{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-cf84f6ca0bbc2978", "name": "Possibly dead Python function: key", "shortDescription": {"text": "Possibly dead Python function: key"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e4e0e3516a90e7f", "name": "Privileged port 18 in use", "shortDescription": {"text": "Privileged port 18 in use"}, "fullDescription": {"text": "Port 18 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 26 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing ci. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b1d2ebb3fe2036f3", "name": "Agent authority lacks a verifier contract: GEMINI.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: GEMINI.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-10752ceb4d017948", "name": "Agent instruction/config may expose a secret: .mcp.json", "shortDescription": {"text": "Agent instruction/config may expose a secret: .mcp.json"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cc55229a7a3c078d", "name": "Agent authority lacks a verifier contract: .mcp.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .mcp.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bea357a6497a2d5d", "name": "Agent authority lacks a verifier contract: CLAUDE.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: CLAUDE.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e725d2ab884fbd49", "name": "Multiple root agent instruction files without precedence", "shortDescription": {"text": "Multiple root agent instruction files without precedence"}, "fullDescription": {"text": "The repo has multiple top-level AI-coder instruction files. Without precedence rules, different agents may follow different policies."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f37a2bbcccfbb4d", "name": "Legacy-named symbol `_derive_legacy` in dashboard/readers/ensembles.py:121", "shortDescription": {"text": "Legacy-named symbol `_derive_legacy` in dashboard/readers/ensembles.py:121"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\ndashboard/paths.py:baton_home, tools/paths.py:baton_home, kb/paths.py:baton_home\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bd96eeae239c1228", "name": "FastAPI POST `post_answer` without auth dependency \u2014 dashboard/routers/runs.py:59", "shortDescription": {"text": "FastAPI POST `post_answer` without auth dependency \u2014 dashboard/routers/runs.py:59"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e91a17eee1c88a1f", "name": "FastAPI POST `ollama_stop_all` without auth dependency \u2014 dashboard/routers/controls.py:10", "shortDescription": {"text": "FastAPI POST `ollama_stop_all` without auth dependency \u2014 dashboard/routers/controls.py:10"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-10596681938cb83e", "name": "FastAPI POST `lmstudio_load` without auth dependency \u2014 dashboard/routers/controls.py:37", "shortDescription": {"text": "FastAPI POST `lmstudio_load` without auth dependency \u2014 dashboard/routers/controls.py:37"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f5dd7f81331963e1", "name": "FastAPI POST `lmstudio_unload` without auth dependency \u2014 dashboard/routers/controls.py:51", "shortDescription": {"text": "FastAPI POST `lmstudio_unload` without auth dependency \u2014 dashboard/routers/controls.py:51"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3c75aad659d3a8bf", "name": "FastAPI POST `lmstudio_server_stop` without auth dependency \u2014 dashboard/routers/controls.py:65", "shortDescription": {"text": "FastAPI POST `lmstudio_server_stop` without auth dependency \u2014 dashboard/routers/controls.py:65"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`dashboard/main.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0b338974bfad8188", "name": "Unused endpoint: GET /partials/spend", "shortDescription": {"text": "Unused endpoint: GET /partials/spend"}, "fullDescription": {"text": "`dashboard/main.py` declares `GET /partials/spend` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-97907355391bca41", "name": "Unused endpoint: GET /partials/leaderboard", "shortDescription": {"text": "Unused endpoint: GET /partials/leaderboard"}, "fullDescription": {"text": "`dashboard/main.py` declares `GET /partials/leaderboard` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4a46c5f8fcd0672", "name": "Unused endpoint: GET /partials/activity", "shortDescription": {"text": "Unused endpoint: GET /partials/activity"}, "fullDescription": {"text": "`dashboard/main.py` declares `GET /partials/activity` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-15dea569069e0f75", "name": "Unused endpoint: GET /partials/controls", "shortDescription": {"text": "Unused endpoint: GET /partials/controls"}, "fullDescription": {"text": "`dashboard/main.py` declares `GET /partials/controls` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b423cc7553c08b0f", "name": "Unused endpoint: GET /partials/fleet", "shortDescription": {"text": "Unused endpoint: GET /partials/fleet"}, "fullDescription": {"text": "`dashboard/main.py` declares `GET /partials/fleet` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1e1ee09590b0a49", "name": "Unused endpoint: GET /projects", "shortDescription": {"text": "Unused endpoint: GET /projects"}, "fullDescription": {"text": "`dashboard/routers/projects.py` declares `GET /projects` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8276e9a42f5cb13a", "name": "Unused endpoint: GET /projects/{project_id}", "shortDescription": {"text": "Unused endpoint: GET /projects/{project_id}"}, "fullDescription": {"text": "`dashboard/routers/projects.py` declares `GET /projects/{project_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-233496d01067a7cf", "name": "Unused endpoint: GET /partials/projects", "shortDescription": {"text": "Unused endpoint: GET /partials/projects"}, "fullDescription": {"text": "`dashboard/routers/projects.py` declares `GET /partials/projects` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4ddcd4ae3187392c", "name": "Unused endpoint: GET /partials/runs", "shortDescription": {"text": "Unused endpoint: GET /partials/runs"}, "fullDescription": {"text": "`dashboard/routers/runs.py` declares `GET /partials/runs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-06b881b4c3ac37f1", "name": "Unused endpoint: GET /partials/assignments", "shortDescription": {"text": "Unused endpoint: GET /partials/assignments"}, "fullDescription": {"text": "`dashboard/routers/runs.py` declares `GET /partials/assignments` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-55f8c8cf959a5664", "name": "Unused endpoint: GET /runs/{run_id}", "shortDescription": {"text": "Unused endpoint: GET /runs/{run_id}"}, "fullDescription": {"text": "`dashboard/routers/runs.py` declares `GET /runs/{run_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5a3d3340b98b754f", "name": "Unused endpoint: GET /partials/runs/{run_id}", "shortDescription": {"text": "Unused endpoint: GET /partials/runs/{run_id}"}, "fullDescription": {"text": "`dashboard/routers/runs.py` declares `GET /partials/runs/{run_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f0c834451e7a81c", "name": "Unused endpoint: POST /runs/{run_id}/answer", "shortDescription": {"text": "Unused endpoint: POST /runs/{run_id}/answer"}, "fullDescription": {"text": "`dashboard/routers/runs.py` declares `POST /runs/{run_id}/answer` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f1b09f647f14d0f", "name": "Unused endpoint: GET /kb/search", "shortDescription": {"text": "Unused endpoint: GET /kb/search"}, "fullDescription": {"text": "`dashboard/routers/kb.py` declares `GET /kb/search` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b832aed7f3f2a70b", "name": "Unused endpoint: GET /partials/kb-search", "shortDescription": {"text": "Unused endpoint: GET /partials/kb-search"}, "fullDescription": {"text": "`dashboard/routers/kb.py` declares `GET /partials/kb-search` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b7f1a7d2e1913247", "name": "Unused endpoint: GET /partials/decision", "shortDescription": {"text": "Unused endpoint: GET /partials/decision"}, "fullDescription": {"text": "`dashboard/routers/kb.py` declares `GET /partials/decision` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7b2fe5f13da625b6", "name": "Unused endpoint: GET /partials/jobs", "shortDescription": {"text": "Unused endpoint: GET /partials/jobs"}, "fullDescription": {"text": "`dashboard/routers/jobs.py` declares `GET /partials/jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee53a8b03729481e", "name": "Unused endpoint: GET /jobs/{job_id}", "shortDescription": {"text": "Unused endpoint: GET /jobs/{job_id}"}, "fullDescription": {"text": "`dashboard/routers/jobs.py` declares `GET /jobs/{job_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee4faca43e1dd750", "name": "Unused endpoint: GET /partials/jobs/{job_id}", "shortDescription": {"text": "Unused endpoint: GET /partials/jobs/{job_id}"}, "fullDescription": {"text": "`dashboard/routers/jobs.py` declares `GET /partials/jobs/{job_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-006b26eba677fc33", "name": "Unused endpoint: POST /controls/ollama/stop-all", "shortDescription": {"text": "Unused endpoint: POST /controls/ollama/stop-all"}, "fullDescription": {"text": "`dashboard/routers/controls.py` declares `POST /controls/ollama/stop-all` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6fbf25e8c7d0d497", "name": "Unused endpoint: POST /controls/lmstudio/load", "shortDescription": {"text": "Unused endpoint: POST /controls/lmstudio/load"}, "fullDescription": {"text": "`dashboard/routers/controls.py` declares `POST /controls/lmstudio/load` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e4938867bfe3505", "name": "Unused endpoint: POST /controls/lmstudio/unload", "shortDescription": {"text": "Unused endpoint: POST /controls/lmstudio/unload"}, "fullDescription": {"text": "`dashboard/routers/controls.py` declares `POST /controls/lmstudio/unload` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fe91e97fefc19728", "name": "Unused endpoint: POST /controls/lmstudio/server/stop", "shortDescription": {"text": "Unused endpoint: POST /controls/lmstudio/server/stop"}, "fullDescription": {"text": "`dashboard/routers/controls.py` declares `POST /controls/lmstudio/server/stop` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b37265900e79a8a", "name": "Unused endpoint: GET /api/stats", "shortDescription": {"text": "Unused endpoint: GET /api/stats"}, "fullDescription": {"text": "`dashboard/routers/api.py` declares `GET /api/stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/18669"}, "properties": {"repository": "Ryfter/baton", "repoUrl": "https://github.com/Ryfter/baton", "branch": "main"}, "results": [{"ruleId": "scanner-cf84f6ca0bbc2978", "level": "note", "message": {"text": "Possibly dead Python function: key"}, "properties": {"repobilityId": "82ad9f64418e6fec", "scanner": "scanner-primary", "fingerprint": "cf84f6ca0bbc2978", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "kb/ab_eval.py:110"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6e4e0e3516a90e7f", "level": "warning", "message": {"text": "Privileged port 18 in use"}, "properties": {"repobilityId": "2d7b5e7d9c158e43", "scanner": "scanner-primary", "fingerprint": "6e4e0e3516a90e7f", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "references/prime-hours.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "ab337c803b9ea7c5", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "271b337bc437ae7f", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "f334ff09c5b344e8", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "9ef6e3da55b227f7", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-b1d2ebb3fe2036f3", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: GEMINI.md"}, "properties": {"repobilityId": "aed665d000b9a23e", "scanner": "scanner-primary", "fingerprint": "b1d2ebb3fe2036f3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "gemini_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "GEMINI.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-10752ceb4d017948", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .mcp.json"}, "properties": {"repobilityId": "3c83dd4fbca4a1df", "scanner": "scanner-primary", "fingerprint": "10752ceb4d017948", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "mcp_config"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".mcp.json"}, "region": {"startLine": 7}}}]}, {"ruleId": "scanner-cc55229a7a3c078d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .mcp.json"}, "properties": {"repobilityId": "51942fb3d5b8b5b4", "scanner": "scanner-primary", "fingerprint": "cc55229a7a3c078d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "mcp_config"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".mcp.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bea357a6497a2d5d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: CLAUDE.md"}, "properties": {"repobilityId": "aae72df3934829ac", "scanner": "scanner-primary", "fingerprint": "bea357a6497a2d5d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "CLAUDE.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e725d2ab884fbd49", "level": "note", "message": {"text": "Multiple root agent instruction files without precedence"}, "properties": {"repobilityId": "1953db6c89508d22", "scanner": "scanner-primary", "fingerprint": "e725d2ab884fbd49", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["agent-instructions", "governance"]}}, {"ruleId": "scanner-2f37a2bbcccfbb4d", "level": "note", "message": {"text": "Legacy-named symbol `_derive_legacy` in dashboard/readers/ensembles.py:121"}, "properties": {"repobilityId": "caab2eafcde32214", "scanner": "scanner-primary", "fingerprint": "2f37a2bbcccfbb4d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "8c752c36a7f594ba", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-bd96eeae239c1228", "level": "error", "message": {"text": "FastAPI POST `post_answer` without auth dependency \u2014 dashboard/routers/runs.py:59"}, "properties": {"repobilityId": "2b7871678e627f63", "scanner": "scanner-primary", "fingerprint": "bd96eeae239c1228", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/routers/runs.py"}, "region": {"startLine": 59}}}]}, {"ruleId": "scanner-e91a17eee1c88a1f", "level": "error", "message": {"text": "FastAPI POST `ollama_stop_all` without auth dependency \u2014 dashboard/routers/controls.py:10"}, "properties": {"repobilityId": "5b46e868a334900a", "scanner": "scanner-primary", "fingerprint": "e91a17eee1c88a1f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/routers/controls.py"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-10596681938cb83e", "level": "error", "message": {"text": "FastAPI POST `lmstudio_load` without auth dependency \u2014 dashboard/routers/controls.py:37"}, "properties": {"repobilityId": "ceab365c43867d24", "scanner": "scanner-primary", "fingerprint": "10596681938cb83e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/routers/controls.py"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-f5dd7f81331963e1", "level": "error", "message": {"text": "FastAPI POST `lmstudio_unload` without auth dependency \u2014 dashboard/routers/controls.py:51"}, "properties": {"repobilityId": "dc842be7ee6aedc5", "scanner": "scanner-primary", "fingerprint": "f5dd7f81331963e1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/routers/controls.py"}, "region": {"startLine": 51}}}]}, {"ruleId": "scanner-3c75aad659d3a8bf", "level": "error", "message": {"text": "FastAPI POST `lmstudio_server_stop` without auth dependency \u2014 dashboard/routers/controls.py:65"}, "properties": {"repobilityId": "02c05ca196f09eaf", "scanner": "scanner-primary", "fingerprint": "3c75aad659d3a8bf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard/routers/controls.py"}, "region": {"startLine": 65}}}]}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "c8f8fb19f05bf31d", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0b338974bfad8188", "level": "note", "message": {"text": "Unused endpoint: GET /partials/spend"}, "properties": {"repobilityId": "1ff34f72d80c03da", "scanner": "scanner-primary", "fingerprint": "0b338974bfad8188", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-97907355391bca41", "level": "note", "message": {"text": "Unused endpoint: GET /partials/leaderboard"}, "properties": {"repobilityId": "641a56eafdd3cfce", "scanner": "scanner-primary", "fingerprint": "97907355391bca41", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b4a46c5f8fcd0672", "level": "note", "message": {"text": "Unused endpoint: GET /partials/activity"}, "properties": {"repobilityId": "31c923bad3d31db8", "scanner": "scanner-primary", "fingerprint": "b4a46c5f8fcd0672", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-15dea569069e0f75", "level": "note", "message": {"text": "Unused endpoint: GET /partials/controls"}, "properties": {"repobilityId": "e7e5d16b063dc4c3", "scanner": "scanner-primary", "fingerprint": "15dea569069e0f75", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b423cc7553c08b0f", "level": "note", "message": {"text": "Unused endpoint: GET /partials/fleet"}, "properties": {"repobilityId": "e7003c0231d39821", "scanner": "scanner-primary", "fingerprint": "b423cc7553c08b0f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c1e1ee09590b0a49", "level": "note", "message": {"text": "Unused endpoint: GET /projects"}, "properties": {"repobilityId": "f6a3e434e144f1f4", "scanner": "scanner-primary", "fingerprint": "c1e1ee09590b0a49", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8276e9a42f5cb13a", "level": "note", "message": {"text": "Unused endpoint: GET /projects/{project_id}"}, "properties": {"repobilityId": "a8042acee965d15d", "scanner": "scanner-primary", "fingerprint": "8276e9a42f5cb13a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-233496d01067a7cf", "level": "note", "message": {"text": "Unused endpoint: GET /partials/projects"}, "properties": {"repobilityId": "c49d357149046112", "scanner": "scanner-primary", "fingerprint": "233496d01067a7cf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4ddcd4ae3187392c", "level": "note", "message": {"text": "Unused endpoint: GET /partials/runs"}, "properties": {"repobilityId": "4b1f7af5efba718d", "scanner": "scanner-primary", "fingerprint": "4ddcd4ae3187392c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-06b881b4c3ac37f1", "level": "note", "message": {"text": "Unused endpoint: GET /partials/assignments"}, "properties": {"repobilityId": "79ae7f73a7dde0b4", "scanner": "scanner-primary", "fingerprint": "06b881b4c3ac37f1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-55f8c8cf959a5664", "level": "note", "message": {"text": "Unused endpoint: GET /runs/{run_id}"}, "properties": {"repobilityId": "0740dbc7507f40f6", "scanner": "scanner-primary", "fingerprint": "55f8c8cf959a5664", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5a3d3340b98b754f", "level": "note", "message": {"text": "Unused endpoint: GET /partials/runs/{run_id}"}, "properties": {"repobilityId": "b5c10d3ab764364e", "scanner": "scanner-primary", "fingerprint": "5a3d3340b98b754f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2f0c834451e7a81c", "level": "note", "message": {"text": "Unused endpoint: POST /runs/{run_id}/answer"}, "properties": {"repobilityId": "cccf40da31758fae", "scanner": "scanner-primary", "fingerprint": "2f0c834451e7a81c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1f1b09f647f14d0f", "level": "note", "message": {"text": "Unused endpoint: GET /kb/search"}, "properties": {"repobilityId": "21c4ed6d3da79ba0", "scanner": "scanner-primary", "fingerprint": "1f1b09f647f14d0f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b832aed7f3f2a70b", "level": "note", "message": {"text": "Unused endpoint: GET /partials/kb-search"}, "properties": {"repobilityId": "4702b27fd1bc484f", "scanner": "scanner-primary", "fingerprint": "b832aed7f3f2a70b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b7f1a7d2e1913247", "level": "note", "message": {"text": "Unused endpoint: GET /partials/decision"}, "properties": {"repobilityId": "bcca1dda22b0e55e", "scanner": "scanner-primary", "fingerprint": "b7f1a7d2e1913247", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7b2fe5f13da625b6", "level": "note", "message": {"text": "Unused endpoint: GET /partials/jobs"}, "properties": {"repobilityId": "b916abfeebe92b65", "scanner": "scanner-primary", "fingerprint": "7b2fe5f13da625b6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ee53a8b03729481e", "level": "note", "message": {"text": "Unused endpoint: GET /jobs/{job_id}"}, "properties": {"repobilityId": "81f1a010bf58422b", "scanner": "scanner-primary", "fingerprint": "ee53a8b03729481e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ee4faca43e1dd750", "level": "note", "message": {"text": "Unused endpoint: GET /partials/jobs/{job_id}"}, "properties": {"repobilityId": "3f544728138d0ae9", "scanner": "scanner-primary", "fingerprint": "ee4faca43e1dd750", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-006b26eba677fc33", "level": "note", "message": {"text": "Unused endpoint: POST /controls/ollama/stop-all"}, "properties": {"repobilityId": "aed6fd3bae553445", "scanner": "scanner-primary", "fingerprint": "006b26eba677fc33", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6fbf25e8c7d0d497", "level": "note", "message": {"text": "Unused endpoint: POST /controls/lmstudio/load"}, "properties": {"repobilityId": "6b10b9134934b64e", "scanner": "scanner-primary", "fingerprint": "6fbf25e8c7d0d497", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8e4938867bfe3505", "level": "note", "message": {"text": "Unused endpoint: POST /controls/lmstudio/unload"}, "properties": {"repobilityId": "10d795d968f28841", "scanner": "scanner-primary", "fingerprint": "8e4938867bfe3505", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fe91e97fefc19728", "level": "note", "message": {"text": "Unused endpoint: POST /controls/lmstudio/server/stop"}, "properties": {"repobilityId": "d604f24aef1f803f", "scanner": "scanner-primary", "fingerprint": "fe91e97fefc19728", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3b37265900e79a8a", "level": "note", "message": {"text": "Unused endpoint: GET /api/stats"}, "properties": {"repobilityId": "8c3a720cac9bc6a4", "scanner": "scanner-primary", "fingerprint": "3b37265900e79a8a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}