{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-80e70dae935e23fd", "name": "Possibly dead Python function: run_one_instance", "shortDescription": {"text": "Possibly dead Python function: run_one_instance"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b90b55ccd28aa20", "name": "Stray `console.log` in TS/JS \u2014 openclaw/test-sse-consumer.js:59", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 openclaw/test-sse-consumer.js:59"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-735dba48798d0047", "name": "Stray `console.log` in TS/JS \u2014 install/public/installer.js:3", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 install/public/installer.js:3"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d3a1e78269a05c5b", "name": "Stray `console.log` in TS/JS \u2014 tests/log-level-audit.test.ts:238", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/log-level-audit.test.ts:238"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b582784cbfd5694e", "name": "Stray `console.log` in TS/JS \u2014 tests/worker-spawn.test.ts:118", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/worker-spawn.test.ts:118"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3cc1a8fabf81501f", "name": "Stray `console.log` in TS/JS \u2014 tests/logger-usage-standards.test.ts:184", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/logger-usage-standards.test.ts:184"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5dfe548be6682444", "name": "Stray `console.log` in TS/JS \u2014 tests/install-non-tty.test.ts:62", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/install-non-tty.test.ts:62"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-74ea0fe727072fce", "name": "Stray `console.log` in TS/JS \u2014 tests/integration/chroma-vector-sync.test.ts:73", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/integration/chroma-vector-sync.test.ts:73"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a3a80be5eb56c1c8", "name": "Stray `console.log` in TS/JS \u2014 tests/services/sqlite/schema-repair.test.ts:56", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/services/sqlite/schema-repair.test.ts:56"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6aa44bfb4c5450a6", "name": "Stray `console.log` in TS/JS \u2014 tests/infrastructure/worker-json-status.test.ts:171", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/infrastructure/worker-json-status.test.ts:171"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-75a658e324f36c71", "name": "Stray `console.log` in TS/JS \u2014 tests/infrastructure/version-consistency.test.ts:56", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 tests/infrastructure/version-consistency.test.ts:56"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-79b0c847a9f52de5", "name": "Stray `console.log` in TS/JS \u2014 plugin/ui/viewer-bundle.js:14", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 plugin/ui/viewer-bundle.js:14"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a18b9076fbfdb49", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 plugin/ui/viewer-bundle.js:9", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 plugin/ui/viewer-bundle.js:9"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6b3ac2c352beb567", "name": "Stray `console.log` in TS/JS \u2014 plugin/scripts/worker-cli.js:4", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 plugin/scripts/worker-cli.js:4"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a896530fa3d8057", "name": "Stray `console.log` in TS/JS \u2014 plugin/scripts/statusline-counts.js:24", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 plugin/scripts/statusline-counts.js:24"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-080138de1160f249", "name": "Stray `console.log` in TS/JS \u2014 plugin/scripts/version-check.js:148", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 plugin/scripts/version-check.js:148"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09a979b1af56e5a9", "name": "Stray `console.log` in TS/JS \u2014 docs/context/agent-sdk-v2-examples.ts:25", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 docs/context/agent-sdk-v2-examples.ts:25"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2fc84aae4a375738", "name": "Stray `console.log` in TS/JS \u2014 ragtime/ragtime.ts:61", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 ragtime/ragtime.ts:61"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-452a9d9b07a0fe6b", "name": "Stray `console.log` in TS/JS \u2014 scripts/check-postinstall-allowlist.js:97", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/check-postinstall-allowlist.js:97"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-31e5b15bbf03d20e", "name": "Stray `console.log` in TS/JS \u2014 scripts/pr-babysit-status.ts:396", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/pr-babysit-status.ts:396"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8fb978f11c8e20d8", "name": "Stray `console.log` in TS/JS \u2014 scripts/check-pending-queue.ts:98", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/check-pending-queue.ts:98"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b6c12d9071b96f63", "name": "Stray `console.log` in TS/JS \u2014 scripts/verify-timestamp-fix.ts:35", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/verify-timestamp-fix.ts:35"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba59d7793452740e", "name": "Stray `console.log` in TS/JS \u2014 scripts/cwd-remap.ts:62", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/cwd-remap.ts:62"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9abb4ae682654134", "name": "Stray `console.log` in TS/JS \u2014 scripts/build-worker-binary.js:11", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/build-worker-binary.js:11"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac13d79a3e4bd99c", "name": "Stray `console.log` in TS/JS \u2014 scripts/discord-release-notify.js:108", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/discord-release-notify.js:108"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fa17aa748869b0fa", "name": "Stray `console.log` in TS/JS \u2014 scripts/investigate-timestamps.ts:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/investigate-timestamps.ts:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b131c6d1b824c02", "name": "Stray `console.log` in TS/JS \u2014 scripts/build-viewer.js:13", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/build-viewer.js:13"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8aa378ec509543bb", "name": "Stray `console.log` in TS/JS \u2014 scripts/export-memories.ts:55", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/export-memories.ts:55"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-656193a6bbc6723f", "name": "Stray `console.log` in TS/JS \u2014 scripts/publish.js:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/publish.js:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-34d3271af28937d8", "name": "Stray `console.log` in TS/JS \u2014 scripts/clear-pending-queue.ts:18", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/clear-pending-queue.ts:18"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-922e0826b3a60c6e", "name": "Stray `console.log` in TS/JS \u2014 scripts/strip-comments.ts:44", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/strip-comments.ts:44"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a0763e9665c7046", "name": "Stray `console.log` in TS/JS \u2014 scripts/validate-timestamp-logic.ts:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/validate-timestamp-logic.ts:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-97e90945c4f09ac7", "name": "Stray `console.log` in TS/JS \u2014 scripts/build-hooks.js:53", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/build-hooks.js:53"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa081fe08d6f8a24", "name": "Stray `console.log` in TS/JS \u2014 scripts/cleanup-duplicates.ts:46", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/cleanup-duplicates.ts:46"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a632a5086dd6c34", "name": "Stray `console.log` in TS/JS \u2014 scripts/generate-changelog.js:82", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-changelog.js:82"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e7b8d04fdcbda4e5", "name": "Stray `console.log` in TS/JS \u2014 scripts/fix-corrupted-timestamps.ts:49", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/fix-corrupted-timestamps.ts:49"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-df28a0c1f76ba4be", "name": "Stray `console.log` in TS/JS \u2014 scripts/sync-plugin-manifests.js:98", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/sync-plugin-manifests.js:98"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8351558f80913c33", "name": "Stray `console.log` in TS/JS \u2014 scripts/regenerate-claude-md.ts:262", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/regenerate-claude-md.ts:262"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d7ff5f77ea3d4b13", "name": "Stray `console.log` in TS/JS \u2014 scripts/import-memories.ts:16", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/import-memories.ts:16"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-13bb79d4454cb6fe", "name": "Stray `console.log` in TS/JS \u2014 scripts/translate-readme/examples.ts:11", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/translate-readme/examples.ts:11"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8364ad861952850", "name": "Stray `console.log` in TS/JS \u2014 scripts/translate-readme/index.ts:276", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/translate-readme/index.ts:276"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be4c9f15fd8a5f5d", "name": "Stray `console.log` in TS/JS \u2014 scripts/translate-readme/cli.ts:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/translate-readme/cli.ts:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b9e5d505907a24e", "name": "Stray `console.log` in TS/JS \u2014 scripts/bug-report/cli.ts:54", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/bug-report/cli.ts:54"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-31697f207f597ead", "name": "Stray `console.log` in TS/JS \u2014 scripts/anti-pattern-test/detect-error-handling-antipatterns.ts:454", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/anti-pattern-test/detect-error-handling-antipatterns.ts:454"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ef84c7a0943c6d08", "name": "Stray `console.log` in TS/JS \u2014 src/integrations/opencode-plugin/index.ts:188", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/integrations/opencode-plugin/index.ts:188"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-045bd430bb8f600c", "name": "Stray `console.log` in TS/JS \u2014 src/npx-cli/index.ts:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/npx-cli/index.ts:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-42de3912c40a1088", "name": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/doctor.ts:130", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/doctor.ts:130"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d04d1528b53ba743", "name": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/runtime.ts:226", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/runtime.ts:226"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a7928413dcfd45b", "name": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/server-jobs.ts:166", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/server-jobs.ts:166"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8aa9cf08af3156c9", "name": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/telemetry.ts:120", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/telemetry.ts:120"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d410075f0ad2e974", "name": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/server.ts:167", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/server.ts:167"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3cc88ba9aadef973", "name": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/install.ts:85", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/install.ts:85"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-69ada56be99db65f", "name": "Stray `console.log` in TS/JS \u2014 src/shared/hook-io.ts:114", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/shared/hook-io.ts:114"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b2fce8f996cfa86d", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 src/ui/viewer/components/TerminalPreview.tsx:134", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 src/ui/viewer/components/TerminalPreview.tsx:134"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f12e5024e2c9cdaa", "name": "Stray `console.log` in TS/JS \u2014 src/ui/viewer/hooks/useSSE.ts:31", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/ui/viewer/hooks/useSSE.ts:31"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-103317486be66818", "name": "Stray `console.log` in TS/JS \u2014 src/server/runtime/ServerBetaService.ts:335", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server/runtime/ServerBetaService.ts:335"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fe939c6574187b06", "name": "Stray `console.log` in TS/JS \u2014 src/services/worker-service.ts:888", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/worker-service.ts:888"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-67113b2067ed24e9", "name": "Stray `console.log` in TS/JS \u2014 src/services/integrations/McpIntegrations.ts:55", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/integrations/McpIntegrations.ts:55"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-451780b913d271fd", "name": "Stray `console.log` in TS/JS \u2014 src/services/integrations/OpenClawInstaller.ts:204", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/integrations/OpenClawInstaller.ts:204"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5806db39e52ef754", "name": "Stray `console.log` in TS/JS \u2014 src/services/integrations/GeminiCliHooksInstaller.ts:159", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/integrations/GeminiCliHooksInstaller.ts:159"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4fd993a9a1401074", "name": "Stray `console.log` in TS/JS \u2014 src/services/integrations/CursorHooksInstaller.ts:168", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/integrations/CursorHooksInstaller.ts:168"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9e03ec3ac7e329a7", "name": "Stray `console.log` in TS/JS \u2014 src/services/integrations/WindsurfHooksInstaller.ts:192", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/integrations/WindsurfHooksInstaller.ts:192"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e1a49834c0f540c", "name": "Stray `console.log` in TS/JS \u2014 src/services/integrations/CodexCliInstaller.ts:132", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/integrations/CodexCliInstaller.ts:132"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-180b0dd6e33ca7a0", "name": "Stray `console.log` in TS/JS \u2014 src/services/integrations/OpenCodeInstaller.ts:82", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/integrations/OpenCodeInstaller.ts:82"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a7b798ff04db30c", "name": "Stray `console.log` in TS/JS \u2014 src/services/transcripts/cli.ts:15", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/services/transcripts/cli.ts:15"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9bcd3ce6888489c8", "name": "TODO/FIXME marker in shipping code \u2014 src/sdk/parser.ts:5", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 src/sdk/parser.ts:5"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b55272acb1588949", "name": "Dockerfile runs as root: docker/claude-mem/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: docker/claude-mem/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ff26f7f8eb4a494b", "name": "Docker base image is tag-pinned but not digest-pinned: node:20", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f691752444e3980c", "name": "Dockerfile pipes a remote installer into a shell", "shortDescription": {"text": "Dockerfile pipes a remote installer into a shell"}, "fullDescription": {"text": "Executing downloaded code during image build gives the remote endpoint build-time code execution. Prefer pinned packages or verify downloaded installers by checksum/signature."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "high", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-df8f08711fe7d0cc", "name": "Possible secret in docker/e2e/server-beta-e2e.mjs", "shortDescription": {"text": "Possible secret in docker/e2e/server-beta-e2e.mjs"}, "fullDescription": {"text": "Detected pattern matching generic_api_key. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-afcd336fd193744d", "name": "Insecure pattern 'node_child_process' in plugin/.mcp.json:8", "shortDescription": {"text": "Insecure pattern 'node_child_process' in plugin/.mcp.json:8"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0c7d809458a1baa6", "name": "Insecure pattern 'dangerous_innerhtml' in plugin/ui/viewer-bundle.js:9", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in plugin/ui/viewer-bundle.js:9"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28c3d21fa4f25068", "name": "Insecure pattern 'direct_innerhtml_assignment' in plugin/ui/viewer-bundle.js:8", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in plugin/ui/viewer-bundle.js:8"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bb58c13707ca19c1", "name": "Insecure pattern 'node_child_process' in plugin/scripts/context-generator.cjs:9", "shortDescription": {"text": "Insecure pattern 'node_child_process' in plugin/scripts/context-generator.cjs:9"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a6b467ec8c62c783", "name": "Insecure pattern 'node_child_process' in plugin/scripts/transcript-watcher.cjs:14", "shortDescription": {"text": "Insecure pattern 'node_child_process' in plugin/scripts/transcript-watcher.cjs:14"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-04432b0429a304db", "name": "Insecure pattern 'node_child_process' in plugin/scripts/bun-runner.js:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in plugin/scripts/bun-runner.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a1e4ea2cb19e62fa", "name": "Insecure pattern 'node_child_process' in plugin/scripts/worker-wrapper.cjs:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in plugin/scripts/worker-wrapper.cjs:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2234b89f09ea6af7", "name": "Insecure pattern 'new_function_used' in plugin/scripts/mcp-server.cjs:6", "shortDescription": {"text": "Insecure pattern 'new_function_used' in plugin/scripts/mcp-server.cjs:6"}, "fullDescription": {"text": "Found a known-risky pattern (new_function_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-179b045a49e51a87", "name": "Insecure pattern 'node_child_process' in plugin/scripts/mcp-server.cjs:82", "shortDescription": {"text": "Insecure pattern 'node_child_process' in plugin/scripts/mcp-server.cjs:82"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-40ec39397f4d323c", "name": "Insecure pattern 'node_child_process' in plugin/scripts/version-check.js:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in plugin/scripts/version-check.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-93dca1f0332f1112", "name": "Insecure pattern 'node_child_process' in plugin/skills/standup/standup.mjs:45", "shortDescription": {"text": "Insecure pattern 'node_child_process' in plugin/skills/standup/standup.mjs:45"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-361e9ff65b1de0d8", "name": "Insecure pattern 'node_child_process' in scripts/smoke-clean-room.cjs:36", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/smoke-clean-room.cjs:36"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-06a89927ae15fd88", "name": "Insecure pattern 'node_child_process' in scripts/cwd-remap.ts:7", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/cwd-remap.ts:7"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ca4651a64d315d3e", "name": "Insecure pattern 'node_child_process' in scripts/build-worker-binary.js:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/build-worker-binary.js:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7334de57b772494a", "name": "Insecure pattern 'node_child_process' in scripts/discord-release-notify.js:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/discord-release-notify.js:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c6121cecc161251c", "name": "Insecure pattern 'node_child_process' in scripts/sync-marketplace.cjs:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/sync-marketplace.cjs:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e31f01f6e10b619d", "name": "Insecure pattern 'node_child_process' in scripts/publish.js:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/publish.js:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-707d570ade372c31", "name": "Insecure pattern 'node_child_process' in scripts/strip-comments.ts:10", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/strip-comments.ts:10"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0f8f20d2d328415f", "name": "Insecure pattern 'node_child_process' in scripts/gen-plugin-lockfile.cjs:12", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/gen-plugin-lockfile.cjs:12"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ababbeca7e8218fd", "name": "Insecure pattern 'node_child_process' in scripts/generate-changelog.js:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/generate-changelog.js:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-84649ea2014bf783", "name": "Insecure pattern 'node_child_process' in scripts/regenerate-claude-md.ts:7", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/regenerate-claude-md.ts:7"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a08b128889e39bbf", "name": "Insecure pattern 'node_child_process' in scripts/bug-report/collector.ts:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/bug-report/collector.ts:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-825728f67d415d42", "name": "Insecure pattern 'node_child_process' in scripts/bug-report/cli.ts:9", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/bug-report/cli.ts:9"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-56bab54c2ea1489e", "name": "Insecure pattern 'node_child_process' in src/npx-cli/install/setup-runtime.ts:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/npx-cli/install/setup-runtime.ts:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-945e28cafb5f6540", "name": "Insecure pattern 'node_child_process' in src/npx-cli/install/npm-install-helper.ts:17", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/npx-cli/install/npm-install-helper.ts:17"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-43ce36cab98062c4", "name": "Insecure pattern 'node_child_process' in src/npx-cli/commands/doctor.ts:10", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/npx-cli/commands/doctor.ts:10"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e33a5663bc1d356d", "name": "Insecure pattern 'node_child_process' in src/npx-cli/commands/ide-detection.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/npx-cli/commands/ide-detection.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-208ffbbdffbd1afa", "name": "Insecure pattern 'node_child_process' in src/npx-cli/commands/install.ts:4", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/npx-cli/commands/install.ts:4"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aefe7a3da76be478", "name": "Insecure pattern 'node_child_process' in src/npx-cli/utils/bun-resolver.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/npx-cli/utils/bun-resolver.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ccb8b1ac80e01bbf", "name": "Insecure pattern 'node_child_process' in src/supervisor/shutdown.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/supervisor/shutdown.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8a6270f027ea5961", "name": "Insecure pattern 'node_child_process' in src/supervisor/process-registry.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/supervisor/process-registry.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cc7db34e80899f0a", "name": "Insecure pattern 'node_child_process' in src/shared/find-claude-executable.ts:25", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/shared/find-claude-executable.ts:25"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-70a4c4a96b7b4667", "name": "Insecure pattern 'node_child_process' in src/shared/paths.ts:4", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/shared/paths.ts:4"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d823a4d375676ef6", "name": "Insecure pattern 'node_child_process' in src/shared/oauth-token.ts:12", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/shared/oauth-token.ts:12"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2ea4ab324d75eeab", "name": "Insecure pattern 'node_child_process' in src/shared/spawn.ts:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/shared/spawn.ts:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fd6addfd7dc21734", "name": "Insecure pattern 'dangerous_innerhtml' in src/ui/viewer/components/TerminalPreview.tsx:134", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in src/ui/viewer/components/TerminalPreview.tsx:134"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-06586c7a28ade509", "name": "Insecure pattern 'node_child_process' in src/cli/claude-md-commands.ts:12", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/cli/claude-md-commands.ts:12"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-addb1bb8fc737b3e", "name": "Insecure pattern 'node_child_process' in src/utils/project-name.ts:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/utils/project-name.ts:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3be2d5e86fb672ba", "name": "Insecure pattern 'node_child_process' in src/server/runtime/ServerBetaService.ts:4", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/server/runtime/ServerBetaService.ts:4"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e126baaa4b49a08", "name": "Insecure pattern 'node_child_process' in src/services/worker-service.ts:4", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/services/worker-service.ts:4"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-da34a56239d029e6", "name": "Insecure pattern 'node_child_process' in src/services/integrations/CursorHooksInstaller.ts:5", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/services/integrations/CursorHooksInstaller.ts:5"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1d9225734c6370da", "name": "Insecure pattern 'node_child_process' in src/services/integrations/CodexCliInstaller.ts:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/services/integrations/CodexCliInstaller.ts:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-958bebf769bce876", "name": "Insecure pattern 'node_child_process' in src/services/sync/ChromaMcpManager.ts:4", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/services/sync/ChromaMcpManager.ts:4"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-30976332e4ae75e9", "name": "Insecure pattern 'node_child_process' in src/services/worker/BranchManager.ts:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/services/worker/BranchManager.ts:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-acc3d3b7da8610f3", "name": "Insecure pattern 'node_child_process' in src/services/infrastructure/WorktreeAdoption.ts:4", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/services/infrastructure/WorktreeAdoption.ts:4"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c4f4b22d60744a28", "name": "Insecure pattern 'node_child_process' in src/services/infrastructure/ProcessManager.ts:5", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/services/infrastructure/ProcessManager.ts:5"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9e9d147c9b1bc0b1", "name": "Insecure pattern 'node_child_process' in src/services/smart-file-read/parser.ts:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/services/smart-file-read/parser.ts:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fb15cc829afed787", "name": "Insecure pattern 'node_child_process' in src/services/sqlite/SchemaRepair.ts:2", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/services/sqlite/SchemaRepair.ts:2"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ac26db99b82e5132", "name": "Insecure pattern 'node_child_process' in src/sdk/commit-verification.ts:12", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/sdk/commit-verification.ts:12"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fa9b995646930c75", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "oven-sh/setup-bun@v2 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0126d0155705b1e7", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/github-script@v8 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a75cea58ae2d50f", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "amondnet/vercel-action@v25 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2cb394d1ab970a0a", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-27924aa79fa4a517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "oven-sh/setup-bun@v2 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-de53ac274e5b4ecf", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v6 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-37716d9c0a33ad5c", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-96c639bd82f3a20b", "name": "Very large file: openclaw/install.sh (1653 lines)", "shortDescription": {"text": "Very large file: openclaw/install.sh (1653 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-269cc0296e8bd3e0", "name": "Very large file: openclaw/test-install.sh (2086 lines)", "shortDescription": {"text": "Very large file: openclaw/test-install.sh (2086 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c1df7f07e681c25", "name": "Very large file: plugin/scripts/context-generator.cjs (821 lines)", "shortDescription": {"text": "Very large file: plugin/scripts/context-generator.cjs (821 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7570b54a2ad2b8b8", "name": "Very large file: src/npx-cli/commands/install.ts (1915 lines)", "shortDescription": {"text": "Very large file: src/npx-cli/commands/install.ts (1915 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c7f2a6ec64293d34", "name": "Very large file: src/server/routes/v1/ServerV1PostgresRoutes.ts (1826 lines)", "shortDescription": {"text": "Very large file: src/server/routes/v1/ServerV1PostgresRoutes.ts (1826 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-110145e497197eb7", "name": "Very large file: src/services/worker-service.ts (1449 lines)", "shortDescription": {"text": "Very large file: src/services/worker-service.ts (1449 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f62558940b2cbe3f", "name": "Very large file: src/services/worker/SearchManager.ts (1710 lines)", "shortDescription": {"text": "Very large file: src/services/worker/SearchManager.ts (1710 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-46c5b59650ca5c8f", "name": "Very large file: src/services/sqlite/SessionStore.ts (2705 lines)", "shortDescription": {"text": "Very large file: src/services/sqlite/SessionStore.ts (2705 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3ed68815bca2f8c", "name": "Node manifest has dependencies but no lockfile: package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b347d884e687248d", "name": "Node manifest has dependencies but no lockfile: openclaw/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: openclaw/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 921 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 33 placeholder/mock markers across 16 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d79c4077342a7d0", "name": "Runtime service client appears to use placeholder configuration", "shortDescription": {"text": "Runtime service client appears to use placeholder configuration"}, "fullDescription": {"text": "A runtime source file appears to wire Supabase/Firebase/AI/payment-style clients to placeholder URLs, keys, or fallback values. In the Fable corpus this often means the UI/API shape is present while the backend service is not actually configured."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a0e868c78da67a3a", "name": "Agent instruction contains unpinned remote install: openclaw/SKILL.md", "shortDescription": {"text": "Agent instruction contains unpinned remote install: openclaw/SKILL.md"}, "fullDescription": {"text": "Remote install commands in agent instructions are a supply-chain risk, especially when an agent can execute shell commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bc15c74853dd18b9", "name": "Agent authority lacks a verifier contract: plugin/.mcp.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: plugin/.mcp.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f3aa044de6062e73", "name": "Agent authority lacks a verifier contract: plugin/skills/pathfinder/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: plugin/skills/pathfinder/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-127e3c944484cf01", "name": "Agent authority lacks a verifier contract: plugin/skills/how-it-works/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: plugin/skills/how-it-works/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6db3880ddae16a15", "name": "Agent authority lacks a verifier contract: .claude/commands/anti-pattern-czar.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/anti-pattern-czar.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5aabe9b6adc0e8d7", "name": "Agent instruction contains unpinned remote install: .claude/plans/animated-installer.md", "shortDescription": {"text": "Agent instruction contains unpinned remote install: .claude/plans/animated-installer.md"}, "fullDescription": {"text": "Remote install commands in agent instructions are a supply-chain risk, especially when an agent can execute shell commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f0e2dffdfc5f0223", "name": "Commented-code block (5 lines) in openclaw/src/index.ts:747", "shortDescription": {"text": "Commented-code block (5 lines) in openclaw/src/index.ts:747"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c25dde1b13878e31", "name": "Commented-code block (8 lines) in docker/e2e/server-beta-e2e.mjs:4", "shortDescription": {"text": "Commented-code block (8 lines) in docker/e2e/server-beta-e2e.mjs:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8b2f4bf0896b55e5", "name": "Commented-code block (5 lines) in tests/write-json-file-atomic.test.ts:78", "shortDescription": {"text": "Commented-code block (5 lines) in tests/write-json-file-atomic.test.ts:78"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3ee0361e47a8faff", "name": "Commented-code block (5 lines) in tests/uninstall-clear-auto-memory.test.ts:48", "shortDescription": {"text": "Commented-code block (5 lines) in tests/uninstall-clear-auto-memory.test.ts:48"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c2e46144b716cfb8", "name": "Commented-code block (7 lines) in tests/plugin-version-check-ensure-deps.test.ts:78", "shortDescription": {"text": "Commented-code block (7 lines) in tests/plugin-version-check-ensure-deps.test.ts:78"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1efd043401ff3e53", "name": "Legacy-named symbol `name_v2` in tests/cursor-hooks-json-utils.test.ts:128", "shortDescription": {"text": "Legacy-named symbol `name_v2` in tests/cursor-hooks-json-utils.test.ts:128"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-093b441a275fe30f", "name": "Legacy-named symbol `project_v2` in tests/cursor-registry.test.ts:97", "shortDescription": {"text": "Legacy-named symbol `project_v2` in tests/cursor-registry.test.ts:97"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0c1b6770cc06fd5e", "name": "Commented-code block (5 lines) in tests/env-isolation.test.ts:130", "shortDescription": {"text": "Commented-code block (5 lines) in tests/env-isolation.test.ts:130"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-04d00a062f286443", "name": "Legacy-named symbol `name_v2` in tests/cursor-mcp-config.test.ts:212", "shortDescription": {"text": "Legacy-named symbol `name_v2` in tests/cursor-mcp-config.test.ts:212"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8aa28cd03f2cff4", "name": "Legacy-named symbol `project_v2` in tests/integration/chroma-vector-sync.test.ts:215", "shortDescription": {"text": "Legacy-named symbol `project_v2` in tests/integration/chroma-vector-sync.test.ts:215"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4c1229f0e85d4c3b", "name": "Commented-code block (5 lines) in tests/shared/timeline-formatting.test.ts:3", "shortDescription": {"text": "Commented-code block (5 lines) in tests/shared/timeline-formatting.test.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0c748612a416c4d5", "name": "Commented-code block (10 lines) in tests/shared/worker-utils-timeout.test.ts:7", "shortDescription": {"text": "Commented-code block (10 lines) in tests/shared/worker-utils-timeout.test.ts:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f7ec83db073c8b37", "name": "Commented-code block (7 lines) in tests/shared/worker-utils-version-recycle.test.ts:41", "shortDescription": {"text": "Commented-code block (7 lines) in tests/shared/worker-utils-version-recycle.test.ts:41"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8765dd1c6804bc86", "name": "Commented-code block (10 lines) in tests/shared/worker-spawn-gate.test.ts:6", "shortDescription": {"text": "Commented-code block (10 lines) in tests/shared/worker-spawn-gate.test.ts:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9d7cb0fd15421146", "name": "Commented-code block (6 lines) in tests/shared/worker-utils-recycle-successor.test.ts:13", "shortDescription": {"text": "Commented-code block (6 lines) in tests/shared/worker-utils-recycle-successor.test.ts:13"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ecfb0ff1c74cdf1c", "name": "Commented-code block (7 lines) in tests/shared/settings-defaults-manager.test.ts:18", "shortDescription": {"text": "Commented-code block (7 lines) in tests/shared/settings-defaults-manager.test.ts:18"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-16dd5da9f0cef4ce", "name": "Commented-code block (5 lines) in tests/cli/hook-stream-discipline.test.ts:14", "shortDescription": {"text": "Commented-code block (5 lines) in tests/cli/hook-stream-discipline.test.ts:14"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-83c0b5c04e718eda", "name": "Commented-code block (5 lines) in tests/cli/hook-io.test.ts:13", "shortDescription": {"text": "Commented-code block (5 lines) in tests/cli/hook-io.test.ts:13"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c393d35a3e841628", "name": "Legacy-named symbol `file_v2` in tests/utils/logger-format-tool.test.ts:354", "shortDescription": {"text": "Legacy-named symbol `file_v2` in tests/utils/logger-format-tool.test.ts:354"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a5b41bab8f882bc6", "name": "Legacy-named symbol `nOld` in tests/utils/claude-md-utils.test.ts:82", "shortDescription": {"text": "Legacy-named symbol `nOld` in tests/utils/claude-md-utils.test.ts:82"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47304d77d852a58a", "name": "Commented-code block (5 lines) in tests/utils/claude-md-utils.test.ts:6", "shortDescription": {"text": "Commented-code block (5 lines) in tests/utils/claude-md-utils.test.ts:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2e4fde7f23813d9b", "name": "Commented-code block (6 lines) in tests/worker/summary-commit-verification.test.ts:11", "shortDescription": {"text": "Commented-code block (6 lines) in tests/worker/summary-commit-verification.test.ts:11"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-eeedd9178f3a34d5", "name": "Commented-code block (5 lines) in tests/worker/poison-respawn.test.ts:4", "shortDescription": {"text": "Commented-code block (5 lines) in tests/worker/poison-respawn.test.ts:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8b2ae86d893d2bde", "name": "Commented-code block (6 lines) in tests/servers/mcp-server-name-safety.test.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in tests/servers/mcp-server-name-safety.test.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bdbfd4b993f1d3ea", "name": "Commented-code block (5 lines) in tests/hooks/runtime-selector.test.ts:108", "shortDescription": {"text": "Commented-code block (5 lines) in tests/hooks/runtime-selector.test.ts:108"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-82adb524cb96c64b", "name": "Commented-code block (5 lines) in tests/server/server-beta-service.test.ts:265", "shortDescription": {"text": "Commented-code block (5 lines) in tests/server/server-beta-service.test.ts:265"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9382073e6a22fd95", "name": "Commented-code block (5 lines) in tests/server/server-viewer-routes.test.ts:3", "shortDescription": {"text": "Commented-code block (5 lines) in tests/server/server-viewer-routes.test.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2dd5ed2bc1f12dd5", "name": "Commented-code block (8 lines) in tests/server/server-runtime-smoke.test.ts:5", "shortDescription": {"text": "Commented-code block (8 lines) in tests/server/server-runtime-smoke.test.ts:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-42d0bdb4f38fc8b6", "name": "Commented-code block (6 lines) in tests/server/generation/process-generated-response.test.ts:167", "shortDescription": {"text": "Commented-code block (6 lines) in tests/server/generation/process-generated-response.test.ts:167"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e08c3ed85894db6d", "name": "Commented-code block (6 lines) in tests/services/worker-shutdown-sequence.test.ts:4", "shortDescription": {"text": "Commented-code block (6 lines) in tests/services/worker-shutdown-sequence.test.ts:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b6ae1d66129c2165", "name": "Commented-code block (7 lines) in tests/services/integrations/spawn-contract-windows.test.ts:5", "shortDescription": {"text": "Commented-code block (7 lines) in tests/services/integrations/spawn-contract-windows.test.ts:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cd1905a8d98aebed", "name": "Commented-code block (6 lines) in tests/services/sync/chroma-mcp-manager-singleton.test.ts:20", "shortDescription": {"text": "Commented-code block (6 lines) in tests/services/sync/chroma-mcp-manager-singleton.test.ts:20"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4d3da672d74fdab9", "name": "Commented-code block (6 lines) in tests/services/sqlite/schema-repair.test.ts:30", "shortDescription": {"text": "Commented-code block (6 lines) in tests/services/sqlite/schema-repair.test.ts:30"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4daf94406a63923b", "name": "Commented-code block (7 lines) in tests/services/sqlite/observations-by-file-path-candidates.test.ts:1", "shortDescription": {"text": "Commented-code block (7 lines) in tests/services/sqlite/observations-by-file-path-candidates.test.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-06541c70e5763b3d", "name": "Commented-code block (5 lines) in tests/context/include-last-message-dot-path.test.ts:1", "shortDescription": {"text": "Commented-code block (5 lines) in tests/context/include-last-message-dot-path.test.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7dc5f80a038f8ebe", "name": "Commented-code block (8 lines) in tests/infrastructure/graceful-shutdown.test.ts:14", "shortDescription": {"text": "Commented-code block (8 lines) in tests/infrastructure/graceful-shutdown.test.ts:14"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5fdc0d4bc548ac68", "name": "Commented-code block (8 lines) in tests/infrastructure/process-manager.test.ts:7", "shortDescription": {"text": "Commented-code block (8 lines) in tests/infrastructure/process-manager.test.ts:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f2610baf5f76ffe5", "name": "Commented-code block (6 lines) in tests/infrastructure/cleanup-v12_4_3.test.ts:166", "shortDescription": {"text": "Commented-code block (6 lines) in tests/infrastructure/cleanup-v12_4_3.test.ts:166"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-11c8a47ea468206c", "name": "Commented-code block (5 lines) in tests/sdk/parser.test.ts:215", "shortDescription": {"text": "Commented-code block (5 lines) in tests/sdk/parser.test.ts:215"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-796042bc3475f9fd", "name": "Legacy-named symbol `unstable_legacy` in plugin/ui/viewer-bundle.js:8", "shortDescription": {"text": "Legacy-named symbol `unstable_legacy` in plugin/ui/viewer-bundle.js:8"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-404a8d7de736166e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 plugin/ui/viewer-bundle.js:11", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 plugin/ui/viewer-bundle.js:11"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bdbe75f7c1cb104b", "name": "`fetch()` without try/.catch or AbortSignal \u2014 plugin/scripts/transcript-watcher.cjs:14", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 plugin/scripts/transcript-watcher.cjs:14"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1b3472c4f544f256", "name": "Commented-code block (8 lines) in plugin/scripts/bun-runner.js:190", "shortDescription": {"text": "Commented-code block (8 lines) in plugin/scripts/bun-runner.js:190"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d5c5fc1adb82dd11", "name": "`fetch()` without try/.catch or AbortSignal \u2014 plugin/scripts/mcp-server.cjs:82", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 plugin/scripts/mcp-server.cjs:82"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7167c2113925fc3b", "name": "Commented-code block (8 lines) in plugin/scripts/version-check.js:45", "shortDescription": {"text": "Commented-code block (8 lines) in plugin/scripts/version-check.js:45"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-83a6e41064bf8693", "name": "Commented-code block (5 lines) in plugin/skills/standup/standup.mjs:4", "shortDescription": {"text": "Commented-code block (5 lines) in plugin/skills/standup/standup.mjs:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2eb675dbb56359ff", "name": "Commented-code block (8 lines) in scripts/smoke-clean-room.cjs:4", "shortDescription": {"text": "Commented-code block (8 lines) in scripts/smoke-clean-room.cjs:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-01ee2eb56ba9766f", "name": "Commented-code block (7 lines) in scripts/check-postinstall-allowlist.js:8", "shortDescription": {"text": "Commented-code block (7 lines) in scripts/check-postinstall-allowlist.js:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8bf21c50d8cca312", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/discord-release-notify.js:84", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/discord-release-notify.js:84"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4a7ef17866ae5444", "name": "Commented-code block (7 lines) in scripts/build-hooks.js:300", "shortDescription": {"text": "Commented-code block (7 lines) in scripts/build-hooks.js:300"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9cb3a73ea3d776f0", "name": "Commented-code block (5 lines) in scripts/gen-plugin-lockfile.cjs:3", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/gen-plugin-lockfile.cjs:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2ca093964d6d7cd5", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/import-memories.ts:39", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/import-memories.ts:39"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-514c6eff3a8fb74f", "name": "Commented-code block (7 lines) in src/npx-cli/install/setup-runtime.ts:249", "shortDescription": {"text": "Commented-code block (7 lines) in src/npx-cli/install/setup-runtime.ts:249"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2af68b2ce06ceedd", "name": "Commented-code block (13 lines) in src/npx-cli/commands/uninstall.ts:138", "shortDescription": {"text": "Commented-code block (13 lines) in src/npx-cli/commands/uninstall.ts:138"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-337e33f0ca9bd835", "name": "Commented-code block (5 lines) in src/npx-cli/commands/server-jobs.ts:6", "shortDescription": {"text": "Commented-code block (5 lines) in src/npx-cli/commands/server-jobs.ts:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-469511d33d217240", "name": "Commented-code block (6 lines) in src/npx-cli/commands/server-runtime-setup.ts:6", "shortDescription": {"text": "Commented-code block (6 lines) in src/npx-cli/commands/server-runtime-setup.ts:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-61d80adde890b087", "name": "Commented-code block (7 lines) in src/npx-cli/commands/install.ts:856", "shortDescription": {"text": "Commented-code block (7 lines) in src/npx-cli/commands/install.ts:856"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6a1f7650520b76bd", "name": "Commented-code block (5 lines) in src/supervisor/shutdown.ts:161", "shortDescription": {"text": "Commented-code block (5 lines) in src/supervisor/shutdown.ts:161"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b82299474636506d", "name": "Commented-code block (5 lines) in src/supervisor/env-sanitizer.ts:1", "shortDescription": {"text": "Commented-code block (5 lines) in src/supervisor/env-sanitizer.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-09d04d2361698541", "name": "Legacy-named symbol `skippedTooOld` in src/shared/find-claude-executable.ts:358", "shortDescription": {"text": "Legacy-named symbol `skippedTooOld` in src/shared/find-claude-executable.ts:358"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1925d89321a87768", "name": "Commented-code block (5 lines) in src/shared/worker-spawn-gate.ts:74", "shortDescription": {"text": "Commented-code block (5 lines) in src/shared/worker-spawn-gate.ts:74"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-abe78e332a3d00d2", "name": "Commented-code block (5 lines) in src/shared/worker-utils.ts:340", "shortDescription": {"text": "Commented-code block (5 lines) in src/shared/worker-utils.ts:340"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-57215af88f934b86", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/shared/worker-utils.ts:63", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/shared/worker-utils.ts:63"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f7ed388111f780c8", "name": "Commented-code block (6 lines) in src/shared/oauth-token.ts:113", "shortDescription": {"text": "Commented-code block (6 lines) in src/shared/oauth-token.ts:113"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-546834d0d266976f", "name": "Commented-code block (11 lines) in src/shared/EnvManager.ts:35", "shortDescription": {"text": "Commented-code block (11 lines) in src/shared/EnvManager.ts:35"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-94f935fda430bb6e", "name": "Commented-code block (5 lines) in src/shared/transcript-parser.ts:115", "shortDescription": {"text": "Commented-code block (5 lines) in src/shared/transcript-parser.ts:115"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-485c896939570a9a", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/ui/viewer/utils/api.ts:2", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/ui/viewer/utils/api.ts:2"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-525e50a3401fbca8", "name": "Commented-code block (6 lines) in src/cli/hook-command.ts:91", "shortDescription": {"text": "Commented-code block (6 lines) in src/cli/hook-command.ts:91"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f6a6cc9f8a2a53b0", "name": "Commented-code block (6 lines) in src/cli/handlers/context.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in src/cli/handlers/context.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-95463298cfe382be", "name": "Commented-code block (6 lines) in src/cli/handlers/file-context.ts:210", "shortDescription": {"text": "Commented-code block (6 lines) in src/cli/handlers/file-context.ts:210"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-192248fcafcd097e", "name": "Commented-code block (7 lines) in src/utils/bmp-safe.ts:3", "shortDescription": {"text": "Commented-code block (7 lines) in src/utils/bmp-safe.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f112c7f527d4de4f", "name": "Commented-code block (5 lines) in src/servers/mcp-server.ts:52", "shortDescription": {"text": "Commented-code block (5 lines) in src/servers/mcp-server.ts:52"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-84d177c41ec30e79", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/servers/mcp-server.ts:516", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/servers/mcp-server.ts:516"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e89fb488f0d8e450", "name": "Commented-code block (7 lines) in src/server/auth/sqlite-api-key-service.ts:36", "shortDescription": {"text": "Commented-code block (7 lines) in src/server/auth/sqlite-api-key-service.ts:36"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e5c9c38d6d66b3b3", "name": "Commented-code block (6 lines) in src/server/middleware/request-id.ts:6", "shortDescription": {"text": "Commented-code block (6 lines) in src/server/middleware/request-id.ts:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2572100d504a42d2", "name": "Commented-code block (9 lines) in src/server/compat/SessionsObservationsAdapter.ts:10", "shortDescription": {"text": "Commented-code block (9 lines) in src/server/compat/SessionsObservationsAdapter.ts:10"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-29a5b98b8dc166e7", "name": "Commented-code block (5 lines) in src/server/routes/v1/ServerV1PostgresRoutes.ts:134", "shortDescription": {"text": "Commented-code block (5 lines) in src/server/routes/v1/ServerV1PostgresRoutes.ts:134"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-758da56b390c4c77", "name": "Commented-code block (5 lines) in src/server/routes/v1/ServerV1Routes.ts:185", "shortDescription": {"text": "Commented-code block (5 lines) in src/server/routes/v1/ServerV1Routes.ts:185"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3b3dd49ae03aa4f5", "name": "Commented-code block (6 lines) in src/server/queue/queue-health-types.ts:3", "shortDescription": {"text": "Commented-code block (6 lines) in src/server/queue/queue-health-types.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-da260df88fc2e22b", "name": "Commented-code block (7 lines) in src/server/runtime/ServerBetaService.ts:140", "shortDescription": {"text": "Commented-code block (7 lines) in src/server/runtime/ServerBetaService.ts:140"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c680c0f72e20473a", "name": "Commented-code block (7 lines) in src/server/runtime/ServerViewerRoutes.ts:5", "shortDescription": {"text": "Commented-code block (7 lines) in src/server/runtime/ServerViewerRoutes.ts:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a45265c9f93f224a", "name": "Commented-code block (12 lines) in src/server/runtime/SessionGenerationPolicy.ts:17", "shortDescription": {"text": "Commented-code block (12 lines) in src/server/runtime/SessionGenerationPolicy.ts:17"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a5d36ca90e590da7", "name": "Commented-code block (5 lines) in src/server/runtime/ActiveServerBetaGenerationWorkerManager.ts:16", "shortDescription": {"text": "Commented-code block (5 lines) in src/server/runtime/ActiveServerBetaGenerationWorkerManager.ts:16"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-18f1aee886099835", "name": "Commented-code block (7 lines) in src/server/runtime/ServerSessionRuntimeRepository.ts:12", "shortDescription": {"text": "Commented-code block (7 lines) in src/server/runtime/ServerSessionRuntimeRepository.ts:12"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0b1560828b1339b4", "name": "Commented-code block (10 lines) in src/server/runtime/create-server-beta-service.ts:46", "shortDescription": {"text": "Commented-code block (10 lines) in src/server/runtime/create-server-beta-service.ts:46"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-90a71d088308db4e", "name": "Commented-code block (5 lines) in src/server/generation/processGeneratedResponse.ts:27", "shortDescription": {"text": "Commented-code block (5 lines) in src/server/generation/processGeneratedResponse.ts:27"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8800cff34f01ef43", "name": "Commented-code block (5 lines) in src/server/generation/ProviderObservationGenerator.ts:78", "shortDescription": {"text": "Commented-code block (5 lines) in src/server/generation/ProviderObservationGenerator.ts:78"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6b0e3aecc6473890", "name": "Commented-code block (5 lines) in src/server/generation/providers/ClaudeObservationProvider.ts:17", "shortDescription": {"text": "Commented-code block (5 lines) in src/server/generation/providers/ClaudeObservationProvider.ts:17"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8973ab51cc8a0ad6", "name": "Commented-code block (5 lines) in src/server/generation/providers/shared/prompt-builder.ts:9", "shortDescription": {"text": "Commented-code block (5 lines) in src/server/generation/providers/shared/prompt-builder.ts:9"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cdd616d790f7b3ec", "name": "Commented-code block (5 lines) in src/server/services/IngestEventsService.ts:3", "shortDescription": {"text": "Commented-code block (5 lines) in src/server/services/IngestEventsService.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-872ae5e33498a888", "name": "Commented-code block (5 lines) in src/server/services/EndSessionService.ts:3", "shortDescription": {"text": "Commented-code block (5 lines) in src/server/services/EndSessionService.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c3d9bc649f6a6b00", "name": "Commented-code block (8 lines) in src/server/jobs/ServerJobQueue.ts:21", "shortDescription": {"text": "Commented-code block (8 lines) in src/server/jobs/ServerJobQueue.ts:21"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-23435e8fe9d6a9ee", "name": "Commented-code block (5 lines) in src/server/jobs/outbox.ts:128", "shortDescription": {"text": "Commented-code block (5 lines) in src/server/jobs/outbox.ts:128"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-706f6d12fa245d3b", "name": "Commented-code block (5 lines) in src/server/jobs/job-id.ts:14", "shortDescription": {"text": "Commented-code block (5 lines) in src/server/jobs/job-id.ts:14"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0d4b17f4a4766cea", "name": "Commented-code block (5 lines) in src/server/jobs/types.ts:80", "shortDescription": {"text": "Commented-code block (5 lines) in src/server/jobs/types.ts:80"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1d81daa8f56ebb14", "name": "Commented-code block (9 lines) in src/services/worker-spawner.ts:131", "shortDescription": {"text": "Commented-code block (9 lines) in src/services/worker-spawner.ts:131"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1a29f8ad62f15c23", "name": "Commented-code block (7 lines) in src/services/worker-shutdown.ts:124", "shortDescription": {"text": "Commented-code block (7 lines) in src/services/worker-shutdown.ts:124"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b9879b5a556d735e", "name": "Commented-code block (5 lines) in src/services/worker-service.ts:130", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/worker-service.ts:130"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-96bcf90385172619", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/integrations/WindsurfHooksInstaller.ts:296", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/integrations/WindsurfHooksInstaller.ts:296"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-64483cdb78cea935", "name": "Legacy-named symbol `nLegacy` in src/services/integrations/CodexCliInstaller.ts:450", "shortDescription": {"text": "Legacy-named symbol `nLegacy` in src/services/integrations/CodexCliInstaller.ts:450"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-85f25d916056be66", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/integrations/TelegramNotifier.ts:50", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/integrations/TelegramNotifier.ts:50"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-669335f3d9d145c9", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/integrations/OpenCodeInstaller.ts:198", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/integrations/OpenCodeInstaller.ts:198"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0361ef211aa4d446", "name": "Commented-code block (5 lines) in src/services/sync/ChromaMcpManager.ts:28", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/sync/ChromaMcpManager.ts:28"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5198c83d5cf2cc8f", "name": "Commented-code block (5 lines) in src/services/sync/ChromaSync.ts:343", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/sync/ChromaSync.ts:343"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f6f811e71f41c4e6", "name": "Commented-code block (6 lines) in src/services/worker/ClaudeProvider.ts:107", "shortDescription": {"text": "Commented-code block (6 lines) in src/services/worker/ClaudeProvider.ts:107"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-947d0063f45b54d2", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/worker/GeminiProvider.ts:43", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/worker/GeminiProvider.ts:43"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8aace4981768ebfa", "name": "Commented-code block (5 lines) in src/services/worker/OpenRouterProvider.ts:606", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/worker/OpenRouterProvider.ts:606"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-07096907d97baa61", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/worker/OpenRouterProvider.ts:52", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/worker/OpenRouterProvider.ts:52"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-025f49b01ee91c28", "name": "Commented-code block (5 lines) in src/services/worker/http/routes/SearchRoutes.ts:37", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/worker/http/routes/SearchRoutes.ts:37"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b25bd7ed1dfe6d72", "name": "Commented-code block (6 lines) in src/services/worker/agents/ResponseProcessor.ts:127", "shortDescription": {"text": "Commented-code block (6 lines) in src/services/worker/agents/ResponseProcessor.ts:127"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4f073d7349a708d2", "name": "Commented-code block (10 lines) in src/services/hooks/server-beta-bootstrap.ts:9", "shortDescription": {"text": "Commented-code block (10 lines) in src/services/hooks/server-beta-bootstrap.ts:9"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-78f1a4bef2027b15", "name": "Commented-code block (7 lines) in src/services/hooks/server-beta-client.ts:281", "shortDescription": {"text": "Commented-code block (7 lines) in src/services/hooks/server-beta-client.ts:281"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8cdf04e27af17dc0", "name": "Commented-code block (5 lines) in src/services/server/Server.ts:100", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/server/Server.ts:100"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-45c582b0b04393ff", "name": "Commented-code block (5 lines) in src/services/context/ObservationCompiler.ts:178", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/context/ObservationCompiler.ts:178"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-117a0eed7a782edf", "name": "Commented-code block (11 lines) in src/services/infrastructure/CleanupV12_4_3.ts:119", "shortDescription": {"text": "Commented-code block (11 lines) in src/services/infrastructure/CleanupV12_4_3.ts:119"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-29d78da04f8d9c7d", "name": "Commented-code block (5 lines) in src/services/telemetry/scrub.ts:89", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/telemetry/scrub.ts:89"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8400bd8af953896f", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/telemetry/cli-telemetry.ts:60", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/telemetry/cli-telemetry.ts:60"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e9c2c81dd7f5b4dd", "name": "Commented-code block (8 lines) in src/services/telemetry/telemetry.ts:37", "shortDescription": {"text": "Commented-code block (8 lines) in src/services/telemetry/telemetry.ts:37"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7e29a31a3d8c9742", "name": "Commented-code block (8 lines) in src/services/telemetry/backfill.ts:320", "shortDescription": {"text": "Commented-code block (8 lines) in src/services/telemetry/backfill.ts:320"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-374fd24f1e2c7a24", "name": "Commented-code block (7 lines) in src/services/sqlite/SchemaRepair.ts:71", "shortDescription": {"text": "Commented-code block (7 lines) in src/services/sqlite/SchemaRepair.ts:71"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d06ee8ed0686e389", "name": "Commented-code block (6 lines) in src/services/sqlite/SessionSearch.ts:163", "shortDescription": {"text": "Commented-code block (6 lines) in src/services/sqlite/SessionSearch.ts:163"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bf8fcf6f79550991", "name": "Commented-code block (5 lines) in src/services/sqlite/observations/get.ts:107", "shortDescription": {"text": "Commented-code block (5 lines) in src/services/sqlite/observations/get.ts:107"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-dfbb10ee7d66bbd5", "name": "Commented-code block (5 lines) in src/sdk/parser.ts:5", "shortDescription": {"text": "Commented-code block (5 lines) in src/sdk/parser.ts:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-614d7fa8d267d78c", "name": "Commented-code block (7 lines) in src/sdk/commit-verification.ts:76", "shortDescription": {"text": "Commented-code block (7 lines) in src/sdk/commit-verification.ts:76"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e4cd095d954d6a98", "name": "Commented-code block (5 lines) in src/sdk/prompts.ts:81", "shortDescription": {"text": "Commented-code block (5 lines) in src/sdk/prompts.ts:81"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ce4152c6fb4c4e3e", "name": "Legacy-named symbol `idx_memory_sources_legacy` in src/storage/sqlite/schema.ts:199", "shortDescription": {"text": "Legacy-named symbol `idx_memory_sources_legacy` in src/storage/sqlite/schema.ts:199"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nevals/swebench/summarize.py:render_summary_markdown, evals/swebench/summarize.py:resolve_rate\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8fa45e022d08be07", "name": "Dangling fetch: GET https://api.github.com/repos/${e}/${t} (plugin/ui/viewer-bundle.js:11)", "shortDescription": {"text": "Dangling fetch: GET https://api.github.com/repos/${e}/${t} (plugin/ui/viewer-bundle.js:11)"}, "fullDescription": {"text": "`plugin/ui/viewer-bundle.js:11` calls `GET https://api.github.com/repos/${e}/${t}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/repos/<p>/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-09336c754d26223a", "name": "Dangling fetch: GET http://127.0.0.1:${t}${e} (plugin/scripts/transcript-watcher.cjs:16)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${t}${e} (plugin/scripts/transcript-watcher.cjs:16)"}, "fullDescription": {"text": "`plugin/scripts/transcript-watcher.cjs:16` calls `GET http://127.0.0.1:${t}${e}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-17f28e4908e1457e", "name": "Dangling fetch: POST http://127.0.0.1:${t}/api/admin/shutdown (plugin/scripts/worker-cli.js:5)", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${t}/api/admin/shutdown (plugin/scripts/worker-cli.js:5)"}, "fullDescription": {"text": "`plugin/scripts/worker-cli.js:5` calls `POST http://127.0.0.1:${t}/api/admin/shutdown` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/admin/shutdown`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-87812c38c62affbd", "name": "Dangling fetch: GET http://127.0.0.1:${t}/api/health (plugin/scripts/worker-cli.js:5)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${t}/api/health (plugin/scripts/worker-cli.js:5)"}, "fullDescription": {"text": "`plugin/scripts/worker-cli.js:5` calls `GET http://127.0.0.1:${t}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-60e6b4a98b07bc49", "name": "Dangling fetch: GET http://127.0.0.1:${e}/api/readiness (plugin/scripts/worker-cli.js:12)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${e}/api/readiness (plugin/scripts/worker-cli.js:12)"}, "fullDescription": {"text": "`plugin/scripts/worker-cli.js:12` calls `GET http://127.0.0.1:${e}/api/readiness` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/readiness`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-402f1cb91e6e372a", "name": "Dangling fetch: GET http://127.0.0.1:${t}${e} (plugin/scripts/mcp-server.cjs:82)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${t}${e} (plugin/scripts/mcp-server.cjs:82)"}, "fullDescription": {"text": "`plugin/scripts/mcp-server.cjs:82` calls `GET http://127.0.0.1:${t}${e}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2fd9ef3af401fb28", "name": "Dangling fetch: GET http://127.0.0.1:${t}/api/health (plugin/scripts/mcp-server.cjs:82)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${t}/api/health (plugin/scripts/mcp-server.cjs:82)"}, "fullDescription": {"text": "`plugin/scripts/mcp-server.cjs:82` calls `GET http://127.0.0.1:${t}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2e37e92468637b43", "name": "Dangling fetch: POST https://api.telegram.org/bot${botToken}/sendMessage (openclaw/src/index.ts:468)", "shortDescription": {"text": "Dangling fetch: POST https://api.telegram.org/bot${botToken}/sendMessage (openclaw/src/index.ts:468)"}, "fullDescription": {"text": "`openclaw/src/index.ts:468` calls `POST https://api.telegram.org/bot${botToken}/sendMessage` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.telegram.org/bot/<p>/sendmessage`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6f7f5e356e9cb943", "name": "Dangling fetch: GET http://127.0.0.1:${port}/api/health (tests/worker-spawn.test.ts:23)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/api/health (tests/worker-spawn.test.ts:23)"}, "fullDescription": {"text": "`tests/worker-spawn.test.ts:23` calls `GET http://127.0.0.1:${port}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9bbd1f3fbe2cddfa", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:75)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:75)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:75` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e59210c1f05bf708", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:101)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:101)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:101` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-98c1a459e9a65920", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/worker-api-endpoints.test.ts:115)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/worker-api-endpoints.test.ts:115)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:115` calls `GET http://127.0.0.1:${testPort}/api/readiness` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/readiness`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3a20b1e477dd05d5", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/worker-api-endpoints.test.ts:136)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/worker-api-endpoints.test.ts:136)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:136` calls `GET http://127.0.0.1:${testPort}/api/readiness` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/readiness`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bcbe3dddd253739f", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/version (tests/integration/worker-api-endpoints.test.ts:150)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/version (tests/integration/worker-api-endpoints.test.ts:150)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:150` calls `GET http://127.0.0.1:${testPort}/api/version` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/version`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8dfcd8c8c473e821", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/unknown-endpoint (tests/integration/worker-api-endpoints.test.ts:16", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/unknown-endpoint (tests/integration/worker-api-endpoints.test.ts:167)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:167` calls `GET http://127.0.0.1:${testPort}/api/unknown-endpoint` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/unknown-endpoint`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c1e128d133a2761f", "name": "Dangling fetch: POST http://127.0.0.1:${testPort}/api/unknown-endpoint (tests/integration/worker-api-endpoints.test.ts:1", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${testPort}/api/unknown-endpoint (tests/integration/worker-api-endpoints.test.ts:179)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:179` calls `POST http://127.0.0.1:${testPort}/api/unknown-endpoint` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/unknown-endpoint`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0178aeb2eadfb766", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/search/nonexistent/nested (tests/integration/worker-api-endpoints.t", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/search/nonexistent/nested (tests/integration/worker-api-endpoints.test.ts:192)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:192` calls `GET http://127.0.0.1:${testPort}/api/search/nonexistent/nested` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/search/nonexistent/nested`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fefe3ae58f44a301", "name": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:202)", "shortDescription": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:202)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:202` calls `OPTIONS http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ed3ef8d5eab1e0d1", "name": "Dangling fetch: POST http://127.0.0.1:${testPort}/api/nonexistent (tests/integration/worker-api-endpoints.test.ts:216)", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${testPort}/api/nonexistent (tests/integration/worker-api-endpoints.test.ts:216)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:216` calls `POST http://127.0.0.1:${testPort}/api/nonexistent` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/nonexistent`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-39cce8acf4b78e89", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:229)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:229)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:229` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9c481aa54bb59224", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/worker-api-endpoints.test.ts:251)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/worker-api-endpoints.test.ts:251)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:251` calls `GET http://127.0.0.1:${testPort}/api/readiness` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/readiness`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0c49d961047e91f6", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/worker-api-endpoints.test.ts:256)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/worker-api-endpoints.test.ts:256)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:256` calls `GET http://127.0.0.1:${testPort}/api/readiness` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/readiness`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-44e98686c37fba55", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:274)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:274)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:274` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9244c8c9d113849e", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:280)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:280)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:280` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-024c0bb7a2252fd5", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:300)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:300)"}, "fullDescription": {"text": "`tests/integration/worker-api-endpoints.test.ts:300` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-efb8021d5edf2157", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/hook-execution-e2e.test.ts:74)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/hook-execution-e2e.test.ts:74)"}, "fullDescription": {"text": "`tests/integration/hook-execution-e2e.test.ts:74` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-172641a1cf1046b8", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/hook-execution-e2e.test.ts:89)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/hook-execution-e2e.test.ts:89)"}, "fullDescription": {"text": "`tests/integration/hook-execution-e2e.test.ts:89` calls `GET http://127.0.0.1:${testPort}/api/readiness` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/readiness`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ecdc08f9a27e2882", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/hook-execution-e2e.test.ts:109)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/hook-execution-e2e.test.ts:109)"}, "fullDescription": {"text": "`tests/integration/hook-execution-e2e.test.ts:109` calls `GET http://127.0.0.1:${testPort}/api/readiness` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/readiness`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-86097b5fbba6d817", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/version (tests/integration/hook-execution-e2e.test.ts:121)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/version (tests/integration/hook-execution-e2e.test.ts:121)"}, "fullDescription": {"text": "`tests/integration/hook-execution-e2e.test.ts:121` calls `GET http://127.0.0.1:${testPort}/api/version` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/version`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f1ea311057ac58b5", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/hook-execution-e2e.test.ts:139)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/hook-execution-e2e.test.ts:139)"}, "fullDescription": {"text": "`tests/integration/hook-execution-e2e.test.ts:139` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a86a16c33c9a9b1a", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/hook-execution-e2e.test.ts:170)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/hook-execution-e2e.test.ts:170)"}, "fullDescription": {"text": "`tests/integration/hook-execution-e2e.test.ts:170` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d5f33f719bd73272", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/hook-execution-e2e.test.ts:176)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/hook-execution-e2e.test.ts:176)"}, "fullDescription": {"text": "`tests/integration/hook-execution-e2e.test.ts:176` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3f6aa0410b59ac6b", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/nonexistent (tests/integration/hook-execution-e2e.test.ts:188)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/nonexistent (tests/integration/hook-execution-e2e.test.ts:188)"}, "fullDescription": {"text": "`tests/integration/hook-execution-e2e.test.ts:188` calls `GET http://127.0.0.1:${testPort}/api/nonexistent` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/nonexistent`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c7c9cf063b8817be", "name": "Dangling fetch: POST http://127.0.0.1:${testPort}/api/test-json (tests/integration/hook-execution-e2e.test.ts:200)", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${testPort}/api/test-json (tests/integration/hook-execution-e2e.test.ts:200)"}, "fullDescription": {"text": "`tests/integration/hook-execution-e2e.test.ts:200` calls `POST http://127.0.0.1:${testPort}/api/test-json` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/test-json`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b90551b1760e7085", "name": "Dangling fetch: GET http://127.0.0.1:${port}${path} (tests/compat/sessions-observations-adapter.test.ts:166)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}${path} (tests/compat/sessions-observations-adapter.test.ts:166)"}, "fullDescription": {"text": "`tests/compat/sessions-observations-adapter.test.ts:166` calls `GET http://127.0.0.1:${port}${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1573e0649f1aad6a", "name": "Dangling fetch: POST http://127.0.0.1:${port}/api/sessions/observations (tests/compat/sessions-observations-adapter.test", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/api/sessions/observations (tests/compat/sessions-observations-adapter.test.ts:350)"}, "fullDescription": {"text": "`tests/compat/sessions-observations-adapter.test.ts:350` calls `POST http://127.0.0.1:${port}/api/sessions/observations` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/sessions/observations`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a4381b18d53b061e", "name": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:85)", "shortDescription": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:85)"}, "fullDescription": {"text": "`tests/worker/middleware/cors-restriction.test.ts:85` calls `OPTIONS http://127.0.0.1:${testPort}/api/settings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/settings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dda321677fab2106", "name": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:99)", "shortDescription": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:99)"}, "fullDescription": {"text": "`tests/worker/middleware/cors-restriction.test.ts:99` calls `OPTIONS http://127.0.0.1:${testPort}/api/settings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/settings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-69ca627480b1e3d1", "name": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:113)", "shortDescription": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:113)"}, "fullDescription": {"text": "`tests/worker/middleware/cors-restriction.test.ts:113` calls `OPTIONS http://127.0.0.1:${testPort}/api/settings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/settings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f9d9091cb025ca9d", "name": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:127)", "shortDescription": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:127)"}, "fullDescription": {"text": "`tests/worker/middleware/cors-restriction.test.ts:127` calls `OPTIONS http://127.0.0.1:${testPort}/api/settings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/settings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-491713f8f9466050", "name": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:142)", "shortDescription": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:142)"}, "fullDescription": {"text": "`tests/worker/middleware/cors-restriction.test.ts:142` calls `OPTIONS http://127.0.0.1:${testPort}/api/settings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/settings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-404b295b578c682e", "name": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:157)", "shortDescription": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:157)"}, "fullDescription": {"text": "`tests/worker/middleware/cors-restriction.test.ts:157` calls `OPTIONS http://127.0.0.1:${testPort}/api/settings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/settings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2fddec1dfa9cc368", "name": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:172)", "shortDescription": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:172)"}, "fullDescription": {"text": "`tests/worker/middleware/cors-restriction.test.ts:172` calls `OPTIONS http://127.0.0.1:${testPort}/api/settings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/settings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9a5ac3e968458523", "name": "Dangling fetch: POST http://127.0.0.1:${testPort}/api/auth/session (tests/server/server.test.ts:83)", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${testPort}/api/auth/session (tests/server/server.test.ts:83)"}, "fullDescription": {"text": "`tests/server/server.test.ts:83` calls `POST http://127.0.0.1:${testPort}/api/auth/session` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/auth/session`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-139dbb3aca47dcc9", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:256)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:256)"}, "fullDescription": {"text": "`tests/server/server.test.ts:256` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-08d97838dfb3cad7", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:270)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:270)"}, "fullDescription": {"text": "`tests/server/server.test.ts:270` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ac9c7c9340ac5e86", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:293)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:293)"}, "fullDescription": {"text": "`tests/server/server.test.ts:293` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5b2901abbb171de1", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:299)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:299)"}, "fullDescription": {"text": "`tests/server/server.test.ts:299` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f2973fdd2a238ab0", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:310)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:310)"}, "fullDescription": {"text": "`tests/server/server.test.ts:310` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-99a7081dc3b2071b", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:337)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:337)"}, "fullDescription": {"text": "`tests/server/server.test.ts:337` calls `GET http://127.0.0.1:${testPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a9a8d2444fd50103", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/server/server.test.ts:353)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/server/server.test.ts:353)"}, "fullDescription": {"text": "`tests/server/server.test.ts:353` calls `GET http://127.0.0.1:${testPort}/api/readiness` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/readiness`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c230660f022a7006", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/server/server.test.ts:376)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/server/server.test.ts:376)"}, "fullDescription": {"text": "`tests/server/server.test.ts:376` calls `GET http://127.0.0.1:${testPort}/api/readiness` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/readiness`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e38deeae0912a6d7", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/version (tests/server/server.test.ts:393)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/version (tests/server/server.test.ts:393)"}, "fullDescription": {"text": "`tests/server/server.test.ts:393` calls `GET http://127.0.0.1:${testPort}/api/version` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/version`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e830cf076edb2581", "name": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/nonexistent (tests/server/server.test.ts:411)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/nonexistent (tests/server/server.test.ts:411)"}, "fullDescription": {"text": "`tests/server/server.test.ts:411` calls `GET http://127.0.0.1:${testPort}/api/nonexistent` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/nonexistent`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3651597206add616", "name": "Dangling fetch: GET http://127.0.0.1:${port}/api/health (tests/server/server-security-headers.test.ts:42)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/api/health (tests/server/server-security-headers.test.ts:42)"}, "fullDescription": {"text": "`tests/server/server-security-headers.test.ts:42` calls `GET http://127.0.0.1:${port}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9955fa77b62f78fc", "name": "Dangling fetch: GET http://127.0.0.1:${port}/api/health (tests/server/server-security-headers.test.ts:57)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/api/health (tests/server/server-security-headers.test.ts:57)"}, "fullDescription": {"text": "`tests/server/server-security-headers.test.ts:57` calls `GET http://127.0.0.1:${port}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-31f754c12f8cec96", "name": "Dangling fetch: GET http://127.0.0.1:${address.port}/api/health (tests/server/server-beta-service.test.ts:49)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${address.port}/api/health (tests/server/server-beta-service.test.ts:49)"}, "fullDescription": {"text": "`tests/server/server-beta-service.test.ts:49` calls `GET http://127.0.0.1:${address.port}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-88c947d0b3659da4", "name": "Dangling fetch: GET http://127.0.0.1:${address.port}/v1/info (tests/server/server-beta-service.test.ts:53)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${address.port}/v1/info (tests/server/server-beta-service.test.ts:53)"}, "fullDescription": {"text": "`tests/server/server-beta-service.test.ts:53` calls `GET http://127.0.0.1:${address.port}/v1/info` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/info`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d82cc3da746f4ac3", "name": "Dangling fetch: POST http://127.0.0.1:${port}/v1/events (tests/server/server-beta-service.test.ts:102)", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/events (tests/server/server-beta-service.test.ts:102)"}, "fullDescription": {"text": "`tests/server/server-beta-service.test.ts:102` calls `POST http://127.0.0.1:${port}/v1/events` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/events`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-368c4013de2dd642", "name": "Dangling fetch: POST http://127.0.0.1:${port}/v1/events?generate=false (tests/server/server-beta-service.test.ts:164)", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/events?generate=false (tests/server/server-beta-service.test.ts:164)"}, "fullDescription": {"text": "`tests/server/server-beta-service.test.ts:164` calls `POST http://127.0.0.1:${port}/v1/events?generate=false` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/events`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1cfc70119bba13ef", "name": "Dangling fetch: POST http://127.0.0.1:${port}/v1/events/batch (tests/server/server-beta-service.test.ts:227)", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/events/batch (tests/server/server-beta-service.test.ts:227)"}, "fullDescription": {"text": "`tests/server/server-beta-service.test.ts:227` calls `POST http://127.0.0.1:${port}/v1/events/batch` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/events/batch`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b4b0e3409397165a", "name": "Dangling fetch: POST http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:188)", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:188)"}, "fullDescription": {"text": "`tests/server/v1-routes.test.ts:188` calls `POST http://127.0.0.1:${port}/v1/projects` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/projects`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4a6e332fe7d64195", "name": "Dangling fetch: POST http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:208)", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:208)"}, "fullDescription": {"text": "`tests/server/v1-routes.test.ts:208` calls `POST http://127.0.0.1:${port}/v1/projects` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/projects`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4b22a0563eadad8e", "name": "Dangling fetch: GET http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:216)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:216)"}, "fullDescription": {"text": "`tests/server/v1-routes.test.ts:216` calls `GET http://127.0.0.1:${port}/v1/projects` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/projects`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cedd1b2ebf813ca8", "name": "Dangling fetch: POST http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:232)", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:232)"}, "fullDescription": {"text": "`tests/server/v1-routes.test.ts:232` calls `POST http://127.0.0.1:${port}/v1/projects` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/projects`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9e3f1fa651257896", "name": "Dangling fetch: GET http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:259)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:259)"}, "fullDescription": {"text": "`tests/server/v1-routes.test.ts:259` calls `GET http://127.0.0.1:${port}/v1/projects` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/projects`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-565c129eb78fc3d8", "name": "Dangling fetch: POST http://127.0.0.1:${port}/v1/events/batch (tests/server/v1-routes.test.ts:283)", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/events/batch (tests/server/v1-routes.test.ts:283)"}, "fullDescription": {"text": "`tests/server/v1-routes.test.ts:283` calls `POST http://127.0.0.1:${port}/v1/events/batch` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/events/batch`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f3ee8657eb6249a7", "name": "Dangling fetch: PATCH http://127.0.0.1:${port}/v1/memories/${memory.id} (tests/server/v1-routes.test.ts:328)", "shortDescription": {"text": "Dangling fetch: PATCH http://127.0.0.1:${port}/v1/memories/${memory.id} (tests/server/v1-routes.test.ts:328)"}, "fullDescription": {"text": "`tests/server/v1-routes.test.ts:328` calls `PATCH http://127.0.0.1:${port}/v1/memories/${memory.id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/memories/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5a1d6d94666f121f", "name": "Dangling fetch: POST http://127.0.0.1:${port}${path} (tests/server/v1-routes.test.ts:346)", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${port}${path} (tests/server/v1-routes.test.ts:346)"}, "fullDescription": {"text": "`tests/server/v1-routes.test.ts:346` calls `POST http://127.0.0.1:${port}${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bf72e4beedd703dc", "name": "Dangling fetch: GET http://127.0.0.1:${port}/v1/info (tests/server/server-viewer-routes.test.ts:61)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/info (tests/server/server-viewer-routes.test.ts:61)"}, "fullDescription": {"text": "`tests/server/server-viewer-routes.test.ts:61` calls `GET http://127.0.0.1:${port}/v1/info` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/info`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9c55894c13a8cbb1", "name": "Dangling fetch: GET http://127.0.0.1:${port}/ (tests/server/server-viewer-routes.test.ts:69)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/ (tests/server/server-viewer-routes.test.ts:69)"}, "fullDescription": {"text": "`tests/server/server-viewer-routes.test.ts:69` calls `GET http://127.0.0.1:${port}/` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e03fc93c77933878", "name": "Dangling fetch: GET http://127.0.0.1:${port}/v1/info (tests/server/server-runtime-smoke.test.ts:88)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/info (tests/server/server-runtime-smoke.test.ts:88)"}, "fullDescription": {"text": "`tests/server/server-runtime-smoke.test.ts:88` calls `GET http://127.0.0.1:${port}/v1/info` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/info`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2612d751f8da6e3a", "name": "Dangling fetch: GET http://127.0.0.1:${port}/v1/projects (tests/server/server-runtime-smoke.test.ts:96)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/projects (tests/server/server-runtime-smoke.test.ts:96)"}, "fullDescription": {"text": "`tests/server/server-runtime-smoke.test.ts:96` calls `GET http://127.0.0.1:${port}/v1/projects` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/projects`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2aef76d3fbdf8f03", "name": "Dangling fetch: POST http://127.0.0.1:${port}/v1/projects (tests/server/server-runtime-smoke.test.ts:106)", "shortDescription": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/projects (tests/server/server-runtime-smoke.test.ts:106)"}, "fullDescription": {"text": "`tests/server/server-runtime-smoke.test.ts:106` calls `POST http://127.0.0.1:${port}/v1/projects` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/projects`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-810bc39e013e70c2", "name": "Dangling fetch: GET http://127.0.0.1:${port}/v1/projects (tests/server/server-runtime-smoke.test.ts:115)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/projects (tests/server/server-runtime-smoke.test.ts:115)"}, "fullDescription": {"text": "`tests/server/server-runtime-smoke.test.ts:115` calls `GET http://127.0.0.1:${port}/v1/projects` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/projects`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ec4c9abe8793f385", "name": "Dangling fetch: GET http://127.0.0.1:${port}/ (tests/server/server-runtime-smoke.test.ts:124)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/ (tests/server/server-runtime-smoke.test.ts:124)"}, "fullDescription": {"text": "`tests/server/server-runtime-smoke.test.ts:124` calls `GET http://127.0.0.1:${port}/` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-90e0e82cf41529ce", "name": "Dangling fetch: GET http://127.0.0.1:${port}/echo (tests/server/middleware/request-id.test.ts:17)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/echo (tests/server/middleware/request-id.test.ts:17)"}, "fullDescription": {"text": "`tests/server/middleware/request-id.test.ts:17` calls `GET http://127.0.0.1:${port}/echo` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/echo`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e7b4014bad0268f3", "name": "Dangling fetch: GET http://127.0.0.1:${port}/echo (tests/server/middleware/request-id.test.ts:36)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/echo (tests/server/middleware/request-id.test.ts:36)"}, "fullDescription": {"text": "`tests/server/middleware/request-id.test.ts:36` calls `GET http://127.0.0.1:${port}/echo` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/echo`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-186ce05fd1d5eab2", "name": "Dangling fetch: GET http://127.0.0.1:${port}/echo (tests/server/middleware/request-id.test.ts:55)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/echo (tests/server/middleware/request-id.test.ts:55)"}, "fullDescription": {"text": "`tests/server/middleware/request-id.test.ts:55` calls `GET http://127.0.0.1:${port}/echo` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/echo`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8af0d4458738a94e", "name": "Dangling fetch: GET http://127.0.0.1:${port}${path} (tests/server/runtime/server-session-routes.test.ts:134)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}${path} (tests/server/runtime/server-session-routes.test.ts:134)"}, "fullDescription": {"text": "`tests/server/runtime/server-session-routes.test.ts:134` calls `GET http://127.0.0.1:${port}${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f6dde0d9bf4ed18f", "name": "Dangling fetch: GET http://127.0.0.1:${port}${path} (tests/server/runtime/jobs-list-and-operator-routes.test.ts:153)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}${path} (tests/server/runtime/jobs-list-and-operator-routes.test.ts:153)"}, "fullDescription": {"text": "`tests/server/runtime/jobs-list-and-operator-routes.test.ts:153` calls `GET http://127.0.0.1:${port}${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5b24b5556a495982", "name": "Dangling fetch: GET http://127.0.0.1:${port}/v1/jobs/${encodeURIComponent(jobId!)} (tests/server/runtime/server-mcp-rout", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/jobs/${encodeURIComponent(jobId!)} (tests/server/runtime/server-mcp-routes.test.ts:225)"}, "fullDescription": {"text": "`tests/server/runtime/server-mcp-routes.test.ts:225` calls `GET http://127.0.0.1:${port}/v1/jobs/${encodeURIComponent(jobId!)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/jobs/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bf37292ee82f3a52", "name": "Dangling fetch: GET http://127.0.0.1:${port}${path} (tests/server/runtime/team-project-jobs-routes.test.ts:174)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}${path} (tests/server/runtime/team-project-jobs-routes.test.ts:174)"}, "fullDescription": {"text": "`tests/server/runtime/team-project-jobs-routes.test.ts:174` calls `GET http://127.0.0.1:${port}${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-526374a05a2f7321", "name": "Dangling fetch: GET http://127.0.0.1:${port}/v1/teams/${teamAId}/jobs (tests/server/runtime/team-project-jobs-routes.tes", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/teams/${teamAId}/jobs (tests/server/runtime/team-project-jobs-routes.test.ts:243)"}, "fullDescription": {"text": "`tests/server/runtime/team-project-jobs-routes.test.ts:243` calls `GET http://127.0.0.1:${port}/v1/teams/${teamAId}/jobs` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/v1/teams/<p>/jobs`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-168eaebba319c0ae", "name": "Dangling fetch: GET http://127.0.0.1:${port}/health (scripts/bug-report/collector.ts:111)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/health (scripts/bug-report/collector.ts:111)"}, "fullDescription": {"text": "`scripts/bug-report/collector.ts:111` calls `GET http://127.0.0.1:${port}/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9a6b55b792308b16", "name": "Dangling fetch: GET http://127.0.0.1:${port}/api/stats (scripts/bug-report/collector.ts:122)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/api/stats (scripts/bug-report/collector.ts:122)"}, "fullDescription": {"text": "`scripts/bug-report/collector.ts:122` calls `GET http://127.0.0.1:${port}/api/stats` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/stats`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-95bfd58384777ab0", "name": "Dangling fetch: GET http://127.0.0.1:${workerPort}/api/health (src/npx-cli/commands/doctor.ts:87)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${workerPort}/api/health (src/npx-cli/commands/doctor.ts:87)"}, "fullDescription": {"text": "`src/npx-cli/commands/doctor.ts:87` calls `GET http://127.0.0.1:${workerPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3acb06ae8299754e", "name": "Dangling fetch: GET http://127.0.0.1:${workerPort}/api/health (src/npx-cli/commands/install.ts:1755)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${workerPort}/api/health (src/npx-cli/commands/install.ts:1755)"}, "fullDescription": {"text": "`src/npx-cli/commands/install.ts:1755` calls `GET http://127.0.0.1:${workerPort}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ccdd8dd00c79aa8f", "name": "Dangling fetch: GET https://api.github.com/repos/${username}/${repo} (src/ui/viewer/hooks/useGitHubStars.ts:23)", "shortDescription": {"text": "Dangling fetch: GET https://api.github.com/repos/${username}/${repo} (src/ui/viewer/hooks/useGitHubStars.ts:23)"}, "fullDescription": {"text": "`src/ui/viewer/hooks/useGitHubStars.ts:23` calls `GET https://api.github.com/repos/${username}/${repo}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/repos/<p>/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-13d8067cf736c853", "name": "Dangling fetch: GET http://127.0.0.1:${port}/api/readiness (src/services/integrations/WindsurfHooksInstaller.ts:296)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/api/readiness (src/services/integrations/WindsurfHooksInstaller.ts:296)"}, "fullDescription": {"text": "`src/services/integrations/WindsurfHooksInstaller.ts:296` calls `GET http://127.0.0.1:${port}/api/readiness` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/readiness`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-41108660e29ee801", "name": "Dangling fetch: GET http://127.0.0.1:${workerPort}/api/readiness (src/services/integrations/OpenCodeInstaller.ts:198)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${workerPort}/api/readiness (src/services/integrations/OpenCodeInstaller.ts:198)"}, "fullDescription": {"text": "`src/services/integrations/OpenCodeInstaller.ts:198` calls `GET http://127.0.0.1:${workerPort}/api/readiness` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/readiness`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5c927011058e8c5f", "name": "Dangling fetch: GET http://127.0.0.1:${port}${endpointPath} (src/services/infrastructure/HealthMonitor.ts:13)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}${endpointPath} (src/services/infrastructure/HealthMonitor.ts:13)"}, "fullDescription": {"text": "`src/services/infrastructure/HealthMonitor.ts:13` calls `GET http://127.0.0.1:${port}${endpointPath}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-abd3c44849963216", "name": "Dangling fetch: GET http://127.0.0.1:${port}/api/health (src/services/infrastructure/HealthMonitor.ts:26)", "shortDescription": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/api/health (src/services/infrastructure/HealthMonitor.ts:26)"}, "fullDescription": {"text": "`src/services/infrastructure/HealthMonitor.ts:26` calls `GET http://127.0.0.1:${port}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/127.0.0.1:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4756b4c4da7d2088", "name": "Unused endpoint: GET /api/health", "shortDescription": {"text": "Unused endpoint: GET /api/health"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `GET /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6c2507f3182299a0", "name": "Unused endpoint: GET /api/version", "shortDescription": {"text": "Unused endpoint: GET /api/version"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `GET /api/version` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cb9942e1574d519c", "name": "Unused endpoint: GET /api/instructions", "shortDescription": {"text": "Unused endpoint: GET /api/instructions"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `GET /api/instructions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1797285e777f21ba", "name": "Unused endpoint: POST /api/admin/restart", "shortDescription": {"text": "Unused endpoint: POST /api/admin/restart"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `POST /api/admin/restart` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c12b983b671f7650", "name": "Unused endpoint: POST /api/admin/shutdown", "shortDescription": {"text": "Unused endpoint: POST /api/admin/shutdown"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `POST /api/admin/shutdown` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99af828a88c982ca", "name": "Unused endpoint: GET /api/admin/doctor", "shortDescription": {"text": "Unused endpoint: GET /api/admin/doctor"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `GET /api/admin/doctor` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1766e6d593b047a", "name": "Unused endpoint: USE /v1", "shortDescription": {"text": "Unused endpoint: USE /v1"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `USE /v1` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c48b167569ccbdf", "name": "Unused endpoint: POST /v1/events", "shortDescription": {"text": "Unused endpoint: POST /v1/events"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `POST /v1/events` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e4ed0369b015de54", "name": "Unused endpoint: POST /v1/events/batch", "shortDescription": {"text": "Unused endpoint: POST /v1/events/batch"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `POST /v1/events/batch` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-547c7e07c03893ca", "name": "Unused endpoint: GET /v1/events/:id", "shortDescription": {"text": "Unused endpoint: GET /v1/events/:id"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `GET /v1/events/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dc0666cc3ea5289f", "name": "Unused endpoint: GET /v1/events/:id/observations", "shortDescription": {"text": "Unused endpoint: GET /v1/events/:id/observations"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `GET /v1/events/:id/observations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bf1828beba1c4da7", "name": "Unused endpoint: GET /v1/teams/:teamId/jobs", "shortDescription": {"text": "Unused endpoint: GET /v1/teams/:teamId/jobs"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `GET /v1/teams/:teamId/jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-902e01996f20c4bf", "name": "Unused endpoint: GET /v1/projects/:projectId/jobs", "shortDescription": {"text": "Unused endpoint: GET /v1/projects/:projectId/jobs"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `GET /v1/projects/:projectId/jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec289b461de13e63", "name": "Unused endpoint: GET /v1/jobs", "shortDescription": {"text": "Unused endpoint: GET /v1/jobs"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `GET /v1/jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9b67ca93f2457ffb", "name": "Unused endpoint: GET /v1/jobs/:id", "shortDescription": {"text": "Unused endpoint: GET /v1/jobs/:id"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `GET /v1/jobs/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7c353cd9a31f6a1a", "name": "Unused endpoint: POST /v1/jobs/:id/retry", "shortDescription": {"text": "Unused endpoint: POST /v1/jobs/:id/retry"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `POST /v1/jobs/:id/retry` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-999f8733365f9df2", "name": "Unused endpoint: POST /v1/jobs/:id/cancel", "shortDescription": {"text": "Unused endpoint: POST /v1/jobs/:id/cancel"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `POST /v1/jobs/:id/cancel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7041d88699f4cf0d", "name": "Unused endpoint: POST /v1/sessions/start", "shortDescription": {"text": "Unused endpoint: POST /v1/sessions/start"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `POST /v1/sessions/start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c3383173b9b9dbe", "name": "Unused endpoint: GET /v1/sessions/:id", "shortDescription": {"text": "Unused endpoint: GET /v1/sessions/:id"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `GET /v1/sessions/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0ec7fa647bc4efbd", "name": "Unused endpoint: POST /v1/sessions/:id/end", "shortDescription": {"text": "Unused endpoint: POST /v1/sessions/:id/end"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `POST /v1/sessions/:id/end` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ae9acc9695ec942a", "name": "Unused endpoint: POST /v1/memories", "shortDescription": {"text": "Unused endpoint: POST /v1/memories"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `POST /v1/memories` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8d83ec85fe852be", "name": "Unused endpoint: POST /v1/search", "shortDescription": {"text": "Unused endpoint: POST /v1/search"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `POST /v1/search` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba9a006b181623b6", "name": "Unused endpoint: POST /v1/context", "shortDescription": {"text": "Unused endpoint: POST /v1/context"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `POST /v1/context` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-076ae4069b338403", "name": "Unused endpoint: POST /api/sessions/observations", "shortDescription": {"text": "Unused endpoint: POST /api/sessions/observations"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `POST /api/sessions/observations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4d5e9716560f1147", "name": "Unused endpoint: POST /api/sessions/summarize", "shortDescription": {"text": "Unused endpoint: POST /api/sessions/summarize"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `POST /api/sessions/summarize` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-19a1a46befe3d6a6", "name": "Unused endpoint: DELETE ", "shortDescription": {"text": "Unused endpoint: DELETE "}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `DELETE ` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-57fe8ccf6e8df35a", "name": "Unused endpoint: GET /v1/info", "shortDescription": {"text": "Unused endpoint: GET /v1/info"}, "fullDescription": {"text": "`plugin/scripts/server-beta-service.cjs` declares `GET /v1/info` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-65c2304134ff231e", "name": "Unused endpoint: ALL /api/auth/*splat", "shortDescription": {"text": "Unused endpoint: ALL /api/auth/*splat"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `ALL /api/auth/*splat` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3fd26491572228c4", "name": "Unused endpoint: GET /v1/projects", "shortDescription": {"text": "Unused endpoint: GET /v1/projects"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `GET /v1/projects` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b0b8181b03ca7de5", "name": "Unused endpoint: POST /v1/projects", "shortDescription": {"text": "Unused endpoint: POST /v1/projects"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/projects` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-912ce2daa79ecad3", "name": "Unused endpoint: GET /v1/projects/:id", "shortDescription": {"text": "Unused endpoint: GET /v1/projects/:id"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `GET /v1/projects/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ef947f347f2d2a39", "name": "Unused endpoint: GET /v1/memories/:id", "shortDescription": {"text": "Unused endpoint: GET /v1/memories/:id"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `GET /v1/memories/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-39b66f5bc970cf68", "name": "Unused endpoint: PATCH /v1/memories/:id", "shortDescription": {"text": "Unused endpoint: PATCH /v1/memories/:id"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `PATCH /v1/memories/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9685abae84f94e76", "name": "Unused endpoint: GET /v1/audit", "shortDescription": {"text": "Unused endpoint: GET /v1/audit"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `GET /v1/audit` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b96372541f48aa3b", "name": "Unused endpoint: POST /v1/environments?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/environments?beta=true"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/environments?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f69ff3386aed8a58", "name": "Unused endpoint: POST /v1/files?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/files?beta=true"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/files?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e42ff2d7e23d4c7", "name": "Unused endpoint: POST /v1/user_profiles?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/user_profiles?beta=true"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/user_profiles?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b8ed4c704a21b2a", "name": "Unused endpoint: POST /v1/agents?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/agents?beta=true"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/agents?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8bdbd7b085e30db", "name": "Unused endpoint: POST /v1/memory_stores?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/memory_stores?beta=true"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/memory_stores?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd7e4d4f2ed43337", "name": "Unused endpoint: POST /v1/messages/batches?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/messages/batches?beta=true"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/messages/batches?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00750df0839bbbd3", "name": "Unused endpoint: POST /v1/messages?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/messages?beta=true"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/messages?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6c096d37f349fa96", "name": "Unused endpoint: POST /v1/messages/count_tokens?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/messages/count_tokens?beta=true"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/messages/count_tokens?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-56fe7aef1427c93d", "name": "Unused endpoint: POST /v1/sessions?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/sessions?beta=true"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/sessions?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bea60f0266e76560", "name": "Unused endpoint: POST /v1/skills?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/skills?beta=true"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/skills?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d29f578584143cf", "name": "Unused endpoint: POST /v1/vaults?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/vaults?beta=true"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/vaults?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1e474744f4149920", "name": "Unused endpoint: POST /v1/complete", "shortDescription": {"text": "Unused endpoint: POST /v1/complete"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/complete` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8bcda56c4c41e5fa", "name": "Unused endpoint: POST /v1/messages/batches", "shortDescription": {"text": "Unused endpoint: POST /v1/messages/batches"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/messages/batches` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50d20b703a1dd1f9", "name": "Unused endpoint: POST /v1/messages", "shortDescription": {"text": "Unused endpoint: POST /v1/messages"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/messages` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e51d72bee485df7b", "name": "Unused endpoint: POST /v1/messages/count_tokens", "shortDescription": {"text": "Unused endpoint: POST /v1/messages/count_tokens"}, "fullDescription": {"text": "`plugin/scripts/worker-service.cjs` declares `POST /v1/messages/count_tokens` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/21105"}, "properties": {"repository": "thedotmack/claude-mem", "repoUrl": "https://github.com/thedotmack/claude-mem", "branch": "main"}, "results": [{"ruleId": "scanner-80e70dae935e23fd", "level": "note", "message": {"text": "Possibly dead Python function: run_one_instance"}, "properties": {"repobilityId": "1d7cc15b3b8f812a", "scanner": "scanner-primary", "fingerprint": "80e70dae935e23fd", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "evals/swebench/run-batch.py:235"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8b90b55ccd28aa20", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 openclaw/test-sse-consumer.js:59"}, "properties": {"repobilityId": "c38052804844fc10", "scanner": "scanner-primary", "fingerprint": "8b90b55ccd28aa20", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-735dba48798d0047", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 install/public/installer.js:3"}, "properties": {"repobilityId": "4f15b72925d87234", "scanner": "scanner-primary", "fingerprint": "735dba48798d0047", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d3a1e78269a05c5b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/log-level-audit.test.ts:238"}, "properties": {"repobilityId": "422d811b3274f0ee", "scanner": "scanner-primary", "fingerprint": "d3a1e78269a05c5b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b582784cbfd5694e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/worker-spawn.test.ts:118"}, "properties": {"repobilityId": "ceb5475f81dad54e", "scanner": "scanner-primary", "fingerprint": "b582784cbfd5694e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3cc1a8fabf81501f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/logger-usage-standards.test.ts:184"}, "properties": {"repobilityId": "dec8d3f7c8eddeef", "scanner": "scanner-primary", "fingerprint": "3cc1a8fabf81501f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5dfe548be6682444", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/install-non-tty.test.ts:62"}, "properties": {"repobilityId": "303f1720471609ff", "scanner": "scanner-primary", "fingerprint": "5dfe548be6682444", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-74ea0fe727072fce", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/integration/chroma-vector-sync.test.ts:73"}, "properties": {"repobilityId": "59b919d3ad0be51f", "scanner": "scanner-primary", "fingerprint": "74ea0fe727072fce", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a3a80be5eb56c1c8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/services/sqlite/schema-repair.test.ts:56"}, "properties": {"repobilityId": "ea7e7e7a6147614b", "scanner": "scanner-primary", "fingerprint": "a3a80be5eb56c1c8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6aa44bfb4c5450a6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/infrastructure/worker-json-status.test.ts:171"}, "properties": {"repobilityId": "8d6bd27494b596b8", "scanner": "scanner-primary", "fingerprint": "6aa44bfb4c5450a6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-75a658e324f36c71", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 tests/infrastructure/version-consistency.test.ts:56"}, "properties": {"repobilityId": "f538c9cf73b679ba", "scanner": "scanner-primary", "fingerprint": "75a658e324f36c71", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-79b0c847a9f52de5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 plugin/ui/viewer-bundle.js:14"}, "properties": {"repobilityId": "1f85ab625d22cfd5", "scanner": "scanner-primary", "fingerprint": "79b0c847a9f52de5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0a18b9076fbfdb49", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 plugin/ui/viewer-bundle.js:9"}, "properties": {"repobilityId": "8e2e78838a17462a", "scanner": "scanner-primary", "fingerprint": "0a18b9076fbfdb49", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-6b3ac2c352beb567", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 plugin/scripts/worker-cli.js:4"}, "properties": {"repobilityId": "349dff8835a2b814", "scanner": "scanner-primary", "fingerprint": "6b3ac2c352beb567", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6a896530fa3d8057", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 plugin/scripts/statusline-counts.js:24"}, "properties": {"repobilityId": "d56838eefd618263", "scanner": "scanner-primary", "fingerprint": "6a896530fa3d8057", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-080138de1160f249", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 plugin/scripts/version-check.js:148"}, "properties": {"repobilityId": "b0669926a3574e51", "scanner": "scanner-primary", "fingerprint": "080138de1160f249", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-09a979b1af56e5a9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 docs/context/agent-sdk-v2-examples.ts:25"}, "properties": {"repobilityId": "d629963421d9f9c8", "scanner": "scanner-primary", "fingerprint": "09a979b1af56e5a9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2fc84aae4a375738", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 ragtime/ragtime.ts:61"}, "properties": {"repobilityId": "cccdaac42a02cfc5", "scanner": "scanner-primary", "fingerprint": "2fc84aae4a375738", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-452a9d9b07a0fe6b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/check-postinstall-allowlist.js:97"}, "properties": {"repobilityId": "2e79f84df1f787ec", "scanner": "scanner-primary", "fingerprint": "452a9d9b07a0fe6b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-31e5b15bbf03d20e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/pr-babysit-status.ts:396"}, "properties": {"repobilityId": "f500315a80691551", "scanner": "scanner-primary", "fingerprint": "31e5b15bbf03d20e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8fb978f11c8e20d8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/check-pending-queue.ts:98"}, "properties": {"repobilityId": "ae1cbfe455294bb0", "scanner": "scanner-primary", "fingerprint": "8fb978f11c8e20d8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b6c12d9071b96f63", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/verify-timestamp-fix.ts:35"}, "properties": {"repobilityId": "fcff0e900d82436c", "scanner": "scanner-primary", "fingerprint": "b6c12d9071b96f63", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ba59d7793452740e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/cwd-remap.ts:62"}, "properties": {"repobilityId": "973772cf60174a0e", "scanner": "scanner-primary", "fingerprint": "ba59d7793452740e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9abb4ae682654134", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/build-worker-binary.js:11"}, "properties": {"repobilityId": "23cafa91fb99b6b5", "scanner": "scanner-primary", "fingerprint": "9abb4ae682654134", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ac13d79a3e4bd99c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/discord-release-notify.js:108"}, "properties": {"repobilityId": "8f66cd5818309594", "scanner": "scanner-primary", "fingerprint": "ac13d79a3e4bd99c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fa17aa748869b0fa", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/investigate-timestamps.ts:21"}, "properties": {"repobilityId": "7e3bea0fcf5a53ef", "scanner": "scanner-primary", "fingerprint": "fa17aa748869b0fa", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4b131c6d1b824c02", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/build-viewer.js:13"}, "properties": {"repobilityId": "5166562a9bdbf5ee", "scanner": "scanner-primary", "fingerprint": "4b131c6d1b824c02", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8aa378ec509543bb", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/export-memories.ts:55"}, "properties": {"repobilityId": "cf8d97694ca0ff08", "scanner": "scanner-primary", "fingerprint": "8aa378ec509543bb", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-656193a6bbc6723f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/publish.js:19"}, "properties": {"repobilityId": "9359b4b151be1b5f", "scanner": "scanner-primary", "fingerprint": "656193a6bbc6723f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-34d3271af28937d8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/clear-pending-queue.ts:18"}, "properties": {"repobilityId": "72f07edcedbc94ed", "scanner": "scanner-primary", "fingerprint": "34d3271af28937d8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-922e0826b3a60c6e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/strip-comments.ts:44"}, "properties": {"repobilityId": "56046d75b7991e70", "scanner": "scanner-primary", "fingerprint": "922e0826b3a60c6e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6a0763e9665c7046", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/validate-timestamp-logic.ts:21"}, "properties": {"repobilityId": "4e82dd4da151a1c6", "scanner": "scanner-primary", "fingerprint": "6a0763e9665c7046", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-97e90945c4f09ac7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/build-hooks.js:53"}, "properties": {"repobilityId": "607712719d1e5a71", "scanner": "scanner-primary", "fingerprint": "97e90945c4f09ac7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-aa081fe08d6f8a24", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/cleanup-duplicates.ts:46"}, "properties": {"repobilityId": "be5275fc242e8a98", "scanner": "scanner-primary", "fingerprint": "aa081fe08d6f8a24", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4a632a5086dd6c34", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-changelog.js:82"}, "properties": {"repobilityId": "b781c6a9ae723e6c", "scanner": "scanner-primary", "fingerprint": "4a632a5086dd6c34", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e7b8d04fdcbda4e5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/fix-corrupted-timestamps.ts:49"}, "properties": {"repobilityId": "74cec3631fb0f7d8", "scanner": "scanner-primary", "fingerprint": "e7b8d04fdcbda4e5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-df28a0c1f76ba4be", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/sync-plugin-manifests.js:98"}, "properties": {"repobilityId": "de1a0e5f3f27a8ca", "scanner": "scanner-primary", "fingerprint": "df28a0c1f76ba4be", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8351558f80913c33", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/regenerate-claude-md.ts:262"}, "properties": {"repobilityId": "1a3d8fc1f222f939", "scanner": "scanner-primary", "fingerprint": "8351558f80913c33", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d7ff5f77ea3d4b13", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/import-memories.ts:16"}, "properties": {"repobilityId": "0529f977e4962b2e", "scanner": "scanner-primary", "fingerprint": "d7ff5f77ea3d4b13", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-13bb79d4454cb6fe", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/translate-readme/examples.ts:11"}, "properties": {"repobilityId": "8ebf6eef737fb6d9", "scanner": "scanner-primary", "fingerprint": "13bb79d4454cb6fe", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b8364ad861952850", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/translate-readme/index.ts:276"}, "properties": {"repobilityId": "d1a07d5a1acaf7e3", "scanner": "scanner-primary", "fingerprint": "b8364ad861952850", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-be4c9f15fd8a5f5d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/translate-readme/cli.ts:21"}, "properties": {"repobilityId": "b841384c58bf7d11", "scanner": "scanner-primary", "fingerprint": "be4c9f15fd8a5f5d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3b9e5d505907a24e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/bug-report/cli.ts:54"}, "properties": {"repobilityId": "3983f6efdf41f0a8", "scanner": "scanner-primary", "fingerprint": "3b9e5d505907a24e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-31697f207f597ead", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/anti-pattern-test/detect-error-handling-antipatterns.ts:454"}, "properties": {"repobilityId": "6d2585e3baad0bc6", "scanner": "scanner-primary", "fingerprint": "31697f207f597ead", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ef84c7a0943c6d08", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/integrations/opencode-plugin/index.ts:188"}, "properties": {"repobilityId": "ae9fddb3f80d6085", "scanner": "scanner-primary", "fingerprint": "ef84c7a0943c6d08", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-045bd430bb8f600c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/npx-cli/index.ts:19"}, "properties": {"repobilityId": "41ee4474ece17d3d", "scanner": "scanner-primary", "fingerprint": "045bd430bb8f600c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-42de3912c40a1088", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/doctor.ts:130"}, "properties": {"repobilityId": "ef719c5763d8b852", "scanner": "scanner-primary", "fingerprint": "42de3912c40a1088", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d04d1528b53ba743", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/runtime.ts:226"}, "properties": {"repobilityId": "622450c6a4a28145", "scanner": "scanner-primary", "fingerprint": "d04d1528b53ba743", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0a7928413dcfd45b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/server-jobs.ts:166"}, "properties": {"repobilityId": "96ac9052e33c7598", "scanner": "scanner-primary", "fingerprint": "0a7928413dcfd45b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8aa9cf08af3156c9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/telemetry.ts:120"}, "properties": {"repobilityId": "e1876ed1d31d4d37", "scanner": "scanner-primary", "fingerprint": "8aa9cf08af3156c9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d410075f0ad2e974", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/server.ts:167"}, "properties": {"repobilityId": "3dfac88ce9d341a0", "scanner": "scanner-primary", "fingerprint": "d410075f0ad2e974", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3cc88ba9aadef973", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/npx-cli/commands/install.ts:85"}, "properties": {"repobilityId": "163e6334010b0fb2", "scanner": "scanner-primary", "fingerprint": "3cc88ba9aadef973", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-69ada56be99db65f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/shared/hook-io.ts:114"}, "properties": {"repobilityId": "96a2bd2a0eb5177f", "scanner": "scanner-primary", "fingerprint": "69ada56be99db65f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b2fce8f996cfa86d", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 src/ui/viewer/components/TerminalPreview.tsx:134"}, "properties": {"repobilityId": "f77d290943b993cb", "scanner": "scanner-primary", "fingerprint": "b2fce8f996cfa86d", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-f12e5024e2c9cdaa", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/ui/viewer/hooks/useSSE.ts:31"}, "properties": {"repobilityId": "3ba81e05c405a53e", "scanner": "scanner-primary", "fingerprint": "f12e5024e2c9cdaa", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-103317486be66818", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server/runtime/ServerBetaService.ts:335"}, "properties": {"repobilityId": "79e34e3dbe6a1d9b", "scanner": "scanner-primary", "fingerprint": "103317486be66818", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fe939c6574187b06", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/worker-service.ts:888"}, "properties": {"repobilityId": "77de84179abc760c", "scanner": "scanner-primary", "fingerprint": "fe939c6574187b06", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-67113b2067ed24e9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/integrations/McpIntegrations.ts:55"}, "properties": {"repobilityId": "e58e3591735922b5", "scanner": "scanner-primary", "fingerprint": "67113b2067ed24e9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-451780b913d271fd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/integrations/OpenClawInstaller.ts:204"}, "properties": {"repobilityId": "afa25695fe1fda3d", "scanner": "scanner-primary", "fingerprint": "451780b913d271fd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5806db39e52ef754", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/integrations/GeminiCliHooksInstaller.ts:159"}, "properties": {"repobilityId": "663771d709650f90", "scanner": "scanner-primary", "fingerprint": "5806db39e52ef754", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4fd993a9a1401074", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/integrations/CursorHooksInstaller.ts:168"}, "properties": {"repobilityId": "f90a45af5851dc6c", "scanner": "scanner-primary", "fingerprint": "4fd993a9a1401074", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9e03ec3ac7e329a7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/integrations/WindsurfHooksInstaller.ts:192"}, "properties": {"repobilityId": "f316fd4833a82f13", "scanner": "scanner-primary", "fingerprint": "9e03ec3ac7e329a7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5e1a49834c0f540c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/integrations/CodexCliInstaller.ts:132"}, "properties": {"repobilityId": "eadf3d3ff8c581ac", "scanner": "scanner-primary", "fingerprint": "5e1a49834c0f540c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-180b0dd6e33ca7a0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/integrations/OpenCodeInstaller.ts:82"}, "properties": {"repobilityId": "0d5ca43c56554970", "scanner": "scanner-primary", "fingerprint": "180b0dd6e33ca7a0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8a7b798ff04db30c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/services/transcripts/cli.ts:15"}, "properties": {"repobilityId": "6cbf0febb2ddb8e4", "scanner": "scanner-primary", "fingerprint": "8a7b798ff04db30c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9bcd3ce6888489c8", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 src/sdk/parser.ts:5"}, "properties": {"repobilityId": "78a70b9f3f817320", "scanner": "scanner-primary", "fingerprint": "9bcd3ce6888489c8", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-b55272acb1588949", "level": "warning", "message": {"text": "Dockerfile runs as root: docker/claude-mem/Dockerfile"}, "properties": {"repobilityId": "a74b596ca697618e", "scanner": "scanner-primary", "fingerprint": "b55272acb1588949", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-ff26f7f8eb4a494b", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:20"}, "properties": {"repobilityId": "27c4301fb8717ddf", "scanner": "scanner-primary", "fingerprint": "ff26f7f8eb4a494b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker/claude-mem/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f691752444e3980c", "level": "error", "message": {"text": "Dockerfile pipes a remote installer into a shell"}, "properties": {"repobilityId": "a35817b83c951603", "scanner": "scanner-primary", "fingerprint": "f691752444e3980c", "layer": "hardware", "severity": "high", "confidence": 1.0, "tags": ["supply-chain", "docker", "remote-installer"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker/claude-mem/Dockerfile"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-df8f08711fe7d0cc", "level": "error", "message": {"text": "Possible secret in docker/e2e/server-beta-e2e.mjs"}, "properties": {"repobilityId": "d64bf5ac48a2e972", "scanner": "scanner-primary", "fingerprint": "df8f08711fe7d0cc", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docker/e2e/server-beta-e2e.mjs"}, "region": {"startLine": 152}}}]}, {"ruleId": "scanner-afcd336fd193744d", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in plugin/.mcp.json:8"}, "properties": {"repobilityId": "0b768cd4b2a55d51", "scanner": "scanner-primary", "fingerprint": "afcd336fd193744d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugin/.mcp.json"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-0c7d809458a1baa6", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in plugin/ui/viewer-bundle.js:9"}, "properties": {"repobilityId": "71655933a5e410d4", "scanner": "scanner-primary", "fingerprint": "0c7d809458a1baa6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugin/ui/viewer-bundle.js"}, "region": {"startLine": 9}}}]}, {"ruleId": "scanner-28c3d21fa4f25068", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in plugin/ui/viewer-bundle.js:8"}, "properties": {"repobilityId": "16bd7841b834e8ec", "scanner": "scanner-primary", "fingerprint": "28c3d21fa4f25068", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugin/ui/viewer-bundle.js"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-bb58c13707ca19c1", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in plugin/scripts/context-generator.cjs:9"}, "properties": {"repobilityId": "4785f1563f6c3f5c", "scanner": "scanner-primary", "fingerprint": "bb58c13707ca19c1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugin/scripts/context-generator.cjs"}, "region": {"startLine": 9}}}]}, {"ruleId": "scanner-a6b467ec8c62c783", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in plugin/scripts/transcript-watcher.cjs:14"}, "properties": {"repobilityId": "96cbe2961976500b", "scanner": "scanner-primary", "fingerprint": "a6b467ec8c62c783", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugin/scripts/transcript-watcher.cjs"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-04432b0429a304db", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in plugin/scripts/bun-runner.js:2"}, "properties": {"repobilityId": "ff81a828e606024f", "scanner": "scanner-primary", "fingerprint": "04432b0429a304db", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugin/scripts/bun-runner.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-a1e4ea2cb19e62fa", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in plugin/scripts/worker-wrapper.cjs:2"}, "properties": {"repobilityId": "b5ce6f3c0d1fadb5", "scanner": "scanner-primary", "fingerprint": "a1e4ea2cb19e62fa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugin/scripts/worker-wrapper.cjs"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-2234b89f09ea6af7", "level": "error", "message": {"text": "Insecure pattern 'new_function_used' in plugin/scripts/mcp-server.cjs:6"}, "properties": {"repobilityId": "292a7f633a1e5851", "scanner": "scanner-primary", "fingerprint": "2234b89f09ea6af7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "new_function_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugin/scripts/mcp-server.cjs"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-179b045a49e51a87", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in plugin/scripts/mcp-server.cjs:82"}, "properties": {"repobilityId": "2e33275673ef6cea", "scanner": "scanner-primary", "fingerprint": "179b045a49e51a87", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugin/scripts/mcp-server.cjs"}, "region": {"startLine": 82}}}]}, {"ruleId": "scanner-40ec39397f4d323c", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in plugin/scripts/version-check.js:2"}, "properties": {"repobilityId": "f89eba71049314d1", "scanner": "scanner-primary", "fingerprint": "40ec39397f4d323c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugin/scripts/version-check.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-93dca1f0332f1112", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in plugin/skills/standup/standup.mjs:45"}, "properties": {"repobilityId": "fd2dd69130fda42a", "scanner": "scanner-primary", "fingerprint": "93dca1f0332f1112", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugin/skills/standup/standup.mjs"}, "region": {"startLine": 45}}}]}, {"ruleId": "scanner-361e9ff65b1de0d8", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/smoke-clean-room.cjs:36"}, "properties": {"repobilityId": "95118888a11df7bd", "scanner": "scanner-primary", "fingerprint": "361e9ff65b1de0d8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/smoke-clean-room.cjs"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-06a89927ae15fd88", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/cwd-remap.ts:7"}, "properties": {"repobilityId": "1f0d5182731d7bc9", "scanner": "scanner-primary", "fingerprint": "06a89927ae15fd88", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/cwd-remap.ts"}, "region": {"startLine": 7}}}]}, {"ruleId": "scanner-ca4651a64d315d3e", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/build-worker-binary.js:3"}, "properties": {"repobilityId": "6cdcfd176631a584", "scanner": "scanner-primary", "fingerprint": "ca4651a64d315d3e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/build-worker-binary.js"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-7334de57b772494a", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/discord-release-notify.js:3"}, "properties": {"repobilityId": "70d34afc31d871b7", "scanner": "scanner-primary", "fingerprint": "7334de57b772494a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/discord-release-notify.js"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-c6121cecc161251c", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/sync-marketplace.cjs:3"}, "properties": {"repobilityId": "06b6ce86aaa757e4", "scanner": "scanner-primary", "fingerprint": "c6121cecc161251c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/sync-marketplace.cjs"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-e31f01f6e10b619d", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/publish.js:3"}, "properties": {"repobilityId": "038f0ff37042529a", "scanner": "scanner-primary", "fingerprint": "e31f01f6e10b619d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/publish.js"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-707d570ade372c31", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/strip-comments.ts:10"}, "properties": {"repobilityId": "851838c5c56a195c", "scanner": "scanner-primary", "fingerprint": "707d570ade372c31", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/strip-comments.ts"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-0f8f20d2d328415f", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/gen-plugin-lockfile.cjs:12"}, "properties": {"repobilityId": "81e8b194ee6165cf", "scanner": "scanner-primary", "fingerprint": "0f8f20d2d328415f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/gen-plugin-lockfile.cjs"}, "region": {"startLine": 12}}}]}, {"ruleId": "scanner-ababbeca7e8218fd", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/generate-changelog.js:3"}, "properties": {"repobilityId": "aaf12f30d4a31aad", "scanner": "scanner-primary", "fingerprint": "ababbeca7e8218fd", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/generate-changelog.js"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-84649ea2014bf783", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/regenerate-claude-md.ts:7"}, "properties": {"repobilityId": "0b233217c04a4745", "scanner": "scanner-primary", "fingerprint": "84649ea2014bf783", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/regenerate-claude-md.ts"}, "region": {"startLine": 7}}}]}, {"ruleId": "scanner-a08b128889e39bbf", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/bug-report/collector.ts:3"}, "properties": {"repobilityId": "45d16ffcfd74079e", "scanner": "scanner-primary", "fingerprint": "a08b128889e39bbf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/bug-report/collector.ts"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-825728f67d415d42", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/bug-report/cli.ts:9"}, "properties": {"repobilityId": "62d7c38829855bf6", "scanner": "scanner-primary", "fingerprint": "825728f67d415d42", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/bug-report/cli.ts"}, "region": {"startLine": 9}}}]}, {"ruleId": "scanner-56bab54c2ea1489e", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/npx-cli/install/setup-runtime.ts:2"}, "properties": {"repobilityId": "9f5a96db216a7001", "scanner": "scanner-primary", "fingerprint": "56bab54c2ea1489e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/npx-cli/install/setup-runtime.ts"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-945e28cafb5f6540", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/npx-cli/install/npm-install-helper.ts:17"}, "properties": {"repobilityId": "105925fd756cfa32", "scanner": "scanner-primary", "fingerprint": "945e28cafb5f6540", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/npx-cli/install/npm-install-helper.ts"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-43ce36cab98062c4", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/npx-cli/commands/doctor.ts:10"}, "properties": {"repobilityId": "ba5a2f54d347d522", "scanner": "scanner-primary", "fingerprint": "43ce36cab98062c4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/npx-cli/commands/doctor.ts"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-e33a5663bc1d356d", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/npx-cli/commands/ide-detection.ts:1"}, "properties": {"repobilityId": "cb224746c10e694b", "scanner": "scanner-primary", "fingerprint": "e33a5663bc1d356d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/npx-cli/commands/ide-detection.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-208ffbbdffbd1afa", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/npx-cli/commands/install.ts:4"}, "properties": {"repobilityId": "3ff31b0e7223a633", "scanner": "scanner-primary", "fingerprint": "208ffbbdffbd1afa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/npx-cli/commands/install.ts"}, "region": {"startLine": 4}}}]}, {"ruleId": "scanner-aefe7a3da76be478", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/npx-cli/utils/bun-resolver.ts:1"}, "properties": {"repobilityId": "a74e72c8a94bd583", "scanner": "scanner-primary", "fingerprint": "aefe7a3da76be478", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/npx-cli/utils/bun-resolver.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ccb8b1ac80e01bbf", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/supervisor/shutdown.ts:1"}, "properties": {"repobilityId": "82196f4148f226b8", "scanner": "scanner-primary", "fingerprint": "ccb8b1ac80e01bbf", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/supervisor/shutdown.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8a6270f027ea5961", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/supervisor/process-registry.ts:1"}, "properties": {"repobilityId": "77f5ce259c839c8f", "scanner": "scanner-primary", "fingerprint": "8a6270f027ea5961", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/supervisor/process-registry.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cc7db34e80899f0a", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/shared/find-claude-executable.ts:25"}, "properties": {"repobilityId": "553b73ae9b0839b0", "scanner": "scanner-primary", "fingerprint": "cc7db34e80899f0a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/shared/find-claude-executable.ts"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-70a4c4a96b7b4667", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/shared/paths.ts:4"}, "properties": {"repobilityId": "6f2ee93833eb8131", "scanner": "scanner-primary", "fingerprint": "70a4c4a96b7b4667", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/shared/paths.ts"}, "region": {"startLine": 4}}}]}, {"ruleId": "scanner-d823a4d375676ef6", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/shared/oauth-token.ts:12"}, "properties": {"repobilityId": "b3753b8abfbc2a72", "scanner": "scanner-primary", "fingerprint": "d823a4d375676ef6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/shared/oauth-token.ts"}, "region": {"startLine": 12}}}]}, {"ruleId": "scanner-2ea4ab324d75eeab", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/shared/spawn.ts:2"}, "properties": {"repobilityId": "3193f8d3a394f91d", "scanner": "scanner-primary", "fingerprint": "2ea4ab324d75eeab", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/shared/spawn.ts"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-fd6addfd7dc21734", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in src/ui/viewer/components/TerminalPreview.tsx:134"}, "properties": {"repobilityId": "325f540ca744ceaf", "scanner": "scanner-primary", "fingerprint": "fd6addfd7dc21734", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/ui/viewer/components/TerminalPreview.tsx"}, "region": {"startLine": 134}}}]}, {"ruleId": "scanner-06586c7a28ade509", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/cli/claude-md-commands.ts:12"}, "properties": {"repobilityId": "f00a3d8e933c770a", "scanner": "scanner-primary", "fingerprint": "06586c7a28ade509", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/cli/claude-md-commands.ts"}, "region": {"startLine": 12}}}]}, {"ruleId": "scanner-addb1bb8fc737b3e", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/utils/project-name.ts:3"}, "properties": {"repobilityId": "75c857637fdaf442", "scanner": "scanner-primary", "fingerprint": "addb1bb8fc737b3e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/utils/project-name.ts"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-3be2d5e86fb672ba", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/server/runtime/ServerBetaService.ts:4"}, "properties": {"repobilityId": "50ccfcc2f161f77f", "scanner": "scanner-primary", "fingerprint": "3be2d5e86fb672ba", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/server/runtime/ServerBetaService.ts"}, "region": {"startLine": 4}}}]}, {"ruleId": "scanner-9e126baaa4b49a08", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/services/worker-service.ts:4"}, "properties": {"repobilityId": "c49a9baa48ca9e5d", "scanner": "scanner-primary", "fingerprint": "9e126baaa4b49a08", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/services/worker-service.ts"}, "region": {"startLine": 4}}}]}, {"ruleId": "scanner-da34a56239d029e6", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/services/integrations/CursorHooksInstaller.ts:5"}, "properties": {"repobilityId": "a0b0d3f1a4cdc044", "scanner": "scanner-primary", "fingerprint": "da34a56239d029e6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/services/integrations/CursorHooksInstaller.ts"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-1d9225734c6370da", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/services/integrations/CodexCliInstaller.ts:3"}, "properties": {"repobilityId": "97fca49ea09bd824", "scanner": "scanner-primary", "fingerprint": "1d9225734c6370da", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/services/integrations/CodexCliInstaller.ts"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-958bebf769bce876", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/services/sync/ChromaMcpManager.ts:4"}, "properties": {"repobilityId": "e1c1ccfcb4400519", "scanner": "scanner-primary", "fingerprint": "958bebf769bce876", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/services/sync/ChromaMcpManager.ts"}, "region": {"startLine": 4}}}]}, {"ruleId": "scanner-30976332e4ae75e9", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/services/worker/BranchManager.ts:2"}, "properties": {"repobilityId": "03d21a6b966a1772", "scanner": "scanner-primary", "fingerprint": "30976332e4ae75e9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/services/worker/BranchManager.ts"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-acc3d3b7da8610f3", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/services/infrastructure/WorktreeAdoption.ts:4"}, "properties": {"repobilityId": "6544ec37a22b01fb", "scanner": "scanner-primary", "fingerprint": "acc3d3b7da8610f3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/services/infrastructure/WorktreeAdoption.ts"}, "region": {"startLine": 4}}}]}, {"ruleId": "scanner-c4f4b22d60744a28", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/services/infrastructure/ProcessManager.ts:5"}, "properties": {"repobilityId": "bebbf1c9639fc874", "scanner": "scanner-primary", "fingerprint": "c4f4b22d60744a28", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/services/infrastructure/ProcessManager.ts"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-9e9d147c9b1bc0b1", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/services/smart-file-read/parser.ts:2"}, "properties": {"repobilityId": "01ce646d21cc66b6", "scanner": "scanner-primary", "fingerprint": "9e9d147c9b1bc0b1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/services/smart-file-read/parser.ts"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-fb15cc829afed787", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/services/sqlite/SchemaRepair.ts:2"}, "properties": {"repobilityId": "d6bf5bf422cbab26", "scanner": "scanner-primary", "fingerprint": "fb15cc829afed787", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/services/sqlite/SchemaRepair.ts"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-ac26db99b82e5132", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/sdk/commit-verification.ts:12"}, "properties": {"repobilityId": "b3d0c4c8f1293a91", "scanner": "scanner-primary", "fingerprint": "ac26db99b82e5132", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/sdk/commit-verification.ts"}, "region": {"startLine": 12}}}]}, {"ruleId": "scanner-fa9b995646930c75", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "6ef9a166bd7f4009", "scanner": "scanner-primary", "fingerprint": "fa9b995646930c75", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/npm-publish.yml"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-0126d0155705b1e7", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "c84a5cab4774a6d5", "scanner": "scanner-primary", "fingerprint": "0126d0155705b1e7", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/convert-feature-requests.yml"}, "region": {"startLine": 28}}}]}, {"ruleId": "scanner-0126d0155705b1e7", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "c84a5cab4774a6d5", "scanner": "scanner-primary", "fingerprint": "0126d0155705b1e7", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/convert-feature-requests.yml"}, "region": {"startLine": 89}}}]}, {"ruleId": "scanner-0126d0155705b1e7", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "c84a5cab4774a6d5", "scanner": "scanner-primary", "fingerprint": "0126d0155705b1e7", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/convert-feature-requests.yml"}, "region": {"startLine": 107}}}]}, {"ruleId": "scanner-6a75cea58ae2d50f", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "9d08bb17c0c7989e", "scanner": "scanner-primary", "fingerprint": "6a75cea58ae2d50f", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/deploy-install-scripts.yml"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-2cb394d1ab970a0a", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b846f663ce8b6cc6", "scanner": "scanner-primary", "fingerprint": "2cb394d1ab970a0a", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/summary.yml"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-2cb394d1ab970a0a", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "126f8427fc785cc7", "scanner": "scanner-primary", "fingerprint": "2cb394d1ab970a0a", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/summary.yml"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "dcb6504096fc20e7", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "dcb6504096fc20e7", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 61}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "dcb6504096fc20e7", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 104}}}]}, {"ruleId": "scanner-de53ac274e5b4ecf", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "69dd0abad9dba1dc", "scanner": "scanner-primary", "fingerprint": "de53ac274e5b4ecf", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/claude.yml"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-de53ac274e5b4ecf", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "8ead6a2c2bfe167b", "scanner": "scanner-primary", "fingerprint": "de53ac274e5b4ecf", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/claude.yml"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-37716d9c0a33ad5c", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "abfb5752158cf655", "scanner": "scanner-primary", "fingerprint": "37716d9c0a33ad5c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/claude.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-96c639bd82f3a20b", "level": "note", "message": {"text": "Very large file: openclaw/install.sh (1653 lines)"}, "properties": {"repobilityId": "34e556d6f79072ae", "scanner": "scanner-primary", "fingerprint": "96c639bd82f3a20b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-269cc0296e8bd3e0", "level": "note", "message": {"text": "Very large file: openclaw/test-install.sh (2086 lines)"}, "properties": {"repobilityId": "de17249483d5979f", "scanner": "scanner-primary", "fingerprint": "269cc0296e8bd3e0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-2c1df7f07e681c25", "level": "note", "message": {"text": "Very large file: plugin/scripts/context-generator.cjs (821 lines)"}, "properties": {"repobilityId": "dea4f977b4056453", "scanner": "scanner-primary", "fingerprint": "2c1df7f07e681c25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-7570b54a2ad2b8b8", "level": "note", "message": {"text": "Very large file: src/npx-cli/commands/install.ts (1915 lines)"}, "properties": {"repobilityId": "a1eedb9b65ccd2f7", "scanner": "scanner-primary", "fingerprint": "7570b54a2ad2b8b8", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-c7f2a6ec64293d34", "level": "note", "message": {"text": "Very large file: src/server/routes/v1/ServerV1PostgresRoutes.ts (1826 lines)"}, "properties": {"repobilityId": "a4a54f2f682e673e", "scanner": "scanner-primary", "fingerprint": "c7f2a6ec64293d34", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-110145e497197eb7", "level": "note", "message": {"text": "Very large file: src/services/worker-service.ts (1449 lines)"}, "properties": {"repobilityId": "739e90550c06fee5", "scanner": "scanner-primary", "fingerprint": "110145e497197eb7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-f62558940b2cbe3f", "level": "note", "message": {"text": "Very large file: src/services/worker/SearchManager.ts (1710 lines)"}, "properties": {"repobilityId": "ece11b07528c9c9c", "scanner": "scanner-primary", "fingerprint": "f62558940b2cbe3f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-46c5b59650ca5c8f", "level": "note", "message": {"text": "Very large file: src/services/sqlite/SessionStore.ts (2705 lines)"}, "properties": {"repobilityId": "3f1b294ce49cdf26", "scanner": "scanner-primary", "fingerprint": "46c5b59650ca5c8f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-b3ed68815bca2f8c", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: package.json"}, "properties": {"repobilityId": "7edae0550c126386", "scanner": "scanner-primary", "fingerprint": "b3ed68815bca2f8c", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b347d884e687248d", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: openclaw/package.json"}, "properties": {"repobilityId": "ebab72171f2e0a9c", "scanner": "scanner-primary", "fingerprint": "b347d884e687248d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "openclaw/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "1230705653744bde", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "4664f01588bc848b", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-9d79c4077342a7d0", "level": "warning", "message": {"text": "Runtime service client appears to use placeholder configuration"}, "properties": {"repobilityId": "96c0b685d25fc652", "scanner": "scanner-primary", "fingerprint": "9d79c4077342a7d0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "runtime-config", "service-client", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "55a1780148d89069", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "271b3766051ac7d3", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "10a42984606fa974", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "b1fe3082c9e2e753", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-a0e868c78da67a3a", "level": "warning", "message": {"text": "Agent instruction contains unpinned remote install: openclaw/SKILL.md"}, "properties": {"repobilityId": "6b47accfcc1648d5", "scanner": "scanner-primary", "fingerprint": "a0e868c78da67a3a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "supply-chain", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "openclaw/SKILL.md"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-bc15c74853dd18b9", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: plugin/.mcp.json"}, "properties": {"repobilityId": "28c831bd0ad754d8", "scanner": "scanner-primary", "fingerprint": "bc15c74853dd18b9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "mcp_config"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugin/.mcp.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f3aa044de6062e73", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: plugin/skills/pathfinder/SKILL.md"}, "properties": {"repobilityId": "fdc2609320d489f3", "scanner": "scanner-primary", "fingerprint": "f3aa044de6062e73", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugin/skills/pathfinder/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-127e3c944484cf01", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: plugin/skills/how-it-works/SKILL.md"}, "properties": {"repobilityId": "65494f6a8f6fe555", "scanner": "scanner-primary", "fingerprint": "127e3c944484cf01", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugin/skills/how-it-works/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6db3880ddae16a15", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/anti-pattern-czar.md"}, "properties": {"repobilityId": "bc545d123ed3fae6", "scanner": "scanner-primary", "fingerprint": "6db3880ddae16a15", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/anti-pattern-czar.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5aabe9b6adc0e8d7", "level": "warning", "message": {"text": "Agent instruction contains unpinned remote install: .claude/plans/animated-installer.md"}, "properties": {"repobilityId": "2f659f68a699081b", "scanner": "scanner-primary", "fingerprint": "5aabe9b6adc0e8d7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "supply-chain", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/plans/animated-installer.md"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-f0e2dffdfc5f0223", "level": "none", "message": {"text": "Commented-code block (5 lines) in openclaw/src/index.ts:747"}, "properties": {"repobilityId": "bf7f52ca6776b5b4", "scanner": "scanner-primary", "fingerprint": "f0e2dffdfc5f0223", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c25dde1b13878e31", "level": "none", "message": {"text": "Commented-code block (8 lines) in docker/e2e/server-beta-e2e.mjs:4"}, "properties": {"repobilityId": "e3d3a3494a86cb37", "scanner": "scanner-primary", "fingerprint": "c25dde1b13878e31", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8b2f4bf0896b55e5", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/write-json-file-atomic.test.ts:78"}, "properties": {"repobilityId": "b1419d79196d27c0", "scanner": "scanner-primary", "fingerprint": "8b2f4bf0896b55e5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3ee0361e47a8faff", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/uninstall-clear-auto-memory.test.ts:48"}, "properties": {"repobilityId": "75d417ba470e237c", "scanner": "scanner-primary", "fingerprint": "3ee0361e47a8faff", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c2e46144b716cfb8", "level": "none", "message": {"text": "Commented-code block (7 lines) in tests/plugin-version-check-ensure-deps.test.ts:78"}, "properties": {"repobilityId": "a260714b3f10db92", "scanner": "scanner-primary", "fingerprint": "c2e46144b716cfb8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1efd043401ff3e53", "level": "note", "message": {"text": "Legacy-named symbol `name_v2` in tests/cursor-hooks-json-utils.test.ts:128"}, "properties": {"repobilityId": "a42c93f3124e0f10", "scanner": "scanner-primary", "fingerprint": "1efd043401ff3e53", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-093b441a275fe30f", "level": "note", "message": {"text": "Legacy-named symbol `project_v2` in tests/cursor-registry.test.ts:97"}, "properties": {"repobilityId": "79c5613cdbd523f3", "scanner": "scanner-primary", "fingerprint": "093b441a275fe30f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-0c1b6770cc06fd5e", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/env-isolation.test.ts:130"}, "properties": {"repobilityId": "cac3a828b280d9a4", "scanner": "scanner-primary", "fingerprint": "0c1b6770cc06fd5e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-04d00a062f286443", "level": "note", "message": {"text": "Legacy-named symbol `name_v2` in tests/cursor-mcp-config.test.ts:212"}, "properties": {"repobilityId": "7077d28a038421e9", "scanner": "scanner-primary", "fingerprint": "04d00a062f286443", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-b8aa28cd03f2cff4", "level": "note", "message": {"text": "Legacy-named symbol `project_v2` in tests/integration/chroma-vector-sync.test.ts:215"}, "properties": {"repobilityId": "1abb5d0a7c712ef5", "scanner": "scanner-primary", "fingerprint": "b8aa28cd03f2cff4", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-4c1229f0e85d4c3b", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/shared/timeline-formatting.test.ts:3"}, "properties": {"repobilityId": "9a202b714a12ef82", "scanner": "scanner-primary", "fingerprint": "4c1229f0e85d4c3b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0c748612a416c4d5", "level": "none", "message": {"text": "Commented-code block (10 lines) in tests/shared/worker-utils-timeout.test.ts:7"}, "properties": {"repobilityId": "7d980140ff2c85dd", "scanner": "scanner-primary", "fingerprint": "0c748612a416c4d5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f7ec83db073c8b37", "level": "none", "message": {"text": "Commented-code block (7 lines) in tests/shared/worker-utils-version-recycle.test.ts:41"}, "properties": {"repobilityId": "fccde5359496d819", "scanner": "scanner-primary", "fingerprint": "f7ec83db073c8b37", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8765dd1c6804bc86", "level": "none", "message": {"text": "Commented-code block (10 lines) in tests/shared/worker-spawn-gate.test.ts:6"}, "properties": {"repobilityId": "a0942c1114bec806", "scanner": "scanner-primary", "fingerprint": "8765dd1c6804bc86", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9d7cb0fd15421146", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/shared/worker-utils-recycle-successor.test.ts:13"}, "properties": {"repobilityId": "fe86a2ce5ee2820f", "scanner": "scanner-primary", "fingerprint": "9d7cb0fd15421146", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ecfb0ff1c74cdf1c", "level": "none", "message": {"text": "Commented-code block (7 lines) in tests/shared/settings-defaults-manager.test.ts:18"}, "properties": {"repobilityId": "ae39470bb4a7fc2b", "scanner": "scanner-primary", "fingerprint": "ecfb0ff1c74cdf1c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-16dd5da9f0cef4ce", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/cli/hook-stream-discipline.test.ts:14"}, "properties": {"repobilityId": "925fc753df701570", "scanner": "scanner-primary", "fingerprint": "16dd5da9f0cef4ce", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-83c0b5c04e718eda", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/cli/hook-io.test.ts:13"}, "properties": {"repobilityId": "9a71f99421625938", "scanner": "scanner-primary", "fingerprint": "83c0b5c04e718eda", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c393d35a3e841628", "level": "note", "message": {"text": "Legacy-named symbol `file_v2` in tests/utils/logger-format-tool.test.ts:354"}, "properties": {"repobilityId": "04fe8cb04e4d75d5", "scanner": "scanner-primary", "fingerprint": "c393d35a3e841628", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-a5b41bab8f882bc6", "level": "note", "message": {"text": "Legacy-named symbol `nOld` in tests/utils/claude-md-utils.test.ts:82"}, "properties": {"repobilityId": "b2bdf08ee9307693", "scanner": "scanner-primary", "fingerprint": "a5b41bab8f882bc6", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-47304d77d852a58a", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/utils/claude-md-utils.test.ts:6"}, "properties": {"repobilityId": "b7c15edaef745edf", "scanner": "scanner-primary", "fingerprint": "47304d77d852a58a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2e4fde7f23813d9b", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/worker/summary-commit-verification.test.ts:11"}, "properties": {"repobilityId": "10f3d8991727d775", "scanner": "scanner-primary", "fingerprint": "2e4fde7f23813d9b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-eeedd9178f3a34d5", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/worker/poison-respawn.test.ts:4"}, "properties": {"repobilityId": "af21a42c62a52a2a", "scanner": "scanner-primary", "fingerprint": "eeedd9178f3a34d5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8b2ae86d893d2bde", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/servers/mcp-server-name-safety.test.ts:1"}, "properties": {"repobilityId": "4f5b6be1b0667ff0", "scanner": "scanner-primary", "fingerprint": "8b2ae86d893d2bde", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bdbfd4b993f1d3ea", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/hooks/runtime-selector.test.ts:108"}, "properties": {"repobilityId": "cc6e39d4373e4915", "scanner": "scanner-primary", "fingerprint": "bdbfd4b993f1d3ea", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-82adb524cb96c64b", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/server/server-beta-service.test.ts:265"}, "properties": {"repobilityId": "eafeccd507779a25", "scanner": "scanner-primary", "fingerprint": "82adb524cb96c64b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9382073e6a22fd95", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/server/server-viewer-routes.test.ts:3"}, "properties": {"repobilityId": "33fc7756d9482a01", "scanner": "scanner-primary", "fingerprint": "9382073e6a22fd95", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2dd5ed2bc1f12dd5", "level": "none", "message": {"text": "Commented-code block (8 lines) in tests/server/server-runtime-smoke.test.ts:5"}, "properties": {"repobilityId": "9d2964c1cb4d2e09", "scanner": "scanner-primary", "fingerprint": "2dd5ed2bc1f12dd5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-42d0bdb4f38fc8b6", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/server/generation/process-generated-response.test.ts:167"}, "properties": {"repobilityId": "9c88b4bbba788801", "scanner": "scanner-primary", "fingerprint": "42d0bdb4f38fc8b6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e08c3ed85894db6d", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/services/worker-shutdown-sequence.test.ts:4"}, "properties": {"repobilityId": "4499aab25955100f", "scanner": "scanner-primary", "fingerprint": "e08c3ed85894db6d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b6ae1d66129c2165", "level": "none", "message": {"text": "Commented-code block (7 lines) in tests/services/integrations/spawn-contract-windows.test.ts:5"}, "properties": {"repobilityId": "80724861a940caee", "scanner": "scanner-primary", "fingerprint": "b6ae1d66129c2165", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cd1905a8d98aebed", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/services/sync/chroma-mcp-manager-singleton.test.ts:20"}, "properties": {"repobilityId": "0a7947eb7f203258", "scanner": "scanner-primary", "fingerprint": "cd1905a8d98aebed", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4d3da672d74fdab9", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/services/sqlite/schema-repair.test.ts:30"}, "properties": {"repobilityId": "cca013d25c7ccc7d", "scanner": "scanner-primary", "fingerprint": "4d3da672d74fdab9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4daf94406a63923b", "level": "none", "message": {"text": "Commented-code block (7 lines) in tests/services/sqlite/observations-by-file-path-candidates.test.ts:1"}, "properties": {"repobilityId": "c91dc1b5d47a7b82", "scanner": "scanner-primary", "fingerprint": "4daf94406a63923b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-06541c70e5763b3d", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/context/include-last-message-dot-path.test.ts:1"}, "properties": {"repobilityId": "d12cdfd71b6f6d31", "scanner": "scanner-primary", "fingerprint": "06541c70e5763b3d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7dc5f80a038f8ebe", "level": "none", "message": {"text": "Commented-code block (8 lines) in tests/infrastructure/graceful-shutdown.test.ts:14"}, "properties": {"repobilityId": "129fe4670f3f69b8", "scanner": "scanner-primary", "fingerprint": "7dc5f80a038f8ebe", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5fdc0d4bc548ac68", "level": "none", "message": {"text": "Commented-code block (8 lines) in tests/infrastructure/process-manager.test.ts:7"}, "properties": {"repobilityId": "b873b8c877b1af49", "scanner": "scanner-primary", "fingerprint": "5fdc0d4bc548ac68", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f2610baf5f76ffe5", "level": "none", "message": {"text": "Commented-code block (6 lines) in tests/infrastructure/cleanup-v12_4_3.test.ts:166"}, "properties": {"repobilityId": "f233f8eafc6cc358", "scanner": "scanner-primary", "fingerprint": "f2610baf5f76ffe5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-11c8a47ea468206c", "level": "none", "message": {"text": "Commented-code block (5 lines) in tests/sdk/parser.test.ts:215"}, "properties": {"repobilityId": "f3a28247eadaf49c", "scanner": "scanner-primary", "fingerprint": "11c8a47ea468206c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-796042bc3475f9fd", "level": "note", "message": {"text": "Legacy-named symbol `unstable_legacy` in plugin/ui/viewer-bundle.js:8"}, "properties": {"repobilityId": "26e15c2081653991", "scanner": "scanner-primary", "fingerprint": "796042bc3475f9fd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-404a8d7de736166e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 plugin/ui/viewer-bundle.js:11"}, "properties": {"repobilityId": "ac2cc951f438c666", "scanner": "scanner-primary", "fingerprint": "404a8d7de736166e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-bdbe75f7c1cb104b", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 plugin/scripts/transcript-watcher.cjs:14"}, "properties": {"repobilityId": "454989ac502215de", "scanner": "scanner-primary", "fingerprint": "bdbe75f7c1cb104b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-1b3472c4f544f256", "level": "none", "message": {"text": "Commented-code block (8 lines) in plugin/scripts/bun-runner.js:190"}, "properties": {"repobilityId": "4694de914e4160a7", "scanner": "scanner-primary", "fingerprint": "1b3472c4f544f256", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d5c5fc1adb82dd11", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 plugin/scripts/mcp-server.cjs:82"}, "properties": {"repobilityId": "68483ec566667463", "scanner": "scanner-primary", "fingerprint": "d5c5fc1adb82dd11", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-7167c2113925fc3b", "level": "none", "message": {"text": "Commented-code block (8 lines) in plugin/scripts/version-check.js:45"}, "properties": {"repobilityId": "0998351911f1b353", "scanner": "scanner-primary", "fingerprint": "7167c2113925fc3b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-83a6e41064bf8693", "level": "none", "message": {"text": "Commented-code block (5 lines) in plugin/skills/standup/standup.mjs:4"}, "properties": {"repobilityId": "2390afcc32dc0ac2", "scanner": "scanner-primary", "fingerprint": "83a6e41064bf8693", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2eb675dbb56359ff", "level": "none", "message": {"text": "Commented-code block (8 lines) in scripts/smoke-clean-room.cjs:4"}, "properties": {"repobilityId": "22652f67ca2157b9", "scanner": "scanner-primary", "fingerprint": "2eb675dbb56359ff", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-01ee2eb56ba9766f", "level": "none", "message": {"text": "Commented-code block (7 lines) in scripts/check-postinstall-allowlist.js:8"}, "properties": {"repobilityId": "b05470f182554326", "scanner": "scanner-primary", "fingerprint": "01ee2eb56ba9766f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8bf21c50d8cca312", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/discord-release-notify.js:84"}, "properties": {"repobilityId": "9d49055bb64f2ef0", "scanner": "scanner-primary", "fingerprint": "8bf21c50d8cca312", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-4a7ef17866ae5444", "level": "none", "message": {"text": "Commented-code block (7 lines) in scripts/build-hooks.js:300"}, "properties": {"repobilityId": "10739403d2114458", "scanner": "scanner-primary", "fingerprint": "4a7ef17866ae5444", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9cb3a73ea3d776f0", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/gen-plugin-lockfile.cjs:3"}, "properties": {"repobilityId": "beb426eff4f53966", "scanner": "scanner-primary", "fingerprint": "9cb3a73ea3d776f0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2ca093964d6d7cd5", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/import-memories.ts:39"}, "properties": {"repobilityId": "df7233e4caf0d523", "scanner": "scanner-primary", "fingerprint": "2ca093964d6d7cd5", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-514c6eff3a8fb74f", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/npx-cli/install/setup-runtime.ts:249"}, "properties": {"repobilityId": "94e38b5c0decd640", "scanner": "scanner-primary", "fingerprint": "514c6eff3a8fb74f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2af68b2ce06ceedd", "level": "none", "message": {"text": "Commented-code block (13 lines) in src/npx-cli/commands/uninstall.ts:138"}, "properties": {"repobilityId": "cdb07241036a57f6", "scanner": "scanner-primary", "fingerprint": "2af68b2ce06ceedd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-337e33f0ca9bd835", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/npx-cli/commands/server-jobs.ts:6"}, "properties": {"repobilityId": "2ad4bb2949527272", "scanner": "scanner-primary", "fingerprint": "337e33f0ca9bd835", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-469511d33d217240", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/npx-cli/commands/server-runtime-setup.ts:6"}, "properties": {"repobilityId": "aac6f00193967099", "scanner": "scanner-primary", "fingerprint": "469511d33d217240", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-61d80adde890b087", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/npx-cli/commands/install.ts:856"}, "properties": {"repobilityId": "9caa2258ff8aa211", "scanner": "scanner-primary", "fingerprint": "61d80adde890b087", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6a1f7650520b76bd", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/supervisor/shutdown.ts:161"}, "properties": {"repobilityId": "669bebfdbf11ad1d", "scanner": "scanner-primary", "fingerprint": "6a1f7650520b76bd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b82299474636506d", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/supervisor/env-sanitizer.ts:1"}, "properties": {"repobilityId": "3ae3b949c81b6b2e", "scanner": "scanner-primary", "fingerprint": "b82299474636506d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-09d04d2361698541", "level": "note", "message": {"text": "Legacy-named symbol `skippedTooOld` in src/shared/find-claude-executable.ts:358"}, "properties": {"repobilityId": "44b32f05458a8d82", "scanner": "scanner-primary", "fingerprint": "09d04d2361698541", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-1925d89321a87768", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/shared/worker-spawn-gate.ts:74"}, "properties": {"repobilityId": "383b544560eeeecf", "scanner": "scanner-primary", "fingerprint": "1925d89321a87768", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-abe78e332a3d00d2", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/shared/worker-utils.ts:340"}, "properties": {"repobilityId": "2b9cf66540505562", "scanner": "scanner-primary", "fingerprint": "abe78e332a3d00d2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-57215af88f934b86", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/shared/worker-utils.ts:63"}, "properties": {"repobilityId": "20efd914c5ef8c9f", "scanner": "scanner-primary", "fingerprint": "57215af88f934b86", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f7ed388111f780c8", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/shared/oauth-token.ts:113"}, "properties": {"repobilityId": "f9cfaa174af9c070", "scanner": "scanner-primary", "fingerprint": "f7ed388111f780c8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-546834d0d266976f", "level": "none", "message": {"text": "Commented-code block (11 lines) in src/shared/EnvManager.ts:35"}, "properties": {"repobilityId": "95f7022192ae5095", "scanner": "scanner-primary", "fingerprint": "546834d0d266976f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-94f935fda430bb6e", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/shared/transcript-parser.ts:115"}, "properties": {"repobilityId": "0f84ab9483a8f8f5", "scanner": "scanner-primary", "fingerprint": "94f935fda430bb6e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-485c896939570a9a", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/ui/viewer/utils/api.ts:2"}, "properties": {"repobilityId": "b6e5782e74780940", "scanner": "scanner-primary", "fingerprint": "485c896939570a9a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-525e50a3401fbca8", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/cli/hook-command.ts:91"}, "properties": {"repobilityId": "0fcfa6af034f0251", "scanner": "scanner-primary", "fingerprint": "525e50a3401fbca8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f6a6cc9f8a2a53b0", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/cli/handlers/context.ts:1"}, "properties": {"repobilityId": "8dcffe49fa333e0b", "scanner": "scanner-primary", "fingerprint": "f6a6cc9f8a2a53b0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-95463298cfe382be", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/cli/handlers/file-context.ts:210"}, "properties": {"repobilityId": "a3ac15ed3f9eb032", "scanner": "scanner-primary", "fingerprint": "95463298cfe382be", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-192248fcafcd097e", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/utils/bmp-safe.ts:3"}, "properties": {"repobilityId": "3c68e3acfb108dc7", "scanner": "scanner-primary", "fingerprint": "192248fcafcd097e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f112c7f527d4de4f", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/servers/mcp-server.ts:52"}, "properties": {"repobilityId": "10a87d360cff4517", "scanner": "scanner-primary", "fingerprint": "f112c7f527d4de4f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-84d177c41ec30e79", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/servers/mcp-server.ts:516"}, "properties": {"repobilityId": "2a3a809b50a1170f", "scanner": "scanner-primary", "fingerprint": "84d177c41ec30e79", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e89fb488f0d8e450", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/server/auth/sqlite-api-key-service.ts:36"}, "properties": {"repobilityId": "9b5c4b4ec2a7e7aa", "scanner": "scanner-primary", "fingerprint": "e89fb488f0d8e450", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e5c9c38d6d66b3b3", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/server/middleware/request-id.ts:6"}, "properties": {"repobilityId": "27e9699fe92bd464", "scanner": "scanner-primary", "fingerprint": "e5c9c38d6d66b3b3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2572100d504a42d2", "level": "none", "message": {"text": "Commented-code block (9 lines) in src/server/compat/SessionsObservationsAdapter.ts:10"}, "properties": {"repobilityId": "feb341ce53c208e8", "scanner": "scanner-primary", "fingerprint": "2572100d504a42d2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-29a5b98b8dc166e7", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/server/routes/v1/ServerV1PostgresRoutes.ts:134"}, "properties": {"repobilityId": "ad245cde3bbcc467", "scanner": "scanner-primary", "fingerprint": "29a5b98b8dc166e7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-758da56b390c4c77", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/server/routes/v1/ServerV1Routes.ts:185"}, "properties": {"repobilityId": "e074a62c9887f184", "scanner": "scanner-primary", "fingerprint": "758da56b390c4c77", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3b3dd49ae03aa4f5", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/server/queue/queue-health-types.ts:3"}, "properties": {"repobilityId": "fe27581c28b48220", "scanner": "scanner-primary", "fingerprint": "3b3dd49ae03aa4f5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-da260df88fc2e22b", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/server/runtime/ServerBetaService.ts:140"}, "properties": {"repobilityId": "97a6adef6fe0dc55", "scanner": "scanner-primary", "fingerprint": "da260df88fc2e22b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c680c0f72e20473a", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/server/runtime/ServerViewerRoutes.ts:5"}, "properties": {"repobilityId": "1d705f03f67bf136", "scanner": "scanner-primary", "fingerprint": "c680c0f72e20473a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a45265c9f93f224a", "level": "none", "message": {"text": "Commented-code block (12 lines) in src/server/runtime/SessionGenerationPolicy.ts:17"}, "properties": {"repobilityId": "547a1a8de11f39c2", "scanner": "scanner-primary", "fingerprint": "a45265c9f93f224a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a5d36ca90e590da7", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/server/runtime/ActiveServerBetaGenerationWorkerManager.ts:16"}, "properties": {"repobilityId": "5ce1c701fafe0973", "scanner": "scanner-primary", "fingerprint": "a5d36ca90e590da7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-18f1aee886099835", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/server/runtime/ServerSessionRuntimeRepository.ts:12"}, "properties": {"repobilityId": "eaf0cf9d5c11bf6e", "scanner": "scanner-primary", "fingerprint": "18f1aee886099835", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0b1560828b1339b4", "level": "none", "message": {"text": "Commented-code block (10 lines) in src/server/runtime/create-server-beta-service.ts:46"}, "properties": {"repobilityId": "b5262a3ca63fceea", "scanner": "scanner-primary", "fingerprint": "0b1560828b1339b4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-90a71d088308db4e", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/server/generation/processGeneratedResponse.ts:27"}, "properties": {"repobilityId": "f2032b9d52bffc09", "scanner": "scanner-primary", "fingerprint": "90a71d088308db4e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8800cff34f01ef43", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/server/generation/ProviderObservationGenerator.ts:78"}, "properties": {"repobilityId": "3534170397746a7a", "scanner": "scanner-primary", "fingerprint": "8800cff34f01ef43", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6b0e3aecc6473890", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/server/generation/providers/ClaudeObservationProvider.ts:17"}, "properties": {"repobilityId": "eba410ebb3619982", "scanner": "scanner-primary", "fingerprint": "6b0e3aecc6473890", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8973ab51cc8a0ad6", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/server/generation/providers/shared/prompt-builder.ts:9"}, "properties": {"repobilityId": "25dfe3b6811aa850", "scanner": "scanner-primary", "fingerprint": "8973ab51cc8a0ad6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-cdd616d790f7b3ec", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/server/services/IngestEventsService.ts:3"}, "properties": {"repobilityId": "aae848daebb1664c", "scanner": "scanner-primary", "fingerprint": "cdd616d790f7b3ec", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-872ae5e33498a888", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/server/services/EndSessionService.ts:3"}, "properties": {"repobilityId": "747625ac2e687352", "scanner": "scanner-primary", "fingerprint": "872ae5e33498a888", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c3d9bc649f6a6b00", "level": "none", "message": {"text": "Commented-code block (8 lines) in src/server/jobs/ServerJobQueue.ts:21"}, "properties": {"repobilityId": "7ebaf22349e8d132", "scanner": "scanner-primary", "fingerprint": "c3d9bc649f6a6b00", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-23435e8fe9d6a9ee", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/server/jobs/outbox.ts:128"}, "properties": {"repobilityId": "a7586e4edbdd24a1", "scanner": "scanner-primary", "fingerprint": "23435e8fe9d6a9ee", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-706f6d12fa245d3b", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/server/jobs/job-id.ts:14"}, "properties": {"repobilityId": "9a17f3c9e6318c57", "scanner": "scanner-primary", "fingerprint": "706f6d12fa245d3b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0d4b17f4a4766cea", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/server/jobs/types.ts:80"}, "properties": {"repobilityId": "a35286579e0a576c", "scanner": "scanner-primary", "fingerprint": "0d4b17f4a4766cea", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1d81daa8f56ebb14", "level": "none", "message": {"text": "Commented-code block (9 lines) in src/services/worker-spawner.ts:131"}, "properties": {"repobilityId": "45e6a84381bf20c7", "scanner": "scanner-primary", "fingerprint": "1d81daa8f56ebb14", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1a29f8ad62f15c23", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/services/worker-shutdown.ts:124"}, "properties": {"repobilityId": "36bbb163cc2c8a52", "scanner": "scanner-primary", "fingerprint": "1a29f8ad62f15c23", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b9879b5a556d735e", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/worker-service.ts:130"}, "properties": {"repobilityId": "32dd28ed4ed389df", "scanner": "scanner-primary", "fingerprint": "b9879b5a556d735e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-96bcf90385172619", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/integrations/WindsurfHooksInstaller.ts:296"}, "properties": {"repobilityId": "9864a1cd07ea8522", "scanner": "scanner-primary", "fingerprint": "96bcf90385172619", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-64483cdb78cea935", "level": "note", "message": {"text": "Legacy-named symbol `nLegacy` in src/services/integrations/CodexCliInstaller.ts:450"}, "properties": {"repobilityId": "7e6e109077ba4d9e", "scanner": "scanner-primary", "fingerprint": "64483cdb78cea935", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-85f25d916056be66", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/integrations/TelegramNotifier.ts:50"}, "properties": {"repobilityId": "aa93a84910cf7a85", "scanner": "scanner-primary", "fingerprint": "85f25d916056be66", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-669335f3d9d145c9", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/integrations/OpenCodeInstaller.ts:198"}, "properties": {"repobilityId": "b9929dfda8de7500", "scanner": "scanner-primary", "fingerprint": "669335f3d9d145c9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0361ef211aa4d446", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/sync/ChromaMcpManager.ts:28"}, "properties": {"repobilityId": "92692c3a5edd9b9e", "scanner": "scanner-primary", "fingerprint": "0361ef211aa4d446", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5198c83d5cf2cc8f", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/sync/ChromaSync.ts:343"}, "properties": {"repobilityId": "097561f209c2f4bc", "scanner": "scanner-primary", "fingerprint": "5198c83d5cf2cc8f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f6f811e71f41c4e6", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/services/worker/ClaudeProvider.ts:107"}, "properties": {"repobilityId": "4ac65981fc3baa6a", "scanner": "scanner-primary", "fingerprint": "f6f811e71f41c4e6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-947d0063f45b54d2", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/worker/GeminiProvider.ts:43"}, "properties": {"repobilityId": "a57edc443cff4ad8", "scanner": "scanner-primary", "fingerprint": "947d0063f45b54d2", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-8aace4981768ebfa", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/worker/OpenRouterProvider.ts:606"}, "properties": {"repobilityId": "e1e9ceff6cdb22d1", "scanner": "scanner-primary", "fingerprint": "8aace4981768ebfa", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-07096907d97baa61", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/worker/OpenRouterProvider.ts:52"}, "properties": {"repobilityId": "8f084171f718d884", "scanner": "scanner-primary", "fingerprint": "07096907d97baa61", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-025f49b01ee91c28", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/worker/http/routes/SearchRoutes.ts:37"}, "properties": {"repobilityId": "dbf415667693d017", "scanner": "scanner-primary", "fingerprint": "025f49b01ee91c28", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b25bd7ed1dfe6d72", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/services/worker/agents/ResponseProcessor.ts:127"}, "properties": {"repobilityId": "eb365a6c1357c1ab", "scanner": "scanner-primary", "fingerprint": "b25bd7ed1dfe6d72", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4f073d7349a708d2", "level": "none", "message": {"text": "Commented-code block (10 lines) in src/services/hooks/server-beta-bootstrap.ts:9"}, "properties": {"repobilityId": "14e283be4f3828ea", "scanner": "scanner-primary", "fingerprint": "4f073d7349a708d2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-78f1a4bef2027b15", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/services/hooks/server-beta-client.ts:281"}, "properties": {"repobilityId": "a891804f076f59e2", "scanner": "scanner-primary", "fingerprint": "78f1a4bef2027b15", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8cdf04e27af17dc0", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/server/Server.ts:100"}, "properties": {"repobilityId": "e5b5ec076c221583", "scanner": "scanner-primary", "fingerprint": "8cdf04e27af17dc0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-45c582b0b04393ff", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/context/ObservationCompiler.ts:178"}, "properties": {"repobilityId": "c490f07a4a6aa997", "scanner": "scanner-primary", "fingerprint": "45c582b0b04393ff", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-117a0eed7a782edf", "level": "none", "message": {"text": "Commented-code block (11 lines) in src/services/infrastructure/CleanupV12_4_3.ts:119"}, "properties": {"repobilityId": "6d38a2c7a72c5fa4", "scanner": "scanner-primary", "fingerprint": "117a0eed7a782edf", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-29d78da04f8d9c7d", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/telemetry/scrub.ts:89"}, "properties": {"repobilityId": "1dbb1b42f6f5cbd2", "scanner": "scanner-primary", "fingerprint": "29d78da04f8d9c7d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8400bd8af953896f", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/services/telemetry/cli-telemetry.ts:60"}, "properties": {"repobilityId": "434e15ba657b0d66", "scanner": "scanner-primary", "fingerprint": "8400bd8af953896f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e9c2c81dd7f5b4dd", "level": "none", "message": {"text": "Commented-code block (8 lines) in src/services/telemetry/telemetry.ts:37"}, "properties": {"repobilityId": "cf365cf464655bed", "scanner": "scanner-primary", "fingerprint": "e9c2c81dd7f5b4dd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7e29a31a3d8c9742", "level": "none", "message": {"text": "Commented-code block (8 lines) in src/services/telemetry/backfill.ts:320"}, "properties": {"repobilityId": "c8f5569c58057d28", "scanner": "scanner-primary", "fingerprint": "7e29a31a3d8c9742", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-374fd24f1e2c7a24", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/services/sqlite/SchemaRepair.ts:71"}, "properties": {"repobilityId": "f57696b96cadcfb1", "scanner": "scanner-primary", "fingerprint": "374fd24f1e2c7a24", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d06ee8ed0686e389", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/services/sqlite/SessionSearch.ts:163"}, "properties": {"repobilityId": "8fac80edd89de48b", "scanner": "scanner-primary", "fingerprint": "d06ee8ed0686e389", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bf8fcf6f79550991", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/services/sqlite/observations/get.ts:107"}, "properties": {"repobilityId": "651a7b5791dc0d36", "scanner": "scanner-primary", "fingerprint": "bf8fcf6f79550991", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-dfbb10ee7d66bbd5", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/sdk/parser.ts:5"}, "properties": {"repobilityId": "cbb03902f17648d7", "scanner": "scanner-primary", "fingerprint": "dfbb10ee7d66bbd5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-614d7fa8d267d78c", "level": "none", "message": {"text": "Commented-code block (7 lines) in src/sdk/commit-verification.ts:76"}, "properties": {"repobilityId": "d014b23792f0a7cf", "scanner": "scanner-primary", "fingerprint": "614d7fa8d267d78c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e4cd095d954d6a98", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/sdk/prompts.ts:81"}, "properties": {"repobilityId": "34fb2b526577c2b0", "scanner": "scanner-primary", "fingerprint": "e4cd095d954d6a98", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ce4152c6fb4c4e3e", "level": "note", "message": {"text": "Legacy-named symbol `idx_memory_sources_legacy` in src/storage/sqlite/schema.ts:199"}, "properties": {"repobilityId": "252beeb6a032a4c6", "scanner": "scanner-primary", "fingerprint": "ce4152c6fb4c4e3e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "dbe2767d74256729", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-8fa45e022d08be07", "level": "error", "message": {"text": "Dangling fetch: GET https://api.github.com/repos/${e}/${t} (plugin/ui/viewer-bundle.js:11)"}, "properties": {"repobilityId": "55b810955e1a8ae1", "scanner": "scanner-primary", "fingerprint": "8fa45e022d08be07", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-09336c754d26223a", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${t}${e} (plugin/scripts/transcript-watcher.cjs:16)"}, "properties": {"repobilityId": "c9f586f8b3535178", "scanner": "scanner-primary", "fingerprint": "09336c754d26223a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-17f28e4908e1457e", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${t}/api/admin/shutdown (plugin/scripts/worker-cli.js:5)"}, "properties": {"repobilityId": "c9a6e74146823e8d", "scanner": "scanner-primary", "fingerprint": "17f28e4908e1457e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-87812c38c62affbd", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${t}/api/health (plugin/scripts/worker-cli.js:5)"}, "properties": {"repobilityId": "0093e1f995d8c1ea", "scanner": "scanner-primary", "fingerprint": "87812c38c62affbd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-60e6b4a98b07bc49", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${e}/api/readiness (plugin/scripts/worker-cli.js:12)"}, "properties": {"repobilityId": "bd6444c9f0bd810f", "scanner": "scanner-primary", "fingerprint": "60e6b4a98b07bc49", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-402f1cb91e6e372a", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${t}${e} (plugin/scripts/mcp-server.cjs:82)"}, "properties": {"repobilityId": "7df96214150f88e6", "scanner": "scanner-primary", "fingerprint": "402f1cb91e6e372a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-2fd9ef3af401fb28", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${t}/api/health (plugin/scripts/mcp-server.cjs:82)"}, "properties": {"repobilityId": "9ef98f34ff8414c7", "scanner": "scanner-primary", "fingerprint": "2fd9ef3af401fb28", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-2e37e92468637b43", "level": "error", "message": {"text": "Dangling fetch: POST https://api.telegram.org/bot${botToken}/sendMessage (openclaw/src/index.ts:468)"}, "properties": {"repobilityId": "b9567e40c41f2b74", "scanner": "scanner-primary", "fingerprint": "2e37e92468637b43", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-6f7f5e356e9cb943", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/api/health (tests/worker-spawn.test.ts:23)"}, "properties": {"repobilityId": "3fe843a8b61507c3", "scanner": "scanner-primary", "fingerprint": "6f7f5e356e9cb943", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9bbd1f3fbe2cddfa", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:75)"}, "properties": {"repobilityId": "d3956ddbac69d8e7", "scanner": "scanner-primary", "fingerprint": "9bbd1f3fbe2cddfa", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e59210c1f05bf708", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:101)"}, "properties": {"repobilityId": "db726f5cb6fde36f", "scanner": "scanner-primary", "fingerprint": "e59210c1f05bf708", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-98c1a459e9a65920", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/worker-api-endpoints.test.ts:115)"}, "properties": {"repobilityId": "636187bf31ee9691", "scanner": "scanner-primary", "fingerprint": "98c1a459e9a65920", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-3a20b1e477dd05d5", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/worker-api-endpoints.test.ts:136)"}, "properties": {"repobilityId": "518b3b189f162d77", "scanner": "scanner-primary", "fingerprint": "3a20b1e477dd05d5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-bcbe3dddd253739f", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/version (tests/integration/worker-api-endpoints.test.ts:150)"}, "properties": {"repobilityId": "c5a686986a4b7433", "scanner": "scanner-primary", "fingerprint": "bcbe3dddd253739f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-8dfcd8c8c473e821", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/unknown-endpoint (tests/integration/worker-api-endpoints.test.ts:167)"}, "properties": {"repobilityId": "26c3564ff962e0a0", "scanner": "scanner-primary", "fingerprint": "8dfcd8c8c473e821", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c1e128d133a2761f", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${testPort}/api/unknown-endpoint (tests/integration/worker-api-endpoints.test.ts:179)"}, "properties": {"repobilityId": "8d51aec5366388da", "scanner": "scanner-primary", "fingerprint": "c1e128d133a2761f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-0178aeb2eadfb766", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/search/nonexistent/nested (tests/integration/worker-api-endpoints.test.ts:192)"}, "properties": {"repobilityId": "8853f147d20a2a53", "scanner": "scanner-primary", "fingerprint": "0178aeb2eadfb766", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-fefe3ae58f44a301", "level": "error", "message": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:202)"}, "properties": {"repobilityId": "4eee584173028174", "scanner": "scanner-primary", "fingerprint": "fefe3ae58f44a301", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-ed3ef8d5eab1e0d1", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${testPort}/api/nonexistent (tests/integration/worker-api-endpoints.test.ts:216)"}, "properties": {"repobilityId": "c113faf5475b40f2", "scanner": "scanner-primary", "fingerprint": "ed3ef8d5eab1e0d1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-39cce8acf4b78e89", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:229)"}, "properties": {"repobilityId": "dd3f93a52e1ce165", "scanner": "scanner-primary", "fingerprint": "39cce8acf4b78e89", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9c481aa54bb59224", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/worker-api-endpoints.test.ts:251)"}, "properties": {"repobilityId": "0439355c78ce2485", "scanner": "scanner-primary", "fingerprint": "9c481aa54bb59224", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-0c49d961047e91f6", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/worker-api-endpoints.test.ts:256)"}, "properties": {"repobilityId": "f9971c2c00d78d00", "scanner": "scanner-primary", "fingerprint": "0c49d961047e91f6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-44e98686c37fba55", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:274)"}, "properties": {"repobilityId": "219d40e67b5affd8", "scanner": "scanner-primary", "fingerprint": "44e98686c37fba55", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9244c8c9d113849e", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:280)"}, "properties": {"repobilityId": "d68f52c35c1f2030", "scanner": "scanner-primary", "fingerprint": "9244c8c9d113849e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-024c0bb7a2252fd5", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/worker-api-endpoints.test.ts:300)"}, "properties": {"repobilityId": "239c0bba1fe4848c", "scanner": "scanner-primary", "fingerprint": "024c0bb7a2252fd5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-efb8021d5edf2157", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/hook-execution-e2e.test.ts:74)"}, "properties": {"repobilityId": "2f74073855fd66e7", "scanner": "scanner-primary", "fingerprint": "efb8021d5edf2157", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-172641a1cf1046b8", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/hook-execution-e2e.test.ts:89)"}, "properties": {"repobilityId": "4af2da4e29fa3a7e", "scanner": "scanner-primary", "fingerprint": "172641a1cf1046b8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-ecdc08f9a27e2882", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/integration/hook-execution-e2e.test.ts:109)"}, "properties": {"repobilityId": "7c07e166084252e8", "scanner": "scanner-primary", "fingerprint": "ecdc08f9a27e2882", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-86097b5fbba6d817", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/version (tests/integration/hook-execution-e2e.test.ts:121)"}, "properties": {"repobilityId": "189806d7272b901f", "scanner": "scanner-primary", "fingerprint": "86097b5fbba6d817", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-f1ea311057ac58b5", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/hook-execution-e2e.test.ts:139)"}, "properties": {"repobilityId": "9233964195823185", "scanner": "scanner-primary", "fingerprint": "f1ea311057ac58b5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a86a16c33c9a9b1a", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/hook-execution-e2e.test.ts:170)"}, "properties": {"repobilityId": "2236394a4a10c44c", "scanner": "scanner-primary", "fingerprint": "a86a16c33c9a9b1a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d5f33f719bd73272", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/integration/hook-execution-e2e.test.ts:176)"}, "properties": {"repobilityId": "ccb2a5bf1b68d10c", "scanner": "scanner-primary", "fingerprint": "d5f33f719bd73272", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-3f6aa0410b59ac6b", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/nonexistent (tests/integration/hook-execution-e2e.test.ts:188)"}, "properties": {"repobilityId": "deb10168d82b64ff", "scanner": "scanner-primary", "fingerprint": "3f6aa0410b59ac6b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c7c9cf063b8817be", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${testPort}/api/test-json (tests/integration/hook-execution-e2e.test.ts:200)"}, "properties": {"repobilityId": "a08b755753e79288", "scanner": "scanner-primary", "fingerprint": "c7c9cf063b8817be", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b90551b1760e7085", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}${path} (tests/compat/sessions-observations-adapter.test.ts:166)"}, "properties": {"repobilityId": "ff58ef9f462b678a", "scanner": "scanner-primary", "fingerprint": "b90551b1760e7085", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-1573e0649f1aad6a", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/api/sessions/observations (tests/compat/sessions-observations-adapter.test.ts:350)"}, "properties": {"repobilityId": "94619f5b89223375", "scanner": "scanner-primary", "fingerprint": "1573e0649f1aad6a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a4381b18d53b061e", "level": "error", "message": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:85)"}, "properties": {"repobilityId": "5af688a4bfcd3d0b", "scanner": "scanner-primary", "fingerprint": "a4381b18d53b061e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-dda321677fab2106", "level": "error", "message": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:99)"}, "properties": {"repobilityId": "1e739acee488b040", "scanner": "scanner-primary", "fingerprint": "dda321677fab2106", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-69ca627480b1e3d1", "level": "error", "message": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:113)"}, "properties": {"repobilityId": "f48e8f1d20b33f29", "scanner": "scanner-primary", "fingerprint": "69ca627480b1e3d1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-f9d9091cb025ca9d", "level": "error", "message": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:127)"}, "properties": {"repobilityId": "5f7e40f0a160fda4", "scanner": "scanner-primary", "fingerprint": "f9d9091cb025ca9d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-491713f8f9466050", "level": "error", "message": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:142)"}, "properties": {"repobilityId": "4695808f1827440d", "scanner": "scanner-primary", "fingerprint": "491713f8f9466050", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-404b295b578c682e", "level": "error", "message": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:157)"}, "properties": {"repobilityId": "15e591d7b2a5c208", "scanner": "scanner-primary", "fingerprint": "404b295b578c682e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-2fddec1dfa9cc368", "level": "error", "message": {"text": "Dangling fetch: OPTIONS http://127.0.0.1:${testPort}/api/settings (tests/worker/middleware/cors-restriction.test.ts:172)"}, "properties": {"repobilityId": "bf42f53eea5293be", "scanner": "scanner-primary", "fingerprint": "2fddec1dfa9cc368", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9a5ac3e968458523", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${testPort}/api/auth/session (tests/server/server.test.ts:83)"}, "properties": {"repobilityId": "2b5857d90010233e", "scanner": "scanner-primary", "fingerprint": "9a5ac3e968458523", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-139dbb3aca47dcc9", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:256)"}, "properties": {"repobilityId": "b4b6af855a546f86", "scanner": "scanner-primary", "fingerprint": "139dbb3aca47dcc9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-08d97838dfb3cad7", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:270)"}, "properties": {"repobilityId": "c7e88fa79b008570", "scanner": "scanner-primary", "fingerprint": "08d97838dfb3cad7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-ac9c7c9340ac5e86", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:293)"}, "properties": {"repobilityId": "9fd9fb31875fdf9f", "scanner": "scanner-primary", "fingerprint": "ac9c7c9340ac5e86", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5b2901abbb171de1", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:299)"}, "properties": {"repobilityId": "8cf3764ba67a9c58", "scanner": "scanner-primary", "fingerprint": "5b2901abbb171de1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-f2973fdd2a238ab0", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:310)"}, "properties": {"repobilityId": "b3b18a267f291ff5", "scanner": "scanner-primary", "fingerprint": "f2973fdd2a238ab0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-99a7081dc3b2071b", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/health (tests/server/server.test.ts:337)"}, "properties": {"repobilityId": "524737d03c03642a", "scanner": "scanner-primary", "fingerprint": "99a7081dc3b2071b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a9a8d2444fd50103", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/server/server.test.ts:353)"}, "properties": {"repobilityId": "fac84438a7d8795e", "scanner": "scanner-primary", "fingerprint": "a9a8d2444fd50103", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c230660f022a7006", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/readiness (tests/server/server.test.ts:376)"}, "properties": {"repobilityId": "054fe979a72f3adc", "scanner": "scanner-primary", "fingerprint": "c230660f022a7006", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e38deeae0912a6d7", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/version (tests/server/server.test.ts:393)"}, "properties": {"repobilityId": "539ad318c695e98e", "scanner": "scanner-primary", "fingerprint": "e38deeae0912a6d7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e830cf076edb2581", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${testPort}/api/nonexistent (tests/server/server.test.ts:411)"}, "properties": {"repobilityId": "34ed186b03c44b68", "scanner": "scanner-primary", "fingerprint": "e830cf076edb2581", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-3651597206add616", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/api/health (tests/server/server-security-headers.test.ts:42)"}, "properties": {"repobilityId": "8dbebc31d2c633d1", "scanner": "scanner-primary", "fingerprint": "3651597206add616", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9955fa77b62f78fc", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/api/health (tests/server/server-security-headers.test.ts:57)"}, "properties": {"repobilityId": "a071e4ba0f2e84ba", "scanner": "scanner-primary", "fingerprint": "9955fa77b62f78fc", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-31f754c12f8cec96", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${address.port}/api/health (tests/server/server-beta-service.test.ts:49)"}, "properties": {"repobilityId": "885bc01f06d94118", "scanner": "scanner-primary", "fingerprint": "31f754c12f8cec96", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-88c947d0b3659da4", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${address.port}/v1/info (tests/server/server-beta-service.test.ts:53)"}, "properties": {"repobilityId": "2d8450aed8510326", "scanner": "scanner-primary", "fingerprint": "88c947d0b3659da4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d82cc3da746f4ac3", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/events (tests/server/server-beta-service.test.ts:102)"}, "properties": {"repobilityId": "e0c7801f88218be2", "scanner": "scanner-primary", "fingerprint": "d82cc3da746f4ac3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-368c4013de2dd642", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/events?generate=false (tests/server/server-beta-service.test.ts:164)"}, "properties": {"repobilityId": "968f3451dcf9fbea", "scanner": "scanner-primary", "fingerprint": "368c4013de2dd642", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-1cfc70119bba13ef", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/events/batch (tests/server/server-beta-service.test.ts:227)"}, "properties": {"repobilityId": "a975ca914f8e0144", "scanner": "scanner-primary", "fingerprint": "1cfc70119bba13ef", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b4b0e3409397165a", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:188)"}, "properties": {"repobilityId": "86eb4d46cecb3188", "scanner": "scanner-primary", "fingerprint": "b4b0e3409397165a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4a6e332fe7d64195", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:208)"}, "properties": {"repobilityId": "2ea5ba2a1dffdc31", "scanner": "scanner-primary", "fingerprint": "4a6e332fe7d64195", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4b22a0563eadad8e", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:216)"}, "properties": {"repobilityId": "889a2aca871c6081", "scanner": "scanner-primary", "fingerprint": "4b22a0563eadad8e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-cedd1b2ebf813ca8", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:232)"}, "properties": {"repobilityId": "9fe56c2a752a038f", "scanner": "scanner-primary", "fingerprint": "cedd1b2ebf813ca8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9e3f1fa651257896", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/projects (tests/server/v1-routes.test.ts:259)"}, "properties": {"repobilityId": "60e58e613a53377e", "scanner": "scanner-primary", "fingerprint": "9e3f1fa651257896", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-565c129eb78fc3d8", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/events/batch (tests/server/v1-routes.test.ts:283)"}, "properties": {"repobilityId": "389ce54978bfddb6", "scanner": "scanner-primary", "fingerprint": "565c129eb78fc3d8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-f3ee8657eb6249a7", "level": "error", "message": {"text": "Dangling fetch: PATCH http://127.0.0.1:${port}/v1/memories/${memory.id} (tests/server/v1-routes.test.ts:328)"}, "properties": {"repobilityId": "a1bf97ce4e9c66fe", "scanner": "scanner-primary", "fingerprint": "f3ee8657eb6249a7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5a1d6d94666f121f", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${port}${path} (tests/server/v1-routes.test.ts:346)"}, "properties": {"repobilityId": "84bcb2cef8fad692", "scanner": "scanner-primary", "fingerprint": "5a1d6d94666f121f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-bf72e4beedd703dc", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/info (tests/server/server-viewer-routes.test.ts:61)"}, "properties": {"repobilityId": "e3ce6520db7bc4e8", "scanner": "scanner-primary", "fingerprint": "bf72e4beedd703dc", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9c55894c13a8cbb1", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/ (tests/server/server-viewer-routes.test.ts:69)"}, "properties": {"repobilityId": "65c478984bf9f083", "scanner": "scanner-primary", "fingerprint": "9c55894c13a8cbb1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e03fc93c77933878", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/info (tests/server/server-runtime-smoke.test.ts:88)"}, "properties": {"repobilityId": "9f63a525c178f538", "scanner": "scanner-primary", "fingerprint": "e03fc93c77933878", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-2612d751f8da6e3a", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/projects (tests/server/server-runtime-smoke.test.ts:96)"}, "properties": {"repobilityId": "823591c12e1be2df", "scanner": "scanner-primary", "fingerprint": "2612d751f8da6e3a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-2aef76d3fbdf8f03", "level": "error", "message": {"text": "Dangling fetch: POST http://127.0.0.1:${port}/v1/projects (tests/server/server-runtime-smoke.test.ts:106)"}, "properties": {"repobilityId": "02d52372c32c6c11", "scanner": "scanner-primary", "fingerprint": "2aef76d3fbdf8f03", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-810bc39e013e70c2", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/projects (tests/server/server-runtime-smoke.test.ts:115)"}, "properties": {"repobilityId": "78da4194ade209d9", "scanner": "scanner-primary", "fingerprint": "810bc39e013e70c2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-ec4c9abe8793f385", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/ (tests/server/server-runtime-smoke.test.ts:124)"}, "properties": {"repobilityId": "0e21fc014944da6c", "scanner": "scanner-primary", "fingerprint": "ec4c9abe8793f385", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-90e0e82cf41529ce", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/echo (tests/server/middleware/request-id.test.ts:17)"}, "properties": {"repobilityId": "447280e6881d2c33", "scanner": "scanner-primary", "fingerprint": "90e0e82cf41529ce", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e7b4014bad0268f3", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/echo (tests/server/middleware/request-id.test.ts:36)"}, "properties": {"repobilityId": "c59158794205e9c0", "scanner": "scanner-primary", "fingerprint": "e7b4014bad0268f3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-186ce05fd1d5eab2", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/echo (tests/server/middleware/request-id.test.ts:55)"}, "properties": {"repobilityId": "700894524ecaec92", "scanner": "scanner-primary", "fingerprint": "186ce05fd1d5eab2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-8af0d4458738a94e", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}${path} (tests/server/runtime/server-session-routes.test.ts:134)"}, "properties": {"repobilityId": "bd32c6d9810ff10c", "scanner": "scanner-primary", "fingerprint": "8af0d4458738a94e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-f6dde0d9bf4ed18f", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}${path} (tests/server/runtime/jobs-list-and-operator-routes.test.ts:153)"}, "properties": {"repobilityId": "27bcc960fe1a5a65", "scanner": "scanner-primary", "fingerprint": "f6dde0d9bf4ed18f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5b24b5556a495982", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/jobs/${encodeURIComponent(jobId!)} (tests/server/runtime/server-mcp-routes.test.ts:225)"}, "properties": {"repobilityId": "5dfb415a1e79fca3", "scanner": "scanner-primary", "fingerprint": "5b24b5556a495982", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-bf37292ee82f3a52", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}${path} (tests/server/runtime/team-project-jobs-routes.test.ts:174)"}, "properties": {"repobilityId": "4c422b7897780dbb", "scanner": "scanner-primary", "fingerprint": "bf37292ee82f3a52", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-526374a05a2f7321", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/v1/teams/${teamAId}/jobs (tests/server/runtime/team-project-jobs-routes.test.ts:243)"}, "properties": {"repobilityId": "4c1a9e800f3895c6", "scanner": "scanner-primary", "fingerprint": "526374a05a2f7321", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-168eaebba319c0ae", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/health (scripts/bug-report/collector.ts:111)"}, "properties": {"repobilityId": "88bcddfedebee66b", "scanner": "scanner-primary", "fingerprint": "168eaebba319c0ae", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9a6b55b792308b16", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/api/stats (scripts/bug-report/collector.ts:122)"}, "properties": {"repobilityId": "196dccdfafeaef8a", "scanner": "scanner-primary", "fingerprint": "9a6b55b792308b16", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-95bfd58384777ab0", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${workerPort}/api/health (src/npx-cli/commands/doctor.ts:87)"}, "properties": {"repobilityId": "04b5f186e3c8383e", "scanner": "scanner-primary", "fingerprint": "95bfd58384777ab0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-3acb06ae8299754e", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${workerPort}/api/health (src/npx-cli/commands/install.ts:1755)"}, "properties": {"repobilityId": "f78cb2ab0a9afd22", "scanner": "scanner-primary", "fingerprint": "3acb06ae8299754e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-ccdd8dd00c79aa8f", "level": "error", "message": {"text": "Dangling fetch: GET https://api.github.com/repos/${username}/${repo} (src/ui/viewer/hooks/useGitHubStars.ts:23)"}, "properties": {"repobilityId": "3928f843c4fa2adf", "scanner": "scanner-primary", "fingerprint": "ccdd8dd00c79aa8f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-13d8067cf736c853", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/api/readiness (src/services/integrations/WindsurfHooksInstaller.ts:296)"}, "properties": {"repobilityId": "a47272aeb8695eb7", "scanner": "scanner-primary", "fingerprint": "13d8067cf736c853", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-41108660e29ee801", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${workerPort}/api/readiness (src/services/integrations/OpenCodeInstaller.ts:198)"}, "properties": {"repobilityId": "5e608b41aa5cf504", "scanner": "scanner-primary", "fingerprint": "41108660e29ee801", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5c927011058e8c5f", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}${endpointPath} (src/services/infrastructure/HealthMonitor.ts:13)"}, "properties": {"repobilityId": "6d0ac5d4d74e2f59", "scanner": "scanner-primary", "fingerprint": "5c927011058e8c5f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-abd3c44849963216", "level": "error", "message": {"text": "Dangling fetch: GET http://127.0.0.1:${port}/api/health (src/services/infrastructure/HealthMonitor.ts:26)"}, "properties": {"repobilityId": "eb5c1871975798be", "scanner": "scanner-primary", "fingerprint": "abd3c44849963216", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4756b4c4da7d2088", "level": "note", "message": {"text": "Unused endpoint: GET /api/health"}, "properties": {"repobilityId": "a1b5c5f4b28c952b", "scanner": "scanner-primary", "fingerprint": "4756b4c4da7d2088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6c2507f3182299a0", "level": "note", "message": {"text": "Unused endpoint: GET /api/version"}, "properties": {"repobilityId": "54df01c36baf1989", "scanner": "scanner-primary", "fingerprint": "6c2507f3182299a0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cb9942e1574d519c", "level": "note", "message": {"text": "Unused endpoint: GET /api/instructions"}, "properties": {"repobilityId": "93b7a246e41fd8d6", "scanner": "scanner-primary", "fingerprint": "cb9942e1574d519c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1797285e777f21ba", "level": "note", "message": {"text": "Unused endpoint: POST /api/admin/restart"}, "properties": {"repobilityId": "27645a8f5f274074", "scanner": "scanner-primary", "fingerprint": "1797285e777f21ba", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c12b983b671f7650", "level": "note", "message": {"text": "Unused endpoint: POST /api/admin/shutdown"}, "properties": {"repobilityId": "a3cac387f340ba09", "scanner": "scanner-primary", "fingerprint": "c12b983b671f7650", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99af828a88c982ca", "level": "note", "message": {"text": "Unused endpoint: GET /api/admin/doctor"}, "properties": {"repobilityId": "b70c219eec9ef6be", "scanner": "scanner-primary", "fingerprint": "99af828a88c982ca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c1766e6d593b047a", "level": "note", "message": {"text": "Unused endpoint: USE /v1"}, "properties": {"repobilityId": "e24318f35c8ca71f", "scanner": "scanner-primary", "fingerprint": "c1766e6d593b047a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5c48b167569ccbdf", "level": "note", "message": {"text": "Unused endpoint: POST /v1/events"}, "properties": {"repobilityId": "ed7e0d3eab8db63f", "scanner": "scanner-primary", "fingerprint": "5c48b167569ccbdf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e4ed0369b015de54", "level": "note", "message": {"text": "Unused endpoint: POST /v1/events/batch"}, "properties": {"repobilityId": "d69934440110a822", "scanner": "scanner-primary", "fingerprint": "e4ed0369b015de54", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-547c7e07c03893ca", "level": "note", "message": {"text": "Unused endpoint: GET /v1/events/:id"}, "properties": {"repobilityId": "b8e7b4405b6c5344", "scanner": "scanner-primary", "fingerprint": "547c7e07c03893ca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dc0666cc3ea5289f", "level": "note", "message": {"text": "Unused endpoint: GET /v1/events/:id/observations"}, "properties": {"repobilityId": "9d538f9eff5f1132", "scanner": "scanner-primary", "fingerprint": "dc0666cc3ea5289f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bf1828beba1c4da7", "level": "note", "message": {"text": "Unused endpoint: GET /v1/teams/:teamId/jobs"}, "properties": {"repobilityId": "4c2b5aba56dc1b42", "scanner": "scanner-primary", "fingerprint": "bf1828beba1c4da7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-902e01996f20c4bf", "level": "note", "message": {"text": "Unused endpoint: GET /v1/projects/:projectId/jobs"}, "properties": {"repobilityId": "c5f40bc4af9587d5", "scanner": "scanner-primary", "fingerprint": "902e01996f20c4bf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ec289b461de13e63", "level": "note", "message": {"text": "Unused endpoint: GET /v1/jobs"}, "properties": {"repobilityId": "c6cad0c7d02dc2b4", "scanner": "scanner-primary", "fingerprint": "ec289b461de13e63", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9b67ca93f2457ffb", "level": "note", "message": {"text": "Unused endpoint: GET /v1/jobs/:id"}, "properties": {"repobilityId": "1512b8eefe86d9df", "scanner": "scanner-primary", "fingerprint": "9b67ca93f2457ffb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7c353cd9a31f6a1a", "level": "note", "message": {"text": "Unused endpoint: POST /v1/jobs/:id/retry"}, "properties": {"repobilityId": "11414df3ded47e48", "scanner": "scanner-primary", "fingerprint": "7c353cd9a31f6a1a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-999f8733365f9df2", "level": "note", "message": {"text": "Unused endpoint: POST /v1/jobs/:id/cancel"}, "properties": {"repobilityId": "411cac5bce49e7a4", "scanner": "scanner-primary", "fingerprint": "999f8733365f9df2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7041d88699f4cf0d", "level": "note", "message": {"text": "Unused endpoint: POST /v1/sessions/start"}, "properties": {"repobilityId": "eebbdde24077bdf0", "scanner": "scanner-primary", "fingerprint": "7041d88699f4cf0d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2c3383173b9b9dbe", "level": "note", "message": {"text": "Unused endpoint: GET /v1/sessions/:id"}, "properties": {"repobilityId": "80b30c403bc4daaf", "scanner": "scanner-primary", "fingerprint": "2c3383173b9b9dbe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0ec7fa647bc4efbd", "level": "note", "message": {"text": "Unused endpoint: POST /v1/sessions/:id/end"}, "properties": {"repobilityId": "e362dce6c0d6da69", "scanner": "scanner-primary", "fingerprint": "0ec7fa647bc4efbd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ae9acc9695ec942a", "level": "note", "message": {"text": "Unused endpoint: POST /v1/memories"}, "properties": {"repobilityId": "00ceeb8b12b78067", "scanner": "scanner-primary", "fingerprint": "ae9acc9695ec942a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f8d83ec85fe852be", "level": "note", "message": {"text": "Unused endpoint: POST /v1/search"}, "properties": {"repobilityId": "0e80dc9767aac6e2", "scanner": "scanner-primary", "fingerprint": "f8d83ec85fe852be", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ba9a006b181623b6", "level": "note", "message": {"text": "Unused endpoint: POST /v1/context"}, "properties": {"repobilityId": "6eddaa7d89b23355", "scanner": "scanner-primary", "fingerprint": "ba9a006b181623b6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-076ae4069b338403", "level": "note", "message": {"text": "Unused endpoint: POST /api/sessions/observations"}, "properties": {"repobilityId": "1b91922c7203d1f4", "scanner": "scanner-primary", "fingerprint": "076ae4069b338403", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4d5e9716560f1147", "level": "note", "message": {"text": "Unused endpoint: POST /api/sessions/summarize"}, "properties": {"repobilityId": "cb23b96f5a522448", "scanner": "scanner-primary", "fingerprint": "4d5e9716560f1147", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-19a1a46befe3d6a6", "level": "note", "message": {"text": "Unused endpoint: DELETE "}, "properties": {"repobilityId": "d7536b316355f6a1", "scanner": "scanner-primary", "fingerprint": "19a1a46befe3d6a6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "9d069c35c817a631", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-57fe8ccf6e8df35a", "level": "note", "message": {"text": "Unused endpoint: GET /v1/info"}, "properties": {"repobilityId": "f2124b0bc0cac703", "scanner": "scanner-primary", "fingerprint": "57fe8ccf6e8df35a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-65c2304134ff231e", "level": "note", "message": {"text": "Unused endpoint: ALL /api/auth/*splat"}, "properties": {"repobilityId": "2fb112dd7efbd74c", "scanner": "scanner-primary", "fingerprint": "65c2304134ff231e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3fd26491572228c4", "level": "note", "message": {"text": "Unused endpoint: GET /v1/projects"}, "properties": {"repobilityId": "55dfd4b89e719d15", "scanner": "scanner-primary", "fingerprint": "3fd26491572228c4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b0b8181b03ca7de5", "level": "note", "message": {"text": "Unused endpoint: POST /v1/projects"}, "properties": {"repobilityId": "ef8a939f3b220402", "scanner": "scanner-primary", "fingerprint": "b0b8181b03ca7de5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-912ce2daa79ecad3", "level": "note", "message": {"text": "Unused endpoint: GET /v1/projects/:id"}, "properties": {"repobilityId": "c8e169541d901482", "scanner": "scanner-primary", "fingerprint": "912ce2daa79ecad3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ef947f347f2d2a39", "level": "note", "message": {"text": "Unused endpoint: GET /v1/memories/:id"}, "properties": {"repobilityId": "e0a7674999528cbf", "scanner": "scanner-primary", "fingerprint": "ef947f347f2d2a39", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-39b66f5bc970cf68", "level": "note", "message": {"text": "Unused endpoint: PATCH /v1/memories/:id"}, "properties": {"repobilityId": "89129c0b8992774a", "scanner": "scanner-primary", "fingerprint": "39b66f5bc970cf68", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9685abae84f94e76", "level": "note", "message": {"text": "Unused endpoint: GET /v1/audit"}, "properties": {"repobilityId": "0abcf1372e0ae3d5", "scanner": "scanner-primary", "fingerprint": "9685abae84f94e76", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b96372541f48aa3b", "level": "note", "message": {"text": "Unused endpoint: POST /v1/environments?beta=true"}, "properties": {"repobilityId": "a73b1a56c3f26a64", "scanner": "scanner-primary", "fingerprint": "b96372541f48aa3b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f69ff3386aed8a58", "level": "note", "message": {"text": "Unused endpoint: POST /v1/files?beta=true"}, "properties": {"repobilityId": "42d9bde692aba027", "scanner": "scanner-primary", "fingerprint": "f69ff3386aed8a58", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5e42ff2d7e23d4c7", "level": "note", "message": {"text": "Unused endpoint: POST /v1/user_profiles?beta=true"}, "properties": {"repobilityId": "ac1a7042887aa5d7", "scanner": "scanner-primary", "fingerprint": "5e42ff2d7e23d4c7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3b8ed4c704a21b2a", "level": "note", "message": {"text": "Unused endpoint: POST /v1/agents?beta=true"}, "properties": {"repobilityId": "0692b4f2972541a3", "scanner": "scanner-primary", "fingerprint": "3b8ed4c704a21b2a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f8bdbd7b085e30db", "level": "note", "message": {"text": "Unused endpoint: POST /v1/memory_stores?beta=true"}, "properties": {"repobilityId": "4d82cb4972aadfd4", "scanner": "scanner-primary", "fingerprint": "f8bdbd7b085e30db", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cd7e4d4f2ed43337", "level": "note", "message": {"text": "Unused endpoint: POST /v1/messages/batches?beta=true"}, "properties": {"repobilityId": "7067eb9bddc936db", "scanner": "scanner-primary", "fingerprint": "cd7e4d4f2ed43337", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-00750df0839bbbd3", "level": "note", "message": {"text": "Unused endpoint: POST /v1/messages?beta=true"}, "properties": {"repobilityId": "ee8bcd751851127f", "scanner": "scanner-primary", "fingerprint": "00750df0839bbbd3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6c096d37f349fa96", "level": "note", "message": {"text": "Unused endpoint: POST /v1/messages/count_tokens?beta=true"}, "properties": {"repobilityId": "85db184fa7cf01c7", "scanner": "scanner-primary", "fingerprint": "6c096d37f349fa96", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-56fe7aef1427c93d", "level": "note", "message": {"text": "Unused endpoint: POST /v1/sessions?beta=true"}, "properties": {"repobilityId": "755589664ee334bd", "scanner": "scanner-primary", "fingerprint": "56fe7aef1427c93d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bea60f0266e76560", "level": "note", "message": {"text": "Unused endpoint: POST /v1/skills?beta=true"}, "properties": {"repobilityId": "f753262f33d79567", "scanner": "scanner-primary", "fingerprint": "bea60f0266e76560", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2d29f578584143cf", "level": "note", "message": {"text": "Unused endpoint: POST /v1/vaults?beta=true"}, "properties": {"repobilityId": "8ceb1fc4d7898bbf", "scanner": "scanner-primary", "fingerprint": "2d29f578584143cf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1e474744f4149920", "level": "note", "message": {"text": "Unused endpoint: POST /v1/complete"}, "properties": {"repobilityId": "0717ab2df7a914e6", "scanner": "scanner-primary", "fingerprint": "1e474744f4149920", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8bcda56c4c41e5fa", "level": "note", "message": {"text": "Unused endpoint: POST /v1/messages/batches"}, "properties": {"repobilityId": "4cf42f7a072544e5", "scanner": "scanner-primary", "fingerprint": "8bcda56c4c41e5fa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-50d20b703a1dd1f9", "level": "note", "message": {"text": "Unused endpoint: POST /v1/messages"}, "properties": {"repobilityId": "7e1d065343079d6c", "scanner": "scanner-primary", "fingerprint": "50d20b703a1dd1f9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e51d72bee485df7b", "level": "note", "message": {"text": "Unused endpoint: POST /v1/messages/count_tokens"}, "properties": {"repobilityId": "18813c02ca67823b", "scanner": "scanner-primary", "fingerprint": "e51d72bee485df7b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}