{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-8835197a2e64b2d8", "name": "Stray `console.log` in TS/JS \u2014 scripts/check-spec-coverage.ts:69", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/check-spec-coverage.ts:69"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd8e815a2b1c5eb8", "name": "Stray `console.log` in TS/JS \u2014 scripts/generate-go-contract.ts:73", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-go-contract.ts:73"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-462b1654766e855f", "name": "Stray `console.log` in TS/JS \u2014 scripts/check-type-escapes.ts:80", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/check-type-escapes.ts:80"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0204ae6eb422a54b", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/ai-elements/tool.tsx:38", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/ai-elements/tool.tsx:38"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8cd593b9bd21440c", "name": "`truncate` class without `title=` for hover reveal \u2014 src/console/components.tsx:126", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/console/components.tsx:126"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-875b34b8ef287191", "name": "`truncate` class without `title=` for hover reveal \u2014 src/features/usage/UsageView.tsx:43", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/usage/UsageView.tsx:43"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-db402478de61ebd7", "name": "`truncate` class without `title=` for hover reveal \u2014 src/features/mcp/McpView.tsx:69", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/mcp/McpView.tsx:69"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-708eaf3e9d52d3fa", "name": "`truncate` class without `title=` for hover reveal \u2014 src/features/sessions/SessionDetailView.tsx:63", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/sessions/SessionDetailView.tsx:63"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f784d705dcabae16", "name": "`truncate` class without `title=` for hover reveal \u2014 src/features/sessions/SessionsView.tsx:87", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/sessions/SessionsView.tsx:87"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2025aa06e65a990c", "name": "`truncate` class without `title=` for hover reveal \u2014 src/features/providers/ProviderPolicyPage.tsx:63", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/providers/ProviderPolicyPage.tsx:63"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6fa75676b7838420", "name": "`truncate` class without `title=` for hover reveal \u2014 src/features/providers/ProvidersView.tsx:45", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/providers/ProvidersView.tsx:45"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-17a90b1896a15d4b", "name": "`truncate` class without `title=` for hover reveal \u2014 src/features/audit/AuditView.tsx:42", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/audit/AuditView.tsx:42"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5a60f5e3057afc1e", "name": "`truncate` class without `title=` for hover reveal \u2014 src/features/agents/AgentsView.tsx:42", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/agents/AgentsView.tsx:42"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6439ffacce83e9ce", "name": "`truncate` class without `title=` for hover reveal \u2014 src/features/vaults/VaultDetailView.tsx:112", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/vaults/VaultDetailView.tsx:112"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a0922e76db83d74d", "name": "`truncate` class without `title=` for hover reveal \u2014 src/features/vaults/VaultsView.tsx:42", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/vaults/VaultsView.tsx:42"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-944b26b531826f17", "name": "`truncate` class without `title=` for hover reveal \u2014 src/features/console/related-resources-table.tsx:44", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/console/related-resources-table.tsx:44"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e9bef6605ee849b7", "name": "`truncate` class without `title=` for hover reveal \u2014 src/features/console/ConsoleShell.tsx:48", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/console/ConsoleShell.tsx:48"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-56ba77978c387631", "name": "`truncate` class without `title=` for hover reveal \u2014 src/features/environments/EnvironmentsView.tsx:52", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/environments/EnvironmentsView.tsx:52"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d63da3583b14afc0", "name": "Dockerfile runs as root: Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-365754187babc1cc", "name": "Docker base image is tag-pinned but not digest-pinned: docker.io/cloudflare/sandbox:0.10.1", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: docker.io/cloudflare/sandbox:0.10.1"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-241a6f49387cfdfa", "name": "Insecure pattern 'node_child_process' in scripts/smoke-runtime.mjs:11", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/smoke-runtime.mjs:11"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-323a38cc7e4ec904", "name": "Insecure pattern 'node_child_process' in scripts/generate-go-contract.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/generate-go-contract.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d7892825061dad9e", "name": "Insecure pattern 'node_child_process' in server/sdk-layout.test.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in server/sdk-layout.test.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eaedc0d8b7cb0934", "name": "Insecure pattern 'exec_used' in server/adapters/runtime/sandbox-runtime-host.ts:140", "shortDescription": {"text": "Insecure pattern 'exec_used' in server/adapters/runtime/sandbox-runtime-host.ts:140"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-220d796f899690a8", "name": "Insecure pattern 'exec_used' in server/adapters/runtime/sandbox-tool-executor.test.ts:194", "shortDescription": {"text": "Insecure pattern 'exec_used' in server/adapters/runtime/sandbox-tool-executor.test.ts:194"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c78545b1e0577604", "name": "Insecure pattern 'node_child_process' in runtime-bridge/src/providers/claude-code.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in runtime-bridge/src/providers/claude-code.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1b7bc91df721f2c6", "name": "Insecure pattern 'node_child_process' in runtime-bridge/src/providers/cli-host.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in runtime-bridge/src/providers/cli-host.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2a155d4d8bccce94", "name": "Insecure pattern 'node_child_process' in runtime-bridge/src/providers/copilot.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in runtime-bridge/src/providers/copilot.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-71286040a3447c56", "name": "Insecure pattern 'exec_used' in runtime-bridge/src/providers/ama.ts:268", "shortDescription": {"text": "Insecure pattern 'exec_used' in runtime-bridge/src/providers/ama.ts:268"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-75dfb84f480818b0", "name": "Insecure pattern 'node_child_process' in runtime-bridge/src/providers/ama.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in runtime-bridge/src/providers/ama.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-93dc89ac7925c1d2", "name": "Insecure pattern 'local_storage_auth_token' in src/App.test.tsx:672", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in src/App.test.tsx:672"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ef3fe680553ef836", "name": "Insecure pattern 'local_storage_auth_token' in src/lib/oidc.test.ts:63", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in src/lib/oidc.test.ts:63"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-144b88dc8b972a4c", "name": "Insecure pattern 'local_storage_auth_token' in src/lib/api.test.ts:6", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in src/lib/api.test.ts:6"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ec40442ea7b7ae9c", "name": "Insecure pattern 'local_storage_auth_token' in e2e/fixtures.ts:56", "shortDescription": {"text": "Insecure pattern 'local_storage_auth_token' in e2e/fixtures.ts:56"}, "fullDescription": {"text": "Found a known-risky pattern (local_storage_auth_token). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-96a8a827200d29af", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0836e961e2b57ada", "name": "Very large file: cmd/ama-runner/runner_test.go (1486 lines)", "shortDescription": {"text": "Very large file: cmd/ama-runner/runner_test.go (1486 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e05c5abfb964c0fa", "name": "Very large file: server/integration/sessions.test.ts (1759 lines)", "shortDescription": {"text": "Very large file: server/integration/sessions.test.ts (1759 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c1e497b93ab59d69", "name": "Very large file: server/usecases/ports.ts (2600 lines)", "shortDescription": {"text": "Very large file: server/usecases/ports.ts (2600 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f685abc61ba16b3e", "name": "Very large file: src/features/sessions/sessions-pages.test.tsx (2161 lines)", "shortDescription": {"text": "Very large file: src/features/sessions/sessions-pages.test.tsx (2161 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f6a0bab83c93583", "name": "Very large file: src/features/vaults/vaults-ui.test.tsx (1424 lines)", "shortDescription": {"text": "Very large file: src/features/vaults/vaults-ui.test.tsx (1424 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f787d2602003cc60", "name": "Node manifest has dependencies but no lockfile: sdk/typescript/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: sdk/typescript/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 14 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 47 placeholder/mock markers across 15 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d79c4077342a7d0", "name": "Runtime service client appears to use placeholder configuration", "shortDescription": {"text": "Runtime service client appears to use placeholder configuration"}, "fullDescription": {"text": "A runtime source file appears to wire Supabase/Firebase/AI/payment-style clients to placeholder URLs, keys, or fallback values. In the Fable corpus this often means the UI/API shape is present while the backend service is not actually configured."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-434f999bd08be46d", "name": "Commented-code block (5 lines) in eslint.config.js:1", "shortDescription": {"text": "Commented-code block (5 lines) in eslint.config.js:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a4183946dbe835e1", "name": "Commented-code block (5 lines) in vitest.config.ts:15", "shortDescription": {"text": "Commented-code block (5 lines) in vitest.config.ts:15"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5dbafa3cb4db8e03", "name": "Commented-code block (5 lines) in shared/runtime-rows.ts:1", "shortDescription": {"text": "Commented-code block (5 lines) in shared/runtime-rows.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a048ff5db42a0ae6", "name": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/generate-openapi-and-sdks.ts:82", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/generate-openapi-and-sdks.ts:82"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ae2fefb14ffeaae0", "name": "Commented-code block (5 lines) in scripts/generate-go-contract.ts:6", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/generate-go-contract.ts:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bd3d4357193173d9", "name": "Commented-code block (6 lines) in scripts/check-type-escapes.ts:38", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/check-type-escapes.ts:38"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-78b5a853723c4855", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/api-contracts.test.ts:15", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/api-contracts.test.ts:15"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8e46ad5bec80edc5", "name": "Commented-code block (12 lines) in server/app.ts:61", "shortDescription": {"text": "Commented-code block (12 lines) in server/app.ts:61"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f8a0b6c933096ec1", "name": "Commented-code block (5 lines) in server/policy.ts:68", "shortDescription": {"text": "Commented-code block (5 lines) in server/policy.ts:68"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a1e6b31db69bfd9c", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/worker.ts:14", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/worker.ts:14"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-591fe9c6dd98059c", "name": "Commented-code block (5 lines) in server/adapters/repos/leases.ts:100", "shortDescription": {"text": "Commented-code block (5 lines) in server/adapters/repos/leases.ts:100"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6d06536a6d03133b", "name": "Commented-code block (6 lines) in server/adapters/repos/runtime-orchestration.ts:67", "shortDescription": {"text": "Commented-code block (6 lines) in server/adapters/repos/runtime-orchestration.ts:67"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-125f09e02a7fab3f", "name": "Commented-code block (6 lines) in server/adapters/runtime/sandbox-runtime-host.ts:23", "shortDescription": {"text": "Commented-code block (6 lines) in server/adapters/runtime/sandbox-runtime-host.ts:23"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-19909a5d50804cc0", "name": "Commented-code block (5 lines) in server/adapters/runtime/sandbox-tool-executor.ts:120", "shortDescription": {"text": "Commented-code block (5 lines) in server/adapters/runtime/sandbox-tool-executor.ts:120"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b1ba31c45c60905c", "name": "Commented-code block (9 lines) in server/adapters/gateways/runtime-secret-env.ts:40", "shortDescription": {"text": "Commented-code block (9 lines) in server/adapters/gateways/runtime-secret-env.ts:40"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9143fcb48b53282e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/adapters/gateways/secret-store.ts:49", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/adapters/gateways/secret-store.ts:49"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1bb7adb2f67a5b3f", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/adapters/gateways/runner-channel.ts:13", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/adapters/gateways/runner-channel.ts:13"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c40d2182c991d5ac", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/health.test.ts:7", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/health.test.ts:7"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-af584dda260bbc28", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/budgets.test.ts:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/budgets.test.ts:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aaf8d5a4d0438249", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/runtimes.test.ts:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/runtimes.test.ts:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-801feee72619e8d3", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/runners.test.ts:9", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/runners.test.ts:9"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0de2584251121350", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/agents.test.ts:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/agents.test.ts:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-58696efe584da4ac", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/federated-tenants.test.ts:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/federated-tenants.test.ts:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-48f490b5fd797a1f", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/providers-governance.test.ts:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/providers-governance.test.ts:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-81c149ead6735983", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/leases.test.ts:10", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/leases.test.ts:10"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-658cc4fb3c5de4ae", "name": "Commented-code block (5 lines) in server/integration/sdk-contract.test.ts:7", "shortDescription": {"text": "Commented-code block (5 lines) in server/integration/sdk-contract.test.ts:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bf17fe36c220cf18", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/sdk-contract.test.ts:8", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/sdk-contract.test.ts:8"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-701601c0811e6ccc", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/connectors.test.ts:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/connectors.test.ts:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-efb14941d7f8f5d9", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/effective-policy.test.ts:8", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/effective-policy.test.ts:8"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-103c8460296a608e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/access-rules.test.ts:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/access-rules.test.ts:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-13b440bdc5ec4d60", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/usage-summary.test.ts:10", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/usage-summary.test.ts:10"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-560ceaea7ac7dcdc", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/policies.test.ts:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/policies.test.ts:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0e6dd10ee5063ac2", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/work-items.test.ts:9", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/work-items.test.ts:9"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-738958f3d586e220", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/vaults.test.ts:7", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/vaults.test.ts:7"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-70a277a46d96e7b1", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/environments.test.ts:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/environments.test.ts:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-efe983bd420b46c6", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/sessions.test.ts:11", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/sessions.test.ts:11"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f0c8ad7fb888fc74", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/usage-records.test.ts:10", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/usage-records.test.ts:10"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f5b9ab48f3548023", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/auth.test.ts:10", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/auth.test.ts:10"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7364298534331ad6", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/openapi.test.ts:46", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/openapi.test.ts:46"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4f355e09e1a812f3", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/connections.test.ts:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/connections.test.ts:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-223ac8993b74ab24", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/restish-openapi.test.ts:17", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/restish-openapi.test.ts:17"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-17bb1a3e6e06adaa", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/providers.test.ts:10", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/providers.test.ts:10"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fb20fda14c148886", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/triggers.test.ts:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/triggers.test.ts:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d475cff9a1214c77", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/audit-records.test.ts:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/audit-records.test.ts:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0a2d31dc01a8f54b", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/runtime-ai.test.ts:6", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/runtime-ai.test.ts:6"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8d9b6266dc83aa47", "name": "Commented-code block (5 lines) in server/auth/oidc.ts:332", "shortDescription": {"text": "Commented-code block (5 lines) in server/auth/oidc.ts:332"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c6e0edfe00c03ae4", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/auth/oidc.ts:132", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/auth/oidc.ts:132"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ca0528cd079e877", "name": "Commented-code block (5 lines) in server/auth/session.ts:216", "shortDescription": {"text": "Commented-code block (5 lines) in server/auth/session.ts:216"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b3f19aba9ebb05b2", "name": "Commented-code block (8 lines) in server/worker/runner-session-channel.ts:1", "shortDescription": {"text": "Commented-code block (8 lines) in server/worker/runner-session-channel.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9c0698f2ff1fee17", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/worker/runner-session-channel.ts:30", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/worker/runner-session-channel.ts:30"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0e7cfc4afc6896af", "name": "Commented-code block (5 lines) in server/http/auth.ts:146", "shortDescription": {"text": "Commented-code block (5 lines) in server/http/auth.ts:146"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-02e8b2699fe1f937", "name": "Commented-code block (6 lines) in server/http/e2e.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in server/http/e2e.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6e01188302113943", "name": "Commented-code block (6 lines) in server/http/runtime-proxy.ts:30", "shortDescription": {"text": "Commented-code block (6 lines) in server/http/runtime-proxy.ts:30"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3bf35887459d02d8", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server/http/leases.ts:288", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/http/leases.ts:288"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e27fb184a1a0ad42", "name": "Commented-code block (5 lines) in server/http/federated-tenants.ts:217", "shortDescription": {"text": "Commented-code block (5 lines) in server/http/federated-tenants.ts:217"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-15e2085fb8f32f02", "name": "Commented-code block (6 lines) in server/http/sessions.ts:358", "shortDescription": {"text": "Commented-code block (6 lines) in server/http/sessions.ts:358"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-be8f603691cd20a5", "name": "Commented-code block (5 lines) in server/http/audit-records.ts:192", "shortDescription": {"text": "Commented-code block (5 lines) in server/http/audit-records.ts:192"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-17b9a57e8a4263bc", "name": "Commented-code block (5 lines) in server/http/usage-records.ts:195", "shortDescription": {"text": "Commented-code block (5 lines) in server/http/usage-records.ts:195"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7d9991d09d3fe982", "name": "Commented-code block (8 lines) in server/db/schema.ts:4", "shortDescription": {"text": "Commented-code block (8 lines) in server/db/schema.ts:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-809e118cf4aaae99", "name": "Commented-code block (6 lines) in server/usecases/ports.ts:227", "shortDescription": {"text": "Commented-code block (6 lines) in server/usecases/ports.ts:227"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-5ddd022482e785b3", "name": "Commented-code block (5 lines) in server/usecases/providers.ts:137", "shortDescription": {"text": "Commented-code block (5 lines) in server/usecases/providers.ts:137"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-496f48c7430f6a3b", "name": "Commented-code block (7 lines) in server/usecases/leases.ts:18", "shortDescription": {"text": "Commented-code block (7 lines) in server/usecases/leases.ts:18"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-42f2726437fdddb2", "name": "Commented-code block (6 lines) in server/usecases/runtime/turn-callbacks.test.ts:4", "shortDescription": {"text": "Commented-code block (6 lines) in server/usecases/runtime/turn-callbacks.test.ts:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b2033f2d8f18ad7a", "name": "Commented-code block (8 lines) in server/usecases/runtime/runner-channel-ingest.ts:5", "shortDescription": {"text": "Commented-code block (8 lines) in server/usecases/runtime/runner-channel-ingest.ts:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-41d53f10595e5264", "name": "Commented-code block (6 lines) in server/usecases/runtime/cloud-turn.test.ts:10", "shortDescription": {"text": "Commented-code block (6 lines) in server/usecases/runtime/cloud-turn.test.ts:10"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-25b5a8afd21138d9", "name": "Commented-code block (6 lines) in server/usecases/runtime/cloud-turn.ts:3", "shortDescription": {"text": "Commented-code block (6 lines) in server/usecases/runtime/cloud-turn.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c593944ea5352442", "name": "Commented-code block (6 lines) in server/usecases/runtime/turn-callbacks.ts:3", "shortDescription": {"text": "Commented-code block (6 lines) in server/usecases/runtime/turn-callbacks.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1a415d2f8da1a416", "name": "Commented-code block (6 lines) in server/usecases/runtime/session-approval.ts:8", "shortDescription": {"text": "Commented-code block (6 lines) in server/usecases/runtime/session-approval.ts:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-07ac0835ef1b4062", "name": "Commented-code block (6 lines) in server/usecases/runtime/session-create.ts:3", "shortDescription": {"text": "Commented-code block (6 lines) in server/usecases/runtime/session-create.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-bb9733b0cd1375b3", "name": "Commented-code block (9 lines) in server/usecases/runtime/sessions.ts:3", "shortDescription": {"text": "Commented-code block (9 lines) in server/usecases/runtime/sessions.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-666988ba27f3d2c7", "name": "Commented-code block (5 lines) in server/usecases/runtime/approval-gate.ts:3", "shortDescription": {"text": "Commented-code block (5 lines) in server/usecases/runtime/approval-gate.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6dcdb6bac02af868", "name": "Commented-code block (6 lines) in server/usecases/runtime/provisioning.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in server/usecases/runtime/provisioning.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6bae1d7cde945eb3", "name": "Commented-code block (6 lines) in server/usecases/runtime/events.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in server/usecases/runtime/events.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-79e7a492f32a63cc", "name": "Commented-code block (6 lines) in server/usecases/runtime/proxy.ts:3", "shortDescription": {"text": "Commented-code block (6 lines) in server/usecases/runtime/proxy.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ed912e2efe479a9f", "name": "Commented-code block (5 lines) in server/usecases/runtime/session-create.test.ts:9", "shortDescription": {"text": "Commented-code block (5 lines) in server/usecases/runtime/session-create.test.ts:9"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-99f75de35605971c", "name": "Commented-code block (5 lines) in server/usecases/runtime/session-prompt.ts:7", "shortDescription": {"text": "Commented-code block (5 lines) in server/usecases/runtime/session-prompt.ts:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-899991e8f109fc87", "name": "Commented-code block (6 lines) in server/domain/provider-adapter.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in server/domain/provider-adapter.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ba6407d710f446f3", "name": "Commented-code block (5 lines) in server/domain/runtime-catalog.ts:20", "shortDescription": {"text": "Commented-code block (5 lines) in server/domain/runtime-catalog.ts:20"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9d1142ebd91c2bdc", "name": "Legacy-named symbol `org_old` in server/domain/policy.test.ts:118", "shortDescription": {"text": "Legacy-named symbol `org_old` in server/domain/policy.test.ts:118"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a5be60e8db2f9f04", "name": "Commented-code block (5 lines) in server/domain/policy.ts:3", "shortDescription": {"text": "Commented-code block (5 lines) in server/domain/policy.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e3178bda481022a2", "name": "Commented-code block (5 lines) in server/domain/runtime/provider.ts:1", "shortDescription": {"text": "Commented-code block (5 lines) in server/domain/runtime/provider.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6b93ff0441aae1cc", "name": "Commented-code block (6 lines) in server/domain/runtime/system-auth.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in server/domain/runtime/system-auth.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f50b186a6ead2a6a", "name": "Commented-code block (5 lines) in server/domain/runtime/turn.ts:4", "shortDescription": {"text": "Commented-code block (5 lines) in server/domain/runtime/turn.ts:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-386fd222f8b7a180", "name": "Commented-code block (5 lines) in runtime-bridge/src/providers/claude-code.ts:65", "shortDescription": {"text": "Commented-code block (5 lines) in runtime-bridge/src/providers/claude-code.ts:65"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7221a1d47448e019", "name": "Commented-code block (7 lines) in runtime-bridge/src/providers/ama.ts:25", "shortDescription": {"text": "Commented-code block (7 lines) in runtime-bridge/src/providers/ama.ts:25"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f6be8bb9207a4f54", "name": "Commented-code block (5 lines) in runtime-core/transcript.ts:1", "shortDescription": {"text": "Commented-code block (5 lines) in runtime-core/transcript.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c4acc374bdda5645", "name": "Commented-code block (5 lines) in runtime-core/turn-engine.ts:1", "shortDescription": {"text": "Commented-code block (5 lines) in runtime-core/turn-engine.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d976502bd3218d13", "name": "Commented-code block (6 lines) in runtime-core/ports.ts:3", "shortDescription": {"text": "Commented-code block (6 lines) in runtime-core/ports.ts:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-be5d1e0d84240056", "name": "Commented-code block (6 lines) in runtime-core/turn-status.ts:1", "shortDescription": {"text": "Commented-code block (6 lines) in runtime-core/turn-status.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-64d1cf6293ead344", "name": "Commented-code block (5 lines) in src/test/msw.ts:4", "shortDescription": {"text": "Commented-code block (5 lines) in src/test/msw.ts:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a324f95d983ade57", "name": "Legacy-named symbol `session_old` in src/features/sessions/sessions-pages.test.tsx:1794", "shortDescription": {"text": "Legacy-named symbol `session_old` in src/features/sessions/sessions-pages.test.tsx:1794"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dbc1e62ba380321e", "name": "Commented-code block (5 lines) in src/features/console/console-ui.test.tsx:548", "shortDescription": {"text": "Commented-code block (5 lines) in src/features/console/console-ui.test.tsx:548"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b3b6910838e1990b", "name": "`fetch()` without try/.catch or AbortSignal \u2014 e2e/fixtures.ts:27", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 e2e/fixtures.ts:27"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-794e6e8a8fb44957", "name": "`fetch()` without try/.catch or AbortSignal \u2014 sdk/typescript/src/index.ts:53", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 sdk/typescript/src/index.ts:53"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ad1f2c0971b89ce0", "name": "10 env vars used in code but missing from .env.example", "shortDescription": {"text": "10 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `AMA_ACCESS_TOKEN`, `AMA_RUNTIME_BRIDGE_TEST_MODE`, `CI`, `CLOUDFLARE_ENV`, `E2E_APP_PORT`, `E2E_BASE_URL`, `E2E_PORT`, `HOME` + 2 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-79addc5ba397859a", "name": "Frontend route `/mcp/:connectorId` has no Link/navigate to it \u2014 src/features/mcp/mcp-ui.test.tsx", "shortDescription": {"text": "Frontend route `/mcp/:connectorId` has no Link/navigate to it \u2014 src/features/mcp/mcp-ui.test.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f43da642896e4af", "name": "Frontend route `/sessions/:sessionId` has no Link/navigate to it \u2014 src/features/sessions/sessions-pages.test.tsx", "shortDescription": {"text": "Frontend route `/sessions/:sessionId` has no Link/navigate to it \u2014 src/features/sessions/sessions-pages.test.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f82e6fbf57800b49", "name": "Frontend route `/providers/:providerId` has no Link/navigate to it \u2014 src/features/providers/providers-ui.test.tsx", "shortDescription": {"text": "Frontend route `/providers/:providerId` has no Link/navigate to it \u2014 src/features/providers/providers-ui.test.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f26c830d2beec5e5", "name": "Frontend route `/providers/` has no Link/navigate to it \u2014 src/features/providers/providers-ui.test.tsx", "shortDescription": {"text": "Frontend route `/providers/` has no Link/navigate to it \u2014 src/features/providers/providers-ui.test.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-928268417b37cb92", "name": "Frontend route `/audit/:recordId` has no Link/navigate to it \u2014 src/features/audit/audit-ui.test.tsx", "shortDescription": {"text": "Frontend route `/audit/:recordId` has no Link/navigate to it \u2014 src/features/audit/audit-ui.test.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3b0a42efc962cbb1", "name": "Frontend route `/agents/:agentId` has no Link/navigate to it \u2014 src/features/agents/AgentDetailPage.test.tsx", "shortDescription": {"text": "Frontend route `/agents/:agentId` has no Link/navigate to it \u2014 src/features/agents/AgentDetailPage.test.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-70312cacad4aa38a", "name": "Frontend route `/vaults/:vaultId` has no Link/navigate to it \u2014 src/features/vaults/vaults-ui.test.tsx", "shortDescription": {"text": "Frontend route `/vaults/:vaultId` has no Link/navigate to it \u2014 src/features/vaults/vaults-ui.test.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2151885ff605c1a3", "name": "Frontend route `/environments/:environmentId` has no Link/navigate to it \u2014 src/features/environments/environments-ui.tes", "shortDescription": {"text": "Frontend route `/environments/:environmentId` has no Link/navigate to it \u2014 src/features/environments/environments-ui.test.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a60f5911c5506678", "name": "Dangling fetch: GET https://runner-session-channel/status (server/adapters/gateways/runner-channel.ts:13)", "shortDescription": {"text": "Dangling fetch: GET https://runner-session-channel/status (server/adapters/gateways/runner-channel.ts:13)"}, "fullDescription": {"text": "`server/adapters/gateways/runner-channel.ts:13` calls `GET https://runner-session-channel/status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/runner-session-channel/status`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-436d83c9aa0711aa", "name": "Dangling fetch: POST https://runner-session-channel/dispatch (server/adapters/gateways/runner-channel.ts:24)", "shortDescription": {"text": "Dangling fetch: POST https://runner-session-channel/dispatch (server/adapters/gateways/runner-channel.ts:24)"}, "fullDescription": {"text": "`server/adapters/gateways/runner-channel.ts:24` calls `POST https://runner-session-channel/dispatch` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/runner-session-channel/dispatch`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a18d441b7ef75017", "name": "Dangling fetch: GET https://example.com/api/v1/health (server/integration/health.test.ts:7)", "shortDescription": {"text": "Dangling fetch: GET https://example.com/api/v1/health (server/integration/health.test.ts:7)"}, "fullDescription": {"text": "`server/integration/health.test.ts:7` calls `GET https://example.com/api/v1/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-baf540c4bcb2f01a", "name": "Dangling fetch: GET https://example.com${path} (server/integration/budgets.test.ts:6)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/budgets.test.ts:6)"}, "fullDescription": {"text": "`server/integration/budgets.test.ts:6` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-dc3c5e5f517fa1f1", "name": "Dangling fetch: GET https://example.com${path} (server/integration/runtimes.test.ts:6)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/runtimes.test.ts:6)"}, "fullDescription": {"text": "`server/integration/runtimes.test.ts:6` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ef25499323b8d138", "name": "Dangling fetch: GET https://example.com${path} (server/integration/runners.test.ts:9)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/runners.test.ts:9)"}, "fullDescription": {"text": "`server/integration/runners.test.ts:9` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-494d3499cc1b1292", "name": "Dangling fetch: GET https://example.com/api/v1/runners (server/integration/runners.test.ts:276)", "shortDescription": {"text": "Dangling fetch: GET https://example.com/api/v1/runners (server/integration/runners.test.ts:276)"}, "fullDescription": {"text": "`server/integration/runners.test.ts:276` calls `GET https://example.com/api/v1/runners` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/runners`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2604c1894b4890db", "name": "Dangling fetch: PUT https://example.com/api/v1/runners/runner_x/heartbeat (server/integration/runners.test.ts:280)", "shortDescription": {"text": "Dangling fetch: PUT https://example.com/api/v1/runners/runner_x/heartbeat (server/integration/runners.test.ts:280)"}, "fullDescription": {"text": "`server/integration/runners.test.ts:280` calls `PUT https://example.com/api/v1/runners/runner_x/heartbeat` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/runners/runner_x/heartbeat`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7de0129b7010e86e", "name": "Dangling fetch: GET https://example.com${path} (server/integration/agents.test.ts:6)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/agents.test.ts:6)"}, "fullDescription": {"text": "`server/integration/agents.test.ts:6` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1ec6a0c1f4f41ff1", "name": "Dangling fetch: POST https://example.com/api/v1/agents (server/integration/agents.test.ts:54)", "shortDescription": {"text": "Dangling fetch: POST https://example.com/api/v1/agents (server/integration/agents.test.ts:54)"}, "fullDescription": {"text": "`server/integration/agents.test.ts:54` calls `POST https://example.com/api/v1/agents` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/agents`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2d741b533149b584", "name": "Dangling fetch: POST https://example.com/api/v1/agents (server/integration/agents.test.ts:70)", "shortDescription": {"text": "Dangling fetch: POST https://example.com/api/v1/agents (server/integration/agents.test.ts:70)"}, "fullDescription": {"text": "`server/integration/agents.test.ts:70` calls `POST https://example.com/api/v1/agents` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/agents`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4bc0109f011bfc54", "name": "Dangling fetch: GET https://example.com${path} (server/integration/federated-tenants.test.ts:6)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/federated-tenants.test.ts:6)"}, "fullDescription": {"text": "`server/integration/federated-tenants.test.ts:6` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-90150aa962fc5bab", "name": "Dangling fetch: GET https://example.com${path} (server/integration/providers-governance.test.ts:6)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/providers-governance.test.ts:6)"}, "fullDescription": {"text": "`server/integration/providers-governance.test.ts:6` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-423e52844c0c2f8f", "name": "Dangling fetch: GET https://example.com${path} (server/integration/leases.test.ts:10)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/leases.test.ts:10)"}, "fullDescription": {"text": "`server/integration/leases.test.ts:10` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-26019dcdfdfffa9e", "name": "Dangling fetch: GET https://example.com/api/v1/leases/${leaseId}/channel (server/integration/leases.test.ts:129)", "shortDescription": {"text": "Dangling fetch: GET https://example.com/api/v1/leases/${leaseId}/channel (server/integration/leases.test.ts:129)"}, "fullDescription": {"text": "`server/integration/leases.test.ts:129` calls `GET https://example.com/api/v1/leases/${leaseId}/channel` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/leases/<p>/channel`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9367b54a9f3f8af1", "name": "Dangling fetch: GET https://example.com/api/v1/leases/lease_missing/channel (server/integration/leases.test.ts:480)", "shortDescription": {"text": "Dangling fetch: GET https://example.com/api/v1/leases/lease_missing/channel (server/integration/leases.test.ts:480)"}, "fullDescription": {"text": "`server/integration/leases.test.ts:480` calls `GET https://example.com/api/v1/leases/lease_missing/channel` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/leases/lease_missing/channel`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e058dac2f79b4179", "name": "Dangling fetch: GET https://example.com/api/v1/leases/${lease.id}/channel (server/integration/leases.test.ts:491)", "shortDescription": {"text": "Dangling fetch: GET https://example.com/api/v1/leases/${lease.id}/channel (server/integration/leases.test.ts:491)"}, "fullDescription": {"text": "`server/integration/leases.test.ts:491` calls `GET https://example.com/api/v1/leases/${lease.id}/channel` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/leases/<p>/channel`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5a40c3ea88a4a789", "name": "Dangling fetch: GET https://example.com${path} (server/integration/connectors.test.ts:6)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/connectors.test.ts:6)"}, "fullDescription": {"text": "`server/integration/connectors.test.ts:6` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d27156527c6e9444", "name": "Dangling fetch: GET https://example.com/api/v1/connectors (server/integration/connectors.test.ts:110)", "shortDescription": {"text": "Dangling fetch: GET https://example.com/api/v1/connectors (server/integration/connectors.test.ts:110)"}, "fullDescription": {"text": "`server/integration/connectors.test.ts:110` calls `GET https://example.com/api/v1/connectors` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/connectors`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-667652625a183585", "name": "Dangling fetch: GET https://example.com${path} (server/integration/effective-policy.test.ts:8)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/effective-policy.test.ts:8)"}, "fullDescription": {"text": "`server/integration/effective-policy.test.ts:8` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d2648080b90bf04a", "name": "Dangling fetch: GET https://example.com${path} (server/integration/access-rules.test.ts:6)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/access-rules.test.ts:6)"}, "fullDescription": {"text": "`server/integration/access-rules.test.ts:6` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a2d43faff9d1be66", "name": "Dangling fetch: GET https://example.com${path} (server/integration/usage-summary.test.ts:10)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/usage-summary.test.ts:10)"}, "fullDescription": {"text": "`server/integration/usage-summary.test.ts:10` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-711b26204388d2ec", "name": "Dangling fetch: GET https://example.com${path} (server/integration/policies.test.ts:6)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/policies.test.ts:6)"}, "fullDescription": {"text": "`server/integration/policies.test.ts:6` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c9e37db90bbcd35c", "name": "Dangling fetch: GET https://example.com${path} (server/integration/work-items.test.ts:9)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/work-items.test.ts:9)"}, "fullDescription": {"text": "`server/integration/work-items.test.ts:9` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f6c59f3f46b8485a", "name": "Dangling fetch: GET https://example.com${path} (server/integration/vaults.test.ts:7)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/vaults.test.ts:7)"}, "fullDescription": {"text": "`server/integration/vaults.test.ts:7` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-70cf8599bb5d2f7e", "name": "Dangling fetch: POST https://example.com/api/v1/vaults (server/integration/vaults.test.ts:27)", "shortDescription": {"text": "Dangling fetch: POST https://example.com/api/v1/vaults (server/integration/vaults.test.ts:27)"}, "fullDescription": {"text": "`server/integration/vaults.test.ts:27` calls `POST https://example.com/api/v1/vaults` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/vaults`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e753d198e059280f", "name": "Dangling fetch: GET https://example.com${path} (server/integration/environments.test.ts:6)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/environments.test.ts:6)"}, "fullDescription": {"text": "`server/integration/environments.test.ts:6` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ea2299799343736f", "name": "Dangling fetch: POST https://example.com/api/v1/environments (server/integration/environments.test.ts:74)", "shortDescription": {"text": "Dangling fetch: POST https://example.com/api/v1/environments (server/integration/environments.test.ts:74)"}, "fullDescription": {"text": "`server/integration/environments.test.ts:74` calls `POST https://example.com/api/v1/environments` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/environments`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e2fb58a5214d0283", "name": "Dangling fetch: POST https://example.com/api/v1/environments (server/integration/environments.test.ts:90)", "shortDescription": {"text": "Dangling fetch: POST https://example.com/api/v1/environments (server/integration/environments.test.ts:90)"}, "fullDescription": {"text": "`server/integration/environments.test.ts:90` calls `POST https://example.com/api/v1/environments` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/environments`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-38074189adfdee15", "name": "Dangling fetch: GET https://example.com${path} (server/integration/sessions.test.ts:11)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/sessions.test.ts:11)"}, "fullDescription": {"text": "`server/integration/sessions.test.ts:11` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5a391a1751c8d339", "name": "Dangling fetch: GET https://example.com/api/v1/sessions (server/integration/sessions.test.ts:1286)", "shortDescription": {"text": "Dangling fetch: GET https://example.com/api/v1/sessions (server/integration/sessions.test.ts:1286)"}, "fullDescription": {"text": "`server/integration/sessions.test.ts:1286` calls `GET https://example.com/api/v1/sessions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/sessions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cb5878d1d66e0eb0", "name": "Dangling fetch: GET https://example.com${path} (server/integration/usage-records.test.ts:10)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/usage-records.test.ts:10)"}, "fullDescription": {"text": "`server/integration/usage-records.test.ts:10` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-06a2daaa943efc3a", "name": "Dangling fetch: GET https://example.com${path} (server/integration/auth.test.ts:10)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/auth.test.ts:10)"}, "fullDescription": {"text": "`server/integration/auth.test.ts:10` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-198dcb81feee81ed", "name": "Dangling fetch: GET https://example.com/api/v1/auth/config (server/integration/auth.test.ts:30)", "shortDescription": {"text": "Dangling fetch: GET https://example.com/api/v1/auth/config (server/integration/auth.test.ts:30)"}, "fullDescription": {"text": "`server/integration/auth.test.ts:30` calls `GET https://example.com/api/v1/auth/config` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/auth/config`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-018c4ff0650f60e1", "name": "Dangling fetch: GET https://example.com/api/v1/auth/config?organization=example-org (server/integration/auth.test.ts:38)", "shortDescription": {"text": "Dangling fetch: GET https://example.com/api/v1/auth/config?organization=example-org (server/integration/auth.test.ts:38)"}, "fullDescription": {"text": "`server/integration/auth.test.ts:38` calls `GET https://example.com/api/v1/auth/config?organization=example-org` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/auth/config`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-13b418b702cc4229", "name": "Dangling fetch: POST https://example.com/api/v1/auth/sessions (server/integration/auth.test.ts:84)", "shortDescription": {"text": "Dangling fetch: POST https://example.com/api/v1/auth/sessions (server/integration/auth.test.ts:84)"}, "fullDescription": {"text": "`server/integration/auth.test.ts:84` calls `POST https://example.com/api/v1/auth/sessions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/auth/sessions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-804f3fb5e634b6ae", "name": "Dangling fetch: DELETE https://example.com/api/v1/auth/sessions/current (server/integration/auth.test.ts:123)", "shortDescription": {"text": "Dangling fetch: DELETE https://example.com/api/v1/auth/sessions/current (server/integration/auth.test.ts:123)"}, "fullDescription": {"text": "`server/integration/auth.test.ts:123` calls `DELETE https://example.com/api/v1/auth/sessions/current` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/auth/sessions/current`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e1e03453008f7df2", "name": "Dangling fetch: GET https://example.com/api/v1/openapi.json (server/integration/openapi.test.ts:46)", "shortDescription": {"text": "Dangling fetch: GET https://example.com/api/v1/openapi.json (server/integration/openapi.test.ts:46)"}, "fullDescription": {"text": "`server/integration/openapi.test.ts:46` calls `GET https://example.com/api/v1/openapi.json` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/openapi.json`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-eb8c7208151e1c2d", "name": "Dangling fetch: GET https://example.com/api/v1/docs (server/integration/openapi.test.ts:449)", "shortDescription": {"text": "Dangling fetch: GET https://example.com/api/v1/docs (server/integration/openapi.test.ts:449)"}, "fullDescription": {"text": "`server/integration/openapi.test.ts:449` calls `GET https://example.com/api/v1/docs` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/docs`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6296fb54efdf271c", "name": "Dangling fetch: GET https://example.com${path} (server/integration/connections.test.ts:6)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/connections.test.ts:6)"}, "fullDescription": {"text": "`server/integration/connections.test.ts:6` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d06b83aa6fd80251", "name": "Dangling fetch: GET https://example.com${path} (server/integration/restish-openapi.test.ts:17)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/restish-openapi.test.ts:17)"}, "fullDescription": {"text": "`server/integration/restish-openapi.test.ts:17` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5804694170aa6bac", "name": "Dangling fetch: GET https://example.com/api/v1/openapi.json (server/integration/restish-openapi.test.ts:28)", "shortDescription": {"text": "Dangling fetch: GET https://example.com/api/v1/openapi.json (server/integration/restish-openapi.test.ts:28)"}, "fullDescription": {"text": "`server/integration/restish-openapi.test.ts:28` calls `GET https://example.com/api/v1/openapi.json` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/openapi.json`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-40031b1dfae525a4", "name": "Dangling fetch: GET https://example.com${path} (server/integration/providers.test.ts:10)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/providers.test.ts:10)"}, "fullDescription": {"text": "`server/integration/providers.test.ts:10` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c35c758ea64bc93d", "name": "Dangling fetch: GET https://example.com${path} (server/integration/triggers.test.ts:6)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/triggers.test.ts:6)"}, "fullDescription": {"text": "`server/integration/triggers.test.ts:6` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c453614ce01cf81a", "name": "Dangling fetch: GET https://example.com${path} (server/integration/audit-records.test.ts:6)", "shortDescription": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/audit-records.test.ts:6)"}, "fullDescription": {"text": "`server/integration/audit-records.test.ts:6` calls `GET https://example.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b8a76afa1d38ab0b", "name": "Dangling fetch: POST https://example.com/api/v1/runtime/workers-ai/v1/chat/completions (server/integration/runtime-ai.te", "shortDescription": {"text": "Dangling fetch: POST https://example.com/api/v1/runtime/workers-ai/v1/chat/completions (server/integration/runtime-ai.test.ts:6)"}, "fullDescription": {"text": "`server/integration/runtime-ai.test.ts:6` calls `POST https://example.com/api/v1/runtime/workers-ai/v1/chat/completions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/example.com/api/v1/runtime/workers-ai/v1/chat/completions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-50a7d6e8ebe2d168", "name": "Dangling fetch: POST /api/v1/auth/sessions (src/lib/oidc.ts:119)", "shortDescription": {"text": "Dangling fetch: POST /api/v1/auth/sessions (src/lib/oidc.ts:119)"}, "fullDescription": {"text": "`src/lib/oidc.ts:119` calls `POST /api/v1/auth/sessions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/v1/auth/sessions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-046dda00f1450b3d", "name": "Unused endpoint: POST /chat/completions", "shortDescription": {"text": "Unused endpoint: POST /chat/completions"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /chat/completions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-731e0756c2fefc2d", "name": "Unused endpoint: POST /audio/speech", "shortDescription": {"text": "Unused endpoint: POST /audio/speech"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /audio/speech` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0703b07fb8e8b6f0", "name": "Unused endpoint: POST /audio/transcriptions", "shortDescription": {"text": "Unused endpoint: POST /audio/transcriptions"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /audio/transcriptions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-977b39ba4216e247", "name": "Unused endpoint: POST /audio/translations", "shortDescription": {"text": "Unused endpoint: POST /audio/translations"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /audio/translations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9ed84d434d52c021", "name": "Unused endpoint: POST /batches", "shortDescription": {"text": "Unused endpoint: POST /batches"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /batches` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7732e5fbd854c6d4", "name": "Unused endpoint: POST /assistants", "shortDescription": {"text": "Unused endpoint: POST /assistants"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /assistants` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30495157336e2746", "name": "Unused endpoint: POST /realtime/sessions", "shortDescription": {"text": "Unused endpoint: POST /realtime/sessions"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /realtime/sessions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bc74f5339c055526", "name": "Unused endpoint: POST /realtime/transcription_sessions", "shortDescription": {"text": "Unused endpoint: POST /realtime/transcription_sessions"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /realtime/transcription_sessions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47c404592e01220b", "name": "Unused endpoint: POST /chatkit/sessions", "shortDescription": {"text": "Unused endpoint: POST /chatkit/sessions"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /chatkit/sessions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-686be4977a495430", "name": "Unused endpoint: POST /threads", "shortDescription": {"text": "Unused endpoint: POST /threads"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /threads` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9390b6aa85bd274e", "name": "Unused endpoint: POST /threads/runs", "shortDescription": {"text": "Unused endpoint: POST /threads/runs"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /threads/runs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f29cff29921a3be", "name": "Unused endpoint: POST /completions", "shortDescription": {"text": "Unused endpoint: POST /completions"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /completions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43887b06a6508e4f", "name": "Unused endpoint: POST /containers", "shortDescription": {"text": "Unused endpoint: POST /containers"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /containers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8ee7ac4b5c5364e8", "name": "Unused endpoint: POST /conversations", "shortDescription": {"text": "Unused endpoint: POST /conversations"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /conversations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2494ea4326b03b3f", "name": "Unused endpoint: POST /embeddings", "shortDescription": {"text": "Unused endpoint: POST /embeddings"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /embeddings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6bc94f0922e3a219", "name": "Unused endpoint: POST /evals", "shortDescription": {"text": "Unused endpoint: POST /evals"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /evals` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f1320a5ffe374dac", "name": "Unused endpoint: POST /files", "shortDescription": {"text": "Unused endpoint: POST /files"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /files` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c974b540a6ec79a6", "name": "Unused endpoint: POST /fine_tuning/alpha/graders/run", "shortDescription": {"text": "Unused endpoint: POST /fine_tuning/alpha/graders/run"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /fine_tuning/alpha/graders/run` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d3fded90dc607ec2", "name": "Unused endpoint: POST /fine_tuning/alpha/graders/validate", "shortDescription": {"text": "Unused endpoint: POST /fine_tuning/alpha/graders/validate"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /fine_tuning/alpha/graders/validate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2439d65365ac9535", "name": "Unused endpoint: POST /fine_tuning/jobs", "shortDescription": {"text": "Unused endpoint: POST /fine_tuning/jobs"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /fine_tuning/jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e6adff703d49c7d2", "name": "Unused endpoint: POST /images/variations", "shortDescription": {"text": "Unused endpoint: POST /images/variations"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /images/variations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-03133b2476295fb4", "name": "Unused endpoint: POST /images/edits", "shortDescription": {"text": "Unused endpoint: POST /images/edits"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /images/edits` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e4c5c41cb8097be5", "name": "Unused endpoint: POST /images/generations", "shortDescription": {"text": "Unused endpoint: POST /images/generations"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /images/generations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dc2b015738c65b1b", "name": "Unused endpoint: POST /moderations", "shortDescription": {"text": "Unused endpoint: POST /moderations"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /moderations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-11e9757ab463439e", "name": "Unused endpoint: POST /realtime/client_secrets", "shortDescription": {"text": "Unused endpoint: POST /realtime/client_secrets"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /realtime/client_secrets` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d58c39d1475cdf14", "name": "Unused endpoint: POST /responses/input_tokens", "shortDescription": {"text": "Unused endpoint: POST /responses/input_tokens"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /responses/input_tokens` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-90e52654c4efbe1d", "name": "Unused endpoint: POST /responses", "shortDescription": {"text": "Unused endpoint: POST /responses"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /responses` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f40182428f41c6a", "name": "Unused endpoint: POST /responses/compact", "shortDescription": {"text": "Unused endpoint: POST /responses/compact"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /responses/compact` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ce7fe565b4caff57", "name": "Unused endpoint: POST /skills", "shortDescription": {"text": "Unused endpoint: POST /skills"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /skills` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f440e5eb48cf128b", "name": "Unused endpoint: POST /uploads", "shortDescription": {"text": "Unused endpoint: POST /uploads"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /uploads` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09e66fd1b47698ad", "name": "Unused endpoint: POST /vector_stores", "shortDescription": {"text": "Unused endpoint: POST /vector_stores"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /vector_stores` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-83b40e43b99732cc", "name": "Unused endpoint: POST /videos", "shortDescription": {"text": "Unused endpoint: POST /videos"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /videos` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b96372541f48aa3b", "name": "Unused endpoint: POST /v1/environments?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/environments?beta=true"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/environments?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f69ff3386aed8a58", "name": "Unused endpoint: POST /v1/files?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/files?beta=true"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/files?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5e42ff2d7e23d4c7", "name": "Unused endpoint: POST /v1/user_profiles?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/user_profiles?beta=true"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/user_profiles?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b8ed4c704a21b2a", "name": "Unused endpoint: POST /v1/agents?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/agents?beta=true"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/agents?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8bdbd7b085e30db", "name": "Unused endpoint: POST /v1/memory_stores?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/memory_stores?beta=true"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/memory_stores?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd7e4d4f2ed43337", "name": "Unused endpoint: POST /v1/messages/batches?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/messages/batches?beta=true"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/messages/batches?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00750df0839bbbd3", "name": "Unused endpoint: POST /v1/messages?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/messages?beta=true"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/messages?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6c096d37f349fa96", "name": "Unused endpoint: POST /v1/messages/count_tokens?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/messages/count_tokens?beta=true"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/messages/count_tokens?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-56fe7aef1427c93d", "name": "Unused endpoint: POST /v1/sessions?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/sessions?beta=true"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/sessions?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bea60f0266e76560", "name": "Unused endpoint: POST /v1/skills?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/skills?beta=true"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/skills?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d29f578584143cf", "name": "Unused endpoint: POST /v1/vaults?beta=true", "shortDescription": {"text": "Unused endpoint: POST /v1/vaults?beta=true"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/vaults?beta=true` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1e474744f4149920", "name": "Unused endpoint: POST /v1/complete", "shortDescription": {"text": "Unused endpoint: POST /v1/complete"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/complete` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8bcda56c4c41e5fa", "name": "Unused endpoint: POST /v1/messages/batches", "shortDescription": {"text": "Unused endpoint: POST /v1/messages/batches"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/messages/batches` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50d20b703a1dd1f9", "name": "Unused endpoint: POST /v1/messages", "shortDescription": {"text": "Unused endpoint: POST /v1/messages"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/messages` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e51d72bee485df7b", "name": "Unused endpoint: POST /v1/messages/count_tokens", "shortDescription": {"text": "Unused endpoint: POST /v1/messages/count_tokens"}, "fullDescription": {"text": "`cmd/ama-runner/runtime_bridge_bundle.mjs` declares `POST /v1/messages/count_tokens` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3abf952b8d28d710", "name": "Unused endpoint: USE /*", "shortDescription": {"text": "Unused endpoint: USE /*"}, "fullDescription": {"text": "`server/app.ts` declares `USE /*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f46cb4ef071fc81", "name": "Unused endpoint: GET /api/v1/docs", "shortDescription": {"text": "Unused endpoint: GET /api/v1/docs"}, "fullDescription": {"text": "`server/app.ts` declares `GET /api/v1/docs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-39b7672113ed17b5", "name": "Unused endpoint: ALL /api/v1/runtime/sessions/:sessionId/*", "shortDescription": {"text": "Unused endpoint: ALL /api/v1/runtime/sessions/:sessionId/*"}, "fullDescription": {"text": "`server/http/runtime-proxy.ts` declares `ALL /api/v1/runtime/sessions/:sessionId/*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/18800"}, "properties": {"repository": "saltbo/any-managed-agents", "repoUrl": "https://github.com/saltbo/any-managed-agents", "branch": "main"}, "results": [{"ruleId": "scanner-8835197a2e64b2d8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/check-spec-coverage.ts:69"}, "properties": {"repobilityId": "de604b3e5539f21c", "scanner": "scanner-primary", "fingerprint": "8835197a2e64b2d8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fd8e815a2b1c5eb8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/generate-go-contract.ts:73"}, "properties": {"repobilityId": "96f3874dabc4a530", "scanner": "scanner-primary", "fingerprint": "fd8e815a2b1c5eb8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-462b1654766e855f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/check-type-escapes.ts:80"}, "properties": {"repobilityId": "769362faee50e033", "scanner": "scanner-primary", "fingerprint": "462b1654766e855f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0204ae6eb422a54b", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/ai-elements/tool.tsx:38"}, "properties": {"repobilityId": "c6ec670a66d52285", "scanner": "scanner-primary", "fingerprint": "0204ae6eb422a54b", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-8cd593b9bd21440c", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/console/components.tsx:126"}, "properties": {"repobilityId": "4f76accb78b1b63b", "scanner": "scanner-primary", "fingerprint": "8cd593b9bd21440c", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-875b34b8ef287191", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/usage/UsageView.tsx:43"}, "properties": {"repobilityId": "798bfd2a1262b562", "scanner": "scanner-primary", "fingerprint": "875b34b8ef287191", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-db402478de61ebd7", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/mcp/McpView.tsx:69"}, "properties": {"repobilityId": "07022b046183d023", "scanner": "scanner-primary", "fingerprint": "db402478de61ebd7", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-708eaf3e9d52d3fa", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/sessions/SessionDetailView.tsx:63"}, "properties": {"repobilityId": "c12bda6f1238baca", "scanner": "scanner-primary", "fingerprint": "708eaf3e9d52d3fa", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-f784d705dcabae16", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/sessions/SessionsView.tsx:87"}, "properties": {"repobilityId": "10bc948682520d10", "scanner": "scanner-primary", "fingerprint": "f784d705dcabae16", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-2025aa06e65a990c", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/providers/ProviderPolicyPage.tsx:63"}, "properties": {"repobilityId": "5e9239d3aeffbba6", "scanner": "scanner-primary", "fingerprint": "2025aa06e65a990c", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-6fa75676b7838420", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/providers/ProvidersView.tsx:45"}, "properties": {"repobilityId": "779e322024e89d22", "scanner": "scanner-primary", "fingerprint": "6fa75676b7838420", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-17a90b1896a15d4b", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/audit/AuditView.tsx:42"}, "properties": {"repobilityId": "9505be94ae4f8b71", "scanner": "scanner-primary", "fingerprint": "17a90b1896a15d4b", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-5a60f5e3057afc1e", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/agents/AgentsView.tsx:42"}, "properties": {"repobilityId": "21009bae22fff631", "scanner": "scanner-primary", "fingerprint": "5a60f5e3057afc1e", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-6439ffacce83e9ce", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/vaults/VaultDetailView.tsx:112"}, "properties": {"repobilityId": "d832962218ccc179", "scanner": "scanner-primary", "fingerprint": "6439ffacce83e9ce", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-a0922e76db83d74d", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/vaults/VaultsView.tsx:42"}, "properties": {"repobilityId": "c8fbbe0f5989c315", "scanner": "scanner-primary", "fingerprint": "a0922e76db83d74d", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-944b26b531826f17", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/console/related-resources-table.tsx:44"}, "properties": {"repobilityId": "af8233ee2ce430a3", "scanner": "scanner-primary", "fingerprint": "944b26b531826f17", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-e9bef6605ee849b7", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/console/ConsoleShell.tsx:48"}, "properties": {"repobilityId": "3246ff5da4399de3", "scanner": "scanner-primary", "fingerprint": "e9bef6605ee849b7", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-56ba77978c387631", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/features/environments/EnvironmentsView.tsx:52"}, "properties": {"repobilityId": "8f9313cd9f832b06", "scanner": "scanner-primary", "fingerprint": "56ba77978c387631", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-d63da3583b14afc0", "level": "warning", "message": {"text": "Dockerfile runs as root: Dockerfile"}, "properties": {"repobilityId": "a2ed1bd120e507db", "scanner": "scanner-primary", "fingerprint": "d63da3583b14afc0", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-365754187babc1cc", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: docker.io/cloudflare/sandbox:0.10.1"}, "properties": {"repobilityId": "b797e7065bed516a", "scanner": "scanner-primary", "fingerprint": "365754187babc1cc", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-241a6f49387cfdfa", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/smoke-runtime.mjs:11"}, "properties": {"repobilityId": "4369a38bf701d83a", "scanner": "scanner-primary", "fingerprint": "241a6f49387cfdfa", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/smoke-runtime.mjs"}, "region": {"startLine": 11}}}]}, {"ruleId": "scanner-323a38cc7e4ec904", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/generate-go-contract.ts:1"}, "properties": {"repobilityId": "1c5a4e30e7e2337f", "scanner": "scanner-primary", "fingerprint": "323a38cc7e4ec904", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/generate-go-contract.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d7892825061dad9e", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in server/sdk-layout.test.ts:1"}, "properties": {"repobilityId": "ca3f261cfbe31839", "scanner": "scanner-primary", "fingerprint": "d7892825061dad9e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "server/sdk-layout.test.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eaedc0d8b7cb0934", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in server/adapters/runtime/sandbox-runtime-host.ts:140"}, "properties": {"repobilityId": "a3d6c7ffe2c6bcb9", "scanner": "scanner-primary", "fingerprint": "eaedc0d8b7cb0934", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "server/adapters/runtime/sandbox-runtime-host.ts"}, "region": {"startLine": 140}}}]}, {"ruleId": "scanner-220d796f899690a8", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in server/adapters/runtime/sandbox-tool-executor.test.ts:194"}, "properties": {"repobilityId": "e0993a973bb4d316", "scanner": "scanner-primary", "fingerprint": "220d796f899690a8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "server/adapters/runtime/sandbox-tool-executor.test.ts"}, "region": {"startLine": 194}}}]}, {"ruleId": "scanner-c78545b1e0577604", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in runtime-bridge/src/providers/claude-code.ts:1"}, "properties": {"repobilityId": "bd74264b8e39c00c", "scanner": "scanner-primary", "fingerprint": "c78545b1e0577604", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "runtime-bridge/src/providers/claude-code.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1b7bc91df721f2c6", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in runtime-bridge/src/providers/cli-host.ts:1"}, "properties": {"repobilityId": "94df0efaa1c1be6a", "scanner": "scanner-primary", "fingerprint": "1b7bc91df721f2c6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "runtime-bridge/src/providers/cli-host.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2a155d4d8bccce94", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in runtime-bridge/src/providers/copilot.ts:1"}, "properties": {"repobilityId": "658d9548dd13bbf9", "scanner": "scanner-primary", "fingerprint": "2a155d4d8bccce94", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "runtime-bridge/src/providers/copilot.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-71286040a3447c56", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in runtime-bridge/src/providers/ama.ts:268"}, "properties": {"repobilityId": "765ba9f60699ea84", "scanner": "scanner-primary", "fingerprint": "71286040a3447c56", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "runtime-bridge/src/providers/ama.ts"}, "region": {"startLine": 268}}}]}, {"ruleId": "scanner-75dfb84f480818b0", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in runtime-bridge/src/providers/ama.ts:1"}, "properties": {"repobilityId": "6a0c72dd4da6a4d8", "scanner": "scanner-primary", "fingerprint": "75dfb84f480818b0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "runtime-bridge/src/providers/ama.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-93dc89ac7925c1d2", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in src/App.test.tsx:672"}, "properties": {"repobilityId": "7428fb96a085a293", "scanner": "scanner-primary", "fingerprint": "93dc89ac7925c1d2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/App.test.tsx"}, "region": {"startLine": 672}}}]}, {"ruleId": "scanner-ef3fe680553ef836", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in src/lib/oidc.test.ts:63"}, "properties": {"repobilityId": "f624286125676965", "scanner": "scanner-primary", "fingerprint": "ef3fe680553ef836", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lib/oidc.test.ts"}, "region": {"startLine": 63}}}]}, {"ruleId": "scanner-144b88dc8b972a4c", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in src/lib/api.test.ts:6"}, "properties": {"repobilityId": "e4e74f016dc4fcc5", "scanner": "scanner-primary", "fingerprint": "144b88dc8b972a4c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/lib/api.test.ts"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-ec40442ea7b7ae9c", "level": "warning", "message": {"text": "Insecure pattern 'local_storage_auth_token' in e2e/fixtures.ts:56"}, "properties": {"repobilityId": "1e462e93d653be2e", "scanner": "scanner-primary", "fingerprint": "ec40442ea7b7ae9c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "local_storage_auth_token"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "e2e/fixtures.ts"}, "region": {"startLine": 56}}}]}, {"ruleId": "scanner-96a8a827200d29af", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "12c7d1f5fc8e4504", "scanner": "scanner-primary", "fingerprint": "96a8a827200d29af", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ama-runner-release.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0836e961e2b57ada", "level": "note", "message": {"text": "Very large file: cmd/ama-runner/runner_test.go (1486 lines)"}, "properties": {"repobilityId": "a74006ce52477cbc", "scanner": "scanner-primary", "fingerprint": "0836e961e2b57ada", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-e05c5abfb964c0fa", "level": "note", "message": {"text": "Very large file: server/integration/sessions.test.ts (1759 lines)"}, "properties": {"repobilityId": "2242e0f736c234ae", "scanner": "scanner-primary", "fingerprint": "e05c5abfb964c0fa", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-c1e497b93ab59d69", "level": "note", "message": {"text": "Very large file: server/usecases/ports.ts (2600 lines)"}, "properties": {"repobilityId": "46ee59a63933aaaa", "scanner": "scanner-primary", "fingerprint": "c1e497b93ab59d69", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-f685abc61ba16b3e", "level": "note", "message": {"text": "Very large file: src/features/sessions/sessions-pages.test.tsx (2161 lines)"}, "properties": {"repobilityId": "8bb1d930198ca77e", "scanner": "scanner-primary", "fingerprint": "f685abc61ba16b3e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-2f6a0bab83c93583", "level": "note", "message": {"text": "Very large file: src/features/vaults/vaults-ui.test.tsx (1424 lines)"}, "properties": {"repobilityId": "08b664c1740ce274", "scanner": "scanner-primary", "fingerprint": "2f6a0bab83c93583", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-f787d2602003cc60", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: sdk/typescript/package.json"}, "properties": {"repobilityId": "5150dcc1260d3576", "scanner": "scanner-primary", "fingerprint": "f787d2602003cc60", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sdk/typescript/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "c523cf9420137207", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "cff447c788683013", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-9d79c4077342a7d0", "level": "warning", "message": {"text": "Runtime service client appears to use placeholder configuration"}, "properties": {"repobilityId": "7b22f57f55a36cb4", "scanner": "scanner-primary", "fingerprint": "9d79c4077342a7d0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "runtime-config", "service-client", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "bde8454b0f53a586", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "2d2dcfcfa302fea7", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "fd2b9c955b461acc", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "cf3767838a785c55", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-434f999bd08be46d", "level": "none", "message": {"text": "Commented-code block (5 lines) in eslint.config.js:1"}, "properties": {"repobilityId": "8c0c697eea69b2a9", "scanner": "scanner-primary", "fingerprint": "434f999bd08be46d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a4183946dbe835e1", "level": "none", "message": {"text": "Commented-code block (5 lines) in vitest.config.ts:15"}, "properties": {"repobilityId": "59dbefd5f13cb94a", "scanner": "scanner-primary", "fingerprint": "a4183946dbe835e1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5dbafa3cb4db8e03", "level": "none", "message": {"text": "Commented-code block (5 lines) in shared/runtime-rows.ts:1"}, "properties": {"repobilityId": "f98273ac3d2dcfdb", "scanner": "scanner-primary", "fingerprint": "5dbafa3cb4db8e03", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a048ff5db42a0ae6", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 scripts/generate-openapi-and-sdks.ts:82"}, "properties": {"repobilityId": "f77c13ff03d422d9", "scanner": "scanner-primary", "fingerprint": "a048ff5db42a0ae6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ae2fefb14ffeaae0", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/generate-go-contract.ts:6"}, "properties": {"repobilityId": "32adc258b14a79c7", "scanner": "scanner-primary", "fingerprint": "ae2fefb14ffeaae0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bd3d4357193173d9", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/check-type-escapes.ts:38"}, "properties": {"repobilityId": "e68d545a2efb2c75", "scanner": "scanner-primary", "fingerprint": "bd3d4357193173d9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-78b5a853723c4855", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/api-contracts.test.ts:15"}, "properties": {"repobilityId": "57fbe774877c52cc", "scanner": "scanner-primary", "fingerprint": "78b5a853723c4855", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-8e46ad5bec80edc5", "level": "none", "message": {"text": "Commented-code block (12 lines) in server/app.ts:61"}, "properties": {"repobilityId": "57b15d661a32d0d2", "scanner": "scanner-primary", "fingerprint": "8e46ad5bec80edc5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f8a0b6c933096ec1", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/policy.ts:68"}, "properties": {"repobilityId": "134c92defd188e84", "scanner": "scanner-primary", "fingerprint": "f8a0b6c933096ec1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a1e6b31db69bfd9c", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/worker.ts:14"}, "properties": {"repobilityId": "6210204cd85ef433", "scanner": "scanner-primary", "fingerprint": "a1e6b31db69bfd9c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-591fe9c6dd98059c", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/adapters/repos/leases.ts:100"}, "properties": {"repobilityId": "79e67cf6a52d0a71", "scanner": "scanner-primary", "fingerprint": "591fe9c6dd98059c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6d06536a6d03133b", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/adapters/repos/runtime-orchestration.ts:67"}, "properties": {"repobilityId": "2ae86caf817b4cf6", "scanner": "scanner-primary", "fingerprint": "6d06536a6d03133b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-125f09e02a7fab3f", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/adapters/runtime/sandbox-runtime-host.ts:23"}, "properties": {"repobilityId": "a03ff5e1d046bfd4", "scanner": "scanner-primary", "fingerprint": "125f09e02a7fab3f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-19909a5d50804cc0", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/adapters/runtime/sandbox-tool-executor.ts:120"}, "properties": {"repobilityId": "ab04857e847548c2", "scanner": "scanner-primary", "fingerprint": "19909a5d50804cc0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b1ba31c45c60905c", "level": "none", "message": {"text": "Commented-code block (9 lines) in server/adapters/gateways/runtime-secret-env.ts:40"}, "properties": {"repobilityId": "b682a8bc18b8f0d8", "scanner": "scanner-primary", "fingerprint": "b1ba31c45c60905c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9143fcb48b53282e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/adapters/gateways/secret-store.ts:49"}, "properties": {"repobilityId": "ef54c40aae3179a0", "scanner": "scanner-primary", "fingerprint": "9143fcb48b53282e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-1bb7adb2f67a5b3f", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/adapters/gateways/runner-channel.ts:13"}, "properties": {"repobilityId": "ff047477f9366e94", "scanner": "scanner-primary", "fingerprint": "1bb7adb2f67a5b3f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c40d2182c991d5ac", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/health.test.ts:7"}, "properties": {"repobilityId": "3ea2b28a36f749c5", "scanner": "scanner-primary", "fingerprint": "c40d2182c991d5ac", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-af584dda260bbc28", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/budgets.test.ts:6"}, "properties": {"repobilityId": "4a82f306562bd1f5", "scanner": "scanner-primary", "fingerprint": "af584dda260bbc28", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-aaf8d5a4d0438249", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/runtimes.test.ts:6"}, "properties": {"repobilityId": "4e5fedefe5c99e0b", "scanner": "scanner-primary", "fingerprint": "aaf8d5a4d0438249", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-801feee72619e8d3", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/runners.test.ts:9"}, "properties": {"repobilityId": "8f67a62fdd4a9378", "scanner": "scanner-primary", "fingerprint": "801feee72619e8d3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0de2584251121350", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/agents.test.ts:6"}, "properties": {"repobilityId": "888749b030475456", "scanner": "scanner-primary", "fingerprint": "0de2584251121350", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-58696efe584da4ac", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/federated-tenants.test.ts:6"}, "properties": {"repobilityId": "ee5acd6b735922fe", "scanner": "scanner-primary", "fingerprint": "58696efe584da4ac", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-48f490b5fd797a1f", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/providers-governance.test.ts:6"}, "properties": {"repobilityId": "27ea1e2dabd22cc9", "scanner": "scanner-primary", "fingerprint": "48f490b5fd797a1f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-81c149ead6735983", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/leases.test.ts:10"}, "properties": {"repobilityId": "5af6d01beef27b6f", "scanner": "scanner-primary", "fingerprint": "81c149ead6735983", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-658cc4fb3c5de4ae", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/integration/sdk-contract.test.ts:7"}, "properties": {"repobilityId": "d1f4a61a4e74ada0", "scanner": "scanner-primary", "fingerprint": "658cc4fb3c5de4ae", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bf17fe36c220cf18", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/sdk-contract.test.ts:8"}, "properties": {"repobilityId": "10f46b402482fe1f", "scanner": "scanner-primary", "fingerprint": "bf17fe36c220cf18", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-701601c0811e6ccc", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/connectors.test.ts:6"}, "properties": {"repobilityId": "65cbb7613de0e9ad", "scanner": "scanner-primary", "fingerprint": "701601c0811e6ccc", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-efb14941d7f8f5d9", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/effective-policy.test.ts:8"}, "properties": {"repobilityId": "8093dbb254b0a63f", "scanner": "scanner-primary", "fingerprint": "efb14941d7f8f5d9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-103c8460296a608e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/access-rules.test.ts:6"}, "properties": {"repobilityId": "62c79e4d09737c46", "scanner": "scanner-primary", "fingerprint": "103c8460296a608e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-13b440bdc5ec4d60", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/usage-summary.test.ts:10"}, "properties": {"repobilityId": "7f37cd972991d8ca", "scanner": "scanner-primary", "fingerprint": "13b440bdc5ec4d60", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-560ceaea7ac7dcdc", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/policies.test.ts:6"}, "properties": {"repobilityId": "4ff088d2cdd15b7c", "scanner": "scanner-primary", "fingerprint": "560ceaea7ac7dcdc", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0e6dd10ee5063ac2", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/work-items.test.ts:9"}, "properties": {"repobilityId": "21ae8792f409d640", "scanner": "scanner-primary", "fingerprint": "0e6dd10ee5063ac2", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-738958f3d586e220", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/vaults.test.ts:7"}, "properties": {"repobilityId": "5fee78d19620b764", "scanner": "scanner-primary", "fingerprint": "738958f3d586e220", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-70a277a46d96e7b1", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/environments.test.ts:6"}, "properties": {"repobilityId": "3395fd8207024695", "scanner": "scanner-primary", "fingerprint": "70a277a46d96e7b1", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-efe983bd420b46c6", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/sessions.test.ts:11"}, "properties": {"repobilityId": "a59947431c608ded", "scanner": "scanner-primary", "fingerprint": "efe983bd420b46c6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f0c8ad7fb888fc74", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/usage-records.test.ts:10"}, "properties": {"repobilityId": "ff588543e382524c", "scanner": "scanner-primary", "fingerprint": "f0c8ad7fb888fc74", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f5b9ab48f3548023", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/auth.test.ts:10"}, "properties": {"repobilityId": "7ef0b0f18d812124", "scanner": "scanner-primary", "fingerprint": "f5b9ab48f3548023", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-7364298534331ad6", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/openapi.test.ts:46"}, "properties": {"repobilityId": "acc86db465d067c3", "scanner": "scanner-primary", "fingerprint": "7364298534331ad6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-4f355e09e1a812f3", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/connections.test.ts:6"}, "properties": {"repobilityId": "f94baa67b43e9709", "scanner": "scanner-primary", "fingerprint": "4f355e09e1a812f3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-223ac8993b74ab24", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/restish-openapi.test.ts:17"}, "properties": {"repobilityId": "413c896b5d8c67f4", "scanner": "scanner-primary", "fingerprint": "223ac8993b74ab24", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-17bb1a3e6e06adaa", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/providers.test.ts:10"}, "properties": {"repobilityId": "afc5207303d9e80f", "scanner": "scanner-primary", "fingerprint": "17bb1a3e6e06adaa", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-fb20fda14c148886", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/triggers.test.ts:6"}, "properties": {"repobilityId": "4528744366687d19", "scanner": "scanner-primary", "fingerprint": "fb20fda14c148886", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-d475cff9a1214c77", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/audit-records.test.ts:6"}, "properties": {"repobilityId": "0768fc2f1d341eb6", "scanner": "scanner-primary", "fingerprint": "d475cff9a1214c77", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0a2d31dc01a8f54b", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/integration/runtime-ai.test.ts:6"}, "properties": {"repobilityId": "7e55606bd58a65f1", "scanner": "scanner-primary", "fingerprint": "0a2d31dc01a8f54b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-8d9b6266dc83aa47", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/auth/oidc.ts:332"}, "properties": {"repobilityId": "e8b30a0ba1cfd333", "scanner": "scanner-primary", "fingerprint": "8d9b6266dc83aa47", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c6e0edfe00c03ae4", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/auth/oidc.ts:132"}, "properties": {"repobilityId": "8e2ba2cd2d58d1e1", "scanner": "scanner-primary", "fingerprint": "c6e0edfe00c03ae4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0ca0528cd079e877", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/auth/session.ts:216"}, "properties": {"repobilityId": "6e571f8a9e0359ce", "scanner": "scanner-primary", "fingerprint": "0ca0528cd079e877", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b3f19aba9ebb05b2", "level": "none", "message": {"text": "Commented-code block (8 lines) in server/worker/runner-session-channel.ts:1"}, "properties": {"repobilityId": "c6c9bafa2da4ddbf", "scanner": "scanner-primary", "fingerprint": "b3f19aba9ebb05b2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9c0698f2ff1fee17", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/worker/runner-session-channel.ts:30"}, "properties": {"repobilityId": "0f82179b36562854", "scanner": "scanner-primary", "fingerprint": "9c0698f2ff1fee17", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0e7cfc4afc6896af", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/http/auth.ts:146"}, "properties": {"repobilityId": "c987199a32a202be", "scanner": "scanner-primary", "fingerprint": "0e7cfc4afc6896af", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-02e8b2699fe1f937", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/http/e2e.ts:1"}, "properties": {"repobilityId": "21e04e58bdbdcdf9", "scanner": "scanner-primary", "fingerprint": "02e8b2699fe1f937", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6e01188302113943", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/http/runtime-proxy.ts:30"}, "properties": {"repobilityId": "d991f33a7688859c", "scanner": "scanner-primary", "fingerprint": "6e01188302113943", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3bf35887459d02d8", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server/http/leases.ts:288"}, "properties": {"repobilityId": "b322db05c5391fe8", "scanner": "scanner-primary", "fingerprint": "3bf35887459d02d8", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e27fb184a1a0ad42", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/http/federated-tenants.ts:217"}, "properties": {"repobilityId": "062bbe18d4c1c036", "scanner": "scanner-primary", "fingerprint": "e27fb184a1a0ad42", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-15e2085fb8f32f02", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/http/sessions.ts:358"}, "properties": {"repobilityId": "37b64b6f7be0c6e6", "scanner": "scanner-primary", "fingerprint": "15e2085fb8f32f02", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-be8f603691cd20a5", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/http/audit-records.ts:192"}, "properties": {"repobilityId": "392520e1dbbf343f", "scanner": "scanner-primary", "fingerprint": "be8f603691cd20a5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-17b9a57e8a4263bc", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/http/usage-records.ts:195"}, "properties": {"repobilityId": "80860e5ecfe59d85", "scanner": "scanner-primary", "fingerprint": "17b9a57e8a4263bc", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7d9991d09d3fe982", "level": "none", "message": {"text": "Commented-code block (8 lines) in server/db/schema.ts:4"}, "properties": {"repobilityId": "e78c67b1ce8aa9ce", "scanner": "scanner-primary", "fingerprint": "7d9991d09d3fe982", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-809e118cf4aaae99", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/usecases/ports.ts:227"}, "properties": {"repobilityId": "67b80b2a366e15ea", "scanner": "scanner-primary", "fingerprint": "809e118cf4aaae99", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-5ddd022482e785b3", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/usecases/providers.ts:137"}, "properties": {"repobilityId": "801561deddb4e17a", "scanner": "scanner-primary", "fingerprint": "5ddd022482e785b3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-496f48c7430f6a3b", "level": "none", "message": {"text": "Commented-code block (7 lines) in server/usecases/leases.ts:18"}, "properties": {"repobilityId": "a3d2a7b83dc8a82d", "scanner": "scanner-primary", "fingerprint": "496f48c7430f6a3b", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-42f2726437fdddb2", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/usecases/runtime/turn-callbacks.test.ts:4"}, "properties": {"repobilityId": "58883f5c2c260d09", "scanner": "scanner-primary", "fingerprint": "42f2726437fdddb2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b2033f2d8f18ad7a", "level": "none", "message": {"text": "Commented-code block (8 lines) in server/usecases/runtime/runner-channel-ingest.ts:5"}, "properties": {"repobilityId": "8ae22168b9422e7e", "scanner": "scanner-primary", "fingerprint": "b2033f2d8f18ad7a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-41d53f10595e5264", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/usecases/runtime/cloud-turn.test.ts:10"}, "properties": {"repobilityId": "21d8ab7afc82ee03", "scanner": "scanner-primary", "fingerprint": "41d53f10595e5264", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-25b5a8afd21138d9", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/usecases/runtime/cloud-turn.ts:3"}, "properties": {"repobilityId": "8ee52362f4e87750", "scanner": "scanner-primary", "fingerprint": "25b5a8afd21138d9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c593944ea5352442", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/usecases/runtime/turn-callbacks.ts:3"}, "properties": {"repobilityId": "52df96ad1114f2c0", "scanner": "scanner-primary", "fingerprint": "c593944ea5352442", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1a415d2f8da1a416", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/usecases/runtime/session-approval.ts:8"}, "properties": {"repobilityId": "25ebe104e5dcfc2c", "scanner": "scanner-primary", "fingerprint": "1a415d2f8da1a416", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-07ac0835ef1b4062", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/usecases/runtime/session-create.ts:3"}, "properties": {"repobilityId": "415fa504eca8ce7d", "scanner": "scanner-primary", "fingerprint": "07ac0835ef1b4062", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-bb9733b0cd1375b3", "level": "none", "message": {"text": "Commented-code block (9 lines) in server/usecases/runtime/sessions.ts:3"}, "properties": {"repobilityId": "3256826062d9d5f7", "scanner": "scanner-primary", "fingerprint": "bb9733b0cd1375b3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-666988ba27f3d2c7", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/usecases/runtime/approval-gate.ts:3"}, "properties": {"repobilityId": "ba03dfffe7ec3f70", "scanner": "scanner-primary", "fingerprint": "666988ba27f3d2c7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6dcdb6bac02af868", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/usecases/runtime/provisioning.ts:1"}, "properties": {"repobilityId": "71bdf6ca1a5c9e3f", "scanner": "scanner-primary", "fingerprint": "6dcdb6bac02af868", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6bae1d7cde945eb3", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/usecases/runtime/events.ts:1"}, "properties": {"repobilityId": "63ff8f4f0d959808", "scanner": "scanner-primary", "fingerprint": "6bae1d7cde945eb3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-79e7a492f32a63cc", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/usecases/runtime/proxy.ts:3"}, "properties": {"repobilityId": "52f4bfb45e56d948", "scanner": "scanner-primary", "fingerprint": "79e7a492f32a63cc", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ed912e2efe479a9f", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/usecases/runtime/session-create.test.ts:9"}, "properties": {"repobilityId": "b1550e76e8ea6c90", "scanner": "scanner-primary", "fingerprint": "ed912e2efe479a9f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-99f75de35605971c", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/usecases/runtime/session-prompt.ts:7"}, "properties": {"repobilityId": "05f1d472486cc861", "scanner": "scanner-primary", "fingerprint": "99f75de35605971c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-899991e8f109fc87", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/domain/provider-adapter.ts:1"}, "properties": {"repobilityId": "b590e70539f6af02", "scanner": "scanner-primary", "fingerprint": "899991e8f109fc87", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ba6407d710f446f3", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/domain/runtime-catalog.ts:20"}, "properties": {"repobilityId": "f4ef13b7612f42eb", "scanner": "scanner-primary", "fingerprint": "ba6407d710f446f3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9d1142ebd91c2bdc", "level": "note", "message": {"text": "Legacy-named symbol `org_old` in server/domain/policy.test.ts:118"}, "properties": {"repobilityId": "a5384599d7ddd562", "scanner": "scanner-primary", "fingerprint": "9d1142ebd91c2bdc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-a5be60e8db2f9f04", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/domain/policy.ts:3"}, "properties": {"repobilityId": "e4eee0121cc25dc6", "scanner": "scanner-primary", "fingerprint": "a5be60e8db2f9f04", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e3178bda481022a2", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/domain/runtime/provider.ts:1"}, "properties": {"repobilityId": "ef1d296bfec173e6", "scanner": "scanner-primary", "fingerprint": "e3178bda481022a2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6b93ff0441aae1cc", "level": "none", "message": {"text": "Commented-code block (6 lines) in server/domain/runtime/system-auth.ts:1"}, "properties": {"repobilityId": "6270cb462d593208", "scanner": "scanner-primary", "fingerprint": "6b93ff0441aae1cc", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f50b186a6ead2a6a", "level": "none", "message": {"text": "Commented-code block (5 lines) in server/domain/runtime/turn.ts:4"}, "properties": {"repobilityId": "2b987d098a9f594e", "scanner": "scanner-primary", "fingerprint": "f50b186a6ead2a6a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-386fd222f8b7a180", "level": "none", "message": {"text": "Commented-code block (5 lines) in runtime-bridge/src/providers/claude-code.ts:65"}, "properties": {"repobilityId": "dbaf3043866a7cb8", "scanner": "scanner-primary", "fingerprint": "386fd222f8b7a180", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7221a1d47448e019", "level": "none", "message": {"text": "Commented-code block (7 lines) in runtime-bridge/src/providers/ama.ts:25"}, "properties": {"repobilityId": "883e73c1bfd733af", "scanner": "scanner-primary", "fingerprint": "7221a1d47448e019", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f6be8bb9207a4f54", "level": "none", "message": {"text": "Commented-code block (5 lines) in runtime-core/transcript.ts:1"}, "properties": {"repobilityId": "ad37a2a8d8f38a29", "scanner": "scanner-primary", "fingerprint": "f6be8bb9207a4f54", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c4acc374bdda5645", "level": "none", "message": {"text": "Commented-code block (5 lines) in runtime-core/turn-engine.ts:1"}, "properties": {"repobilityId": "d9ec83cb353dbe0f", "scanner": "scanner-primary", "fingerprint": "c4acc374bdda5645", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d976502bd3218d13", "level": "none", "message": {"text": "Commented-code block (6 lines) in runtime-core/ports.ts:3"}, "properties": {"repobilityId": "110ba6f4a011ee5f", "scanner": "scanner-primary", "fingerprint": "d976502bd3218d13", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-be5d1e0d84240056", "level": "none", "message": {"text": "Commented-code block (6 lines) in runtime-core/turn-status.ts:1"}, "properties": {"repobilityId": "818bd6605a712879", "scanner": "scanner-primary", "fingerprint": "be5d1e0d84240056", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-64d1cf6293ead344", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/test/msw.ts:4"}, "properties": {"repobilityId": "f1001fb2d558a7c7", "scanner": "scanner-primary", "fingerprint": "64d1cf6293ead344", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a324f95d983ade57", "level": "note", "message": {"text": "Legacy-named symbol `session_old` in src/features/sessions/sessions-pages.test.tsx:1794"}, "properties": {"repobilityId": "da6acb4e40ef954e", "scanner": "scanner-primary", "fingerprint": "a324f95d983ade57", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-dbc1e62ba380321e", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/features/console/console-ui.test.tsx:548"}, "properties": {"repobilityId": "3b0a542e87d9e6c3", "scanner": "scanner-primary", "fingerprint": "dbc1e62ba380321e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b3b6910838e1990b", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 e2e/fixtures.ts:27"}, "properties": {"repobilityId": "7524863a48c9ed5c", "scanner": "scanner-primary", "fingerprint": "b3b6910838e1990b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-794e6e8a8fb44957", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 sdk/typescript/src/index.ts:53"}, "properties": {"repobilityId": "693441741dda8503", "scanner": "scanner-primary", "fingerprint": "794e6e8a8fb44957", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ad1f2c0971b89ce0", "level": "note", "message": {"text": "10 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "3bfdc60c61f1870e", "scanner": "scanner-primary", "fingerprint": "ad1f2c0971b89ce0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-79addc5ba397859a", "level": "warning", "message": {"text": "Frontend route `/mcp/:connectorId` has no Link/navigate to it \u2014 src/features/mcp/mcp-ui.test.tsx"}, "properties": {"repobilityId": "a6c75ce0c31ed75d", "scanner": "scanner-primary", "fingerprint": "79addc5ba397859a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-8f43da642896e4af", "level": "warning", "message": {"text": "Frontend route `/sessions/:sessionId` has no Link/navigate to it \u2014 src/features/sessions/sessions-pages.test.tsx"}, "properties": {"repobilityId": "6eb94c77331e91aa", "scanner": "scanner-primary", "fingerprint": "8f43da642896e4af", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-f82e6fbf57800b49", "level": "warning", "message": {"text": "Frontend route `/providers/:providerId` has no Link/navigate to it \u2014 src/features/providers/providers-ui.test.tsx"}, "properties": {"repobilityId": "40357fe7db8e9205", "scanner": "scanner-primary", "fingerprint": "f82e6fbf57800b49", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-f26c830d2beec5e5", "level": "warning", "message": {"text": "Frontend route `/providers/` has no Link/navigate to it \u2014 src/features/providers/providers-ui.test.tsx"}, "properties": {"repobilityId": "6ef14ecadb910085", "scanner": "scanner-primary", "fingerprint": "f26c830d2beec5e5", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-928268417b37cb92", "level": "warning", "message": {"text": "Frontend route `/audit/:recordId` has no Link/navigate to it \u2014 src/features/audit/audit-ui.test.tsx"}, "properties": {"repobilityId": "f72a535a9a804538", "scanner": "scanner-primary", "fingerprint": "928268417b37cb92", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-3b0a42efc962cbb1", "level": "warning", "message": {"text": "Frontend route `/agents/:agentId` has no Link/navigate to it \u2014 src/features/agents/AgentDetailPage.test.tsx"}, "properties": {"repobilityId": "60ca77bc70dc9dca", "scanner": "scanner-primary", "fingerprint": "3b0a42efc962cbb1", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-70312cacad4aa38a", "level": "warning", "message": {"text": "Frontend route `/vaults/:vaultId` has no Link/navigate to it \u2014 src/features/vaults/vaults-ui.test.tsx"}, "properties": {"repobilityId": "977c796f0b7fb14c", "scanner": "scanner-primary", "fingerprint": "70312cacad4aa38a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-2151885ff605c1a3", "level": "warning", "message": {"text": "Frontend route `/environments/:environmentId` has no Link/navigate to it \u2014 src/features/environments/environments-ui.test.tsx"}, "properties": {"repobilityId": "78f3c3f315c5b0cb", "scanner": "scanner-primary", "fingerprint": "2151885ff605c1a3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-a60f5911c5506678", "level": "error", "message": {"text": "Dangling fetch: GET https://runner-session-channel/status (server/adapters/gateways/runner-channel.ts:13)"}, "properties": {"repobilityId": "c60e96a302752798", "scanner": "scanner-primary", "fingerprint": "a60f5911c5506678", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-436d83c9aa0711aa", "level": "error", "message": {"text": "Dangling fetch: POST https://runner-session-channel/dispatch (server/adapters/gateways/runner-channel.ts:24)"}, "properties": {"repobilityId": "611da68e62270a07", "scanner": "scanner-primary", "fingerprint": "436d83c9aa0711aa", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a18d441b7ef75017", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com/api/v1/health (server/integration/health.test.ts:7)"}, "properties": {"repobilityId": "a56f1cc0899ee269", "scanner": "scanner-primary", "fingerprint": "a18d441b7ef75017", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-baf540c4bcb2f01a", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/budgets.test.ts:6)"}, "properties": {"repobilityId": "a4a90de3e73a7cdf", "scanner": "scanner-primary", "fingerprint": "baf540c4bcb2f01a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-dc3c5e5f517fa1f1", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/runtimes.test.ts:6)"}, "properties": {"repobilityId": "6088a371605e992a", "scanner": "scanner-primary", "fingerprint": "dc3c5e5f517fa1f1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-ef25499323b8d138", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/runners.test.ts:9)"}, "properties": {"repobilityId": "ae15400968d16c86", "scanner": "scanner-primary", "fingerprint": "ef25499323b8d138", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-494d3499cc1b1292", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com/api/v1/runners (server/integration/runners.test.ts:276)"}, "properties": {"repobilityId": "390156da5cfff08b", "scanner": "scanner-primary", "fingerprint": "494d3499cc1b1292", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-2604c1894b4890db", "level": "error", "message": {"text": "Dangling fetch: PUT https://example.com/api/v1/runners/runner_x/heartbeat (server/integration/runners.test.ts:280)"}, "properties": {"repobilityId": "e12de9815d3551d2", "scanner": "scanner-primary", "fingerprint": "2604c1894b4890db", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-7de0129b7010e86e", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/agents.test.ts:6)"}, "properties": {"repobilityId": "30f9fc47ab73a732", "scanner": "scanner-primary", "fingerprint": "7de0129b7010e86e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-1ec6a0c1f4f41ff1", "level": "error", "message": {"text": "Dangling fetch: POST https://example.com/api/v1/agents (server/integration/agents.test.ts:54)"}, "properties": {"repobilityId": "7b35fc23105ad348", "scanner": "scanner-primary", "fingerprint": "1ec6a0c1f4f41ff1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-2d741b533149b584", "level": "error", "message": {"text": "Dangling fetch: POST https://example.com/api/v1/agents (server/integration/agents.test.ts:70)"}, "properties": {"repobilityId": "71ec61ff5dece0be", "scanner": "scanner-primary", "fingerprint": "2d741b533149b584", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4bc0109f011bfc54", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/federated-tenants.test.ts:6)"}, "properties": {"repobilityId": "d627dae2e69e5ed0", "scanner": "scanner-primary", "fingerprint": "4bc0109f011bfc54", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-90150aa962fc5bab", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/providers-governance.test.ts:6)"}, "properties": {"repobilityId": "7f1d8fa3a5fd7680", "scanner": "scanner-primary", "fingerprint": "90150aa962fc5bab", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-423e52844c0c2f8f", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/leases.test.ts:10)"}, "properties": {"repobilityId": "243b6987f9d0993d", "scanner": "scanner-primary", "fingerprint": "423e52844c0c2f8f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-26019dcdfdfffa9e", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com/api/v1/leases/${leaseId}/channel (server/integration/leases.test.ts:129)"}, "properties": {"repobilityId": "27703ce30c544bff", "scanner": "scanner-primary", "fingerprint": "26019dcdfdfffa9e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-9367b54a9f3f8af1", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com/api/v1/leases/lease_missing/channel (server/integration/leases.test.ts:480)"}, "properties": {"repobilityId": "d97fedc291591aff", "scanner": "scanner-primary", "fingerprint": "9367b54a9f3f8af1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e058dac2f79b4179", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com/api/v1/leases/${lease.id}/channel (server/integration/leases.test.ts:491)"}, "properties": {"repobilityId": "d144fa8bd18de831", "scanner": "scanner-primary", "fingerprint": "e058dac2f79b4179", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5a40c3ea88a4a789", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/connectors.test.ts:6)"}, "properties": {"repobilityId": "3311282a1cc85971", "scanner": "scanner-primary", "fingerprint": "5a40c3ea88a4a789", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d27156527c6e9444", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com/api/v1/connectors (server/integration/connectors.test.ts:110)"}, "properties": {"repobilityId": "c350f02b5aba65ef", "scanner": "scanner-primary", "fingerprint": "d27156527c6e9444", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-667652625a183585", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/effective-policy.test.ts:8)"}, "properties": {"repobilityId": "90d0f31e7315034b", "scanner": "scanner-primary", "fingerprint": "667652625a183585", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d2648080b90bf04a", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/access-rules.test.ts:6)"}, "properties": {"repobilityId": "1d5439f64d690647", "scanner": "scanner-primary", "fingerprint": "d2648080b90bf04a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a2d43faff9d1be66", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/usage-summary.test.ts:10)"}, "properties": {"repobilityId": "b4998065027bd2c6", "scanner": "scanner-primary", "fingerprint": "a2d43faff9d1be66", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-711b26204388d2ec", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/policies.test.ts:6)"}, "properties": {"repobilityId": "a914887c705c1426", "scanner": "scanner-primary", "fingerprint": "711b26204388d2ec", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c9e37db90bbcd35c", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/work-items.test.ts:9)"}, "properties": {"repobilityId": "e9ee4b017cc9defb", "scanner": "scanner-primary", "fingerprint": "c9e37db90bbcd35c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-f6c59f3f46b8485a", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/vaults.test.ts:7)"}, "properties": {"repobilityId": "d09f94163cbfe436", "scanner": "scanner-primary", "fingerprint": "f6c59f3f46b8485a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-70cf8599bb5d2f7e", "level": "error", "message": {"text": "Dangling fetch: POST https://example.com/api/v1/vaults (server/integration/vaults.test.ts:27)"}, "properties": {"repobilityId": "fd9c4f4468687cf1", "scanner": "scanner-primary", "fingerprint": "70cf8599bb5d2f7e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e753d198e059280f", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/environments.test.ts:6)"}, "properties": {"repobilityId": "8b69453ce2787d3f", "scanner": "scanner-primary", "fingerprint": "e753d198e059280f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-ea2299799343736f", "level": "error", "message": {"text": "Dangling fetch: POST https://example.com/api/v1/environments (server/integration/environments.test.ts:74)"}, "properties": {"repobilityId": "1f03ebd5b559e35f", "scanner": "scanner-primary", "fingerprint": "ea2299799343736f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e2fb58a5214d0283", "level": "error", "message": {"text": "Dangling fetch: POST https://example.com/api/v1/environments (server/integration/environments.test.ts:90)"}, "properties": {"repobilityId": "4f02ed29aa01dc36", "scanner": "scanner-primary", "fingerprint": "e2fb58a5214d0283", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-38074189adfdee15", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/sessions.test.ts:11)"}, "properties": {"repobilityId": "2a5b879b4c11978b", "scanner": "scanner-primary", "fingerprint": "38074189adfdee15", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5a391a1751c8d339", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com/api/v1/sessions (server/integration/sessions.test.ts:1286)"}, "properties": {"repobilityId": "a433fb6a3b1e3aa1", "scanner": "scanner-primary", "fingerprint": "5a391a1751c8d339", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-cb5878d1d66e0eb0", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/usage-records.test.ts:10)"}, "properties": {"repobilityId": "c085e9bbf4d89442", "scanner": "scanner-primary", "fingerprint": "cb5878d1d66e0eb0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-06a2daaa943efc3a", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/auth.test.ts:10)"}, "properties": {"repobilityId": "f6504d82ccf46410", "scanner": "scanner-primary", "fingerprint": "06a2daaa943efc3a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-198dcb81feee81ed", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com/api/v1/auth/config (server/integration/auth.test.ts:30)"}, "properties": {"repobilityId": "08dba4cc72250604", "scanner": "scanner-primary", "fingerprint": "198dcb81feee81ed", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-018c4ff0650f60e1", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com/api/v1/auth/config?organization=example-org (server/integration/auth.test.ts:38)"}, "properties": {"repobilityId": "c9695c1e0f42c364", "scanner": "scanner-primary", "fingerprint": "018c4ff0650f60e1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-13b418b702cc4229", "level": "error", "message": {"text": "Dangling fetch: POST https://example.com/api/v1/auth/sessions (server/integration/auth.test.ts:84)"}, "properties": {"repobilityId": "409d99fe48a6acdc", "scanner": "scanner-primary", "fingerprint": "13b418b702cc4229", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-804f3fb5e634b6ae", "level": "error", "message": {"text": "Dangling fetch: DELETE https://example.com/api/v1/auth/sessions/current (server/integration/auth.test.ts:123)"}, "properties": {"repobilityId": "f67b036a28b2fc22", "scanner": "scanner-primary", "fingerprint": "804f3fb5e634b6ae", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-e1e03453008f7df2", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com/api/v1/openapi.json (server/integration/openapi.test.ts:46)"}, "properties": {"repobilityId": "f7a49d276c0125e4", "scanner": "scanner-primary", "fingerprint": "e1e03453008f7df2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-eb8c7208151e1c2d", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com/api/v1/docs (server/integration/openapi.test.ts:449)"}, "properties": {"repobilityId": "7255dabdc4634a59", "scanner": "scanner-primary", "fingerprint": "eb8c7208151e1c2d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-6296fb54efdf271c", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/connections.test.ts:6)"}, "properties": {"repobilityId": "67a973773ccf30f2", "scanner": "scanner-primary", "fingerprint": "6296fb54efdf271c", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d06b83aa6fd80251", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/restish-openapi.test.ts:17)"}, "properties": {"repobilityId": "1e163b1b9c7be2f9", "scanner": "scanner-primary", "fingerprint": "d06b83aa6fd80251", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5804694170aa6bac", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com/api/v1/openapi.json (server/integration/restish-openapi.test.ts:28)"}, "properties": {"repobilityId": "7d0809b6b62807ae", "scanner": "scanner-primary", "fingerprint": "5804694170aa6bac", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-40031b1dfae525a4", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/providers.test.ts:10)"}, "properties": {"repobilityId": "4d8579123abe94d9", "scanner": "scanner-primary", "fingerprint": "40031b1dfae525a4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c35c758ea64bc93d", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/triggers.test.ts:6)"}, "properties": {"repobilityId": "749897a1de3231bf", "scanner": "scanner-primary", "fingerprint": "c35c758ea64bc93d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c453614ce01cf81a", "level": "error", "message": {"text": "Dangling fetch: GET https://example.com${path} (server/integration/audit-records.test.ts:6)"}, "properties": {"repobilityId": "8b9accc8dbfadd48", "scanner": "scanner-primary", "fingerprint": "c453614ce01cf81a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-b8a76afa1d38ab0b", "level": "error", "message": {"text": "Dangling fetch: POST https://example.com/api/v1/runtime/workers-ai/v1/chat/completions (server/integration/runtime-ai.test.ts:6)"}, "properties": {"repobilityId": "02dfe81871122e90", "scanner": "scanner-primary", "fingerprint": "b8a76afa1d38ab0b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-50a7d6e8ebe2d168", "level": "error", "message": {"text": "Dangling fetch: POST /api/v1/auth/sessions (src/lib/oidc.ts:119)"}, "properties": {"repobilityId": "6a4b51197440fc73", "scanner": "scanner-primary", "fingerprint": "50a7d6e8ebe2d168", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-046dda00f1450b3d", "level": "note", "message": {"text": "Unused endpoint: POST /chat/completions"}, "properties": {"repobilityId": "e7c2c5303c5c38b1", "scanner": "scanner-primary", "fingerprint": "046dda00f1450b3d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-731e0756c2fefc2d", "level": "note", "message": {"text": "Unused endpoint: POST /audio/speech"}, "properties": {"repobilityId": "c51aae9b09b96c39", "scanner": "scanner-primary", "fingerprint": "731e0756c2fefc2d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0703b07fb8e8b6f0", "level": "note", "message": {"text": "Unused endpoint: POST /audio/transcriptions"}, "properties": {"repobilityId": "576c601068055a10", "scanner": "scanner-primary", "fingerprint": "0703b07fb8e8b6f0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-977b39ba4216e247", "level": "note", "message": {"text": "Unused endpoint: POST /audio/translations"}, "properties": {"repobilityId": "5f12a7242ebc5780", "scanner": "scanner-primary", "fingerprint": "977b39ba4216e247", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9ed84d434d52c021", "level": "note", "message": {"text": "Unused endpoint: POST /batches"}, "properties": {"repobilityId": "684891f099878a02", "scanner": "scanner-primary", "fingerprint": "9ed84d434d52c021", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7732e5fbd854c6d4", "level": "note", "message": {"text": "Unused endpoint: POST /assistants"}, "properties": {"repobilityId": "8d58a5389d0dd9c7", "scanner": "scanner-primary", "fingerprint": "7732e5fbd854c6d4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-30495157336e2746", "level": "note", "message": {"text": "Unused endpoint: POST /realtime/sessions"}, "properties": {"repobilityId": "1a6e1f3922e21ab5", "scanner": "scanner-primary", "fingerprint": "30495157336e2746", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bc74f5339c055526", "level": "note", "message": {"text": "Unused endpoint: POST /realtime/transcription_sessions"}, "properties": {"repobilityId": "3a781dabe7eb8727", "scanner": "scanner-primary", "fingerprint": "bc74f5339c055526", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-47c404592e01220b", "level": "note", "message": {"text": "Unused endpoint: POST /chatkit/sessions"}, "properties": {"repobilityId": "3117e757903e62f6", "scanner": "scanner-primary", "fingerprint": "47c404592e01220b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-686be4977a495430", "level": "note", "message": {"text": "Unused endpoint: POST /threads"}, "properties": {"repobilityId": "66a78d18123762b8", "scanner": "scanner-primary", "fingerprint": "686be4977a495430", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9390b6aa85bd274e", "level": "note", "message": {"text": "Unused endpoint: POST /threads/runs"}, "properties": {"repobilityId": "270b821d73bf21b8", "scanner": "scanner-primary", "fingerprint": "9390b6aa85bd274e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8f29cff29921a3be", "level": "note", "message": {"text": "Unused endpoint: POST /completions"}, "properties": {"repobilityId": "52d9e22de407b762", "scanner": "scanner-primary", "fingerprint": "8f29cff29921a3be", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-43887b06a6508e4f", "level": "note", "message": {"text": "Unused endpoint: POST /containers"}, "properties": {"repobilityId": "09034c24bf6aec2a", "scanner": "scanner-primary", "fingerprint": "43887b06a6508e4f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8ee7ac4b5c5364e8", "level": "note", "message": {"text": "Unused endpoint: POST /conversations"}, "properties": {"repobilityId": "5b41fdd6b8c82ef0", "scanner": "scanner-primary", "fingerprint": "8ee7ac4b5c5364e8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2494ea4326b03b3f", "level": "note", "message": {"text": "Unused endpoint: POST /embeddings"}, "properties": {"repobilityId": "8a862308000892c7", "scanner": "scanner-primary", "fingerprint": "2494ea4326b03b3f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6bc94f0922e3a219", "level": "note", "message": {"text": "Unused endpoint: POST /evals"}, "properties": {"repobilityId": "6b140926ceaed160", "scanner": "scanner-primary", "fingerprint": "6bc94f0922e3a219", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f1320a5ffe374dac", "level": "note", "message": {"text": "Unused endpoint: POST /files"}, "properties": {"repobilityId": "aad64fc40ef8e4dd", "scanner": "scanner-primary", "fingerprint": "f1320a5ffe374dac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c974b540a6ec79a6", "level": "note", "message": {"text": "Unused endpoint: POST /fine_tuning/alpha/graders/run"}, "properties": {"repobilityId": "7ed53b3dca044386", "scanner": "scanner-primary", "fingerprint": "c974b540a6ec79a6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d3fded90dc607ec2", "level": "note", "message": {"text": "Unused endpoint: POST /fine_tuning/alpha/graders/validate"}, "properties": {"repobilityId": "2a37c1711f6042e9", "scanner": "scanner-primary", "fingerprint": "d3fded90dc607ec2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2439d65365ac9535", "level": "note", "message": {"text": "Unused endpoint: POST /fine_tuning/jobs"}, "properties": {"repobilityId": "700093b71e01754a", "scanner": "scanner-primary", "fingerprint": "2439d65365ac9535", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e6adff703d49c7d2", "level": "note", "message": {"text": "Unused endpoint: POST /images/variations"}, "properties": {"repobilityId": "13c909c9a271409e", "scanner": "scanner-primary", "fingerprint": "e6adff703d49c7d2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-03133b2476295fb4", "level": "note", "message": {"text": "Unused endpoint: POST /images/edits"}, "properties": {"repobilityId": "2aee56f462ac3720", "scanner": "scanner-primary", "fingerprint": "03133b2476295fb4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e4c5c41cb8097be5", "level": "note", "message": {"text": "Unused endpoint: POST /images/generations"}, "properties": {"repobilityId": "e2182273c513f012", "scanner": "scanner-primary", "fingerprint": "e4c5c41cb8097be5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dc2b015738c65b1b", "level": "note", "message": {"text": "Unused endpoint: POST /moderations"}, "properties": {"repobilityId": "d66a3ce475fcb9dd", "scanner": "scanner-primary", "fingerprint": "dc2b015738c65b1b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-11e9757ab463439e", "level": "note", "message": {"text": "Unused endpoint: POST /realtime/client_secrets"}, "properties": {"repobilityId": "50faf1e6445d0532", "scanner": "scanner-primary", "fingerprint": "11e9757ab463439e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d58c39d1475cdf14", "level": "note", "message": {"text": "Unused endpoint: POST /responses/input_tokens"}, "properties": {"repobilityId": "21838d626554f1a1", "scanner": "scanner-primary", "fingerprint": "d58c39d1475cdf14", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-90e52654c4efbe1d", "level": "note", "message": {"text": "Unused endpoint: POST /responses"}, "properties": {"repobilityId": "fe892299fa23d333", "scanner": "scanner-primary", "fingerprint": "90e52654c4efbe1d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2f40182428f41c6a", "level": "note", "message": {"text": "Unused endpoint: POST /responses/compact"}, "properties": {"repobilityId": "29b283d99570b298", "scanner": "scanner-primary", "fingerprint": "2f40182428f41c6a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ce7fe565b4caff57", "level": "note", "message": {"text": "Unused endpoint: POST /skills"}, "properties": {"repobilityId": "b955add46d66437b", "scanner": "scanner-primary", "fingerprint": "ce7fe565b4caff57", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f440e5eb48cf128b", "level": "note", "message": {"text": "Unused endpoint: POST /uploads"}, "properties": {"repobilityId": "ec88705e68c065fb", "scanner": "scanner-primary", "fingerprint": "f440e5eb48cf128b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-09e66fd1b47698ad", "level": "note", "message": {"text": "Unused endpoint: POST /vector_stores"}, "properties": {"repobilityId": "9b76c44ca0d9301c", "scanner": "scanner-primary", "fingerprint": "09e66fd1b47698ad", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-83b40e43b99732cc", "level": "note", "message": {"text": "Unused endpoint: POST /videos"}, "properties": {"repobilityId": "13c5fdaad3e4da6d", "scanner": "scanner-primary", "fingerprint": "83b40e43b99732cc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b96372541f48aa3b", "level": "note", "message": {"text": "Unused endpoint: POST /v1/environments?beta=true"}, "properties": {"repobilityId": "fd0c794b57b00926", "scanner": "scanner-primary", "fingerprint": "b96372541f48aa3b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f69ff3386aed8a58", "level": "note", "message": {"text": "Unused endpoint: POST /v1/files?beta=true"}, "properties": {"repobilityId": "21aeaec2212c3dce", "scanner": "scanner-primary", "fingerprint": "f69ff3386aed8a58", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5e42ff2d7e23d4c7", "level": "note", "message": {"text": "Unused endpoint: POST /v1/user_profiles?beta=true"}, "properties": {"repobilityId": "c1305de4aa68aa4a", "scanner": "scanner-primary", "fingerprint": "5e42ff2d7e23d4c7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3b8ed4c704a21b2a", "level": "note", "message": {"text": "Unused endpoint: POST /v1/agents?beta=true"}, "properties": {"repobilityId": "cefee24485fbf3cc", "scanner": "scanner-primary", "fingerprint": "3b8ed4c704a21b2a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f8bdbd7b085e30db", "level": "note", "message": {"text": "Unused endpoint: POST /v1/memory_stores?beta=true"}, "properties": {"repobilityId": "04b8e8705e0b7ea2", "scanner": "scanner-primary", "fingerprint": "f8bdbd7b085e30db", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cd7e4d4f2ed43337", "level": "note", "message": {"text": "Unused endpoint: POST /v1/messages/batches?beta=true"}, "properties": {"repobilityId": "1c9f9c781226d66f", "scanner": "scanner-primary", "fingerprint": "cd7e4d4f2ed43337", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-00750df0839bbbd3", "level": "note", "message": {"text": "Unused endpoint: POST /v1/messages?beta=true"}, "properties": {"repobilityId": "cae66f8058d25883", "scanner": "scanner-primary", "fingerprint": "00750df0839bbbd3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6c096d37f349fa96", "level": "note", "message": {"text": "Unused endpoint: POST /v1/messages/count_tokens?beta=true"}, "properties": {"repobilityId": "a05d2e81a2b4c146", "scanner": "scanner-primary", "fingerprint": "6c096d37f349fa96", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-56fe7aef1427c93d", "level": "note", "message": {"text": "Unused endpoint: POST /v1/sessions?beta=true"}, "properties": {"repobilityId": "e9551bce2e00ba1b", "scanner": "scanner-primary", "fingerprint": "56fe7aef1427c93d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bea60f0266e76560", "level": "note", "message": {"text": "Unused endpoint: POST /v1/skills?beta=true"}, "properties": {"repobilityId": "c8b03a8b74d8ab3d", "scanner": "scanner-primary", "fingerprint": "bea60f0266e76560", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2d29f578584143cf", "level": "note", "message": {"text": "Unused endpoint: POST /v1/vaults?beta=true"}, "properties": {"repobilityId": "202e8bb6d236068b", "scanner": "scanner-primary", "fingerprint": "2d29f578584143cf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1e474744f4149920", "level": "note", "message": {"text": "Unused endpoint: POST /v1/complete"}, "properties": {"repobilityId": "659f95978a92e720", "scanner": "scanner-primary", "fingerprint": "1e474744f4149920", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8bcda56c4c41e5fa", "level": "note", "message": {"text": "Unused endpoint: POST /v1/messages/batches"}, "properties": {"repobilityId": "f6a0b5beee29e250", "scanner": "scanner-primary", "fingerprint": "8bcda56c4c41e5fa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-50d20b703a1dd1f9", "level": "note", "message": {"text": "Unused endpoint: POST /v1/messages"}, "properties": {"repobilityId": "626bacfbf8749b41", "scanner": "scanner-primary", "fingerprint": "50d20b703a1dd1f9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e51d72bee485df7b", "level": "note", "message": {"text": "Unused endpoint: POST /v1/messages/count_tokens"}, "properties": {"repobilityId": "4dbaa4bc3a08c284", "scanner": "scanner-primary", "fingerprint": "e51d72bee485df7b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3abf952b8d28d710", "level": "note", "message": {"text": "Unused endpoint: USE /*"}, "properties": {"repobilityId": "5a5e082f03e10ed2", "scanner": "scanner-primary", "fingerprint": "3abf952b8d28d710", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1f46cb4ef071fc81", "level": "note", "message": {"text": "Unused endpoint: GET /api/v1/docs"}, "properties": {"repobilityId": "fd7ef341e3b526e2", "scanner": "scanner-primary", "fingerprint": "1f46cb4ef071fc81", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-39b7672113ed17b5", "level": "note", "message": {"text": "Unused endpoint: ALL /api/v1/runtime/sessions/:sessionId/*"}, "properties": {"repobilityId": "e1b04e70e9e9a041", "scanner": "scanner-primary", "fingerprint": "39b7672113ed17b5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}