{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-c06434b5821bfb24", "name": "Stray `console.log` in TS/JS \u2014 scripts/verify-session-limit-wakeup.ts:98", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/verify-session-limit-wakeup.ts:98"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-db5e73b69bc0f511", "name": "Stray `console.log` in TS/JS \u2014 src/index.ts:51", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/index.ts:51"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8b6932738598ae05", "name": "Stray `console.log` in TS/JS \u2014 src/bot/worker-mode.ts:176", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/bot/worker-mode.ts:176"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f88a1b7351532752", "name": "Stray `console.log` in TS/JS \u2014 src/bot/gateway-watchdog.ts:60", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/bot/gateway-watchdog.ts:60"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5ee3a8e9aebc1975", "name": "Stray `console.log` in TS/JS \u2014 src/bot/background-jobs.ts:55", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/bot/background-jobs.ts:55"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cfef79c9fe5904e4", "name": "Stray `console.log` in TS/JS \u2014 src/bot/scheduler.ts:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/bot/scheduler.ts:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7621f0a76a9fe3e3", "name": "Stray `console.log` in TS/JS \u2014 src/bot/client.ts:119", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/bot/client.ts:119"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-10cc003132d9490a", "name": "Stray `console.log` in TS/JS \u2014 src/bot/commands.ts:152", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/bot/commands.ts:152"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a478a733c102d89", "name": "Stray `console.log` in TS/JS \u2014 src/bot/session-manager.ts:417", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/bot/session-manager.ts:417"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-68dff6b9843695b1", "name": "Stray `console.log` in TS/JS \u2014 src/github/webhook.ts:28", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/github/webhook.ts:28"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-83ce452a5027ad1e", "name": "Stray `console.log` in TS/JS \u2014 src/github/handler.ts:96", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/github/handler.ts:96"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1a9522088069e688", "name": "Stray `console.log` in TS/JS \u2014 src/mcp/permissions.ts:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/mcp/permissions.ts:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7b88522fd8833dbd", "name": "Stray `console.log` in TS/JS \u2014 src/mcp/permission-manager.ts:32", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/mcp/permission-manager.ts:32"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b2bd91b3bbe12bc0", "name": "Stray `console.log` in TS/JS \u2014 src/mcp/server.ts:217", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/mcp/server.ts:217"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cfa3157ad81f54bb", "name": "Stray `console.log` in TS/JS \u2014 src/utils/shell.ts:203", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/utils/shell.ts:203"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7febe6695165f975", "name": "Stray `console.log` in TS/JS \u2014 src/utils/attachments.ts:208", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/utils/attachments.ts:208"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a3d44355c620932d", "name": "Stray `console.log` in TS/JS \u2014 src/utils/path-resolver.ts:143", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/utils/path-resolver.ts:143"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-293a6c6015346e51", "name": "Insecure pattern 'node_child_process' in scripts/verify-session-limit-wakeup.ts:6", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/verify-session-limit-wakeup.ts:6"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-06f661e0865eddf6", "name": "Insecure pattern 'node_child_process' in src/bot/worker-mode.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/bot/worker-mode.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fc0a038b18fe1d90", "name": "Insecure pattern 'node_child_process' in src/bot/background-jobs.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/bot/background-jobs.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4935ca478264412f", "name": "Insecure pattern 'node_child_process' in src/bot/client.ts:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/bot/client.ts:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c1d6111363c10dd5", "name": "Insecure pattern 'node_child_process' in src/bot/session-manager.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/bot/session-manager.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-15eb1a84e2f05aec", "name": "Insecure pattern 'node_child_process' in src/github/handler.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/github/handler.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f092528cd4d78bc1", "name": "Insecure pattern 'node_child_process' in src/utils/path-resolver.ts:3", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/utils/path-resolver.ts:3"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9ed31c2ed5d37451", "name": "Very large file: src/bot/session-manager.ts (1559 lines)", "shortDescription": {"text": "Very large file: src/bot/session-manager.ts (1559 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 112 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c7c5cb486f967581", "name": "Commented-code block (5 lines) in mcp-bridge.cjs:9", "shortDescription": {"text": "Commented-code block (5 lines) in mcp-bridge.cjs:9"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b733a5e839ea4b42", "name": "Legacy-named symbol `ig_old` in test/bot/outbox.test.ts:207", "shortDescription": {"text": "Legacy-named symbol `ig_old` in test/bot/outbox.test.ts:207"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1276aded16f85be9", "name": "Commented-code block (5 lines) in test/utils/shell.test.ts:27", "shortDescription": {"text": "Commented-code block (5 lines) in test/utils/shell.test.ts:27"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7bf571ee91bd34c2", "name": "Commented-code block (5 lines) in src/bot/client.ts:290", "shortDescription": {"text": "Commented-code block (5 lines) in src/bot/client.ts:290"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3c99f183af6645c8", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/bot/client.ts:1052", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/bot/client.ts:1052"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5435a8c03ee78024", "name": "Commented-code block (5 lines) in src/bot/session-manager.ts:28", "shortDescription": {"text": "Commented-code block (5 lines) in src/bot/session-manager.ts:28"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a67b6d55eac78cb7", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/github/pr-comment.ts:17", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/github/pr-comment.ts:17"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ca0accc101dcdef6", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/github/webhook.ts:31", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/github/webhook.ts:31"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7708c2f6a5bb9bb6", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/github/handler.ts:544", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/github/handler.ts:544"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e24612d60196cfd7", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/mcp/server.ts:75", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/mcp/server.ts:75"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7c67d07a04e789aa", "name": "Commented-code block (5 lines) in src/utils/thread-status.ts:8", "shortDescription": {"text": "Commented-code block (5 lines) in src/utils/thread-status.ts:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c389dae9e6d17913", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/utils/attachments.ts:42", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/utils/attachments.ts:42"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f808a4ef3e1071fb", "name": "14 env vars used in code but missing from .env.example", "shortDescription": {"text": "14 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ALLOWED_USER_ID`, `CODEX_HOME`, `DISCORD_AI_TERMINAL_CHANNEL_ID`, `DISCORD_AI_TERMINAL_THREAD_ID`, `DISCORD_CHANNEL_ID`, `DISCORD_CHANNEL_NAME`, `DISCORD_MESSAGE_ID`, `DISCORD_USER_ID` + 6 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c300c7d3ed026dad", "name": "Dangling fetch: GET https://api.github.com/repos/${repo}/hooks (src/github/webhook.ts:16)", "shortDescription": {"text": "Dangling fetch: GET https://api.github.com/repos/${repo}/hooks (src/github/webhook.ts:16)"}, "fullDescription": {"text": "`src/github/webhook.ts:16` calls `GET https://api.github.com/repos/${repo}/hooks` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/repos/<p>/hooks`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-396d9ad163249459", "name": "Dangling fetch: PATCH https://api.github.com/repos/${repo}/hooks/${existing.id} (src/github/webhook.ts:31)", "shortDescription": {"text": "Dangling fetch: PATCH https://api.github.com/repos/${repo}/hooks/${existing.id} (src/github/webhook.ts:31)"}, "fullDescription": {"text": "`src/github/webhook.ts:31` calls `PATCH https://api.github.com/repos/${repo}/hooks/${existing.id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/repos/<p>/hooks/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d7345768fe5ec026", "name": "Dangling fetch: POST https://api.github.com/repos/${repo}/hooks (src/github/webhook.ts:38)", "shortDescription": {"text": "Dangling fetch: POST https://api.github.com/repos/${repo}/hooks (src/github/webhook.ts:38)"}, "fullDescription": {"text": "`src/github/webhook.ts:38` calls `POST https://api.github.com/repos/${repo}/hooks` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/repos/<p>/hooks`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-239a938869adf673", "name": "Unused endpoint: POST /mcp", "shortDescription": {"text": "Unused endpoint: POST /mcp"}, "fullDescription": {"text": "`src/mcp/server.ts` declares `POST /mcp` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cc1d680cdc3d6aa1", "name": "Unused endpoint: GET /mcp", "shortDescription": {"text": "Unused endpoint: GET /mcp"}, "fullDescription": {"text": "`src/mcp/server.ts` declares `GET /mcp` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-56b4efafa0127feb", "name": "Unused endpoint: DELETE /mcp", "shortDescription": {"text": "Unused endpoint: DELETE /mcp"}, "fullDescription": {"text": "`src/mcp/server.ts` declares `DELETE /mcp` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a5d5b44f7004def2", "name": "Unused endpoint: POST /tool/approve_tool", "shortDescription": {"text": "Unused endpoint: POST /tool/approve_tool"}, "fullDescription": {"text": "`src/mcp/server.ts` declares `POST /tool/approve_tool` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8597845dab5f2ddf", "name": "Unused endpoint: POST /tool/ask_user_question", "shortDescription": {"text": "Unused endpoint: POST /tool/ask_user_question"}, "fullDescription": {"text": "`src/mcp/server.ts` declares `POST /tool/ask_user_question` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e43078b0737d9f73", "name": "Unused endpoint: POST /tool/schedule_task", "shortDescription": {"text": "Unused endpoint: POST /tool/schedule_task"}, "fullDescription": {"text": "`src/mcp/server.ts` declares `POST /tool/schedule_task` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d9728a9d0903d1b", "name": "Unused endpoint: POST /tool/list_scheduled_tasks", "shortDescription": {"text": "Unused endpoint: POST /tool/list_scheduled_tasks"}, "fullDescription": {"text": "`src/mcp/server.ts` declares `POST /tool/list_scheduled_tasks` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d6b165d6deef96b", "name": "Unused endpoint: POST /tool/cancel_scheduled_task", "shortDescription": {"text": "Unused endpoint: POST /tool/cancel_scheduled_task"}, "fullDescription": {"text": "`src/mcp/server.ts` declares `POST /tool/cancel_scheduled_task` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-89e344afce3e2824", "name": "Unused endpoint: POST /tool/run_in_background", "shortDescription": {"text": "Unused endpoint: POST /tool/run_in_background"}, "fullDescription": {"text": "`src/mcp/server.ts` declares `POST /tool/run_in_background` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5cc5b7ebf2428a37", "name": "Unused endpoint: POST /tool/list_background_jobs", "shortDescription": {"text": "Unused endpoint: POST /tool/list_background_jobs"}, "fullDescription": {"text": "`src/mcp/server.ts` declares `POST /tool/list_background_jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bd3561fbf1172f7b", "name": "Unused endpoint: POST /tool/cancel_background_job", "shortDescription": {"text": "Unused endpoint: POST /tool/cancel_background_job"}, "fullDescription": {"text": "`src/mcp/server.ts` declares `POST /tool/cancel_background_job` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/23224"}, "properties": {"repository": "yidongw/discord-ai-terminal", "repoUrl": "https://github.com/yidongw/discord-ai-terminal", "branch": "main"}, "results": [{"ruleId": "scanner-c06434b5821bfb24", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/verify-session-limit-wakeup.ts:98"}, "properties": {"repobilityId": "5911980668556830", "scanner": "scanner-primary", "fingerprint": "c06434b5821bfb24", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-db5e73b69bc0f511", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/index.ts:51"}, "properties": {"repobilityId": "867f5b4f120dafeb", "scanner": "scanner-primary", "fingerprint": "db5e73b69bc0f511", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8b6932738598ae05", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/bot/worker-mode.ts:176"}, "properties": {"repobilityId": "c6d6fbd28badb688", "scanner": "scanner-primary", "fingerprint": "8b6932738598ae05", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f88a1b7351532752", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/bot/gateway-watchdog.ts:60"}, "properties": {"repobilityId": "0dc85ec6265998cf", "scanner": "scanner-primary", "fingerprint": "f88a1b7351532752", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5ee3a8e9aebc1975", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/bot/background-jobs.ts:55"}, "properties": {"repobilityId": "2d43741af1f11637", "scanner": "scanner-primary", "fingerprint": "5ee3a8e9aebc1975", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cfef79c9fe5904e4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/bot/scheduler.ts:41"}, "properties": {"repobilityId": "13f3546c3179245b", "scanner": "scanner-primary", "fingerprint": "cfef79c9fe5904e4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7621f0a76a9fe3e3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/bot/client.ts:119"}, "properties": {"repobilityId": "9e95570e7a30d091", "scanner": "scanner-primary", "fingerprint": "7621f0a76a9fe3e3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-10cc003132d9490a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/bot/commands.ts:152"}, "properties": {"repobilityId": "4f4c9c4970627bcb", "scanner": "scanner-primary", "fingerprint": "10cc003132d9490a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0a478a733c102d89", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/bot/session-manager.ts:417"}, "properties": {"repobilityId": "8c46c3a5971529a0", "scanner": "scanner-primary", "fingerprint": "0a478a733c102d89", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-68dff6b9843695b1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/github/webhook.ts:28"}, "properties": {"repobilityId": "36e1e69431cc0b13", "scanner": "scanner-primary", "fingerprint": "68dff6b9843695b1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-83ce452a5027ad1e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/github/handler.ts:96"}, "properties": {"repobilityId": "36fd0423d085da63", "scanner": "scanner-primary", "fingerprint": "83ce452a5027ad1e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1a9522088069e688", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/mcp/permissions.ts:19"}, "properties": {"repobilityId": "d3c7d19dd1e32211", "scanner": "scanner-primary", "fingerprint": "1a9522088069e688", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7b88522fd8833dbd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/mcp/permission-manager.ts:32"}, "properties": {"repobilityId": "a089bb8eae374589", "scanner": "scanner-primary", "fingerprint": "7b88522fd8833dbd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b2bd91b3bbe12bc0", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/mcp/server.ts:217"}, "properties": {"repobilityId": "41a099f0a22f75e1", "scanner": "scanner-primary", "fingerprint": "b2bd91b3bbe12bc0", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cfa3157ad81f54bb", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/utils/shell.ts:203"}, "properties": {"repobilityId": "ab6ca9e846b8bc70", "scanner": "scanner-primary", "fingerprint": "cfa3157ad81f54bb", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7febe6695165f975", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/utils/attachments.ts:208"}, "properties": {"repobilityId": "3b26d36f7acb9705", "scanner": "scanner-primary", "fingerprint": "7febe6695165f975", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a3d44355c620932d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/utils/path-resolver.ts:143"}, "properties": {"repobilityId": "7fd9e310e31bb218", "scanner": "scanner-primary", "fingerprint": "a3d44355c620932d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-293a6c6015346e51", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/verify-session-limit-wakeup.ts:6"}, "properties": {"repobilityId": "f672e075861c9201", "scanner": "scanner-primary", "fingerprint": "293a6c6015346e51", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/verify-session-limit-wakeup.ts"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-06f661e0865eddf6", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/bot/worker-mode.ts:1"}, "properties": {"repobilityId": "909945ee8a32cf94", "scanner": "scanner-primary", "fingerprint": "06f661e0865eddf6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/bot/worker-mode.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-fc0a038b18fe1d90", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/bot/background-jobs.ts:1"}, "properties": {"repobilityId": "af021e6c89d1bd0c", "scanner": "scanner-primary", "fingerprint": "fc0a038b18fe1d90", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/bot/background-jobs.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4935ca478264412f", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/bot/client.ts:3"}, "properties": {"repobilityId": "ccaf5e9eee5719e5", "scanner": "scanner-primary", "fingerprint": "4935ca478264412f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/bot/client.ts"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-c1d6111363c10dd5", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/bot/session-manager.ts:1"}, "properties": {"repobilityId": "bcc85f5d307beff0", "scanner": "scanner-primary", "fingerprint": "c1d6111363c10dd5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/bot/session-manager.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-15eb1a84e2f05aec", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/github/handler.ts:1"}, "properties": {"repobilityId": "668d125161ec520e", "scanner": "scanner-primary", "fingerprint": "15eb1a84e2f05aec", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/github/handler.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f092528cd4d78bc1", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/utils/path-resolver.ts:3"}, "properties": {"repobilityId": "78cac6c26ee7437c", "scanner": "scanner-primary", "fingerprint": "f092528cd4d78bc1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/utils/path-resolver.ts"}, "region": {"startLine": 3}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-9ed31c2ed5d37451", "level": "note", "message": {"text": "Very large file: src/bot/session-manager.ts (1559 lines)"}, "properties": {"repobilityId": "f51343f894b2f6d3", "scanner": "scanner-primary", "fingerprint": "9ed31c2ed5d37451", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "0ca9edaaacf0ae82", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "9461bdabd6ba6343", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "122c62ecd2cc1e0f", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "6d52a9e2361210ea", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "b2b864147cb3e9b9", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-c7c5cb486f967581", "level": "none", "message": {"text": "Commented-code block (5 lines) in mcp-bridge.cjs:9"}, "properties": {"repobilityId": "8bc4e322f15beba7", "scanner": "scanner-primary", "fingerprint": "c7c5cb486f967581", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b733a5e839ea4b42", "level": "note", "message": {"text": "Legacy-named symbol `ig_old` in test/bot/outbox.test.ts:207"}, "properties": {"repobilityId": "5df7acfcb5669b99", "scanner": "scanner-primary", "fingerprint": "b733a5e839ea4b42", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-1276aded16f85be9", "level": "none", "message": {"text": "Commented-code block (5 lines) in test/utils/shell.test.ts:27"}, "properties": {"repobilityId": "888e9d023638402e", "scanner": "scanner-primary", "fingerprint": "1276aded16f85be9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7bf571ee91bd34c2", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/bot/client.ts:290"}, "properties": {"repobilityId": "31b34d67b4493d01", "scanner": "scanner-primary", "fingerprint": "7bf571ee91bd34c2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3c99f183af6645c8", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/bot/client.ts:1052"}, "properties": {"repobilityId": "63d792a3d96e03d5", "scanner": "scanner-primary", "fingerprint": "3c99f183af6645c8", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-5435a8c03ee78024", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/bot/session-manager.ts:28"}, "properties": {"repobilityId": "e10ce039b0305bb6", "scanner": "scanner-primary", "fingerprint": "5435a8c03ee78024", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a67b6d55eac78cb7", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/github/pr-comment.ts:17"}, "properties": {"repobilityId": "b13a47e4cbca19af", "scanner": "scanner-primary", "fingerprint": "a67b6d55eac78cb7", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ca0accc101dcdef6", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/github/webhook.ts:31"}, "properties": {"repobilityId": "0e12b4d0356747b2", "scanner": "scanner-primary", "fingerprint": "ca0accc101dcdef6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-7708c2f6a5bb9bb6", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/github/handler.ts:544"}, "properties": {"repobilityId": "4cad5e8e887b5994", "scanner": "scanner-primary", "fingerprint": "7708c2f6a5bb9bb6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e24612d60196cfd7", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/mcp/server.ts:75"}, "properties": {"repobilityId": "840ca3f8bf3f00a7", "scanner": "scanner-primary", "fingerprint": "e24612d60196cfd7", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-7c67d07a04e789aa", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/utils/thread-status.ts:8"}, "properties": {"repobilityId": "7ec5ebc2071504ab", "scanner": "scanner-primary", "fingerprint": "7c67d07a04e789aa", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c389dae9e6d17913", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/utils/attachments.ts:42"}, "properties": {"repobilityId": "a6494d29d7fe4921", "scanner": "scanner-primary", "fingerprint": "c389dae9e6d17913", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f808a4ef3e1071fb", "level": "note", "message": {"text": "14 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "ce6b2ec4be4ec75a", "scanner": "scanner-primary", "fingerprint": "f808a4ef3e1071fb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-c300c7d3ed026dad", "level": "error", "message": {"text": "Dangling fetch: GET https://api.github.com/repos/${repo}/hooks (src/github/webhook.ts:16)"}, "properties": {"repobilityId": "4ce1c39e72980a9b", "scanner": "scanner-primary", "fingerprint": "c300c7d3ed026dad", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-396d9ad163249459", "level": "error", "message": {"text": "Dangling fetch: PATCH https://api.github.com/repos/${repo}/hooks/${existing.id} (src/github/webhook.ts:31)"}, "properties": {"repobilityId": "e3825889a5397b35", "scanner": "scanner-primary", "fingerprint": "396d9ad163249459", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-d7345768fe5ec026", "level": "error", "message": {"text": "Dangling fetch: POST https://api.github.com/repos/${repo}/hooks (src/github/webhook.ts:38)"}, "properties": {"repobilityId": "85c2cff957c2797e", "scanner": "scanner-primary", "fingerprint": "d7345768fe5ec026", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-239a938869adf673", "level": "note", "message": {"text": "Unused endpoint: POST /mcp"}, "properties": {"repobilityId": "1f9a966b089d65a7", "scanner": "scanner-primary", "fingerprint": "239a938869adf673", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cc1d680cdc3d6aa1", "level": "note", "message": {"text": "Unused endpoint: GET /mcp"}, "properties": {"repobilityId": "b823116255265f9b", "scanner": "scanner-primary", "fingerprint": "cc1d680cdc3d6aa1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-56b4efafa0127feb", "level": "note", "message": {"text": "Unused endpoint: DELETE /mcp"}, "properties": {"repobilityId": "1e43c5db5b31c214", "scanner": "scanner-primary", "fingerprint": "56b4efafa0127feb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a5d5b44f7004def2", "level": "note", "message": {"text": "Unused endpoint: POST /tool/approve_tool"}, "properties": {"repobilityId": "010e617f60c2688e", "scanner": "scanner-primary", "fingerprint": "a5d5b44f7004def2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8597845dab5f2ddf", "level": "note", "message": {"text": "Unused endpoint: POST /tool/ask_user_question"}, "properties": {"repobilityId": "43d9677d0f31f992", "scanner": "scanner-primary", "fingerprint": "8597845dab5f2ddf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e43078b0737d9f73", "level": "note", "message": {"text": "Unused endpoint: POST /tool/schedule_task"}, "properties": {"repobilityId": "c9b4505c6511b29d", "scanner": "scanner-primary", "fingerprint": "e43078b0737d9f73", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9d9728a9d0903d1b", "level": "note", "message": {"text": "Unused endpoint: POST /tool/list_scheduled_tasks"}, "properties": {"repobilityId": "f2f481c7fe68f2d0", "scanner": "scanner-primary", "fingerprint": "9d9728a9d0903d1b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8d6b165d6deef96b", "level": "note", "message": {"text": "Unused endpoint: POST /tool/cancel_scheduled_task"}, "properties": {"repobilityId": "2918ec2dda721a37", "scanner": "scanner-primary", "fingerprint": "8d6b165d6deef96b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-89e344afce3e2824", "level": "note", "message": {"text": "Unused endpoint: POST /tool/run_in_background"}, "properties": {"repobilityId": "a1686b3d5930142d", "scanner": "scanner-primary", "fingerprint": "89e344afce3e2824", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5cc5b7ebf2428a37", "level": "note", "message": {"text": "Unused endpoint: POST /tool/list_background_jobs"}, "properties": {"repobilityId": "0d0ac2ad93629e72", "scanner": "scanner-primary", "fingerprint": "5cc5b7ebf2428a37", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bd3561fbf1172f7b", "level": "note", "message": {"text": "Unused endpoint: POST /tool/cancel_background_job"}, "properties": {"repobilityId": "de6d200cde9af97e", "scanner": "scanner-primary", "fingerprint": "bd3561fbf1172f7b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}