CRIT
MINED107
[MINED107] Missing import: `warnings` used but not imported: The file uses `warnings.some…
core/audit/action_challenger.py:23
CRIT
MINED107
[MINED107] Missing import: `operator` used but not imported: The file uses `operator.some…
core/actuators/code_execution_actuator.…:98
CRIT
MINED107
[MINED107] Missing import: `stat` used but not imported: The file uses `stat.something(..…
core/agency/private_phenomenology.py:266
CRIT
MINED107
[MINED107] Missing import: `stat` used but not imported: The file uses `stat.something(..…
core/agency/canvas_manager.py:216
CRIT
MINED107
[MINED107] Missing import: `queue` used but not imported: The file uses `queue.something(…
aura_bench/aletheia_runner.py:760
CRIT
MINED107
[MINED107] Missing import: `queue` used but not imported: The file uses `queue.something(…
core/autonomous_initiative_loop.py:303
HIGH
MINED106
[MINED106] Phantom test coverage: test_swarm_review: Test function `test_swarm_review` ru…
archive/verification_scripts/verify_pha…:42
HIGH
MINED106
[MINED106] Phantom test coverage: test_autogenesis: Test function `test_autogenesis` runs…
archive/verification_scripts/verify_pha…:13
HIGH
MINED106
[MINED106] Phantom test coverage: test_swarm_debate: Test function `test_swarm_debate` ru…
archive/verification_scripts/verify_pha…:83
HIGH
MINED106
[MINED106] Phantom test coverage: test_adaptive_reasoning: Test function `test_adaptive_r…
archive/verification_scripts/verify_pha…:46
HIGH
MINED106
[MINED106] Phantom test coverage: test_mortality_integration: Test function `test_mortali…
archive/verification_scripts/verify_pha…:17
HIGH
MINED106
[MINED106] Phantom test coverage: test_syntax_gating: Test function `test_syntax_gating` …
archive/verification_scripts/verify_syn…:23
HIGH
MINED106
[MINED106] Phantom test coverage: test_robustness: Test function `test_robustness` runs c…
archive/verification_scripts/verify_rob…:18
HIGH
MINED106
[MINED106] Phantom test coverage: test_telemetry_emission: Test function `test_telemetry_…
archive/verification_scripts/verify_tel…:13
HIGH
MINED106
[MINED106] Phantom test coverage: test_boot_sequence: Test function `test_boot_sequence` …
archive/one_off_scripts/repro_loop_moni…:16
HIGH
MINED106
[MINED106] Phantom test coverage: test_zenith_fixes: Test function `test_zenith_fixes` ru…
archive/one_off_scripts/verify_zenith.py:22
HIGH
MINED106
[MINED106] Phantom test coverage: test_robust_lock: Test function `test_robust_lock` runs…
archive/one_off_scripts/verify_architec…:112
HIGH
MINED106
[MINED106] Phantom test coverage: test_affect_telemetry_sync: Test function `test_affect_…
archive/one_off_scripts/verify_architec…:83
HIGH
MINED106
[MINED106] Phantom test coverage: test_response_phase_watchdog: Test function `test_respo…
archive/one_off_scripts/verify_architec…:58
HIGH
MINED106
[MINED106] Phantom test coverage: test_mlx_client_retries: Test function `test_mlx_client…
archive/one_off_scripts/verify_architec…:24
HIGH
MINED106
[MINED106] Phantom test coverage: test_fallbacks: Test function `test_fallbacks` runs cod…
archive/one_off_scripts/verify_leak_pre…:55
HIGH
MINED106
[MINED106] Phantom test coverage: test_scrubbing: Test function `test_scrubbing` runs cod…
archive/one_off_scripts/verify_leak_pre…:20
HIGH
MINED106
[MINED106] Phantom test coverage: test_mind_tick_resilience: Test function `test_mind_tic…
archive/one_off_scripts/reproduce_stall…:8
HIGH
MINED106
[MINED106] Phantom test coverage: test_viability_total: Test function `test_viability_tot…
aura_bench/property_tests/property_runn…:109
HIGH
MINED106
[MINED106] Phantom test coverage: test_receipt_completeness_invariant: Test function `tes…
aura_bench/property_tests/property_runn…:88
HIGH
MINED106
[MINED106] Phantom test coverage: test_bridge_caps_max_tokens: Test function `test_bridge…
aura_bench/property_tests/property_runn…:80
HIGH
MINED106
[MINED106] Phantom test coverage: test_provenance_round_trip: Test function `test_provena…
aura_bench/property_tests/property_runn…:69
HIGH
MINED106
[MINED106] Phantom test coverage: test_conscience_paraphrase: Test function `test_conscie…
aura_bench/property_tests/property_runn…:52
HIGH
MINED106
[MINED106] Phantom test coverage: test_capability_token_replay: Test function `test_capab…
aura_bench/property_tests/property_runn…:40
HIGH
MINED108
[MINED108] `self._task_status` used but never assigned in __init__: Method `start` of cla…
core/autonomous_initiative_loop.py:171
HIGH
MINED108
[MINED108] `self._social_interaction_loop` used but never assigned in __init__: Method `s…
core/autonomous_initiative_loop.py:164
HIGH
MINED108
[MINED108] `self._self_development_loop` used but never assigned in __init__: Method `sta…
core/autonomous_initiative_loop.py:160
HIGH
MINED108
[MINED108] `self._knowledge_gap_monitor_loop` used but never assigned in __init__: Method…
core/autonomous_initiative_loop.py:157
HIGH
MINED108
[MINED108] `self._world_watcher_loop` used but never assigned in __init__: Method `start`…
core/autonomous_initiative_loop.py:154
HIGH
MINED108
[MINED108] `self.handle_error` used but never assigned in __init__: Method `error_boundar…
core/base_module.py:86
HIGH
MINED108
[MINED108] `self.handle_error` used but never assigned in __init__: Method `error_boundar…
core/base_module.py:68
HIGH
MINED108
[MINED108] `self._update_latency` used but never assigned in __init__: Method `error_boun…
core/base_module.py:78
HIGH
MINED108
[MINED108] `self._update_latency` used but never assigned in __init__: Method `error_boun…
core/base_module.py:60
HIGH
MINED108
[MINED108] `self._list_backups_sync` used but never assigned in __init__: Method `get_hea…
core/backup.py:339
HIGH
MINED108
[MINED108] `self.create_backup` used but never assigned in __init__: Method `on_start_asy…
core/backup.py:324
HIGH
MINED108
[MINED108] `self.run_vacuum` used but never assigned in __init__: Method `on_start_async`…
core/backup.py:315
HIGH
MINED108
[MINED108] `self.create_backup` used but never assigned in __init__: Method `ensure_recen…
core/backup.py:300
HIGH
MINED108
[MINED108] `self._list_backups_sync` used but never assigned in __init__: Method `_enforc…
core/backup.py:278
HIGH
MINED108
[MINED108] `self._enforce_rotation` used but never assigned in __init__: Method `create_b…
core/backup.py:252
HIGH
MINED108
[MINED108] `self.run_vacuum` used but never assigned in __init__: Method `create_backup` …
core/backup.py:237
HIGH
MINED108
[MINED108] `self._maintenance_block_reason` used but never assigned in __init__: Method `…
core/backup.py:225
HIGH
MINED108
[MINED108] `self._vacuum_database_sync` used but never assigned in __init__: Method `run_…
core/backup.py:188
HIGH
MINED108
[MINED108] `self._discover_database_paths` used but never assigned in __init__: Method `r…
core/backup.py:179
HIGH
MINED108
[MINED108] `self._maintenance_block_reason` used but never assigned in __init__: Method `…
core/backup.py:170
HIGH
MINED108
[MINED108] `self._sign` used but never assigned in __init__: Method `verify_integrity` of…
core/audit_logger.py:93
HIGH
MINED108
[MINED108] `self._sign` used but never assigned in __init__: Method `log` of class `Audit…
core/audit_logger.py:72
HIGH
MINED108
[MINED108] `self._redact` used but never assigned in __init__: Method `log` of class `Aud…
core/audit_logger.py:70
HIGH
MINED108
[MINED108] `self._redact` used but never assigned in __init__: Method `_redact` of class …
core/audit_logger.py:64
HIGH
MINED108
[MINED108] `self._redact` used but never assigned in __init__: Method `_redact` of class …
core/audit_logger.py:62
HIGH
MINED009
[MINED009] Floats For Money: Variable named price/amount/cost typed as float instead of D…
core/brain/cognition_models.py:37
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
core/autonomy/curated_media_loader.py:9
HIGH
MINED006
[MINED006] Overcatch Baseexception: except BaseException: ... — prevents Ctrl+C and Syste…
archive/verification_scripts/verify_pul…:72
HIGH
MINED036
[MINED036] Python Os System Call: os.system() invokes shell with no escaping.
archive/verification_scripts/verify_pha…:58
HIGH
SEC103
[SEC103] LDAP injection — non-constant search filter: User input concatenated into an LDA…
archive/repair_scripts/fix_write_text.py:31
HIGH
SEC103
[SEC103] LDAP injection — non-constant search filter: User input concatenated into an LDA…
archive/repair_scripts/fix_all_write_te…:21
HIGH
SEC103
[SEC103] LDAP injection — non-constant search filter: User input concatenated into an LDA…
archive/repair_scripts/fix_all_repos.py:52
HIGH
MINED001
[MINED001] Bare Except Pass: except: pass or except Exception: pass — silently swallows e…
archive/one_off_scripts/live_orchestrat…:21
HIGH
MINED001
[MINED001] Bare Except Pass: except: pass or except Exception: pass — silently swallows e…
archive/one_off_scripts/live_mlx_solver…:31
HIGH
MINED001
[MINED001] Bare Except Pass: except: pass or except Exception: pass — silently swallows e…
archive/one_off_scripts/live_mlx_first_…:29
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
core/actuators/process_supervisor.py:94
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
core/actuators/code_execution_actuator.…:53
HIGH
SEC128
[SEC128] Async function without await — fire-and-forget Promise (AI mistake): Async call …
archive/one_off_scripts/launch_aura_3d.…:114
HIGH
COMP001
[COMP001] High cognitive complexity: Function `build_skill_index` has cognitive complexit…
archive/one_off_scripts/aura_m1_ext.py:26
HIGH
DKR014
Dockerfile copies the entire context without .dockerignore
Dockerfile:40
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/decisive.yml:13
HIGH
MINED115
[MINED115] Action `actions/setup-python` pinned to mutable ref `@v5`: `uses: actions/setu…
.github/workflows/security-gates.yml:134
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/security-gates.yml:133
HIGH
MINED115
[MINED115] Action `actions/setup-python` pinned to mutable ref `@v5`: `uses: actions/setu…
.github/workflows/security-gates.yml:121
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/security-gates.yml:120
HIGH
MINED115
[MINED115] Action `actions/upload-artifact` pinned to mutable ref `@v4`: `uses: actions/u…
.github/workflows/security-gates.yml:111
HIGH
MINED115
[MINED115] Action `actions/setup-python` pinned to mutable ref `@v5`: `uses: actions/setu…
.github/workflows/security-gates.yml:102
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/security-gates.yml:101
HIGH
MINED115
[MINED115] Action `actions/upload-artifact` pinned to mutable ref `@v4`: `uses: actions/u…
.github/workflows/security-gates.yml:92
HIGH
MINED115
[MINED115] Action `actions/setup-python` pinned to mutable ref `@v5`: `uses: actions/setu…
.github/workflows/security-gates.yml:82
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/security-gates.yml:81
HIGH
MINED115
[MINED115] Action `github/codeql-action/upload-sarif` pinned to mutable ref `@v3`: `uses:…
.github/workflows/security-gates.yml:73
HIGH
MINED115
[MINED115] Action `aquasecurity/trivy-action` pinned to mutable ref `@master`: `uses: aqu…
.github/workflows/security-gates.yml:66
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/security-gates.yml:62
HIGH
MINED115
[MINED115] Action `trufflesecurity/trufflehog` pinned to mutable ref `@main`: `uses: truf…
.github/workflows/security-gates.yml:54
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/security-gates.yml:50
HIGH
MINED115
[MINED115] Action `google/osv-scanner-action/osv-scanner-action` pinned to mutable ref `@…
.github/workflows/security-gates.yml:41
HIGH
MINED115
[MINED115] Action `actions/setup-python` pinned to mutable ref `@v5`: `uses: actions/setu…
.github/workflows/security-gates.yml:31
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/security-gates.yml:30
HIGH
MINED115
[MINED115] Action `github/codeql-action/analyze` pinned to mutable ref `@v3`: `uses: gith…
.github/workflows/security-gates.yml:24
HIGH
MINED115
[MINED115] Action `github/codeql-action/init` pinned to mutable ref `@v3`: `uses: github/…
.github/workflows/security-gates.yml:20
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/security-gates.yml:18
HIGH
MINED115
[MINED115] Action `actions/upload-artifact` pinned to mutable ref `@v4`: `uses: actions/u…
.github/workflows/production-readiness.…:30
HIGH
MINED115
[MINED115] Action `actions/setup-python` pinned to mutable ref `@v5`: `uses: actions/setu…
.github/workflows/production-readiness.…:14
HIGH
MINED115
[MINED115] Action `actions/checkout` pinned to mutable ref `@v4`: `uses: actions/checkout…
.github/workflows/production-readiness.…:13
HIGH
MINED118
[MINED118] Dockerfile FROM `python:3.12-slim` not pinned by digest: `FROM python:3.12-sli…
docker/Dockerfile:3
HIGH
MINED118
[MINED118] Dockerfile FROM `python:3.12-slim` not pinned by digest: `FROM python:3.12-sli…
Dockerfile:8
HIGH
SEC016
[SEC016] LLM Prompt Injection — User Input in AI Prompt: User-supplied text is interpolat…
core/autonomy/personhood_engine.py:187
HIGH
SEC020
[SEC020] Secret Printed to Logs: Debug or diagnostic code appears to print a credential-b…
core/agency/capability_system.py:41
MED
CFG006
[CFG006] Missing .gitignore: No .gitignore file. Risk of committing secrets and build art…
—
MED
SEC015
[SEC015] Insecure Randomness for Security: Weak PRNG used in security-sensitive context. …
core/agency/capability_system.py:35
MED
SEC119
[SEC119] World-writable / world-readable file permissions: World-writable files let any l…
cloud/_write_retry_script.py:168
MED
COMP001
[COMP001] High cognitive complexity: Function `export_source` has cognitive complexity 25…
archive/one_off_scripts/export_aura.py:25
MED
AUC001
[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks…
—
MED
MINED124
[MINED124] requirements.txt: `aiohttp` has no version pin: Unpinned pip requirement means…
requirements.txt:39
MED
MINED124
[MINED124] requirements.txt: `astor` has no version pin: Unpinned pip requirement means e…
requirements.txt:38
MED
MINED124
[MINED124] requirements.txt: `mss` has no version pin: Unpinned pip requirement means eve…
requirements.txt:37
MED
MINED124
[MINED124] requirements.txt: `prometheus-client` has no version pin: Unpinned pip require…
requirements.txt:36
MED
MINED124
[MINED124] requirements.txt: `tenacity` has no version pin: Unpinned pip requirement mean…
requirements.txt:35
MED
MINED124
[MINED124] requirements.txt: `PyYAML` has no version pin: Unpinned pip requirement means …
requirements.txt:34
MED
MINED124
[MINED124] requirements.txt: `aiosqlite` has no version pin: Unpinned pip requirement mea…
requirements.txt:33
MED
MINED124
[MINED124] requirements.txt: `pydantic-settings` has no version pin: Unpinned pip require…
requirements.txt:32
MED
MINED124
[MINED124] requirements.txt: `praw` has no version pin: Unpinned pip requirement means ev…
requirements.txt:31
MED
MINED124
[MINED124] requirements.txt: `tweepy` has no version pin: Unpinned pip requirement means …
requirements.txt:30
MED
MINED124
[MINED124] requirements.txt: `cryptography` has no version pin: Unpinned pip requirement …
requirements.txt:29
MED
MINED124
[MINED124] requirements.txt: `opencv-python-headless` has no version pin: Unpinned pip re…
requirements.txt:22
MED
MINED124
[MINED124] requirements.txt: `requests` has no version pin: Unpinned pip requirement mean…
requirements.txt:19
MED
MINED124
[MINED124] requirements.txt: `Pillow` has no version pin: Unpinned pip requirement means …
requirements.txt:18
MED
MINED124
[MINED124] requirements.txt: `pyautogui` has no version pin: Unpinned pip requirement mea…
requirements.txt:17
MED
MINED124
[MINED124] requirements.txt: `structlog` has no version pin: Unpinned pip requirement mea…
requirements.txt:14
MED
MINED124
[MINED124] requirements.txt: `pydantic` has no version pin: Unpinned pip requirement mean…
requirements.txt:13
MED
MINED124
[MINED124] requirements.txt: `uvicorn[standard]` has no version pin: Unpinned pip require…
requirements.txt:9
MED
MINED124
[MINED124] requirements.txt: `webrtcvad` has no version pin: Unpinned pip requirement mea…
requirements.txt:5
MED
MINED124
[MINED124] requirements.txt: `faster-whisper` has no version pin: Unpinned pip requiremen…
requirements.txt:4
MED
MINED124
[MINED124] requirements.txt: `mlx-whisper` has no version pin: Unpinned pip requirement m…
requirements.txt:3
MED
DKR007
Docker build context has no .dockerignore
.dockerignore
MED
SEC017
[SEC017] Unbounded Input to LLM/External API: User input is passed to an LLM or external …
core/autonomy/personhood_engine.py:187
MED
WEB003
Public web service has no security.txt
.well-known/security.txt
MED
AGT012
Agent control bridge may listen on a network interface without visible auth
aura_main.py:26
LOW
SEC124
[SEC124] TOCTOU file access (os.access then open): Check-then-use file pattern (access/ex…
archive/repair_scripts/fix_tests_v2.py:16
LOW
SEC124
[SEC124] TOCTOU file access (os.access then open): Check-then-use file pattern (access/ex…
archive/repair_scripts/fix_remaining.py:10
LOW
COMP001
[COMP001] High cognitive complexity: Function `main` has cognitive complexity 8 (SonarSou…
archive/one_off_scripts/aura_cleanup.py:17
LOW
AIC003
Duplicated implementation block across source files
core/autonomy/content_fetcher.py:64
LOW
AIC003
Duplicated implementation block across source files
core/autonomy/content_fetcher.py:59
LOW
AIC003
Duplicated implementation block across source files
core/architect/proof_obligations.py:102
LOW
AIC003
Duplicated implementation block across source files
core/architect/ghost_boot.py:100
LOW
AIC003
Duplicated implementation block across source files
core/agency/skill_library.py:34
LOW
AIC003
Duplicated implementation block across source files
core/agency/neural_intent_router.py:39
LOW
AIC003
Duplicated implementation block across source files
core/advanced_cognition/zero_shot_trans…:296
LOW
AIC003
Duplicated implementation block across source files
artifacts/rsi_frozen_generations/reprod…:8
LOW
AIC003
Duplicated implementation block across source files
artifacts/rsi_frozen_generations/reprod…:1
LOW
AIC003
Duplicated implementation block across source files
artifacts/rsi_frozen_generations/reprod…:1
LOW
AIC003
Duplicated implementation block across source files
artifacts/rsi_frozen_generations/reprod…:1
LOW
AIC003
Duplicated implementation block across source files
artifacts/rsi_frozen_generations/frozen…:1
LOW
AUC005
[AUC005] No authorization-focused tests detected: No test files with common authorization…
—
LOW
AIC006
Archive or legacy directory is mixed into the active repository root
archive:1
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
core/autonomic/iot_bridge.py:19
INFO
MINED062
[MINED062] Python Dataclass No Fields: @dataclass over an empty class — unfinished model.
aura_bench/capability_delta/runner.py:43
INFO
MINED062
[MINED062] Python Dataclass No Fields: @dataclass over an empty class — unfinished model.
aura_bench/capability_delta/profiles.py:19
INFO
MINED062
[MINED062] Python Dataclass No Fields: @dataclass over an empty class — unfinished model.
aura_bench/capability_delta/adapter.py:25
INFO
MINED063
[MINED063] Toctou Os Path Exists: if os.path.exists(p): open(p) — file can be replaced/de…
core/actuators/process_supervisor.py:208
INFO
MINED063
[MINED063] Toctou Os Path Exists: if os.path.exists(p): open(p) — file can be replaced/de…
archive/repair_scripts/fix_tests_v2.py:16
INFO
MINED063
[MINED063] Toctou Os Path Exists: if os.path.exists(p): open(p) — file can be replaced/de…
archive/repair_scripts/fix_remaining.py:10
INFO
MINED050
[MINED050] Stub Only Function: Function declared but body is just pass, return None, rais…
archive/one_off_scripts/live_orchestrat…:22
INFO
MINED050
[MINED050] Stub Only Function: Function declared but body is just pass, return None, rais…
archive/one_off_scripts/live_mlx_solver…:32
INFO
MINED050
[MINED050] Stub Only Function: Function declared but body is just pass, return None, rais…
archive/one_off_scripts/live_mlx_first_…:30
INFO
MINED077
[MINED077] Python Open No Context: fp = open(path) outside with-block leaks file handles.
cloud/_write_retry_script.py:56
INFO
MINED077
[MINED077] Python Open No Context: fp = open(path) outside with-block leaks file handles.
archive/verification_scripts/verify_rob…:74
INFO
MINED077
[MINED077] Python Open No Context: fp = open(path) outside with-block leaks file handles.
archive/one_off_scripts/export_aura.py:58