{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-b10825628918a132", "name": "Possibly dead Python function: process_bind_param", "shortDescription": {"text": "Possibly dead Python function: process_bind_param"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c24ccf8e08307a1d", "name": "Possibly dead Python function: process_result_value", "shortDescription": {"text": "Possibly dead Python function: process_result_value"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f66ad88286ca30a", "name": "Dockerfile runs as root: backend/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: backend/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-714c31ca9f474ae6", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cac3c8fafe3827eb", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-updates.html:262", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-updates.html:262"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b28c1ee21f34cd3a", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-trace.html:245", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-trace.html:245"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-afcd48690c0b812b", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-settings.html:401", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-settings.html:401"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea3e2171dbf6f752", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-meeting-detail.html:396", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-meeting-detail.html:396"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b398f08497b5dfb5", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/projects-new.html:501", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/projects-new.html:501"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-03fddd30e58e58c7", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/login.html:140", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/login.html:140"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fe204165dfad5f40", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/projects.html:278", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/projects.html:278"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-be3f451882da8451", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-meetings.html:208", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-meetings.html:208"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9c001e0c27457294", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-chat.html:270", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-chat.html:270"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8d4f8a46cabd92a9", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/js/nav.js:66", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/js/nav.js:66"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-caa6635dc73b94c6", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/js/app.js:138", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/js/app.js:138"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1af4322af8309c81", "name": "Insecure pattern 'local_storage_auth_token' in docs/design-concept/concept-navigation/js/app.js:20", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in docs/design-concept/concept-navigation/js/app.js:20"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 13 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 54 placeholder/mock markers across 36 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, ci. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cc55229a7a3c078d", "name": "Agent authority lacks a verifier contract: .mcp.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .mcp.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-57e78c399738e8a3", "name": "Agent authority lacks a verifier contract: wiki/domains/agents.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: wiki/domains/agents.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-122f91b7f2906dc4", "name": "Agent authority lacks a verifier contract: .claude/settings.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/settings.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-505bc666a82f9849", "name": "Agent instruction/config may expose a secret: .claude/settings.local.json", "shortDescription": {"text": "Agent instruction/config may expose a secret: .claude/settings.local.json"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2c5f98b152cddb6d", "name": "Agent authority lacks a verifier contract: .claude/launch.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/launch.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e725d2ab884fbd49", "name": "Multiple root agent instruction files without precedence", "shortDescription": {"text": "Multiple root agent instruction files without precedence"}, "fullDescription": {"text": "The repo has multiple top-level AI-coder instruction files. Without precedence rules, different agents may follow different policies."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-37805c74ecf8d5c1", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/lib/api.ts:27", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/lib/api.ts:27"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d3986664d48e90f1", "name": "Commented-code block (5 lines) in apps/web/lib/auth.ts:3", "shortDescription": {"text": "Commented-code block (5 lines) in apps/web/lib/auth.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-319e66a630e14977", "name": "2 env vars used in code but missing from .env.example", "shortDescription": {"text": "2 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `CI`, `NEXT_PUBLIC_API_BASE_URL`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-902551594084ecc5", "name": "Unused endpoint: POST /integrations/google/start", "shortDescription": {"text": "Unused endpoint: POST /integrations/google/start"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `POST /integrations/google/start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5d0f7fb986f5389c", "name": "Unused endpoint: GET /integrations/google/callback", "shortDescription": {"text": "Unused endpoint: GET /integrations/google/callback"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `GET /integrations/google/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-930a90d5a5b9f0b5", "name": "Unused endpoint: POST /integrations/jira/test", "shortDescription": {"text": "Unused endpoint: POST /integrations/jira/test"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `POST /integrations/jira/test` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-95a0a140ad0c6bac", "name": "Unused endpoint: POST /integrations/notion/test", "shortDescription": {"text": "Unused endpoint: POST /integrations/notion/test"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `POST /integrations/notion/test` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-de2935726a0f216a", "name": "Unused endpoint: GET /{project_id}/meetings", "shortDescription": {"text": "Unused endpoint: GET /{project_id}/meetings"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `GET /{project_id}/meetings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99e66b6604732aea", "name": "Unused endpoint: GET /{project_id}/settings/agent", "shortDescription": {"text": "Unused endpoint: GET /{project_id}/settings/agent"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `GET /{project_id}/settings/agent` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a3252c0fa84f1e7a", "name": "Unused endpoint: PUT /{project_id}/settings/agent", "shortDescription": {"text": "Unused endpoint: PUT /{project_id}/settings/agent"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `PUT /{project_id}/settings/agent` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-83d883dc2a34eaa5", "name": "Unused endpoint: GET /{project_id}/billing", "shortDescription": {"text": "Unused endpoint: GET /{project_id}/billing"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `GET /{project_id}/billing` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-271f7f6f9b00d323", "name": "Unused endpoint: GET /{project_id}/integrations", "shortDescription": {"text": "Unused endpoint: GET /{project_id}/integrations"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `GET /{project_id}/integrations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5634d9b475154f9d", "name": "Unused endpoint: PUT /{project_id}/integrations/jira", "shortDescription": {"text": "Unused endpoint: PUT /{project_id}/integrations/jira"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `PUT /{project_id}/integrations/jira` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9bffed39c58ed39f", "name": "Unused endpoint: PUT /{project_id}/integrations/notion", "shortDescription": {"text": "Unused endpoint: PUT /{project_id}/integrations/notion"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `PUT /{project_id}/integrations/notion` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5ce2e323ef47ee53", "name": "Unused endpoint: PUT /{project_id}/integrations/google", "shortDescription": {"text": "Unused endpoint: PUT /{project_id}/integrations/google"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `PUT /{project_id}/integrations/google` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-46259bf8691a5d80", "name": "Unused endpoint: POST /{project_id}/integrations/{provider}/test", "shortDescription": {"text": "Unused endpoint: POST /{project_id}/integrations/{provider}/test"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `POST /{project_id}/integrations/{provider}/test` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-106f3e7fc5f65e4f", "name": "Unused endpoint: GET /{project_id}", "shortDescription": {"text": "Unused endpoint: GET /{project_id}"}, "fullDescription": {"text": "`backend/app/routers/projects.py` declares `GET /{project_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3d3bb7b8a4e0c87f", "name": "Unused endpoint: GET /google/start", "shortDescription": {"text": "Unused endpoint: GET /google/start"}, "fullDescription": {"text": "`backend/app/routers/auth.py` declares `GET /google/start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-424854ab10436e86", "name": "Unused endpoint: GET /google/callback", "shortDescription": {"text": "Unused endpoint: GET /google/callback"}, "fullDescription": {"text": "`backend/app/routers/auth.py` declares `GET /google/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd1dc91abf32142d", "name": "Unused endpoint: GET /me", "shortDescription": {"text": "Unused endpoint: GET /me"}, "fullDescription": {"text": "`backend/app/routers/auth.py` declares `GET /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bd0c2f1b4f41a8be", "name": "Unused endpoint: GET /directory", "shortDescription": {"text": "Unused endpoint: GET /directory"}, "fullDescription": {"text": "`backend/app/routers/users.py` declares `GET /directory` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/18885"}, "properties": {"repository": "SanCHEESE/ScrumAgent", "repoUrl": "https://github.com/SanCHEESE/ScrumAgent", "branch": "main"}, "results": [{"ruleId": "scanner-b10825628918a132", "level": "note", "message": {"text": "Possibly dead Python function: process_bind_param"}, "properties": {"repobilityId": "a51428934072abb6", "scanner": "scanner-primary", "fingerprint": "b10825628918a132", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/models/types.py:39"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c24ccf8e08307a1d", "level": "note", "message": {"text": "Possibly dead Python function: process_result_value"}, "properties": {"repobilityId": "2b4ef95eaf3928de", "scanner": "scanner-primary", "fingerprint": "c24ccf8e08307a1d", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/app/models/types.py:42"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1f66ad88286ca30a", "level": "warning", "message": {"text": "Dockerfile runs as root: backend/Dockerfile"}, "properties": {"repobilityId": "7afd2b0e8a8c9eeb", "scanner": "scanner-primary", "fingerprint": "1f66ad88286ca30a", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-714c31ca9f474ae6", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "f614a1e41f331b37", "scanner": "scanner-primary", "fingerprint": "714c31ca9f474ae6", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-cac3c8fafe3827eb", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-updates.html:262"}, "properties": {"repobilityId": "3d1701d85496e1bd", "scanner": "scanner-primary", "fingerprint": "cac3c8fafe3827eb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/design-concept/concept-navigation/project-updates.html"}, "region": {"startLine": 262}}}]}, {"ruleId": "scanner-b28c1ee21f34cd3a", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-trace.html:245"}, "properties": {"repobilityId": "23ce330cdba87bed", "scanner": "scanner-primary", "fingerprint": "b28c1ee21f34cd3a", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/design-concept/concept-navigation/project-trace.html"}, "region": {"startLine": 245}}}]}, {"ruleId": "scanner-afcd48690c0b812b", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-settings.html:401"}, "properties": {"repobilityId": "d1269cb4b2223417", "scanner": "scanner-primary", "fingerprint": "afcd48690c0b812b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/design-concept/concept-navigation/project-settings.html"}, "region": {"startLine": 401}}}]}, {"ruleId": "scanner-ea3e2171dbf6f752", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-meeting-detail.html:396"}, "properties": {"repobilityId": "ae276ae9d8e005f4", "scanner": "scanner-primary", "fingerprint": "ea3e2171dbf6f752", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/design-concept/concept-navigation/project-meeting-detail.html"}, "region": {"startLine": 396}}}]}, {"ruleId": "scanner-b398f08497b5dfb5", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/projects-new.html:501"}, "properties": {"repobilityId": "651a61a9eae55531", "scanner": "scanner-primary", "fingerprint": "b398f08497b5dfb5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/design-concept/concept-navigation/projects-new.html"}, "region": {"startLine": 501}}}]}, {"ruleId": "scanner-03fddd30e58e58c7", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/login.html:140"}, "properties": {"repobilityId": "7f41279b76504aa9", "scanner": "scanner-primary", "fingerprint": "03fddd30e58e58c7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/design-concept/concept-navigation/login.html"}, "region": {"startLine": 140}}}]}, {"ruleId": "scanner-fe204165dfad5f40", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/projects.html:278"}, "properties": {"repobilityId": "b74625b562a5cba9", "scanner": "scanner-primary", "fingerprint": "fe204165dfad5f40", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/design-concept/concept-navigation/projects.html"}, "region": {"startLine": 278}}}]}, {"ruleId": "scanner-be3f451882da8451", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-meetings.html:208"}, "properties": {"repobilityId": "6fb6ef46777f51e2", "scanner": "scanner-primary", "fingerprint": "be3f451882da8451", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/design-concept/concept-navigation/project-meetings.html"}, "region": {"startLine": 208}}}]}, {"ruleId": "scanner-9c001e0c27457294", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/project-chat.html:270"}, "properties": {"repobilityId": "a01906501f05f3fd", "scanner": "scanner-primary", "fingerprint": "9c001e0c27457294", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/design-concept/concept-navigation/project-chat.html"}, "region": {"startLine": 270}}}]}, {"ruleId": "scanner-8d4f8a46cabd92a9", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/js/nav.js:66"}, "properties": {"repobilityId": "b3c9b843e739193f", "scanner": "scanner-primary", "fingerprint": "8d4f8a46cabd92a9", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/design-concept/concept-navigation/js/nav.js"}, "region": {"startLine": 66}}}]}, {"ruleId": "scanner-caa6635dc73b94c6", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/design-concept/concept-navigation/js/app.js:138"}, "properties": {"repobilityId": "cdc5b18294139e49", "scanner": "scanner-primary", "fingerprint": "caa6635dc73b94c6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/design-concept/concept-navigation/js/app.js"}, "region": {"startLine": 138}}}]}, {"ruleId": "scanner-1af4322af8309c81", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in docs/design-concept/concept-navigation/js/app.js:20"}, "properties": {"repobilityId": "9592e02d215210e0", "scanner": "scanner-primary", "fingerprint": "1af4322af8309c81", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/design-concept/concept-navigation/js/app.js"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "cf665d3fcc87366c", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "2bb98f9f9ef85407", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "a9b8f31b784c9b8d", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "5746f7f2c46ad1d6", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "c7698ef0c627ae94", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "bf2f3438c87279f9", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "a02db0a140fca0b3", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "6b7ceac877ddea3a", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-cc55229a7a3c078d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .mcp.json"}, "properties": {"repobilityId": "51942fb3d5b8b5b4", "scanner": "scanner-primary", "fingerprint": "cc55229a7a3c078d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "mcp_config"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".mcp.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-57e78c399738e8a3", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: wiki/domains/agents.md"}, "properties": {"repobilityId": "8836df965e6868fa", "scanner": "scanner-primary", "fingerprint": "57e78c399738e8a3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "agents_md"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "wiki/domains/agents.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-122f91b7f2906dc4", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/settings.json"}, "properties": {"repobilityId": "a2967269048b6a9d", "scanner": "scanner-primary", "fingerprint": "122f91b7f2906dc4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/settings.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-505bc666a82f9849", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .claude/settings.local.json"}, "properties": {"repobilityId": "777970b0fce0a93b", "scanner": "scanner-primary", "fingerprint": "505bc666a82f9849", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/settings.local.json"}, "region": {"startLine": 83}}}]}, {"ruleId": "scanner-2c5f98b152cddb6d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/launch.json"}, "properties": {"repobilityId": "0de48c0f4ab303d8", "scanner": "scanner-primary", "fingerprint": "2c5f98b152cddb6d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/launch.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e725d2ab884fbd49", "level": "note", "message": {"text": "Multiple root agent instruction files without precedence"}, "properties": {"repobilityId": "1953db6c89508d22", "scanner": "scanner-primary", "fingerprint": "e725d2ab884fbd49", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["agent-instructions", "governance"]}}, {"ruleId": "scanner-37805c74ecf8d5c1", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/lib/api.ts:27"}, "properties": {"repobilityId": "1c0ffaf5a36decb1", "scanner": "scanner-primary", "fingerprint": "37805c74ecf8d5c1", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-d3986664d48e90f1", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/web/lib/auth.ts:3"}, "properties": {"repobilityId": "219c54644625e461", "scanner": "scanner-primary", "fingerprint": "d3986664d48e90f1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-319e66a630e14977", "level": "none", "message": {"text": "2 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "d838d1fc5d8231c9", "scanner": "scanner-primary", "fingerprint": "319e66a630e14977", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-902551594084ecc5", "level": "note", "message": {"text": "Unused endpoint: POST /integrations/google/start"}, "properties": {"repobilityId": "a3b83200d8a04877", "scanner": "scanner-primary", "fingerprint": "902551594084ecc5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5d0f7fb986f5389c", "level": "note", "message": {"text": "Unused endpoint: GET /integrations/google/callback"}, "properties": {"repobilityId": "98964f956ce27f53", "scanner": "scanner-primary", "fingerprint": "5d0f7fb986f5389c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-930a90d5a5b9f0b5", "level": "note", "message": {"text": "Unused endpoint: POST /integrations/jira/test"}, "properties": {"repobilityId": "76e20b32cc705f46", "scanner": "scanner-primary", "fingerprint": "930a90d5a5b9f0b5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-95a0a140ad0c6bac", "level": "note", "message": {"text": "Unused endpoint: POST /integrations/notion/test"}, "properties": {"repobilityId": "88f84406196dad7b", "scanner": "scanner-primary", "fingerprint": "95a0a140ad0c6bac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "cd21e499dddd78a8", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "58f557b58301b281", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-de2935726a0f216a", "level": "note", "message": {"text": "Unused endpoint: GET /{project_id}/meetings"}, "properties": {"repobilityId": "822ca43b8d0229a1", "scanner": "scanner-primary", "fingerprint": "de2935726a0f216a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99e66b6604732aea", "level": "note", "message": {"text": "Unused endpoint: GET /{project_id}/settings/agent"}, "properties": {"repobilityId": "65038970831030b0", "scanner": "scanner-primary", "fingerprint": "99e66b6604732aea", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a3252c0fa84f1e7a", "level": "note", "message": {"text": "Unused endpoint: PUT /{project_id}/settings/agent"}, "properties": {"repobilityId": "be0b4d44339fbba8", "scanner": "scanner-primary", "fingerprint": "a3252c0fa84f1e7a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-83d883dc2a34eaa5", "level": "note", "message": {"text": "Unused endpoint: GET /{project_id}/billing"}, "properties": {"repobilityId": "b44bc73dd5672164", "scanner": "scanner-primary", "fingerprint": "83d883dc2a34eaa5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-271f7f6f9b00d323", "level": "note", "message": {"text": "Unused endpoint: GET /{project_id}/integrations"}, "properties": {"repobilityId": "817641e6b2c303e4", "scanner": "scanner-primary", "fingerprint": "271f7f6f9b00d323", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5634d9b475154f9d", "level": "note", "message": {"text": "Unused endpoint: PUT /{project_id}/integrations/jira"}, "properties": {"repobilityId": "64ea2f8cbdf02a48", "scanner": "scanner-primary", "fingerprint": "5634d9b475154f9d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9bffed39c58ed39f", "level": "note", "message": {"text": "Unused endpoint: PUT /{project_id}/integrations/notion"}, "properties": {"repobilityId": "19a96a56cb3edb8e", "scanner": "scanner-primary", "fingerprint": "9bffed39c58ed39f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5ce2e323ef47ee53", "level": "note", "message": {"text": "Unused endpoint: PUT /{project_id}/integrations/google"}, "properties": {"repobilityId": "38a0bb6bd4e705cd", "scanner": "scanner-primary", "fingerprint": "5ce2e323ef47ee53", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-46259bf8691a5d80", "level": "note", "message": {"text": "Unused endpoint: POST /{project_id}/integrations/{provider}/test"}, "properties": {"repobilityId": "5d52306e2f7455d8", "scanner": "scanner-primary", "fingerprint": "46259bf8691a5d80", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-106f3e7fc5f65e4f", "level": "note", "message": {"text": "Unused endpoint: GET /{project_id}"}, "properties": {"repobilityId": "b815ab0594653940", "scanner": "scanner-primary", "fingerprint": "106f3e7fc5f65e4f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3d3bb7b8a4e0c87f", "level": "note", "message": {"text": "Unused endpoint: GET /google/start"}, "properties": {"repobilityId": "3e7dbc118e6b854d", "scanner": "scanner-primary", "fingerprint": "3d3bb7b8a4e0c87f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-424854ab10436e86", "level": "note", "message": {"text": "Unused endpoint: GET /google/callback"}, "properties": {"repobilityId": "54bf054325748bf4", "scanner": "scanner-primary", "fingerprint": "424854ab10436e86", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd1dc91abf32142d", "level": "note", "message": {"text": "Unused endpoint: GET /me"}, "properties": {"repobilityId": "d59abcc5b893707a", "scanner": "scanner-primary", "fingerprint": "fd1dc91abf32142d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bd0c2f1b4f41a8be", "level": "note", "message": {"text": "Unused endpoint: GET /directory"}, "properties": {"repobilityId": "0edfc3dae92faf1c", "scanner": "scanner-primary", "fingerprint": "bd0c2f1b4f41a8be", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}