MED
LOG001
PII printed to stdout/stderr
cli/mcp_client.py:73
MED
LOG001
PII printed to stdout/stderr
cli/mcp_client.py:71
MED
LOG001
PII printed to stdout/stderr
cli/mcp_client.py:70
MED
LOG001
PII printed to stdout/stderr
cli/mcp_client.py:67
MED
LOG001
PII printed to stdout/stderr
cli/get_user_token.py:296
MED
LOG001
PII printed to stdout/stderr
cli/get_user_token.py:294
MED
LOG001
PII printed to stdout/stderr
cli/get_user_token.py:282
MED
LOG001
PII printed to stdout/stderr
cli/get_user_token.py:280
MED
LOG001
PII printed to stdout/stderr
metrics-service/create_api_key.py:36
MED
LOG001
PII printed to stdout/stderr
metrics-service/create_api_key.py:33
MED
LOG001
PII printed to stdout/stderr
tests/e2e/test_virtual_mcp_protocol.py:200
MED
LOG001
PII printed to stdout/stderr
docker/registry-entrypoint.sh:100
MED
LOG001
PII printed to stdout/stderr
api/registry_management.py:3324
MED
LOG001
PII printed to stdout/stderr
api/registry_management.py:2784
MED
LOG001
PII printed to stdout/stderr
api/registry_management.py:2779
MED
LOG001
PII printed to stdout/stderr
terraform/aws-ecs/scripts/service_mgmt.…:647
MED
LOG001
PII printed to stdout/stderr
terraform/aws-ecs/variables.tf:610
MED
LOG001
PII printed to stdout/stderr
terraform/aws-ecs/variables.tf:581
MED
LOG001
PII printed to stdout/stderr
get_asor_token.py:90
MED
LOG001
PII printed to stdout/stderr
get_asor_token.py:78
MED
LOG001
PII printed to stdout/stderr
get_asor_token.py:71
MED
LOG001
PII printed to stdout/stderr
get_asor_token.py:70
MED
LOG001
PII printed to stdout/stderr
build_and_run.sh:415
MED
CONC002
Concurrency — TOCTOU race via os.path.exists+open
agents/agent.py:681
MED
CORS001
CORS misconfiguration — wildcard Access-Control-Allow-Origin
terraform/telemetry-collector/variables…:78
MED
CORS001
CORS misconfiguration — wildcard Access-Control-Allow-Origin
terraform/telemetry-collector/lambda.tf:45
MED
SUPC002
Supply chain — npm install without lockfile
metrics-service/Dockerfile:15
MED
SUPC002
Supply chain — npm install without lockfile
Makefile:77
MED
SUPC002
Supply chain — npm install without lockfile
docker-compose.yml:66
MED
SUPC002
Supply chain — npm install without lockfile
build_and_run.sh:196
MED
SUPC002
Supply chain — npm install without lockfile
docker-compose.podman.yml:495
MED
SUPC002
Supply chain — npm install without lockfile
docker-compose.prebuilt.yml:538
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
frontend/src/pages/RegisterPage.tsx:676
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
frontend/src/pages/RegisterPage.tsx:664
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/mcp_security_scanner.py:275
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/service_mgmt.sh:944
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/service_mgmt.sh:385
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/service_mgmt.sh:384
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
agents/a2a/docker-compose.arm.yml:57
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
agents/a2a/docker-compose.arm.yml:54
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
agents/a2a/docker-compose.arm.yml:23
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
agents/a2a/docker-compose.arm.yml:20
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
agents/a2a/docker-compose.local.yml:57
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
agents/a2a/docker-compose.local.yml:54
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
agents/a2a/docker-compose.local.yml:23
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
agents/a2a/docker-compose.local.yml:20
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
docker/registry-entrypoint.sh:293
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/schemas/agent_models.py:139
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/schemas/peer_federation_schema…:50
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/schemas/registry_card.py:139
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/core/nginx_service.py:409
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/core/config.py:164
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/core/mcp_client.py:145
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/core/mcp_client.py:138
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/servers/currenttime.json:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/servers/realserverfaketools.js…:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/servers/mcpgw.json:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/servers/atlassian.json:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/servers/fininfo.json:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/services/peer_federation_servi…:262
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/metrics/utils.py:19
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/api/server_routes.py:2245
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/utils/keycloak_manager.py:17
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/utils/agent_validator.py:60
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
registry/utils/scopes_manager_old.py:221
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
api/test-management-api-e2e.sh:489
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/modules/mcp-gateway/o…:186
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/modules/mcp-gateway/o…:42
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/modules/mcp-gateway/o…:41
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/modules/mcp-gateway/o…:40
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/modules/mcp-gateway/e…:1234
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/modules/mcp-gateway/e…:846
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/modules/mcp-gateway/e…:559
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/modules/mcp-gateway/e…:555
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/modules/mcp-gateway/e…:543
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/modules/mcp-gateway/e…:305
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/modules/mcp-gateway/e…:98
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/scripts/post-deployme…:320
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/scripts/service_mgmt.…:962
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/scripts/service_mgmt.…:403
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/scripts/service_mgmt.…:402
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/outputs.tf:116
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
terraform/aws-ecs/outputs.tf:109
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
docker-compose.yml:421
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
docker-compose.yml:312
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
docker-compose.yml:307
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
docker-compose.yml:114
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
docker-compose.yml:108
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
docker-compose.podman.yml:295
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
docker-compose.podman.yml:209
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/examples/currenttime-v2.json:6
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/examples/currenttime-v2.json:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/examples/working_agent.json:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/examples/flight_booking_agent_ecs.j…:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/examples/minimal-server-config.json:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/examples/currenttime.json:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/examples/airegistry.json:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/examples/realserverfaketools.json:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/examples/travel_assistant_agent_ecs…:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/examples/travel_assistant_agent_car…:41
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/examples/flight_booking_agent_card.…:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
cli/examples/server-config.json:5
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/auth_server/unit/providers/test_k…:385
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/auth_server/unit/providers/test_k…:63
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/auth_server/unit/providers/test_k…:55
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_endpoint_utils.py:73
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_endpoint_utils.py:68
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_endpoint_utils.py:66
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_endpoint_utils.py:64
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_endpoint_utils.py:48
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_endpoint_utils.py:44
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_endpoint_utils.py:40
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_endpoint_utils.py:36
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_endpoint_utils.py:32
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_endpoint_utils.py:28
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_config.py:860
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_config.py:853
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_config.py:697
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_config.py:692
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_config.py:234
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_config.py:227
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_nginx_service.py:927
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_nginx_service.py:889
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_nginx_service.py:701
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_nginx_service.py:657
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_nginx_service.py:572
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_nginx_service.py:568
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_nginx_service.py:365
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/core/test_nginx_service.py:319
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/services/test_peer_federatio…:129
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/schemas/test_registry_card.py:245
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/schemas/test_registry_card.py:241
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/schemas/test_peer_federation…:56
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/health/test_health_service.py:305
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/unit/test_url_validation.py:12
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/integration/test_peer_federation_…:253
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/integration/test_peer_federation_…:112
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/integration/test_peer_federation_…:106
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/integration/test_peer_federation_…:100
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
tests/integration/conftest.py:98
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
agents/a2a/test/travel_assistant_agent_…:59
MED
CRYP001
Crypto — plaintext HTTP for sensitive endpoint
agents/a2a/test/flight_booking_agent_ca…:47