{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-19b35cb77e91e0a4", "name": "Possibly dead Python function: require_admin", "shortDescription": {"text": "Possibly dead Python function: require_admin"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d8b9dd9bfd8e95c5", "name": "Stray `console.log` in TS/JS \u2014 install.js:29", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 install.js:29"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1559de887fed9aef", "name": "Stray `console.log` in TS/JS \u2014 scripts/check-update.js:105", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/check-update.js:105"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f3c4639abddedef", "name": "Stray `console.log` in TS/JS \u2014 _workspace_prev_temp/03_code/src/server.js:47", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 _workspace_prev_temp/03_code/src/server.js:47"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1410de647097e475", "name": "Stray `console.log` in TS/JS \u2014 _workspace_prev_temp/03_code/src/routes/health.js:26", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 _workspace_prev_temp/03_code/src/routes/health.js:26"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d046746829a44e18", "name": "Stray `console.log` in TS/JS \u2014 .claude/hooks/spec-validator.js:65", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/spec-validator.js:65"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d3a58169404a4ffe", "name": "Stray `console.log` in TS/JS \u2014 .claude/hooks/spec-parser.js:214", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/spec-parser.js:214"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a2a3798f58e9f7fd", "name": "Stray `console.log` in TS/JS \u2014 .claude/hooks/deploy-lock.js:86", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/deploy-lock.js:86"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-362e2cadbcf77267", "name": "Stray `console.log` in TS/JS \u2014 .claude/hooks/code-analyzer.js:58", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/code-analyzer.js:58"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aee066fa57fc80a7", "name": "Stray `console.log` in TS/JS \u2014 .claude/hooks/post-deploy.js:283", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/post-deploy.js:283"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-129e81d64a93846a", "name": "Stray `console.log` in TS/JS \u2014 .claude/hooks/pre-commit.js:291", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/pre-commit.js:291"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-63a8caaa956e70b5", "name": "Stray `console.log` in TS/JS \u2014 .claude/hooks/pre-deploy.js:162", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/pre-deploy.js:162"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cebee65668c5fa01", "name": "Stray `console.log` in TS/JS \u2014 .claude/hooks/check-update.js:118", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/check-update.js:118"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-18a2c7b82a7a372a", "name": "Stray `console.log` in TS/JS \u2014 .claude/hooks/environment-validator.js:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/environment-validator.js:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a12cb6674a96bf06", "name": "Stray `console.log` in TS/JS \u2014 .claude/skills/coolhan-spec-driven-framework/scripts/generate-framework.js:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 .claude/skills/coolhan-spec-driven-framework/scripts/generate-framework.js:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6240f941a3b056d2", "name": "Stray `console.log` in TS/JS \u2014 coverage/lcov-report/prettify.js:2", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 coverage/lcov-report/prettify.js:2"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a51b5e9152e6d45", "name": "Stray `console.log` in TS/JS \u2014 src/server.js:54", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server.js:54"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e9b3dd00923db3f", "name": "Stray `console.log` in TS/JS \u2014 src/routes/health.js:26", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/health.js:26"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de3c1f217d72a063", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-838774050c848d35", "name": "Insecure pattern 'cors_wildcard' in main.py:35", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in main.py:35"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d9ee597c5c14f1d5", "name": "Insecure pattern 'node_child_process' in install.js:17", "shortDescription": {"text": "Insecure pattern 'node_child_process' in install.js:17"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-19b1bd93b3a62582", "name": "Insecure pattern 'node_child_process' in .claude/hooks/post-deploy.js:174", "shortDescription": {"text": "Insecure pattern 'node_child_process' in .claude/hooks/post-deploy.js:174"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4d42c9c07528d06d", "name": "Insecure pattern 'node_child_process' in .claude/hooks/pre-commit.js:10", "shortDescription": {"text": "Insecure pattern 'node_child_process' in .claude/hooks/pre-commit.js:10"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-de5b1ac75596a01c", "name": "Insecure pattern 'node_child_process' in .claude/hooks/pre-deploy.js:8", "shortDescription": {"text": "Insecure pattern 'node_child_process' in .claude/hooks/pre-deploy.js:8"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-79e8a5298e120dd3", "name": "Insecure pattern 'node_child_process' in .claude/hooks/environment-validator.js:15", "shortDescription": {"text": "Insecure pattern 'node_child_process' in .claude/hooks/environment-validator.js:15"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-561cf4fb66e16a0c", "name": "Insecure pattern 'direct_innerhtml_assignment' in coverage/lcov-report/sorter.js:84", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in coverage/lcov-report/sorter.js:84"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d38ab4c821f6de46", "name": "Insecure pattern 'direct_innerhtml_assignment' in coverage/lcov-report/prettify.js:2", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in coverage/lcov-report/prettify.js:2"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7efbda965f283c17", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v3 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-46c644c6227e4d4a", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "softprops/action-gh-release@v1 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1838a141491ce38c", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e9c970a16f87aa37", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-python@v5 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a53bf972e19b52fd", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v3 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ffa33751be3d771", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "8 tests / 64 src (ratio 0.12)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 289 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3ddef78f457004d8", "name": "Agent instruction/config may expose a secret: .claude/LOCAL_ENVIRONMENT_CONFIG.md", "shortDescription": {"text": "Agent instruction/config may expose a secret: .claude/LOCAL_ENVIRONMENT_CONFIG.md"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f677e25ae345d9af", "name": "Agent instruction/config may expose a secret: .claude/PRODUCTION_ENVIRONMENT_CONFIG.md", "shortDescription": {"text": "Agent instruction/config may expose a secret: .claude/PRODUCTION_ENVIRONMENT_CONFIG.md"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eed6dd96ae1918c8", "name": "Agent instruction/config may expose a secret: .claude/DEPLOY_PROTOCOL.md", "shortDescription": {"text": "Agent instruction/config may expose a secret: .claude/DEPLOY_PROTOCOL.md"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8bf5f57fa96d86a2", "name": "Agent instruction/config may expose a secret: .claude/STAGING_ENVIRONMENT_CONFIG.md", "shortDescription": {"text": "Agent instruction/config may expose a secret: .claude/STAGING_ENVIRONMENT_CONFIG.md"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7c46f119e7df66ee", "name": "Agent authority lacks a verifier contract: .claude/agents/intent-analyzer.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/agents/intent-analyzer.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d94e1c4b058cd7d8", "name": "Agent instruction contains unpinned remote install: .claude/skills/coolhan-development-orchestrator/SKILL.md", "shortDescription": {"text": "Agent instruction contains unpinned remote install: .claude/skills/coolhan-development-orchestrator/SKILL.md"}, "fullDescription": {"text": "Remote install commands in agent instructions are a supply-chain risk, especially when an agent can execute shell commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-61ad81c117a86f34", "name": "Agent instruction/config may expose a secret: .claude/skills/coolhan-installer/SKILL.md", "shortDescription": {"text": "Agent instruction/config may expose a secret: .claude/skills/coolhan-installer/SKILL.md"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-52dc791b56b0b633", "name": "Agent authority lacks a verifier contract: .claude/skills/coolhan-installer/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/coolhan-installer/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a7a71c454dd21dd8", "name": "Agent instruction contains unpinned remote install: .claude/skills/coolhan-installer/SKILL.md", "shortDescription": {"text": "Agent instruction contains unpinned remote install: .claude/skills/coolhan-installer/SKILL.md"}, "fullDescription": {"text": "Remote install commands in agent instructions are a supply-chain risk, especially when an agent can execute shell commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-40066ca4cee9a928", "name": "Commented-code block (6 lines) in src/__tests__/feedback.test.js:319", "shortDescription": {"text": "Commented-code block (6 lines) in src/__tests__/feedback.test.js:319"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ad1f2c0971b89ce0", "name": "10 env vars used in code but missing from .env.example", "shortDescription": {"text": "10 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ACCESS_TOKEN_EXPIRE_MINUTES`, `APP_VERSION`, `GIT_COMMIT_MESSAGE_FILE`, `LOCK_FORCE_PASSWORD`, `NODE_ENV`, `NOTIFICATION_API_URL`, `PAYMENT_API_URL`, `PORT` + 2 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e9b38db1767a5db", "name": "FastAPI POST `create_user` without auth dependency \u2014 src/routes/member.py:37", "shortDescription": {"text": "FastAPI POST `create_user` without auth dependency \u2014 src/routes/member.py:37"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b3892850dd3e27b1", "name": "FastAPI PUT `update_user` without auth dependency \u2014 src/routes/member.py:71", "shortDescription": {"text": "FastAPI PUT `update_user` without auth dependency \u2014 src/routes/member.py:71"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-953f02d361890ddd", "name": "FastAPI DELETE `delete_user` without auth dependency \u2014 src/routes/member.py:80", "shortDescription": {"text": "FastAPI DELETE `delete_user` without auth dependency \u2014 src/routes/member.py:80"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ba753ca0de66df17", "name": "FastAPI POST `create_inventory_item` without auth dependency \u2014 src/routes/inventory.py:15", "shortDescription": {"text": "FastAPI POST `create_inventory_item` without auth dependency \u2014 src/routes/inventory.py:15"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7894a5b114709ef4", "name": "FastAPI POST `reserve` without auth dependency \u2014 src/routes/inventory.py:34", "shortDescription": {"text": "FastAPI POST `reserve` without auth dependency \u2014 src/routes/inventory.py:34"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a66c3bf03718b648", "name": "FastAPI POST `release` without auth dependency \u2014 src/routes/inventory.py:41", "shortDescription": {"text": "FastAPI POST `release` without auth dependency \u2014 src/routes/inventory.py:41"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8f4b52d4107663d1", "name": "FastAPI POST `create_payment` without auth dependency \u2014 src/routes/payment.py:40", "shortDescription": {"text": "FastAPI POST `create_payment` without auth dependency \u2014 src/routes/payment.py:40"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d9568ea089ce21de", "name": "FastAPI POST `complete_payment` without auth dependency \u2014 src/routes/payment.py:69", "shortDescription": {"text": "FastAPI POST `complete_payment` without auth dependency \u2014 src/routes/payment.py:69"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-df3a157a4d8e7f25", "name": "FastAPI POST `fail_payment` without auth dependency \u2014 src/routes/payment.py:78", "shortDescription": {"text": "FastAPI POST `fail_payment` without auth dependency \u2014 src/routes/payment.py:78"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1ce7285a9b33546f", "name": "FastAPI POST `create_log` without auth dependency \u2014 src/routes/admin.py:17", "shortDescription": {"text": "FastAPI POST `create_log` without auth dependency \u2014 src/routes/admin.py:17"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1ee6d0c4001f56da", "name": "FastAPI POST `log_user_action` without auth dependency \u2014 src/routes/admin.py:51", "shortDescription": {"text": "FastAPI POST `log_user_action` without auth dependency \u2014 src/routes/admin.py:51"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b904e82ab49155e0", "name": "FastAPI POST `create_category` without auth dependency \u2014 src/routes/shopping.py:21", "shortDescription": {"text": "FastAPI POST `create_category` without auth dependency \u2014 src/routes/shopping.py:21"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-21fbe99d11423e4d", "name": "FastAPI POST `create_product` without auth dependency \u2014 src/routes/shopping.py:38", "shortDescription": {"text": "FastAPI POST `create_product` without auth dependency \u2014 src/routes/shopping.py:38"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5bceb5b7fe1407af", "name": "FastAPI POST `send_notification` without auth dependency \u2014 src/routes/notification.py:17", "shortDescription": {"text": "FastAPI POST `send_notification` without auth dependency \u2014 src/routes/notification.py:17"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b616723568f6ed0f", "name": "FastAPI POST `mark_sent` without auth dependency \u2014 src/routes/notification.py:36", "shortDescription": {"text": "FastAPI POST `mark_sent` without auth dependency \u2014 src/routes/notification.py:36"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9a29dccc7ea4dc14", "name": "FastAPI POST `mark_failed` without auth dependency \u2014 src/routes/notification.py:43", "shortDescription": {"text": "FastAPI POST `mark_failed` without auth dependency \u2014 src/routes/notification.py:43"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b7d85c45bb6f4111", "name": "FastAPI POST `create_shipment` without auth dependency \u2014 src/routes/shipping.py:16", "shortDescription": {"text": "FastAPI POST `create_shipment` without auth dependency \u2014 src/routes/shipping.py:16"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-380cae91f173a236", "name": "FastAPI PUT `update_status` without auth dependency \u2014 src/routes/shipping.py:40", "shortDescription": {"text": "FastAPI PUT `update_status` without auth dependency \u2014 src/routes/shipping.py:40"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d18e9555e6f5d720", "name": "FastAPI POST `create_order` without auth dependency \u2014 src/routes/order.py:47", "shortDescription": {"text": "FastAPI POST `create_order` without auth dependency \u2014 src/routes/order.py:47"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7ce0ff3d89e8762e", "name": "FastAPI PUT `update_order_status` without auth dependency \u2014 src/routes/order.py:94", "shortDescription": {"text": "FastAPI PUT `update_order_status` without auth dependency \u2014 src/routes/order.py:94"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9a3df47576e208a4", "name": "FastAPI POST `cancel_order` without auth dependency \u2014 src/routes/order.py:108", "shortDescription": {"text": "FastAPI POST `cancel_order` without auth dependency \u2014 src/routes/order.py:108"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b441b1da9542b267", "name": "FastAPI POST `request_deletion` without auth dependency \u2014 src/routes/gdpr.py:24", "shortDescription": {"text": "FastAPI POST `request_deletion` without auth dependency \u2014 src/routes/gdpr.py:24"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c5aaea089a82c23b", "name": "FastAPI POST `request_export` without auth dependency \u2014 src/routes/gdpr.py:29", "shortDescription": {"text": "FastAPI POST `request_export` without auth dependency \u2014 src/routes/gdpr.py:29"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-10a6a1de1987510b", "name": "FastAPI POST `update_consent` without auth dependency \u2014 src/routes/gdpr.py:34", "shortDescription": {"text": "FastAPI POST `update_consent` without auth dependency \u2014 src/routes/gdpr.py:34"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8e85460df2d6cead", "name": "FastAPI POST `create_review` without auth dependency \u2014 src/routes/review.py:21", "shortDescription": {"text": "FastAPI POST `create_review` without auth dependency \u2014 src/routes/review.py:21"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-74723173825859cd", "name": "FastAPI POST `create_rating` without auth dependency \u2014 src/routes/review.py:43", "shortDescription": {"text": "FastAPI POST `create_rating` without auth dependency \u2014 src/routes/review.py:43"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-723e563122ca76c6", "name": "Dangling fetch: POST /api/orders/... (.claude/hooks/code-analyzer.js:156)", "shortDescription": {"text": "Dangling fetch: POST /api/orders/... (.claude/hooks/code-analyzer.js:156)"}, "fullDescription": {"text": "`.claude/hooks/code-analyzer.js:156` calls `POST /api/orders/...` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/orders/...`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`main.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`src/routes/member.py` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-627cdd6ec2c1df73", "name": "Unused endpoint: GET /{user_id}", "shortDescription": {"text": "Unused endpoint: GET /{user_id}"}, "fullDescription": {"text": "`src/routes/member.py` declares `GET /{user_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3cdc30f2b9308e3f", "name": "Unused endpoint: PUT /{user_id}", "shortDescription": {"text": "Unused endpoint: PUT /{user_id}"}, "fullDescription": {"text": "`src/routes/member.py` declares `PUT /{user_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-55c93ee7e031a509", "name": "Unused endpoint: DELETE /{user_id}", "shortDescription": {"text": "Unused endpoint: DELETE /{user_id}"}, "fullDescription": {"text": "`src/routes/member.py` declares `DELETE /{user_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2a8536d3fe9b321a", "name": "Unused endpoint: POST /items/", "shortDescription": {"text": "Unused endpoint: POST /items/"}, "fullDescription": {"text": "`src/routes/inventory.py` declares `POST /items/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-24839830176a6b46", "name": "Unused endpoint: GET /items/{item_id}", "shortDescription": {"text": "Unused endpoint: GET /items/{item_id}"}, "fullDescription": {"text": "`src/routes/inventory.py` declares `GET /items/{item_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3d074283d8f1ecd6", "name": "Unused endpoint: GET /product/{product_id}", "shortDescription": {"text": "Unused endpoint: GET /product/{product_id}"}, "fullDescription": {"text": "`src/routes/inventory.py` declares `GET /product/{product_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6fe52f3259ebbffe", "name": "Unused endpoint: POST /{item_id}/reserve", "shortDescription": {"text": "Unused endpoint: POST /{item_id}/reserve"}, "fullDescription": {"text": "`src/routes/inventory.py` declares `POST /{item_id}/reserve` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5dd5ccb3e7948a64", "name": "Unused endpoint: POST /{item_id}/release", "shortDescription": {"text": "Unused endpoint: POST /{item_id}/release"}, "fullDescription": {"text": "`src/routes/inventory.py` declares `POST /{item_id}/release` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-304b6f2b403d93f7", "name": "Unused endpoint: POST /register", "shortDescription": {"text": "Unused endpoint: POST /register"}, "fullDescription": {"text": "`src/routes/auth.py` declares `POST /register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`src/routes/auth.py` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd1dc91abf32142d", "name": "Unused endpoint: GET /me", "shortDescription": {"text": "Unused endpoint: GET /me"}, "fullDescription": {"text": "`src/routes/auth.py` declares `GET /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99fc36db98c134ce", "name": "Unused endpoint: POST /logout", "shortDescription": {"text": "Unused endpoint: POST /logout"}, "fullDescription": {"text": "`src/routes/auth.py` declares `POST /logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5bfeee7296fae138", "name": "Unused endpoint: GET /{payment_id}", "shortDescription": {"text": "Unused endpoint: GET /{payment_id}"}, "fullDescription": {"text": "`src/routes/payment.py` declares `GET /{payment_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f44ddfe8a04cfdf7", "name": "Unused endpoint: GET /order/{order_id}", "shortDescription": {"text": "Unused endpoint: GET /order/{order_id}"}, "fullDescription": {"text": "`src/routes/payment.py` declares `GET /order/{order_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-031d4787f081b2b8", "name": "Unused endpoint: POST /{payment_id}/complete", "shortDescription": {"text": "Unused endpoint: POST /{payment_id}/complete"}, "fullDescription": {"text": "`src/routes/payment.py` declares `POST /{payment_id}/complete` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3c9e750a103d5087", "name": "Unused endpoint: POST /{payment_id}/fail", "shortDescription": {"text": "Unused endpoint: POST /{payment_id}/fail"}, "fullDescription": {"text": "`src/routes/payment.py` declares `POST /{payment_id}/fail` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-995910dc13d5f338", "name": "Unused endpoint: POST /logs/", "shortDescription": {"text": "Unused endpoint: POST /logs/"}, "fullDescription": {"text": "`src/routes/admin.py` declares `POST /logs/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-abac7757ed24919a", "name": "Unused endpoint: GET /logs/{log_id}", "shortDescription": {"text": "Unused endpoint: GET /logs/{log_id}"}, "fullDescription": {"text": "`src/routes/admin.py` declares `GET /logs/{log_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1657be0d0073c191", "name": "Unused endpoint: GET /logs/admin/{admin_user_id}", "shortDescription": {"text": "Unused endpoint: GET /logs/admin/{admin_user_id}"}, "fullDescription": {"text": "`src/routes/admin.py` declares `GET /logs/admin/{admin_user_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4d93f8e64f3a3d1f", "name": "Unused endpoint: GET /logs/resource/{resource_type}/{resource_id}", "shortDescription": {"text": "Unused endpoint: GET /logs/resource/{resource_type}/{resource_id}"}, "fullDescription": {"text": "`src/routes/admin.py` declares `GET /logs/resource/{resource_type}/{resource_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-170e350371d09616", "name": "Unused endpoint: GET /logs/", "shortDescription": {"text": "Unused endpoint: GET /logs/"}, "fullDescription": {"text": "`src/routes/admin.py` declares `GET /logs/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f58a445c3ae09be", "name": "Unused endpoint: POST /logs/user-action/", "shortDescription": {"text": "Unused endpoint: POST /logs/user-action/"}, "fullDescription": {"text": "`src/routes/admin.py` declares `POST /logs/user-action/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-16ef5e13748eb751", "name": "Unused endpoint: POST /categories/", "shortDescription": {"text": "Unused endpoint: POST /categories/"}, "fullDescription": {"text": "`src/routes/shopping.py` declares `POST /categories/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-32b1f5c3d5732d57", "name": "Unused endpoint: GET /categories/", "shortDescription": {"text": "Unused endpoint: GET /categories/"}, "fullDescription": {"text": "`src/routes/shopping.py` declares `GET /categories/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d7fbfb3c5f137cf", "name": "Unused endpoint: GET /categories/{category_id}", "shortDescription": {"text": "Unused endpoint: GET /categories/{category_id}"}, "fullDescription": {"text": "`src/routes/shopping.py` declares `GET /categories/{category_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-42b1afeb9237fab6", "name": "Unused endpoint: POST /products/", "shortDescription": {"text": "Unused endpoint: POST /products/"}, "fullDescription": {"text": "`src/routes/shopping.py` declares `POST /products/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-57b89110ee581ac8", "name": "Unused endpoint: GET /products/", "shortDescription": {"text": "Unused endpoint: GET /products/"}, "fullDescription": {"text": "`src/routes/shopping.py` declares `GET /products/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-470acd7665628615", "name": "Unused endpoint: GET /products/{product_id}", "shortDescription": {"text": "Unused endpoint: GET /products/{product_id}"}, "fullDescription": {"text": "`src/routes/shopping.py` declares `GET /products/{product_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3fe062f80a10699", "name": "Unused endpoint: GET /products/category/{category_id}", "shortDescription": {"text": "Unused endpoint: GET /products/category/{category_id}"}, "fullDescription": {"text": "`src/routes/shopping.py` declares `GET /products/category/{category_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-04358f3f70a14f10", "name": "Unused endpoint: GET /featured/", "shortDescription": {"text": "Unused endpoint: GET /featured/"}, "fullDescription": {"text": "`src/routes/shopping.py` declares `GET /featured/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8990e797b221c95", "name": "Unused endpoint: GET /{notification_id}", "shortDescription": {"text": "Unused endpoint: GET /{notification_id}"}, "fullDescription": {"text": "`src/routes/notification.py` declares `GET /{notification_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-704af9c7c65c3a1c", "name": "Unused endpoint: GET /user/{user_id}", "shortDescription": {"text": "Unused endpoint: GET /user/{user_id}"}, "fullDescription": {"text": "`src/routes/notification.py` declares `GET /user/{user_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-83a1daa14d63d6ee", "name": "Unused endpoint: POST /{notification_id}/sent", "shortDescription": {"text": "Unused endpoint: POST /{notification_id}/sent"}, "fullDescription": {"text": "`src/routes/notification.py` declares `POST /{notification_id}/sent` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cac790cf2ea43c82", "name": "Unused endpoint: POST /{notification_id}/failed", "shortDescription": {"text": "Unused endpoint: POST /{notification_id}/failed"}, "fullDescription": {"text": "`src/routes/notification.py` declares `POST /{notification_id}/failed` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0289f2672742887f", "name": "Unused endpoint: GET /pending/list", "shortDescription": {"text": "Unused endpoint: GET /pending/list"}, "fullDescription": {"text": "`src/routes/notification.py` declares `GET /pending/list` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed66fceef9a94743", "name": "Unused endpoint: GET /{shipment_id}", "shortDescription": {"text": "Unused endpoint: GET /{shipment_id}"}, "fullDescription": {"text": "`src/routes/shipping.py` declares `GET /{shipment_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fc206947def1f7b7", "name": "Unused endpoint: GET /tracking/{tracking_number}", "shortDescription": {"text": "Unused endpoint: GET /tracking/{tracking_number}"}, "fullDescription": {"text": "`src/routes/shipping.py` declares `GET /tracking/{tracking_number}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-93f8c9111d6de118", "name": "Unused endpoint: PUT /{shipment_id}/status", "shortDescription": {"text": "Unused endpoint: PUT /{shipment_id}/status"}, "fullDescription": {"text": "`src/routes/shipping.py` declares `PUT /{shipment_id}/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3fbc4c468921afb", "name": "Unused endpoint: GET /{order_id}", "shortDescription": {"text": "Unused endpoint: GET /{order_id}"}, "fullDescription": {"text": "`src/routes/order.py` declares `GET /{order_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99c6276904c46397", "name": "Unused endpoint: PUT /{order_id}/status", "shortDescription": {"text": "Unused endpoint: PUT /{order_id}/status"}, "fullDescription": {"text": "`src/routes/order.py` declares `PUT /{order_id}/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a46ed6b4a52b1ee", "name": "Unused endpoint: POST /{order_id}/cancel", "shortDescription": {"text": "Unused endpoint: POST /{order_id}/cancel"}, "fullDescription": {"text": "`src/routes/order.py` declares `POST /{order_id}/cancel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-39548b6f8edc11d5", "name": "Unused endpoint: GET /data-subject/{user_id}", "shortDescription": {"text": "Unused endpoint: GET /data-subject/{user_id}"}, "fullDescription": {"text": "`src/routes/gdpr.py` declares `GET /data-subject/{user_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b5bb86a1cb5dcb03", "name": "Unused endpoint: POST /deletion-request/{user_id}", "shortDescription": {"text": "Unused endpoint: POST /deletion-request/{user_id}"}, "fullDescription": {"text": "`src/routes/gdpr.py` declares `POST /deletion-request/{user_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-21921d6293de0b21", "name": "Unused endpoint: POST /data-export/{user_id}", "shortDescription": {"text": "Unused endpoint: POST /data-export/{user_id}"}, "fullDescription": {"text": "`src/routes/gdpr.py` declares `POST /data-export/{user_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a51287a14fe3e788", "name": "Unused endpoint: POST /consent/{user_id}", "shortDescription": {"text": "Unused endpoint: POST /consent/{user_id}"}, "fullDescription": {"text": "`src/routes/gdpr.py` declares `POST /consent/{user_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-66c33a5f8ddb31a8", "name": "Unused endpoint: GET /consent-history/{user_id}", "shortDescription": {"text": "Unused endpoint: GET /consent-history/{user_id}"}, "fullDescription": {"text": "`src/routes/gdpr.py` declares `GET /consent-history/{user_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-54ccc47ca2002227", "name": "Unused endpoint: GET /deletion-requests/", "shortDescription": {"text": "Unused endpoint: GET /deletion-requests/"}, "fullDescription": {"text": "`src/routes/gdpr.py` declares `GET /deletion-requests/` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6861adfb0bf70cc4", "name": "Unused endpoint: GET /{review_id}", "shortDescription": {"text": "Unused endpoint: GET /{review_id}"}, "fullDescription": {"text": "`src/routes/review.py` declares `GET /{review_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/23686"}, "properties": {"repository": "zmjckim-fa/coolhan", "repoUrl": "https://github.com/zmjckim-fa/coolhan", "branch": "main"}, "results": [{"ruleId": "scanner-19b35cb77e91e0a4", "level": "note", "message": {"text": "Possibly dead Python function: require_admin"}, "properties": {"repobilityId": "3c06db2e25566bf7", "scanner": "scanner-primary", "fingerprint": "19b35cb77e91e0a4", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/auth.py:72"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d8b9dd9bfd8e95c5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 install.js:29"}, "properties": {"repobilityId": "ac0bc6d64db1c1c8", "scanner": "scanner-primary", "fingerprint": "d8b9dd9bfd8e95c5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1559de887fed9aef", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/check-update.js:105"}, "properties": {"repobilityId": "285f6eabfac6376d", "scanner": "scanner-primary", "fingerprint": "1559de887fed9aef", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1f3c4639abddedef", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 _workspace_prev_temp/03_code/src/server.js:47"}, "properties": {"repobilityId": "0301dcc04ada764f", "scanner": "scanner-primary", "fingerprint": "1f3c4639abddedef", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1410de647097e475", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 _workspace_prev_temp/03_code/src/routes/health.js:26"}, "properties": {"repobilityId": "de031b5ac82a14bf", "scanner": "scanner-primary", "fingerprint": "1410de647097e475", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d046746829a44e18", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/spec-validator.js:65"}, "properties": {"repobilityId": "a0162844320daf09", "scanner": "scanner-primary", "fingerprint": "d046746829a44e18", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d3a58169404a4ffe", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/spec-parser.js:214"}, "properties": {"repobilityId": "780136fc7d16679d", "scanner": "scanner-primary", "fingerprint": "d3a58169404a4ffe", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a2a3798f58e9f7fd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/deploy-lock.js:86"}, "properties": {"repobilityId": "03116cf94475a9ae", "scanner": "scanner-primary", "fingerprint": "a2a3798f58e9f7fd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-362e2cadbcf77267", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/code-analyzer.js:58"}, "properties": {"repobilityId": "a9dd2328689597ce", "scanner": "scanner-primary", "fingerprint": "362e2cadbcf77267", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-aee066fa57fc80a7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/post-deploy.js:283"}, "properties": {"repobilityId": "6ba9b761bf7d70c0", "scanner": "scanner-primary", "fingerprint": "aee066fa57fc80a7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-129e81d64a93846a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/pre-commit.js:291"}, "properties": {"repobilityId": "3e02f7fdf4b234bf", "scanner": "scanner-primary", "fingerprint": "129e81d64a93846a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-63a8caaa956e70b5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/pre-deploy.js:162"}, "properties": {"repobilityId": "ef9bc21079bd7756", "scanner": "scanner-primary", "fingerprint": "63a8caaa956e70b5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cebee65668c5fa01", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/check-update.js:118"}, "properties": {"repobilityId": "ee6e5e37a3ac2868", "scanner": "scanner-primary", "fingerprint": "cebee65668c5fa01", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-18a2c7b82a7a372a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 .claude/hooks/environment-validator.js:23"}, "properties": {"repobilityId": "11023a8ae0a42096", "scanner": "scanner-primary", "fingerprint": "18a2c7b82a7a372a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a12cb6674a96bf06", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 .claude/skills/coolhan-spec-driven-framework/scripts/generate-framework.js:21"}, "properties": {"repobilityId": "4a67674d4d4de8db", "scanner": "scanner-primary", "fingerprint": "a12cb6674a96bf06", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6240f941a3b056d2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 coverage/lcov-report/prettify.js:2"}, "properties": {"repobilityId": "f5469c712b31777f", "scanner": "scanner-primary", "fingerprint": "6240f941a3b056d2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8a51b5e9152e6d45", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server.js:54"}, "properties": {"repobilityId": "51ec0d6adae748e2", "scanner": "scanner-primary", "fingerprint": "8a51b5e9152e6d45", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5e9b3dd00923db3f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/routes/health.js:26"}, "properties": {"repobilityId": "057c71a688af9929", "scanner": "scanner-primary", "fingerprint": "5e9b3dd00923db3f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-de3c1f217d72a063", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "1de0ecd007803dbd", "scanner": "scanner-primary", "fingerprint": "de3c1f217d72a063", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-838774050c848d35", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in main.py:35"}, "properties": {"repobilityId": "7efce937690fb5d6", "scanner": "scanner-primary", "fingerprint": "838774050c848d35", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "main.py"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-d9ee597c5c14f1d5", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in install.js:17"}, "properties": {"repobilityId": "f2a0ed411b633f52", "scanner": "scanner-primary", "fingerprint": "d9ee597c5c14f1d5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "install.js"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-19b1bd93b3a62582", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in .claude/hooks/post-deploy.js:174"}, "properties": {"repobilityId": "5ba661c9e2dd0719", "scanner": "scanner-primary", "fingerprint": "19b1bd93b3a62582", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/hooks/post-deploy.js"}, "region": {"startLine": 174}}}]}, {"ruleId": "scanner-4d42c9c07528d06d", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in .claude/hooks/pre-commit.js:10"}, "properties": {"repobilityId": "9ea5d83d6261ff80", "scanner": "scanner-primary", "fingerprint": "4d42c9c07528d06d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/hooks/pre-commit.js"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-de5b1ac75596a01c", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in .claude/hooks/pre-deploy.js:8"}, "properties": {"repobilityId": "e321c6ee8fdc0040", "scanner": "scanner-primary", "fingerprint": "de5b1ac75596a01c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/hooks/pre-deploy.js"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-79e8a5298e120dd3", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in .claude/hooks/environment-validator.js:15"}, "properties": {"repobilityId": "2817bdb81a3060e7", "scanner": "scanner-primary", "fingerprint": "79e8a5298e120dd3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/hooks/environment-validator.js"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-561cf4fb66e16a0c", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in coverage/lcov-report/sorter.js:84"}, "properties": {"repobilityId": "3e42e111e0f73064", "scanner": "scanner-primary", "fingerprint": "561cf4fb66e16a0c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "coverage/lcov-report/sorter.js"}, "region": {"startLine": 84}}}]}, {"ruleId": "scanner-d38ab4c821f6de46", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in coverage/lcov-report/prettify.js:2"}, "properties": {"repobilityId": "f20a7741f511e6ea", "scanner": "scanner-primary", "fingerprint": "d38ab4c821f6de46", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "coverage/lcov-report/prettify.js"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-7efbda965f283c17", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "72b104470e1a3927", "scanner": "scanner-primary", "fingerprint": "7efbda965f283c17", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/test.yml"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-7efbda965f283c17", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "dfbb5c73610ac21c", "scanner": "scanner-primary", "fingerprint": "7efbda965f283c17", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/test.yml"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-7efbda965f283c17", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "72b104470e1a3927", "scanner": "scanner-primary", "fingerprint": "7efbda965f283c17", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/test.yml"}, "region": {"startLine": 265}}}]}, {"ruleId": "scanner-7efbda965f283c17", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "72b104470e1a3927", "scanner": "scanner-primary", "fingerprint": "7efbda965f283c17", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/test.yml"}, "region": {"startLine": 293}}}]}, {"ruleId": "scanner-7efbda965f283c17", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "dfbb5c73610ac21c", "scanner": "scanner-primary", "fingerprint": "7efbda965f283c17", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/test.yml"}, "region": {"startLine": 296}}}]}, {"ruleId": "scanner-46c644c6227e4d4a", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f60d9951f1477eef", "scanner": "scanner-primary", "fingerprint": "46c644c6227e4d4a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 81}}}]}, {"ruleId": "scanner-1838a141491ce38c", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "b8fd4f5048f96576", "scanner": "scanner-primary", "fingerprint": "1838a141491ce38c", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/release.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e9c970a16f87aa37", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "44662d14d0176514", "scanner": "scanner-primary", "fingerprint": "e9c970a16f87aa37", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/python-api.yml"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-a53bf972e19b52fd", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "6e41f096612c5e81", "scanner": "scanner-primary", "fingerprint": "a53bf972e19b52fd", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish.yml"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-a53bf972e19b52fd", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "e81242b34528b80b", "scanner": "scanner-primary", "fingerprint": "a53bf972e19b52fd", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish.yml"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-a53bf972e19b52fd", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "03bc0e843f2d6947", "scanner": "scanner-primary", "fingerprint": "a53bf972e19b52fd", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish.yml"}, "region": {"startLine": 73}}}]}, {"ruleId": "scanner-7ffa33751be3d771", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "491a3ad29cbaf189", "scanner": "scanner-primary", "fingerprint": "7ffa33751be3d771", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/publish.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "f94f95ddd1f959a6", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "e45146931670c21c", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "2855ed8fd6086ca0", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "9081fea9219d3d12", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ddef78f457004d8", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .claude/LOCAL_ENVIRONMENT_CONFIG.md"}, "properties": {"repobilityId": "fca59458c40a2b2a", "scanner": "scanner-primary", "fingerprint": "3ddef78f457004d8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/LOCAL_ENVIRONMENT_CONFIG.md"}, "region": {"startLine": 147}}}]}, {"ruleId": "scanner-f677e25ae345d9af", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .claude/PRODUCTION_ENVIRONMENT_CONFIG.md"}, "properties": {"repobilityId": "1dcda7955210966f", "scanner": "scanner-primary", "fingerprint": "f677e25ae345d9af", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/PRODUCTION_ENVIRONMENT_CONFIG.md"}, "region": {"startLine": 201}}}]}, {"ruleId": "scanner-eed6dd96ae1918c8", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .claude/DEPLOY_PROTOCOL.md"}, "properties": {"repobilityId": "96ce33420d705997", "scanner": "scanner-primary", "fingerprint": "eed6dd96ae1918c8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/DEPLOY_PROTOCOL.md"}, "region": {"startLine": 104}}}]}, {"ruleId": "scanner-8bf5f57fa96d86a2", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .claude/STAGING_ENVIRONMENT_CONFIG.md"}, "properties": {"repobilityId": "e21504920a8cc33c", "scanner": "scanner-primary", "fingerprint": "8bf5f57fa96d86a2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/STAGING_ENVIRONMENT_CONFIG.md"}, "region": {"startLine": 127}}}]}, {"ruleId": "scanner-7c46f119e7df66ee", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/agents/intent-analyzer.md"}, "properties": {"repobilityId": "a906c7ae471903c5", "scanner": "scanner-primary", "fingerprint": "7c46f119e7df66ee", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/agents/intent-analyzer.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d94e1c4b058cd7d8", "level": "warning", "message": {"text": "Agent instruction contains unpinned remote install: .claude/skills/coolhan-development-orchestrator/SKILL.md"}, "properties": {"repobilityId": "04f723717e023df4", "scanner": "scanner-primary", "fingerprint": "d94e1c4b058cd7d8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "supply-chain", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/coolhan-development-orchestrator/SKILL.md"}, "region": {"startLine": 604}}}]}, {"ruleId": "scanner-61ad81c117a86f34", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .claude/skills/coolhan-installer/SKILL.md"}, "properties": {"repobilityId": "ac421b69cfaf04d9", "scanner": "scanner-primary", "fingerprint": "61ad81c117a86f34", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/coolhan-installer/SKILL.md"}, "region": {"startLine": 171}}}]}, {"ruleId": "scanner-52dc791b56b0b633", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/coolhan-installer/SKILL.md"}, "properties": {"repobilityId": "2968203bc9475d9f", "scanner": "scanner-primary", "fingerprint": "52dc791b56b0b633", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/coolhan-installer/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a7a71c454dd21dd8", "level": "warning", "message": {"text": "Agent instruction contains unpinned remote install: .claude/skills/coolhan-installer/SKILL.md"}, "properties": {"repobilityId": "8d403ad337882bd1", "scanner": "scanner-primary", "fingerprint": "a7a71c454dd21dd8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "supply-chain", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/coolhan-installer/SKILL.md"}, "region": {"startLine": 82}}}]}, {"ruleId": "scanner-40066ca4cee9a928", "level": "none", "message": {"text": "Commented-code block (6 lines) in src/__tests__/feedback.test.js:319"}, "properties": {"repobilityId": "7271d4e759f5680a", "scanner": "scanner-primary", "fingerprint": "40066ca4cee9a928", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ad1f2c0971b89ce0", "level": "note", "message": {"text": "10 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "3bfdc60c61f1870e", "scanner": "scanner-primary", "fingerprint": "ad1f2c0971b89ce0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-8e9b38db1767a5db", "level": "error", "message": {"text": "FastAPI POST `create_user` without auth dependency \u2014 src/routes/member.py:37"}, "properties": {"repobilityId": "ab3baaa18948e786", "scanner": "scanner-primary", "fingerprint": "8e9b38db1767a5db", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/member.py"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-b3892850dd3e27b1", "level": "error", "message": {"text": "FastAPI PUT `update_user` without auth dependency \u2014 src/routes/member.py:71"}, "properties": {"repobilityId": "98bf08822907cc2a", "scanner": "scanner-primary", "fingerprint": "b3892850dd3e27b1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/member.py"}, "region": {"startLine": 71}}}]}, {"ruleId": "scanner-953f02d361890ddd", "level": "error", "message": {"text": "FastAPI DELETE `delete_user` without auth dependency \u2014 src/routes/member.py:80"}, "properties": {"repobilityId": "5aaed0c44ada373c", "scanner": "scanner-primary", "fingerprint": "953f02d361890ddd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/member.py"}, "region": {"startLine": 80}}}]}, {"ruleId": "scanner-ba753ca0de66df17", "level": "error", "message": {"text": "FastAPI POST `create_inventory_item` without auth dependency \u2014 src/routes/inventory.py:15"}, "properties": {"repobilityId": "90454ec9ce54ed71", "scanner": "scanner-primary", "fingerprint": "ba753ca0de66df17", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/inventory.py"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-7894a5b114709ef4", "level": "error", "message": {"text": "FastAPI POST `reserve` without auth dependency \u2014 src/routes/inventory.py:34"}, "properties": {"repobilityId": "a3de35a0cd78a735", "scanner": "scanner-primary", "fingerprint": "7894a5b114709ef4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/inventory.py"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-a66c3bf03718b648", "level": "error", "message": {"text": "FastAPI POST `release` without auth dependency \u2014 src/routes/inventory.py:41"}, "properties": {"repobilityId": "d9be3e8495654569", "scanner": "scanner-primary", "fingerprint": "a66c3bf03718b648", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/inventory.py"}, "region": {"startLine": 41}}}]}, {"ruleId": "scanner-8f4b52d4107663d1", "level": "error", "message": {"text": "FastAPI POST `create_payment` without auth dependency \u2014 src/routes/payment.py:40"}, "properties": {"repobilityId": "55fc6e1f08c52330", "scanner": "scanner-primary", "fingerprint": "8f4b52d4107663d1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/payment.py"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-d9568ea089ce21de", "level": "error", "message": {"text": "FastAPI POST `complete_payment` without auth dependency \u2014 src/routes/payment.py:69"}, "properties": {"repobilityId": "df181de87d0afde1", "scanner": "scanner-primary", "fingerprint": "d9568ea089ce21de", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/payment.py"}, "region": {"startLine": 69}}}]}, {"ruleId": "scanner-df3a157a4d8e7f25", "level": "error", "message": {"text": "FastAPI POST `fail_payment` without auth dependency \u2014 src/routes/payment.py:78"}, "properties": {"repobilityId": "1be23902e1a2a6a2", "scanner": "scanner-primary", "fingerprint": "df3a157a4d8e7f25", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/payment.py"}, "region": {"startLine": 78}}}]}, {"ruleId": "scanner-1ce7285a9b33546f", "level": "error", "message": {"text": "FastAPI POST `create_log` without auth dependency \u2014 src/routes/admin.py:17"}, "properties": {"repobilityId": "51bc2d4fd8c10bb4", "scanner": "scanner-primary", "fingerprint": "1ce7285a9b33546f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/admin.py"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-1ee6d0c4001f56da", "level": "error", "message": {"text": "FastAPI POST `log_user_action` without auth dependency \u2014 src/routes/admin.py:51"}, "properties": {"repobilityId": "d5d690bfffed08cd", "scanner": "scanner-primary", "fingerprint": "1ee6d0c4001f56da", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/admin.py"}, "region": {"startLine": 51}}}]}, {"ruleId": "scanner-b904e82ab49155e0", "level": "error", "message": {"text": "FastAPI POST `create_category` without auth dependency \u2014 src/routes/shopping.py:21"}, "properties": {"repobilityId": "3d310d5484b40bdc", "scanner": "scanner-primary", "fingerprint": "b904e82ab49155e0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/shopping.py"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-21fbe99d11423e4d", "level": "error", "message": {"text": "FastAPI POST `create_product` without auth dependency \u2014 src/routes/shopping.py:38"}, "properties": {"repobilityId": "78ab63c3ef6068af", "scanner": "scanner-primary", "fingerprint": "21fbe99d11423e4d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/shopping.py"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-5bceb5b7fe1407af", "level": "error", "message": {"text": "FastAPI POST `send_notification` without auth dependency \u2014 src/routes/notification.py:17"}, "properties": {"repobilityId": "8191e362d84c0659", "scanner": "scanner-primary", "fingerprint": "5bceb5b7fe1407af", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/notification.py"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-b616723568f6ed0f", "level": "error", "message": {"text": "FastAPI POST `mark_sent` without auth dependency \u2014 src/routes/notification.py:36"}, "properties": {"repobilityId": "103343c584159ccc", "scanner": "scanner-primary", "fingerprint": "b616723568f6ed0f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/notification.py"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-9a29dccc7ea4dc14", "level": "error", "message": {"text": "FastAPI POST `mark_failed` without auth dependency \u2014 src/routes/notification.py:43"}, "properties": {"repobilityId": "13b0cacab795d558", "scanner": "scanner-primary", "fingerprint": "9a29dccc7ea4dc14", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/notification.py"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-b7d85c45bb6f4111", "level": "error", "message": {"text": "FastAPI POST `create_shipment` without auth dependency \u2014 src/routes/shipping.py:16"}, "properties": {"repobilityId": "daa89e62c1942a4a", "scanner": "scanner-primary", "fingerprint": "b7d85c45bb6f4111", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/shipping.py"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-380cae91f173a236", "level": "error", "message": {"text": "FastAPI PUT `update_status` without auth dependency \u2014 src/routes/shipping.py:40"}, "properties": {"repobilityId": "7c0b1e8e93593d9f", "scanner": "scanner-primary", "fingerprint": "380cae91f173a236", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/shipping.py"}, "region": {"startLine": 40}}}]}, {"ruleId": "scanner-d18e9555e6f5d720", "level": "error", "message": {"text": "FastAPI POST `create_order` without auth dependency \u2014 src/routes/order.py:47"}, "properties": {"repobilityId": "c7efcc2eaca59104", "scanner": "scanner-primary", "fingerprint": "d18e9555e6f5d720", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/order.py"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-7ce0ff3d89e8762e", "level": "error", "message": {"text": "FastAPI PUT `update_order_status` without auth dependency \u2014 src/routes/order.py:94"}, "properties": {"repobilityId": "05446e6ce709dc02", "scanner": "scanner-primary", "fingerprint": "7ce0ff3d89e8762e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/order.py"}, "region": {"startLine": 94}}}]}, {"ruleId": "scanner-9a3df47576e208a4", "level": "error", "message": {"text": "FastAPI POST `cancel_order` without auth dependency \u2014 src/routes/order.py:108"}, "properties": {"repobilityId": "17fd25152825432b", "scanner": "scanner-primary", "fingerprint": "9a3df47576e208a4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/order.py"}, "region": {"startLine": 108}}}]}, {"ruleId": "scanner-b441b1da9542b267", "level": "error", "message": {"text": "FastAPI POST `request_deletion` without auth dependency \u2014 src/routes/gdpr.py:24"}, "properties": {"repobilityId": "dda38283137efa66", "scanner": "scanner-primary", "fingerprint": "b441b1da9542b267", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/gdpr.py"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-c5aaea089a82c23b", "level": "error", "message": {"text": "FastAPI POST `request_export` without auth dependency \u2014 src/routes/gdpr.py:29"}, "properties": {"repobilityId": "e697824423c730a2", "scanner": "scanner-primary", "fingerprint": "c5aaea089a82c23b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/gdpr.py"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-10a6a1de1987510b", "level": "error", "message": {"text": "FastAPI POST `update_consent` without auth dependency \u2014 src/routes/gdpr.py:34"}, "properties": {"repobilityId": "253a80d32835eb1c", "scanner": "scanner-primary", "fingerprint": "10a6a1de1987510b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/gdpr.py"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-8e85460df2d6cead", "level": "error", "message": {"text": "FastAPI POST `create_review` without auth dependency \u2014 src/routes/review.py:21"}, "properties": {"repobilityId": "7947e7a6c279b755", "scanner": "scanner-primary", "fingerprint": "8e85460df2d6cead", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/review.py"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-74723173825859cd", "level": "error", "message": {"text": "FastAPI POST `create_rating` without auth dependency \u2014 src/routes/review.py:43"}, "properties": {"repobilityId": "dd9fdc5cd67d1885", "scanner": "scanner-primary", "fingerprint": "74723173825859cd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/routes/review.py"}, "region": {"startLine": 43}}}]}, {"ruleId": "scanner-723e563122ca76c6", "level": "error", "message": {"text": "Dangling fetch: POST /api/orders/... (.claude/hooks/code-analyzer.js:156)"}, "properties": {"repobilityId": "eea0d40e197d6cdf", "scanner": "scanner-primary", "fingerprint": "723e563122ca76c6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "6b8de433dc23649f", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "9677d2badc3edd99", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-627cdd6ec2c1df73", "level": "note", "message": {"text": "Unused endpoint: GET /{user_id}"}, "properties": {"repobilityId": "5bd593a5addc8e4c", "scanner": "scanner-primary", "fingerprint": "627cdd6ec2c1df73", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3cdc30f2b9308e3f", "level": "note", "message": {"text": "Unused endpoint: PUT /{user_id}"}, "properties": {"repobilityId": "c04265257378c609", "scanner": "scanner-primary", "fingerprint": "3cdc30f2b9308e3f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-55c93ee7e031a509", "level": "note", "message": {"text": "Unused endpoint: DELETE /{user_id}"}, "properties": {"repobilityId": "63a6fdef5f7f33d1", "scanner": "scanner-primary", "fingerprint": "55c93ee7e031a509", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2a8536d3fe9b321a", "level": "note", "message": {"text": "Unused endpoint: POST /items/"}, "properties": {"repobilityId": "96dca85a537d45ec", "scanner": "scanner-primary", "fingerprint": "2a8536d3fe9b321a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-24839830176a6b46", "level": "note", "message": {"text": "Unused endpoint: GET /items/{item_id}"}, "properties": {"repobilityId": "a756e629f86fc499", "scanner": "scanner-primary", "fingerprint": "24839830176a6b46", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3d074283d8f1ecd6", "level": "note", "message": {"text": "Unused endpoint: GET /product/{product_id}"}, "properties": {"repobilityId": "04e179b320bb1713", "scanner": "scanner-primary", "fingerprint": "3d074283d8f1ecd6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6fe52f3259ebbffe", "level": "note", "message": {"text": "Unused endpoint: POST /{item_id}/reserve"}, "properties": {"repobilityId": "f89a8ea27ece8cd5", "scanner": "scanner-primary", "fingerprint": "6fe52f3259ebbffe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5dd5ccb3e7948a64", "level": "note", "message": {"text": "Unused endpoint: POST /{item_id}/release"}, "properties": {"repobilityId": "0ba1165e0244f0af", "scanner": "scanner-primary", "fingerprint": "5dd5ccb3e7948a64", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-304b6f2b403d93f7", "level": "note", "message": {"text": "Unused endpoint: POST /register"}, "properties": {"repobilityId": "ca4b39bb4acedcca", "scanner": "scanner-primary", "fingerprint": "304b6f2b403d93f7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "f8a5b9efd1f9754f", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd1dc91abf32142d", "level": "note", "message": {"text": "Unused endpoint: GET /me"}, "properties": {"repobilityId": "efe4d7a532fd3a91", "scanner": "scanner-primary", "fingerprint": "fd1dc91abf32142d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99fc36db98c134ce", "level": "note", "message": {"text": "Unused endpoint: POST /logout"}, "properties": {"repobilityId": "8bd47dfd8148bc18", "scanner": "scanner-primary", "fingerprint": "99fc36db98c134ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5bfeee7296fae138", "level": "note", "message": {"text": "Unused endpoint: GET /{payment_id}"}, "properties": {"repobilityId": "d44740239ca7bf06", "scanner": "scanner-primary", "fingerprint": "5bfeee7296fae138", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f44ddfe8a04cfdf7", "level": "note", "message": {"text": "Unused endpoint: GET /order/{order_id}"}, "properties": {"repobilityId": "6b1d01f39e1883af", "scanner": "scanner-primary", "fingerprint": "f44ddfe8a04cfdf7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-031d4787f081b2b8", "level": "note", "message": {"text": "Unused endpoint: POST /{payment_id}/complete"}, "properties": {"repobilityId": "91b3c988d23a3bc6", "scanner": "scanner-primary", "fingerprint": "031d4787f081b2b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3c9e750a103d5087", "level": "note", "message": {"text": "Unused endpoint: POST /{payment_id}/fail"}, "properties": {"repobilityId": "aa5830a0fd5147f6", "scanner": "scanner-primary", "fingerprint": "3c9e750a103d5087", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-995910dc13d5f338", "level": "note", "message": {"text": "Unused endpoint: POST /logs/"}, "properties": {"repobilityId": "01632c5b91803a18", "scanner": "scanner-primary", "fingerprint": "995910dc13d5f338", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-abac7757ed24919a", "level": "note", "message": {"text": "Unused endpoint: GET /logs/{log_id}"}, "properties": {"repobilityId": "218618ab8bb095d0", "scanner": "scanner-primary", "fingerprint": "abac7757ed24919a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1657be0d0073c191", "level": "note", "message": {"text": "Unused endpoint: GET /logs/admin/{admin_user_id}"}, "properties": {"repobilityId": "89272a482db6437d", "scanner": "scanner-primary", "fingerprint": "1657be0d0073c191", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4d93f8e64f3a3d1f", "level": "note", "message": {"text": "Unused endpoint: GET /logs/resource/{resource_type}/{resource_id}"}, "properties": {"repobilityId": "16ebddf2fead086b", "scanner": "scanner-primary", "fingerprint": "4d93f8e64f3a3d1f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-170e350371d09616", "level": "note", "message": {"text": "Unused endpoint: GET /logs/"}, "properties": {"repobilityId": "f3df7aafc02a411d", "scanner": "scanner-primary", "fingerprint": "170e350371d09616", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7f58a445c3ae09be", "level": "note", "message": {"text": "Unused endpoint: POST /logs/user-action/"}, "properties": {"repobilityId": "0307dedc7307d60b", "scanner": "scanner-primary", "fingerprint": "7f58a445c3ae09be", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-16ef5e13748eb751", "level": "note", "message": {"text": "Unused endpoint: POST /categories/"}, "properties": {"repobilityId": "036a4d2f4b8da284", "scanner": "scanner-primary", "fingerprint": "16ef5e13748eb751", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-32b1f5c3d5732d57", "level": "note", "message": {"text": "Unused endpoint: GET /categories/"}, "properties": {"repobilityId": "c852096aafc7bf09", "scanner": "scanner-primary", "fingerprint": "32b1f5c3d5732d57", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9d7fbfb3c5f137cf", "level": "note", "message": {"text": "Unused endpoint: GET /categories/{category_id}"}, "properties": {"repobilityId": "9b8463ad7d1c06ef", "scanner": "scanner-primary", "fingerprint": "9d7fbfb3c5f137cf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-42b1afeb9237fab6", "level": "note", "message": {"text": "Unused endpoint: POST /products/"}, "properties": {"repobilityId": "cfcdbac37bdc5d71", "scanner": "scanner-primary", "fingerprint": "42b1afeb9237fab6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-57b89110ee581ac8", "level": "note", "message": {"text": "Unused endpoint: GET /products/"}, "properties": {"repobilityId": "de4d124891a33efb", "scanner": "scanner-primary", "fingerprint": "57b89110ee581ac8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-470acd7665628615", "level": "note", "message": {"text": "Unused endpoint: GET /products/{product_id}"}, "properties": {"repobilityId": "128cd20182736dd3", "scanner": "scanner-primary", "fingerprint": "470acd7665628615", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b3fe062f80a10699", "level": "note", "message": {"text": "Unused endpoint: GET /products/category/{category_id}"}, "properties": {"repobilityId": "47f03d5c5bda5c47", "scanner": "scanner-primary", "fingerprint": "b3fe062f80a10699", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-04358f3f70a14f10", "level": "note", "message": {"text": "Unused endpoint: GET /featured/"}, "properties": {"repobilityId": "7d315afcd6f37cf4", "scanner": "scanner-primary", "fingerprint": "04358f3f70a14f10", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f8990e797b221c95", "level": "note", "message": {"text": "Unused endpoint: GET /{notification_id}"}, "properties": {"repobilityId": "a95ce66a4d6d8bd0", "scanner": "scanner-primary", "fingerprint": "f8990e797b221c95", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-704af9c7c65c3a1c", "level": "note", "message": {"text": "Unused endpoint: GET /user/{user_id}"}, "properties": {"repobilityId": "ea094d03669c2ef9", "scanner": "scanner-primary", "fingerprint": "704af9c7c65c3a1c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-83a1daa14d63d6ee", "level": "note", "message": {"text": "Unused endpoint: POST /{notification_id}/sent"}, "properties": {"repobilityId": "17cd90497146d713", "scanner": "scanner-primary", "fingerprint": "83a1daa14d63d6ee", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cac790cf2ea43c82", "level": "note", "message": {"text": "Unused endpoint: POST /{notification_id}/failed"}, "properties": {"repobilityId": "e1f346a01a8e5e73", "scanner": "scanner-primary", "fingerprint": "cac790cf2ea43c82", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0289f2672742887f", "level": "note", "message": {"text": "Unused endpoint: GET /pending/list"}, "properties": {"repobilityId": "88a0d2a22682fbc9", "scanner": "scanner-primary", "fingerprint": "0289f2672742887f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ed66fceef9a94743", "level": "note", "message": {"text": "Unused endpoint: GET /{shipment_id}"}, "properties": {"repobilityId": "8303606c1e900da8", "scanner": "scanner-primary", "fingerprint": "ed66fceef9a94743", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fc206947def1f7b7", "level": "note", "message": {"text": "Unused endpoint: GET /tracking/{tracking_number}"}, "properties": {"repobilityId": "7ec25a24cd1a16bd", "scanner": "scanner-primary", "fingerprint": "fc206947def1f7b7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-93f8c9111d6de118", "level": "note", "message": {"text": "Unused endpoint: PUT /{shipment_id}/status"}, "properties": {"repobilityId": "9976b00ccece5df7", "scanner": "scanner-primary", "fingerprint": "93f8c9111d6de118", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b3fbc4c468921afb", "level": "note", "message": {"text": "Unused endpoint: GET /{order_id}"}, "properties": {"repobilityId": "45cfd8bc1c3c772e", "scanner": "scanner-primary", "fingerprint": "b3fbc4c468921afb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99c6276904c46397", "level": "note", "message": {"text": "Unused endpoint: PUT /{order_id}/status"}, "properties": {"repobilityId": "7592c98a0ec44fec", "scanner": "scanner-primary", "fingerprint": "99c6276904c46397", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6a46ed6b4a52b1ee", "level": "note", "message": {"text": "Unused endpoint: POST /{order_id}/cancel"}, "properties": {"repobilityId": "217e9f9560174992", "scanner": "scanner-primary", "fingerprint": "6a46ed6b4a52b1ee", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-39548b6f8edc11d5", "level": "note", "message": {"text": "Unused endpoint: GET /data-subject/{user_id}"}, "properties": {"repobilityId": "7b0254907a694a55", "scanner": "scanner-primary", "fingerprint": "39548b6f8edc11d5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b5bb86a1cb5dcb03", "level": "note", "message": {"text": "Unused endpoint: POST /deletion-request/{user_id}"}, "properties": {"repobilityId": "78eb9b83e595a51d", "scanner": "scanner-primary", "fingerprint": "b5bb86a1cb5dcb03", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-21921d6293de0b21", "level": "note", "message": {"text": "Unused endpoint: POST /data-export/{user_id}"}, "properties": {"repobilityId": "a09567feef658c10", "scanner": "scanner-primary", "fingerprint": "21921d6293de0b21", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a51287a14fe3e788", "level": "note", "message": {"text": "Unused endpoint: POST /consent/{user_id}"}, "properties": {"repobilityId": "9f87fefd26c7a186", "scanner": "scanner-primary", "fingerprint": "a51287a14fe3e788", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-66c33a5f8ddb31a8", "level": "note", "message": {"text": "Unused endpoint: GET /consent-history/{user_id}"}, "properties": {"repobilityId": "dcb2bac6c4672231", "scanner": "scanner-primary", "fingerprint": "66c33a5f8ddb31a8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-54ccc47ca2002227", "level": "note", "message": {"text": "Unused endpoint: GET /deletion-requests/"}, "properties": {"repobilityId": "42904903e3801e5a", "scanner": "scanner-primary", "fingerprint": "54ccc47ca2002227", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6861adfb0bf70cc4", "level": "note", "message": {"text": "Unused endpoint: GET /{review_id}"}, "properties": {"repobilityId": "9030d32517af5ad6", "scanner": "scanner-primary", "fingerprint": "6861adfb0bf70cc4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}