{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ef7afb4fe583b10d", "name": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/proto-home-1.html:106", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/proto-home-1.html:106"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c9c1434a611fd547", "name": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/proto-home-3.html:75", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/proto-home-3.html:75"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-42bf6dd825dd1d31", "name": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/proto-home-2.html:89", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/proto-home-2.html:89"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c169a5d6a092eefd", "name": "Insecure pattern 'document_write' in dashboard/public/main.js:809", "shortDescription": {"text": "Insecure pattern 'document_write' in dashboard/public/main.js:809"}, "fullDescription": {"text": "Found a known-risky pattern (document_write). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-764ba569b07f3287", "name": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/main.js:53", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/main.js:53"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e93d4a0f29d2429f", "name": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/surface.html:277", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/surface.html:277"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ef588814108da898", "name": "Insecure pattern 'domparser_html_parse' in dashboard/public/surface.html:538", "shortDescription": {"text": "Insecure pattern 'domparser_html_parse' in dashboard/public/surface.html:538"}, "fullDescription": {"text": "Found a known-risky pattern (domparser_html_parse). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-24ae43bda3278b5a", "name": "Very large file: dashboard/server/server.py (2386 lines)", "shortDescription": {"text": "Very large file: dashboard/server/server.py (2386 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-93fffcfb536b6ca3", "name": "Agent authority lacks a verifier contract: skills/open/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: skills/open/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f1795a00f0db118f", "name": "Commented-code block (9 lines) in dashboard/server/server.py:201", "shortDescription": {"text": "Commented-code block (9 lines) in dashboard/server/server.py:201"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3b849d020c527a92", "name": "Commented-code block (7 lines) in dashboard/public/main.js:3", "shortDescription": {"text": "Commented-code block (7 lines) in dashboard/public/main.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e95c0f7e735a7e9c", "name": "`fetch()` without try/.catch or AbortSignal \u2014 dashboard/public/main.js:618", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 dashboard/public/main.js:618"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8ea5489af8379344", "name": "FastAPI POST `archive_frame` without auth dependency \u2014 dashboard/server/server.py:330", "shortDescription": {"text": "FastAPI POST `archive_frame` without auth dependency \u2014 dashboard/server/server.py:330"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-279ddbe9379dfb89", "name": "FastAPI POST `unarchive_frame` without auth dependency \u2014 dashboard/server/server.py:336", "shortDescription": {"text": "FastAPI POST `unarchive_frame` without auth dependency \u2014 dashboard/server/server.py:336"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-07cbf8a75b6ec592", "name": "FastAPI POST `create_mindframe` without auth dependency \u2014 dashboard/server/server.py:623", "shortDescription": {"text": "FastAPI POST `create_mindframe` without auth dependency \u2014 dashboard/server/server.py:623"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-608c50393e92c0cd", "name": "FastAPI POST `frame_message` without auth dependency \u2014 dashboard/server/server.py:832", "shortDescription": {"text": "FastAPI POST `frame_message` without auth dependency \u2014 dashboard/server/server.py:832"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1ff59f4d64a7a9d5", "name": "FastAPI POST `set_frame_kind` without auth dependency \u2014 dashboard/server/server.py:848", "shortDescription": {"text": "FastAPI POST `set_frame_kind` without auth dependency \u2014 dashboard/server/server.py:848"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-97cfb206a78ac08b", "name": "FastAPI DELETE `delete_frame` without auth dependency \u2014 dashboard/server/server.py:877", "shortDescription": {"text": "FastAPI DELETE `delete_frame` without auth dependency \u2014 dashboard/server/server.py:877"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8386bafac3da577a", "name": "FastAPI PUT `frame_data_put` without auth dependency \u2014 dashboard/server/server.py:964", "shortDescription": {"text": "FastAPI PUT `frame_data_put` without auth dependency \u2014 dashboard/server/server.py:964"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a92cfb1896c2bfd5", "name": "FastAPI POST `api_dashboard_event` without auth dependency \u2014 dashboard/server/server.py:1255", "shortDescription": {"text": "FastAPI POST `api_dashboard_event` without auth dependency \u2014 dashboard/server/server.py:1255"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5a55fc560023053a", "name": "FastAPI POST `pause_watch` without auth dependency \u2014 dashboard/server/server.py:2148", "shortDescription": {"text": "FastAPI POST `pause_watch` without auth dependency \u2014 dashboard/server/server.py:2148"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-732a5014cabe1ee5", "name": "FastAPI POST `resume_watch` without auth dependency \u2014 dashboard/server/server.py:2154", "shortDescription": {"text": "FastAPI POST `resume_watch` without auth dependency \u2014 dashboard/server/server.py:2154"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3b52e31d206f96bd", "name": "FastAPI POST `open_watch` without auth dependency \u2014 dashboard/server/server.py:2159", "shortDescription": {"text": "FastAPI POST `open_watch` without auth dependency \u2014 dashboard/server/server.py:2159"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-24097c9f268cfc94", "name": "FastAPI POST `stop_run` without auth dependency \u2014 dashboard/server/server.py:2254", "shortDescription": {"text": "FastAPI POST `stop_run` without auth dependency \u2014 dashboard/server/server.py:2254"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d3ab335cb4a9183f", "name": "Dangling fetch: POST /api/watches/${encodeURIComponent(id)}/${act} (dashboard/public/main.js:156)", "shortDescription": {"text": "Dangling fetch: POST /api/watches/${encodeURIComponent(id)}/${act} (dashboard/public/main.js:156)"}, "fullDescription": {"text": "`dashboard/public/main.js:156` calls `POST /api/watches/${encodeURIComponent(id)}/${act}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/watches/<p>/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9bf2b8b51b460ae6", "name": "Unused endpoint: POST /api/frame/{mid}/unarchive", "shortDescription": {"text": "Unused endpoint: POST /api/frame/{mid}/unarchive"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `POST /api/frame/{mid}/unarchive` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9712ebb7a861ed87", "name": "Unused endpoint: GET /api/frames/activity", "shortDescription": {"text": "Unused endpoint: GET /api/frames/activity"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `GET /api/frames/activity` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-344cafa563158cd3", "name": "Unused endpoint: GET /m/{mid}", "shortDescription": {"text": "Unused endpoint: GET /m/{mid}"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `GET /m/{mid}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0722afbb93433571", "name": "Unused endpoint: GET /api/frame/{mid}/page", "shortDescription": {"text": "Unused endpoint: GET /api/frame/{mid}/page"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `GET /api/frame/{mid}/page` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-730f0d9aef861dee", "name": "Unused endpoint: GET /api/frame/{mid}/rev", "shortDescription": {"text": "Unused endpoint: GET /api/frame/{mid}/rev"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `GET /api/frame/{mid}/rev` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-78a157cf0fa275b0", "name": "Unused endpoint: POST /api/frame/{mid}/message", "shortDescription": {"text": "Unused endpoint: POST /api/frame/{mid}/message"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `POST /api/frame/{mid}/message` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-95d75c3079e5c381", "name": "Unused endpoint: POST /api/frame/{mid}/kind", "shortDescription": {"text": "Unused endpoint: POST /api/frame/{mid}/kind"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `POST /api/frame/{mid}/kind` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50a7247c4415b686", "name": "Unused endpoint: DELETE /api/frame/{mid}", "shortDescription": {"text": "Unused endpoint: DELETE /api/frame/{mid}"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `DELETE /api/frame/{mid}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f800cccb40031c9", "name": "Unused endpoint: GET /api/frame/{mid}/data", "shortDescription": {"text": "Unused endpoint: GET /api/frame/{mid}/data"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `GET /api/frame/{mid}/data` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-27a1ccee9760ce46", "name": "Unused endpoint: GET /api/frame/{mid}/data/{key}", "shortDescription": {"text": "Unused endpoint: GET /api/frame/{mid}/data/{key}"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `GET /api/frame/{mid}/data/{key}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-07d5fa2a421bf562", "name": "Unused endpoint: PUT /api/frame/{mid}/data/{key}", "shortDescription": {"text": "Unused endpoint: PUT /api/frame/{mid}/data/{key}"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `PUT /api/frame/{mid}/data/{key}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-055a0630c4691450", "name": "Unused endpoint: GET /api/frame/{mid}/export", "shortDescription": {"text": "Unused endpoint: GET /api/frame/{mid}/export"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `GET /api/frame/{mid}/export` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-899c72a7d61a5fd9", "name": "Unused endpoint: GET /api/frame/{mid}/activity", "shortDescription": {"text": "Unused endpoint: GET /api/frame/{mid}/activity"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `GET /api/frame/{mid}/activity` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8adeec22a82e77c4", "name": "Unused endpoint: POST /api/dashboard-event", "shortDescription": {"text": "Unused endpoint: POST /api/dashboard-event"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `POST /api/dashboard-event` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-af816e5e7d814fc3", "name": "Unused endpoint: GET /artifacts/{sid}/{path:path}", "shortDescription": {"text": "Unused endpoint: GET /artifacts/{sid}/{path:path}"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `GET /artifacts/{sid}/{path:path}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-175a21eb11155e59", "name": "Unused endpoint: GET /api/vault/entries", "shortDescription": {"text": "Unused endpoint: GET /api/vault/entries"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `GET /api/vault/entries` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-32af5edd087acbbc", "name": "Unused endpoint: GET /api/events", "shortDescription": {"text": "Unused endpoint: GET /api/events"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `GET /api/events` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac5b7cc82037ec35", "name": "Unused endpoint: POST /api/watches/{rid}/pause", "shortDescription": {"text": "Unused endpoint: POST /api/watches/{rid}/pause"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `POST /api/watches/{rid}/pause` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d4453b2630b5219d", "name": "Unused endpoint: POST /api/watches/{rid}/resume", "shortDescription": {"text": "Unused endpoint: POST /api/watches/{rid}/resume"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `POST /api/watches/{rid}/resume` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c4b0361ac0f5eeb9", "name": "Unused endpoint: GET /api/agents", "shortDescription": {"text": "Unused endpoint: GET /api/agents"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `GET /api/agents` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1b1d5926fda286fa", "name": "Unused endpoint: GET /{full_path:path}", "shortDescription": {"text": "Unused endpoint: GET /{full_path:path}"}, "fullDescription": {"text": "`dashboard/server/server.py` declares `GET /{full_path:path}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/19961"}, "properties": {"repository": "softwaresoftware-dev/mindframe", "repoUrl": "https://github.com/softwaresoftware-dev/mindframe", "branch": "main"}, "results": [{"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-ef7afb4fe583b10d", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/proto-home-1.html:106"}, "properties": {"repobilityId": "45d09754c0134d5c", "scanner": "scanner-primary", "fingerprint": "ef7afb4fe583b10d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/public/proto-home-1.html"}, "region": {"startLine": 106}}}]}, {"ruleId": "scanner-c9c1434a611fd547", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/proto-home-3.html:75"}, "properties": {"repobilityId": "68aabc40d0f8143b", "scanner": "scanner-primary", "fingerprint": "c9c1434a611fd547", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/public/proto-home-3.html"}, "region": {"startLine": 75}}}]}, {"ruleId": "scanner-42bf6dd825dd1d31", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/proto-home-2.html:89"}, "properties": {"repobilityId": "2515a81ba2edda73", "scanner": "scanner-primary", "fingerprint": "42bf6dd825dd1d31", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/public/proto-home-2.html"}, "region": {"startLine": 89}}}]}, {"ruleId": "scanner-c169a5d6a092eefd", "level": "note", "message": {"text": "Insecure pattern 'document_write' in dashboard/public/main.js:809"}, "properties": {"repobilityId": "0630aeca205f408c", "scanner": "scanner-primary", "fingerprint": "c169a5d6a092eefd", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["owasp", "document_write"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/public/main.js"}, "region": {"startLine": 809}}}]}, {"ruleId": "scanner-764ba569b07f3287", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/main.js:53"}, "properties": {"repobilityId": "7d299f2241a17eb7", "scanner": "scanner-primary", "fingerprint": "764ba569b07f3287", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/public/main.js"}, "region": {"startLine": 53}}}]}, {"ruleId": "scanner-e93d4a0f29d2429f", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in dashboard/public/surface.html:277"}, "properties": {"repobilityId": "cf05cbbab0e498d0", "scanner": "scanner-primary", "fingerprint": "e93d4a0f29d2429f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/public/surface.html"}, "region": {"startLine": 277}}}]}, {"ruleId": "scanner-ef588814108da898", "level": "warning", "message": {"text": "Insecure pattern 'domparser_html_parse' in dashboard/public/surface.html:538"}, "properties": {"repobilityId": "9475a55034be37c3", "scanner": "scanner-primary", "fingerprint": "ef588814108da898", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "domparser_html_parse"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/public/surface.html"}, "region": {"startLine": 538}}}]}, {"ruleId": "scanner-24ae43bda3278b5a", "level": "note", "message": {"text": "Very large file: dashboard/server/server.py (2386 lines)"}, "properties": {"repobilityId": "84ed0ee35375febf", "scanner": "scanner-primary", "fingerprint": "24ae43bda3278b5a", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "4bc503a72ebfad80", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "43bbe2e023d91dd8", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "c281669bed043dda", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "feb81006b0257c68", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-93fffcfb536b6ca3", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: skills/open/SKILL.md"}, "properties": {"repobilityId": "8a6f8e2032db3f0e", "scanner": "scanner-primary", "fingerprint": "93fffcfb536b6ca3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "skills/open/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f1795a00f0db118f", "level": "none", "message": {"text": "Commented-code block (9 lines) in dashboard/server/server.py:201"}, "properties": {"repobilityId": "e738b2fba4427bf0", "scanner": "scanner-primary", "fingerprint": "f1795a00f0db118f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3b849d020c527a92", "level": "none", "message": {"text": "Commented-code block (7 lines) in dashboard/public/main.js:3"}, "properties": {"repobilityId": "22f9fb1fd2fde36f", "scanner": "scanner-primary", "fingerprint": "3b849d020c527a92", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e95c0f7e735a7e9c", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 dashboard/public/main.js:618"}, "properties": {"repobilityId": "e42e8df3bbbd8787", "scanner": "scanner-primary", "fingerprint": "e95c0f7e735a7e9c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-8ea5489af8379344", "level": "error", "message": {"text": "FastAPI POST `archive_frame` without auth dependency \u2014 dashboard/server/server.py:330"}, "properties": {"repobilityId": "a7181f6ad4a386ed", "scanner": "scanner-primary", "fingerprint": "8ea5489af8379344", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/server/server.py"}, "region": {"startLine": 330}}}]}, {"ruleId": "scanner-279ddbe9379dfb89", "level": "error", "message": {"text": "FastAPI POST `unarchive_frame` without auth dependency \u2014 dashboard/server/server.py:336"}, "properties": {"repobilityId": "6fe2c715e7eb607b", "scanner": "scanner-primary", "fingerprint": "279ddbe9379dfb89", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/server/server.py"}, "region": {"startLine": 336}}}]}, {"ruleId": "scanner-07cbf8a75b6ec592", "level": "error", "message": {"text": "FastAPI POST `create_mindframe` without auth dependency \u2014 dashboard/server/server.py:623"}, "properties": {"repobilityId": "4f72bd2654746c99", "scanner": "scanner-primary", "fingerprint": "07cbf8a75b6ec592", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/server/server.py"}, "region": {"startLine": 623}}}]}, {"ruleId": "scanner-608c50393e92c0cd", "level": "error", "message": {"text": "FastAPI POST `frame_message` without auth dependency \u2014 dashboard/server/server.py:832"}, "properties": {"repobilityId": "ff09a1a2315e142f", "scanner": "scanner-primary", "fingerprint": "608c50393e92c0cd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/server/server.py"}, "region": {"startLine": 832}}}]}, {"ruleId": "scanner-1ff59f4d64a7a9d5", "level": "error", "message": {"text": "FastAPI POST `set_frame_kind` without auth dependency \u2014 dashboard/server/server.py:848"}, "properties": {"repobilityId": "b8955904996fb552", "scanner": "scanner-primary", "fingerprint": "1ff59f4d64a7a9d5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/server/server.py"}, "region": {"startLine": 848}}}]}, {"ruleId": "scanner-97cfb206a78ac08b", "level": "error", "message": {"text": "FastAPI DELETE `delete_frame` without auth dependency \u2014 dashboard/server/server.py:877"}, "properties": {"repobilityId": "5bc6a11f543041a3", "scanner": "scanner-primary", "fingerprint": "97cfb206a78ac08b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/server/server.py"}, "region": {"startLine": 877}}}]}, {"ruleId": "scanner-8386bafac3da577a", "level": "error", "message": {"text": "FastAPI PUT `frame_data_put` without auth dependency \u2014 dashboard/server/server.py:964"}, "properties": {"repobilityId": "55afb69f01e51d40", "scanner": "scanner-primary", "fingerprint": "8386bafac3da577a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/server/server.py"}, "region": {"startLine": 964}}}]}, {"ruleId": "scanner-a92cfb1896c2bfd5", "level": "error", "message": {"text": "FastAPI POST `api_dashboard_event` without auth dependency \u2014 dashboard/server/server.py:1255"}, "properties": {"repobilityId": "49682421bee38dfa", "scanner": "scanner-primary", "fingerprint": "a92cfb1896c2bfd5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/server/server.py"}, "region": {"startLine": 1255}}}]}, {"ruleId": "scanner-5a55fc560023053a", "level": "error", "message": {"text": "FastAPI POST `pause_watch` without auth dependency \u2014 dashboard/server/server.py:2148"}, "properties": {"repobilityId": "4cf2dbdff371f8c4", "scanner": "scanner-primary", "fingerprint": "5a55fc560023053a", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/server/server.py"}, "region": {"startLine": 2148}}}]}, {"ruleId": "scanner-732a5014cabe1ee5", "level": "error", "message": {"text": "FastAPI POST `resume_watch` without auth dependency \u2014 dashboard/server/server.py:2154"}, "properties": {"repobilityId": "364631625d90b5d4", "scanner": "scanner-primary", "fingerprint": "732a5014cabe1ee5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/server/server.py"}, "region": {"startLine": 2154}}}]}, {"ruleId": "scanner-3b52e31d206f96bd", "level": "error", "message": {"text": "FastAPI POST `open_watch` without auth dependency \u2014 dashboard/server/server.py:2159"}, "properties": {"repobilityId": "6dc7fd5c4bcabd08", "scanner": "scanner-primary", "fingerprint": "3b52e31d206f96bd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/server/server.py"}, "region": {"startLine": 2159}}}]}, {"ruleId": "scanner-24097c9f268cfc94", "level": "error", "message": {"text": "FastAPI POST `stop_run` without auth dependency \u2014 dashboard/server/server.py:2254"}, "properties": {"repobilityId": "7300aff2c53402e3", "scanner": "scanner-primary", "fingerprint": "24097c9f268cfc94", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/server/server.py"}, "region": {"startLine": 2254}}}]}, {"ruleId": "scanner-d3ab335cb4a9183f", "level": "error", "message": {"text": "Dangling fetch: POST /api/watches/${encodeURIComponent(id)}/${act} (dashboard/public/main.js:156)"}, "properties": {"repobilityId": "c23819c8e70a9808", "scanner": "scanner-primary", "fingerprint": "d3ab335cb4a9183f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9bf2b8b51b460ae6", "level": "note", "message": {"text": "Unused endpoint: POST /api/frame/{mid}/unarchive"}, "properties": {"repobilityId": "89dcf0a3e973efe2", "scanner": "scanner-primary", "fingerprint": "9bf2b8b51b460ae6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9712ebb7a861ed87", "level": "note", "message": {"text": "Unused endpoint: GET /api/frames/activity"}, "properties": {"repobilityId": "872ac435cd74184e", "scanner": "scanner-primary", "fingerprint": "9712ebb7a861ed87", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-344cafa563158cd3", "level": "note", "message": {"text": "Unused endpoint: GET /m/{mid}"}, "properties": {"repobilityId": "3f8b773b97083d59", "scanner": "scanner-primary", "fingerprint": "344cafa563158cd3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0722afbb93433571", "level": "note", "message": {"text": "Unused endpoint: GET /api/frame/{mid}/page"}, "properties": {"repobilityId": "e366c4abeecbb56c", "scanner": "scanner-primary", "fingerprint": "0722afbb93433571", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-730f0d9aef861dee", "level": "note", "message": {"text": "Unused endpoint: GET /api/frame/{mid}/rev"}, "properties": {"repobilityId": "b8f8085380b88352", "scanner": "scanner-primary", "fingerprint": "730f0d9aef861dee", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-78a157cf0fa275b0", "level": "note", "message": {"text": "Unused endpoint: POST /api/frame/{mid}/message"}, "properties": {"repobilityId": "0341058dee2443f2", "scanner": "scanner-primary", "fingerprint": "78a157cf0fa275b0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-95d75c3079e5c381", "level": "note", "message": {"text": "Unused endpoint: POST /api/frame/{mid}/kind"}, "properties": {"repobilityId": "c30b7f1f4ea90d9a", "scanner": "scanner-primary", "fingerprint": "95d75c3079e5c381", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-50a7247c4415b686", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/frame/{mid}"}, "properties": {"repobilityId": "30227161de10346a", "scanner": "scanner-primary", "fingerprint": "50a7247c4415b686", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8f800cccb40031c9", "level": "note", "message": {"text": "Unused endpoint: GET /api/frame/{mid}/data"}, "properties": {"repobilityId": "d416bbcd2845ed36", "scanner": "scanner-primary", "fingerprint": "8f800cccb40031c9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-27a1ccee9760ce46", "level": "note", "message": {"text": "Unused endpoint: GET /api/frame/{mid}/data/{key}"}, "properties": {"repobilityId": "2ddc12e06a456a7b", "scanner": "scanner-primary", "fingerprint": "27a1ccee9760ce46", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-07d5fa2a421bf562", "level": "note", "message": {"text": "Unused endpoint: PUT /api/frame/{mid}/data/{key}"}, "properties": {"repobilityId": "cc58735ee1e6c64b", "scanner": "scanner-primary", "fingerprint": "07d5fa2a421bf562", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-055a0630c4691450", "level": "note", "message": {"text": "Unused endpoint: GET /api/frame/{mid}/export"}, "properties": {"repobilityId": "ae28970944ca97e1", "scanner": "scanner-primary", "fingerprint": "055a0630c4691450", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-899c72a7d61a5fd9", "level": "note", "message": {"text": "Unused endpoint: GET /api/frame/{mid}/activity"}, "properties": {"repobilityId": "5689de201b6fa8e3", "scanner": "scanner-primary", "fingerprint": "899c72a7d61a5fd9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8adeec22a82e77c4", "level": "note", "message": {"text": "Unused endpoint: POST /api/dashboard-event"}, "properties": {"repobilityId": "cab9940d92e3a0d3", "scanner": "scanner-primary", "fingerprint": "8adeec22a82e77c4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-af816e5e7d814fc3", "level": "note", "message": {"text": "Unused endpoint: GET /artifacts/{sid}/{path:path}"}, "properties": {"repobilityId": "952e1a116c00e0c6", "scanner": "scanner-primary", "fingerprint": "af816e5e7d814fc3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-175a21eb11155e59", "level": "note", "message": {"text": "Unused endpoint: GET /api/vault/entries"}, "properties": {"repobilityId": "e89a6cc2c2589168", "scanner": "scanner-primary", "fingerprint": "175a21eb11155e59", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-32af5edd087acbbc", "level": "note", "message": {"text": "Unused endpoint: GET /api/events"}, "properties": {"repobilityId": "21072177c883e103", "scanner": "scanner-primary", "fingerprint": "32af5edd087acbbc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ac5b7cc82037ec35", "level": "note", "message": {"text": "Unused endpoint: POST /api/watches/{rid}/pause"}, "properties": {"repobilityId": "ea49306a7d4be3c7", "scanner": "scanner-primary", "fingerprint": "ac5b7cc82037ec35", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d4453b2630b5219d", "level": "note", "message": {"text": "Unused endpoint: POST /api/watches/{rid}/resume"}, "properties": {"repobilityId": "ad7180407d71adff", "scanner": "scanner-primary", "fingerprint": "d4453b2630b5219d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c4b0361ac0f5eeb9", "level": "note", "message": {"text": "Unused endpoint: GET /api/agents"}, "properties": {"repobilityId": "b20bd21e45cb4422", "scanner": "scanner-primary", "fingerprint": "c4b0361ac0f5eeb9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1b1d5926fda286fa", "level": "note", "message": {"text": "Unused endpoint: GET /{full_path:path}"}, "properties": {"repobilityId": "29d18129873f3de5", "scanner": "scanner-primary", "fingerprint": "1b1d5926fda286fa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}