{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-2fa910107fc460f1", "name": "Possibly dead Python function: compose_prompt", "shortDescription": {"text": "Possibly dead Python function: compose_prompt"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6c60854999b2dfa5", "name": "Possibly dead Python function: head_one", "shortDescription": {"text": "Possibly dead Python function: head_one"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f9adebf829dff9b", "name": "Possibly dead Python function: compose_prompt", "shortDescription": {"text": "Possibly dead Python function: compose_prompt"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-53356e610750c9fa", "name": "Possibly dead Python function: compose_prompt", "shortDescription": {"text": "Possibly dead Python function: compose_prompt"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9b9acf79e853b258", "name": "Privileged port 29 in use", "shortDescription": {"text": "Privileged port 29 in use"}, "fullDescription": {"text": "Port 29 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b3241643bfb148b0", "name": "Privileged port 32 in use", "shortDescription": {"text": "Privileged port 32 in use"}, "fullDescription": {"text": "Port 32 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4d8ad27c9d3602fc", "name": "Privileged port 11 in use", "shortDescription": {"text": "Privileged port 11 in use"}, "fullDescription": {"text": "Port 11 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5150343635f11868", "name": "Privileged port 12 in use", "shortDescription": {"text": "Privileged port 12 in use"}, "fullDescription": {"text": "Port 12 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-10f4b18174b35756", "name": "Privileged port 13 in use", "shortDescription": {"text": "Privileged port 13 in use"}, "fullDescription": {"text": "Port 13 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6e82cdb84e9b2b2c", "name": "Privileged port 49 in use", "shortDescription": {"text": "Privileged port 49 in use"}, "fullDescription": {"text": "Port 49 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6e351639b30739ea", "name": "Privileged port 57 in use", "shortDescription": {"text": "Privileged port 57 in use"}, "fullDescription": {"text": "Port 57 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e30d876397cd7d08", "name": "Privileged port 21 in use", "shortDescription": {"text": "Privileged port 21 in use"}, "fullDescription": {"text": "Port 21 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1e21a430f063e901", "name": "Privileged port 41 in use", "shortDescription": {"text": "Privileged port 41 in use"}, "fullDescription": {"text": "Port 41 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c95aeb3aa18e7cd7", "name": "Privileged port 40 in use", "shortDescription": {"text": "Privileged port 40 in use"}, "fullDescription": {"text": "Port 40 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4ce5304e2b743d35", "name": "Privileged port 59 in use", "shortDescription": {"text": "Privileged port 59 in use"}, "fullDescription": {"text": "Port 59 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ec3ec2b388a3f686", "name": "Privileged port 34 in use", "shortDescription": {"text": "Privileged port 34 in use"}, "fullDescription": {"text": "Port 34 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-01b47d15f18c8556", "name": "Privileged port 26 in use", "shortDescription": {"text": "Privileged port 26 in use"}, "fullDescription": {"text": "Port 26 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d1244aa26262716f", "name": "Privileged port 54 in use", "shortDescription": {"text": "Privileged port 54 in use"}, "fullDescription": {"text": "Port 54 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-924fcc5a497a57bf", "name": "Privileged port 38 in use", "shortDescription": {"text": "Privileged port 38 in use"}, "fullDescription": {"text": "Port 38 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-74e4bd7cdc4c4a8e", "name": "Privileged port 37 in use", "shortDescription": {"text": "Privileged port 37 in use"}, "fullDescription": {"text": "Port 37 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1fc7ab0fa0b3df1b", "name": "Privileged port 47 in use", "shortDescription": {"text": "Privileged port 47 in use"}, "fullDescription": {"text": "Port 47 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5c35b5779a47d009", "name": "Privileged port 55 in use", "shortDescription": {"text": "Privileged port 55 in use"}, "fullDescription": {"text": "Port 55 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4d11fe99f4fc5088", "name": "Privileged port 27 in use", "shortDescription": {"text": "Privileged port 27 in use"}, "fullDescription": {"text": "Port 27 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b45454ca850fb64c", "name": "Insecure pattern 'weak_hash' in scripts/r2_manifest_from_bucket.py:70", "shortDescription": {"text": "Insecure pattern 'weak_hash' in scripts/r2_manifest_from_bucket.py:70"}, "fullDescription": {"text": "Found a known-risky pattern (weak_hash). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-569f3b052e90fab1", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-python@v5 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f36b61c1556ab677", "name": "Very large file: scripts/playtest_dashboard.py (1042 lines)", "shortDescription": {"text": "Very large file: scripts/playtest_dashboard.py (1042 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ddbf517e3e459975", "name": "Very large file: scripts/playtest.py (1446 lines)", "shortDescription": {"text": "Very large file: scripts/playtest.py (1446 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 103 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-768082747b4cdd87", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-fix-blocker.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-fix-blocker.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-82578d70046150c5", "name": "Agent authority lacks a verifier contract: .claude/commands/work.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/work.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-489f303d4e4ead61", "name": "Agent authority lacks a verifier contract: .claude/commands/tech-writer.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/tech-writer.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4f05f73c2a26b647", "name": "Agent authority lacks a verifier contract: .claude/commands/peloton.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/peloton.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3bbad82439c84ebe", "name": "Agent authority lacks a verifier contract: .claude/commands/brainstorming.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/brainstorming.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aa034001a8b7032f", "name": "Agent authority lacks a verifier contract: .claude/commands/session.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/session.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3e0499fa3aa738b4", "name": "Agent authority lacks a verifier contract: .claude/commands/ba.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/ba.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c0d0b1c2f889065b", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-brainstorming.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-brainstorming.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d436a27bd025c6e9", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-setup.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-setup.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-87140f614200b8dd", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-reviewer.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-reviewer.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7b889d12077b415c", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-peloton.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-peloton.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5d04bf155a724be9", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-orchestrator.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-orchestrator.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e6522154bfd04d3a", "name": "Agent authority lacks a verifier contract: .claude/commands/architect.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/architect.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9c688fa0966f4160", "name": "Agent authority lacks a verifier contract: .claude/commands/fix-blocker.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/fix-blocker.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0d10a6b2d7cd82a7", "name": "Agent authority lacks a verifier contract: .claude/commands/setup.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/setup.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-13579452eb100ad0", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-architect.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-architect.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f89bdbb372647d44", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-workflow.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-workflow.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-884ebcae271fc1ae", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-pm.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-pm.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-517799f1298e51f9", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-sm.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-sm.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-438d3dcb6180aa20", "name": "Agent authority lacks a verifier contract: .claude/commands/job-fair.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/job-fair.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-079f6020673d2a3f", "name": "Agent authority lacks a verifier contract: .claude/commands/benchmark-control.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/benchmark-control.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5e0018464444f0eb", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-dev.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-dev.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-74bf10254693ff17", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-theme.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-theme.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aecb8a03989dc134", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-tech-writer.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-tech-writer.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aebd9d53aa24326e", "name": "Agent authority lacks a verifier contract: .claude/commands/theme.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/theme.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bf888e55fd3fb166", "name": "Agent authority lacks a verifier contract: .claude/commands/pm.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pm.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1c2a1d85f5de0809", "name": "Agent authority lacks a verifier contract: .claude/commands/dev.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/dev.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5797766b11b5842b", "name": "Agent authority lacks a verifier contract: .claude/commands/workflow.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/workflow.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e3fc505f15865940", "name": "Agent authority lacks a verifier contract: .claude/commands/orchestrator.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/orchestrator.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b1f3b9d56b23274a", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-benchmark-control.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-benchmark-control.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c3a60aeeb91eb288", "name": "Agent authority lacks a verifier contract: .claude/commands/sq-poi.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/sq-poi.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a39ba1cef82c519c", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-job-fair.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-job-fair.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-05bde4975b842efb", "name": "Agent authority lacks a verifier contract: .claude/commands/ux-designer.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/ux-designer.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ace00160f3f40983", "name": "Agent authority lacks a verifier contract: .claude/commands/sm.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/sm.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7cfed6031d7241ed", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-ba.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-ba.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1e5a5d2c3ba0540a", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-devops.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-devops.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ae33f20ca85529ae", "name": "Agent authority lacks a verifier contract: .claude/commands/sq-music.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/sq-music.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8a5cddef07d1bf85", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-work.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-work.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6cba894b49b107ec", "name": "Agent authority lacks a verifier contract: .claude/commands/devops.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/devops.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1bb9e81a88257945", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-gm.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-gm.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ffa974891e7d5977", "name": "Agent authority lacks a verifier contract: .claude/commands/reviewer.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/reviewer.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-579aab259be237d6", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-session.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-session.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c332debf90981d26", "name": "Agent authority lacks a verifier contract: .claude/commands/tour.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/tour.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d145673200a73e0c", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-ux-designer.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-ux-designer.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ca828c28317cc5eb", "name": "Agent authority lacks a verifier contract: .claude/commands/pf-tour.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-tour.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1ae2da59550f57c5", "name": "Agent instruction/config may expose a secret: .claude/agents/art-director.md", "shortDescription": {"text": "Agent instruction/config may expose a secret: .claude/agents/art-director.md"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d3b774e32e90b1e2", "name": "Agent authority lacks a verifier contract: .claude/agents/reviewer-edge-hunter.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/agents/reviewer-edge-hunter.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2752e5d45c3d5b29", "name": "Agent authority lacks a verifier contract: .claude/agents/pm.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/agents/pm.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1e2f9b7dcc7a3cfe", "name": "Agent authority lacks a verifier contract: .claude/agents/templates/agent-template-strategic.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/agents/templates/agent-template-strategic.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c78e4a85400fabf1", "name": "Agent authority lacks a verifier contract: .claude/skills/settings/usage.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/settings/usage.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-735a632f8adbc11c", "name": "Agent authority lacks a verifier contract: .claude/skills/settings/settings.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/settings/settings.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a3e71733c4b88541", "name": "Agent authority lacks a verifier contract: .claude/skills/demo/demo.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/demo/demo.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-46fe1bbe8a116689", "name": "Agent authority lacks a verifier contract: .claude/skills/jira/jira.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/jira/jira.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-054424c61b3eb990", "name": "Agent authority lacks a verifier contract: .claude/skills/jira/usage.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/jira/usage.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f6ca6c162b40105f", "name": "Agent authority lacks a verifier contract: .claude/skills/jira/examples.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/jira/examples.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b1ca3da86180ddd0", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-theme/usage.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-theme/usage.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c90a55f2d24147ad", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-theme/skill.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-theme/skill.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-67b82eedc6077e60", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-theme/theme.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-theme/theme.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d235e2c5b1c6344", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-theme/examples.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-theme/examples.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-39c3b1a160c8f84e", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-workflow/usage.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-workflow/usage.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5e19ebc3b6b12c9c", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-workflow/skill.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-workflow/skill.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7c7f3901cbbecc9e", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-workflow/workflow.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-workflow/workflow.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4692789bc5b18b2f", "name": "Agent instruction/config may expose a secret: .claude/skills/pf-systematic-debugging/systematic-debugging.md", "shortDescription": {"text": "Agent instruction/config may expose a secret: .claude/skills/pf-systematic-debugging/systematic-debugging.md"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-541d29ded5d91d6c", "name": "Agent instruction/config may expose a secret: .claude/skills/pf-systematic-debugging/SKILL.md", "shortDescription": {"text": "Agent instruction/config may expose a secret: .claude/skills/pf-systematic-debugging/SKILL.md"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ef1a5a0b61509e70", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-settings/usage.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-settings/usage.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-14810bd7ec87709c", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-settings/skill.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-settings/skill.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ebcde388387e8c14", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-settings/settings.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-settings/settings.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6b661db68ef2233b", "name": "Agent authority lacks a verifier contract: .claude/skills/theme/usage.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/theme/usage.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea3db862bedae4d3", "name": "Agent authority lacks a verifier contract: .claude/skills/theme/theme.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/theme/theme.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b323ac03f47e6f57", "name": "Agent authority lacks a verifier contract: .claude/skills/theme/examples.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/theme/examples.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bc78642104d844fc", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-bc/usage.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-bc/usage.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-81160727f176c679", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-bc/skill.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-bc/skill.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a2c92fba7af75374", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-bc/bc.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-bc/bc.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8bf92b626c8b4017", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-bc/examples.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-bc/examples.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5f90868f21f19a42", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-jira/jira.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-jira/jira.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-812e9db2696731e1", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-jira/usage.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-jira/usage.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a1cd0034bacaf28c", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-jira/examples.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-jira/examples.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-88bb628c1509aafe", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-jira/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-jira/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c3df1378ab9b8882", "name": "Agent authority lacks a verifier contract: .claude/skills/yq/yq.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/yq/yq.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ffd5fbbb7afd846d", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-yq/yq.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-yq/yq.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b952479ce3042cec", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-yq/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-yq/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-29e57ac346a95903", "name": "Agent instruction contains unpinned remote install: .claude/skills/pf-mermaid/mermaid.md", "shortDescription": {"text": "Agent instruction contains unpinned remote install: .claude/skills/pf-mermaid/mermaid.md"}, "fullDescription": {"text": "Remote install commands in agent instructions are a supply-chain risk, especially when an agent can execute shell commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d771c68f387131cc", "name": "Agent instruction contains unpinned remote install: .claude/skills/pf-mermaid/SKILL.md", "shortDescription": {"text": "Agent instruction contains unpinned remote install: .claude/skills/pf-mermaid/SKILL.md"}, "fullDescription": {"text": "Remote install commands in agent instructions are a supply-chain risk, especially when an agent can execute shell commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-631874a82f75a0a0", "name": "Agent authority lacks a verifier contract: .claude/skills/workflow/usage.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/workflow/usage.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3921e35fa76f76d9", "name": "Agent authority lacks a verifier contract: .claude/skills/workflow/workflow.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/workflow/workflow.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f3474558b4f5448d", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-otel/skill.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-otel/skill.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ac6fc0cef9119406", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-otel/otel.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-otel/otel.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4f215a9571116055", "name": "Agent authority lacks a verifier contract: .claude/skills/pf-demo/demo.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-demo/demo.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-71fd8e280f04287e", "name": "Agent instruction contains unpinned remote install: .claude/skills/mermaid/mermaid.md", "shortDescription": {"text": "Agent instruction contains unpinned remote install: .claude/skills/mermaid/mermaid.md"}, "fullDescription": {"text": "Remote install commands in agent instructions are a supply-chain risk, especially when an agent can execute shell commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3a6362f8405fa671", "name": "Agent authority lacks a verifier contract: .claude/skills/bc/usage.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/bc/usage.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-12f5f2d31d26d940", "name": "Agent authority lacks a verifier contract: .claude/skills/bc/bc.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/bc/bc.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-81e69470d5093d56", "name": "Agent authority lacks a verifier contract: .claude/skills/bc/examples.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/bc/examples.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f67be5ff9c8f780b", "name": "Agent authority lacks a verifier contract: .claude/skills/otel/otel.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/otel/otel.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0eb4b3cd822f6577", "name": "Agent instruction/config may expose a secret: .claude/skills/systematic-debugging/systematic-debugging.md", "shortDescription": {"text": "Agent instruction/config may expose a secret: .claude/skills/systematic-debugging/systematic-debugging.md"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-52f69c7702b72357", "name": "Commented-code block (5 lines) in scripts/render_pd_audio.py:45", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/render_pd_audio.py:45"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b24dc5f9c08b011a", "name": "Network/subprocess call without timeout or try/except \u2014 scripts/render_pd_audio.py:254", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/render_pd_audio.py:254"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bfcaa0e466f8d991", "name": "Legacy-named symbol `has_legacy` in scripts/render_common.py:279", "shortDescription": {"text": "Legacy-named symbol `has_legacy` in scripts/render_common.py:279"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-606705c1064b91d2", "name": "Commented-code block (6 lines) in scripts/render_common.py:376", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/render_common.py:376"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0a07a4f265c519d4", "name": "Commented-code block (5 lines) in scripts/r2_audit.py:126", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/r2_audit.py:126"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b9c292427d39e11f", "name": "Legacy-named symbol `list_objects_v2` in scripts/r2_pull.py:31", "shortDescription": {"text": "Legacy-named symbol `list_objects_v2` in scripts/r2_pull.py:31"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7d14b2dfe43e82c5", "name": "Network/subprocess call without timeout or try/except \u2014 scripts/grab_stills.py:56", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/grab_stills.py:56"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b849853cbe524c1a", "name": "Network/subprocess call without timeout or try/except \u2014 scripts/generate_r2_preview.py:471", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/generate_r2_preview.py:471"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fb3d936b402ca340", "name": "Commented-code block (6 lines) in scripts/playtest.py:130", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/playtest.py:130"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-17124a6e6684b5fd", "name": "Legacy-named symbol `list_objects_v2` in scripts/r2_manifest_from_bucket.py:50", "shortDescription": {"text": "Legacy-named symbol `list_objects_v2` in scripts/r2_manifest_from_bucket.py:50"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4bb3b01f53b2b601", "name": "Network/subprocess call without timeout or try/except \u2014 scripts/playtest_manifest.py:208", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/playtest_manifest.py:208"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-22a0841ec3ea44d9", "name": "Network/subprocess call without timeout or try/except \u2014 scripts/render_queue.py:88", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/render_queue.py:88"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7fb076987c9f3109", "name": "Commented-code block (5 lines) in scripts/playtest_messages.py:321", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/playtest_messages.py:321"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-44cda9d6ffcefc36", "name": "Network/subprocess call without timeout or try/except \u2014 scripts/generate_image_sheets.py:217", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/generate_image_sheets.py:217"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d958d5bcab6b8d1", "name": "Commented-code block (7 lines) in scripts/anthropic_usage.py:33", "shortDescription": {"text": "Commented-code block (7 lines) in scripts/anthropic_usage.py:33"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2e024a2d52f150b4", "name": "Commented-code block (10 lines) in scripts/tests/test_r2_audit.py:202", "shortDescription": {"text": "Commented-code block (10 lines) in scripts/tests/test_r2_audit.py:202"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d95d8cf1cb58bad7", "name": "Legacy-named symbol `list_objects_v2` in scripts/tests/test_r2_manifest_from_bucket.py:4", "shortDescription": {"text": "Legacy-named symbol `list_objects_v2` in scripts/tests/test_r2_manifest_from_bucket.py:4"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7aa38409644a9a42", "name": "Commented-code block (5 lines) in scripts/tests/test_render_pd_audio.py:107", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/tests/test_render_pd_audio.py:107"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-250f57e8a1dbd3c5", "name": "4 env vars used in code but missing from .env.example", "shortDescription": {"text": "4 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ANTHROPIC_ADMIN_KEY`, `ANTHROPIC_API_KEY`, `SIDEQUEST_RENDER_NO_UPLOAD`, `SIDEQUEST_SERVER_URL`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nscripts/r2_audit.py:main, scripts/r2_verify_packs.py:main, scripts/r2_sync_packs.py:main\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nscripts/generate_creature_images.py:compose_prompt, scripts/generate_portrait_images.py:compose_prompt\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/19840"}, "properties": {"repository": "slabgorb/sidequest", "repoUrl": "https://github.com/slabgorb/sidequest", "branch": "main"}, "results": [{"ruleId": "scanner-2fa910107fc460f1", "level": "note", "message": {"text": "Possibly dead Python function: compose_prompt"}, "properties": {"repobilityId": "d491c048d59cd151", "scanner": "scanner-primary", "fingerprint": "2fa910107fc460f1", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/generate_poi_images.py:88"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6c60854999b2dfa5", "level": "note", "message": {"text": "Possibly dead Python function: head_one"}, "properties": {"repobilityId": "89336892277d8d94", "scanner": "scanner-primary", "fingerprint": "6c60854999b2dfa5", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/r2_verify_packs.py:21"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1f9adebf829dff9b", "level": "note", "message": {"text": "Possibly dead Python function: compose_prompt"}, "properties": {"repobilityId": "d491c048d59cd151", "scanner": "scanner-primary", "fingerprint": "1f9adebf829dff9b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/generate_creature_images.py:66"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-53356e610750c9fa", "level": "note", "message": {"text": "Possibly dead Python function: compose_prompt"}, "properties": {"repobilityId": "d491c048d59cd151", "scanner": "scanner-primary", "fingerprint": "53356e610750c9fa", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/generate_portrait_images.py:82"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9b9acf79e853b258", "level": "warning", "message": {"text": "Privileged port 29 in use"}, "properties": {"repobilityId": "f09242400239b5a3", "scanner": "scanner-primary", "fingerprint": "9b9acf79e853b258", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/45-32/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b3241643bfb148b0", "level": "warning", "message": {"text": "Privileged port 32 in use"}, "properties": {"repobilityId": "20c0fabc691cdde4", "scanner": "scanner-primary", "fingerprint": "b3241643bfb148b0", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/82-2/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4d8ad27c9d3602fc", "level": "warning", "message": {"text": "Privileged port 11 in use"}, "properties": {"repobilityId": "5b3038c67fabb4c8", "scanner": "scanner-primary", "fingerprint": "4d8ad27c9d3602fc", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/108-3/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5150343635f11868", "level": "warning", "message": {"text": "Privileged port 12 in use"}, "properties": {"repobilityId": "65e7eefa33f2def4", "scanner": "scanner-primary", "fingerprint": "5150343635f11868", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/108-8/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-10f4b18174b35756", "level": "warning", "message": {"text": "Privileged port 13 in use"}, "properties": {"repobilityId": "79d721e4d6f64798", "scanner": "scanner-primary", "fingerprint": "10f4b18174b35756", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/108-6/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6e82cdb84e9b2b2c", "level": "warning", "message": {"text": "Privileged port 49 in use"}, "properties": {"repobilityId": "6108a3341973dcab", "scanner": "scanner-primary", "fingerprint": "6e82cdb84e9b2b2c", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/91-5/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6e351639b30739ea", "level": "warning", "message": {"text": "Privileged port 57 in use"}, "properties": {"repobilityId": "7f473bea32892301", "scanner": "scanner-primary", "fingerprint": "6e351639b30739ea", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/102-4/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e30d876397cd7d08", "level": "warning", "message": {"text": "Privileged port 21 in use"}, "properties": {"repobilityId": "d920b7cd1b1a16dc", "scanner": "scanner-primary", "fingerprint": "e30d876397cd7d08", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/118-1/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1e21a430f063e901", "level": "warning", "message": {"text": "Privileged port 41 in use"}, "properties": {"repobilityId": "21c3be090ea64fdb", "scanner": "scanner-primary", "fingerprint": "1e21a430f063e901", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/102-2/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c95aeb3aa18e7cd7", "level": "warning", "message": {"text": "Privileged port 40 in use"}, "properties": {"repobilityId": "28c59d470d4929c6", "scanner": "scanner-primary", "fingerprint": "c95aeb3aa18e7cd7", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/103-2/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4ce5304e2b743d35", "level": "warning", "message": {"text": "Privileged port 59 in use"}, "properties": {"repobilityId": "6c14a9dab4958e92", "scanner": "scanner-primary", "fingerprint": "4ce5304e2b743d35", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/45-46/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ec3ec2b388a3f686", "level": "warning", "message": {"text": "Privileged port 34 in use"}, "properties": {"repobilityId": "2febb579b1c7080d", "scanner": "scanner-primary", "fingerprint": "ec3ec2b388a3f686", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/86-1/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-01b47d15f18c8556", "level": "warning", "message": {"text": "Privileged port 26 in use"}, "properties": {"repobilityId": "9c5e4d9c5edd9bd2", "scanner": "scanner-primary", "fingerprint": "01b47d15f18c8556", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/117-1/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d1244aa26262716f", "level": "warning", "message": {"text": "Privileged port 54 in use"}, "properties": {"repobilityId": "cfa860c24fdc3eef", "scanner": "scanner-primary", "fingerprint": "d1244aa26262716f", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/47-10/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-924fcc5a497a57bf", "level": "warning", "message": {"text": "Privileged port 38 in use"}, "properties": {"repobilityId": "b7214bb254c5881d", "scanner": "scanner-primary", "fingerprint": "924fcc5a497a57bf", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/73-6/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-74e4bd7cdc4c4a8e", "level": "warning", "message": {"text": "Privileged port 37 in use"}, "properties": {"repobilityId": "3bc0728a81a76695", "scanner": "scanner-primary", "fingerprint": "74e4bd7cdc4c4a8e", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/108-5/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1fc7ab0fa0b3df1b", "level": "warning", "message": {"text": "Privileged port 47 in use"}, "properties": {"repobilityId": "986e85543d70890d", "scanner": "scanner-primary", "fingerprint": "1fc7ab0fa0b3df1b", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/63-5/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5c35b5779a47d009", "level": "warning", "message": {"text": "Privileged port 55 in use"}, "properties": {"repobilityId": "51a768b3e1831ac0", "scanner": "scanner-primary", "fingerprint": "5c35b5779a47d009", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/76-1/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4d11fe99f4fc5088", "level": "warning", "message": {"text": "Privileged port 27 in use"}, "properties": {"repobilityId": "69cb2b980eb576a0", "scanner": "scanner-primary", "fingerprint": "4d11fe99f4fc5088", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "sprint/demos/45-3/metadata.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-b45454ca850fb64c", "level": "warning", "message": {"text": "Insecure pattern 'weak_hash' in scripts/r2_manifest_from_bucket.py:70"}, "properties": {"repobilityId": "78ef468377c75725", "scanner": "scanner-primary", "fingerprint": "b45454ca850fb64c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "weak_hash"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/r2_manifest_from_bucket.py"}, "region": {"startLine": 70}}}]}, {"ruleId": "scanner-569f3b052e90fab1", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "1b0d05fa1819d7a3", "scanner": "scanner-primary", "fingerprint": "569f3b052e90fab1", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/just-otel-smoke.yml"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-f36b61c1556ab677", "level": "note", "message": {"text": "Very large file: scripts/playtest_dashboard.py (1042 lines)"}, "properties": {"repobilityId": "6e29d277ad936b4b", "scanner": "scanner-primary", "fingerprint": "f36b61c1556ab677", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ddbf517e3e459975", "level": "note", "message": {"text": "Very large file: scripts/playtest.py (1446 lines)"}, "properties": {"repobilityId": "2ecf6076ce285fcf", "scanner": "scanner-primary", "fingerprint": "ddbf517e3e459975", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "4dc1d4b5d24edbbb", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "6931dce0db99d96c", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "eccaa3269075b255", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "ecbd89a31a6a0105", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "75243a2310e9d38a", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "40a4f06542798ea7", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-768082747b4cdd87", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-fix-blocker.md"}, "properties": {"repobilityId": "963b168b0b73ee64", "scanner": "scanner-primary", "fingerprint": "768082747b4cdd87", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-fix-blocker.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-82578d70046150c5", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/work.md"}, "properties": {"repobilityId": "89ae655b57ad3280", "scanner": "scanner-primary", "fingerprint": "82578d70046150c5", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/work.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-489f303d4e4ead61", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/tech-writer.md"}, "properties": {"repobilityId": "6f28baf8099f0a63", "scanner": "scanner-primary", "fingerprint": "489f303d4e4ead61", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/tech-writer.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4f05f73c2a26b647", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/peloton.md"}, "properties": {"repobilityId": "c441d52d95b61d4d", "scanner": "scanner-primary", "fingerprint": "4f05f73c2a26b647", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/peloton.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3bbad82439c84ebe", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/brainstorming.md"}, "properties": {"repobilityId": "3241f55c8d06b49c", "scanner": "scanner-primary", "fingerprint": "3bbad82439c84ebe", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/brainstorming.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa034001a8b7032f", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/session.md"}, "properties": {"repobilityId": "cf00c59b46e57d41", "scanner": "scanner-primary", "fingerprint": "aa034001a8b7032f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/session.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3e0499fa3aa738b4", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/ba.md"}, "properties": {"repobilityId": "f0e8df3de8203b11", "scanner": "scanner-primary", "fingerprint": "3e0499fa3aa738b4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/ba.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c0d0b1c2f889065b", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-brainstorming.md"}, "properties": {"repobilityId": "b594b786b8892fa9", "scanner": "scanner-primary", "fingerprint": "c0d0b1c2f889065b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-brainstorming.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d436a27bd025c6e9", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-setup.md"}, "properties": {"repobilityId": "b666df6bf05d9da4", "scanner": "scanner-primary", "fingerprint": "d436a27bd025c6e9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-setup.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-87140f614200b8dd", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-reviewer.md"}, "properties": {"repobilityId": "5753dfdc1974753b", "scanner": "scanner-primary", "fingerprint": "87140f614200b8dd", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-reviewer.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7b889d12077b415c", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-peloton.md"}, "properties": {"repobilityId": "5b32ed4d959b7b6d", "scanner": "scanner-primary", "fingerprint": "7b889d12077b415c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-peloton.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5d04bf155a724be9", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-orchestrator.md"}, "properties": {"repobilityId": "38ef322778fd59fb", "scanner": "scanner-primary", "fingerprint": "5d04bf155a724be9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-orchestrator.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e6522154bfd04d3a", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/architect.md"}, "properties": {"repobilityId": "f310078fcbffdf38", "scanner": "scanner-primary", "fingerprint": "e6522154bfd04d3a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/architect.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9c688fa0966f4160", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/fix-blocker.md"}, "properties": {"repobilityId": "0128467ff518f66f", "scanner": "scanner-primary", "fingerprint": "9c688fa0966f4160", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/fix-blocker.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0d10a6b2d7cd82a7", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/setup.md"}, "properties": {"repobilityId": "27162bec6c28a812", "scanner": "scanner-primary", "fingerprint": "0d10a6b2d7cd82a7", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/setup.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-13579452eb100ad0", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-architect.md"}, "properties": {"repobilityId": "d423acad06ba1a03", "scanner": "scanner-primary", "fingerprint": "13579452eb100ad0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-architect.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f89bdbb372647d44", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-workflow.md"}, "properties": {"repobilityId": "e8b5148a18b6bd78", "scanner": "scanner-primary", "fingerprint": "f89bdbb372647d44", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-workflow.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-884ebcae271fc1ae", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-pm.md"}, "properties": {"repobilityId": "44bf3baaf039f1f1", "scanner": "scanner-primary", "fingerprint": "884ebcae271fc1ae", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-pm.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-517799f1298e51f9", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-sm.md"}, "properties": {"repobilityId": "4bce37bc113e4dd2", "scanner": "scanner-primary", "fingerprint": "517799f1298e51f9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-sm.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-438d3dcb6180aa20", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/job-fair.md"}, "properties": {"repobilityId": "b5c050abd48d0cdb", "scanner": "scanner-primary", "fingerprint": "438d3dcb6180aa20", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/job-fair.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-079f6020673d2a3f", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/benchmark-control.md"}, "properties": {"repobilityId": "c7fe23c25eab9c42", "scanner": "scanner-primary", "fingerprint": "079f6020673d2a3f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/benchmark-control.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5e0018464444f0eb", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-dev.md"}, "properties": {"repobilityId": "de55c13410daa276", "scanner": "scanner-primary", "fingerprint": "5e0018464444f0eb", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-dev.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-74bf10254693ff17", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-theme.md"}, "properties": {"repobilityId": "7e8e4267c4e56173", "scanner": "scanner-primary", "fingerprint": "74bf10254693ff17", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-theme.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aecb8a03989dc134", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-tech-writer.md"}, "properties": {"repobilityId": "ca7ca90ef90f1b23", "scanner": "scanner-primary", "fingerprint": "aecb8a03989dc134", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-tech-writer.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aebd9d53aa24326e", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/theme.md"}, "properties": {"repobilityId": "15bcaf31b7ee00ba", "scanner": "scanner-primary", "fingerprint": "aebd9d53aa24326e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/theme.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bf888e55fd3fb166", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pm.md"}, "properties": {"repobilityId": "08e5e097e376390a", "scanner": "scanner-primary", "fingerprint": "bf888e55fd3fb166", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pm.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1c2a1d85f5de0809", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/dev.md"}, "properties": {"repobilityId": "56438a79484e5c4d", "scanner": "scanner-primary", "fingerprint": "1c2a1d85f5de0809", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/dev.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5797766b11b5842b", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/workflow.md"}, "properties": {"repobilityId": "e063bba5d1af4e5a", "scanner": "scanner-primary", "fingerprint": "5797766b11b5842b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/workflow.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e3fc505f15865940", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/orchestrator.md"}, "properties": {"repobilityId": "f0f7e796669cdd62", "scanner": "scanner-primary", "fingerprint": "e3fc505f15865940", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/orchestrator.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b1f3b9d56b23274a", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-benchmark-control.md"}, "properties": {"repobilityId": "8f497859e9c80850", "scanner": "scanner-primary", "fingerprint": "b1f3b9d56b23274a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-benchmark-control.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c3a60aeeb91eb288", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/sq-poi.md"}, "properties": {"repobilityId": "ff89be6a160f4d17", "scanner": "scanner-primary", "fingerprint": "c3a60aeeb91eb288", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/sq-poi.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a39ba1cef82c519c", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-job-fair.md"}, "properties": {"repobilityId": "aabbfae1db714257", "scanner": "scanner-primary", "fingerprint": "a39ba1cef82c519c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-job-fair.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-05bde4975b842efb", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/ux-designer.md"}, "properties": {"repobilityId": "a58e3a90571a9079", "scanner": "scanner-primary", "fingerprint": "05bde4975b842efb", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/ux-designer.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ace00160f3f40983", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/sm.md"}, "properties": {"repobilityId": "fa72ad9447dffafa", "scanner": "scanner-primary", "fingerprint": "ace00160f3f40983", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/sm.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7cfed6031d7241ed", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-ba.md"}, "properties": {"repobilityId": "653949bf1bb67af6", "scanner": "scanner-primary", "fingerprint": "7cfed6031d7241ed", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-ba.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1e5a5d2c3ba0540a", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-devops.md"}, "properties": {"repobilityId": "dff27cd16c6a59bd", "scanner": "scanner-primary", "fingerprint": "1e5a5d2c3ba0540a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-devops.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ae33f20ca85529ae", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/sq-music.md"}, "properties": {"repobilityId": "84e872ead2cdd485", "scanner": "scanner-primary", "fingerprint": "ae33f20ca85529ae", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/sq-music.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8a5cddef07d1bf85", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-work.md"}, "properties": {"repobilityId": "09cc63ed74957960", "scanner": "scanner-primary", "fingerprint": "8a5cddef07d1bf85", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-work.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6cba894b49b107ec", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/devops.md"}, "properties": {"repobilityId": "c1b9a4737c45d3d9", "scanner": "scanner-primary", "fingerprint": "6cba894b49b107ec", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/devops.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1bb9e81a88257945", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-gm.md"}, "properties": {"repobilityId": "bc391d4c0524baf7", "scanner": "scanner-primary", "fingerprint": "1bb9e81a88257945", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-gm.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ffa974891e7d5977", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/reviewer.md"}, "properties": {"repobilityId": "29b476791a65086a", "scanner": "scanner-primary", "fingerprint": "ffa974891e7d5977", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/reviewer.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-579aab259be237d6", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-session.md"}, "properties": {"repobilityId": "0d5bbd5291e3ba3d", "scanner": "scanner-primary", "fingerprint": "579aab259be237d6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-session.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c332debf90981d26", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/tour.md"}, "properties": {"repobilityId": "36768d77bbe7996d", "scanner": "scanner-primary", "fingerprint": "c332debf90981d26", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/tour.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d145673200a73e0c", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-ux-designer.md"}, "properties": {"repobilityId": "935417cf0aee112f", "scanner": "scanner-primary", "fingerprint": "d145673200a73e0c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-ux-designer.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ca828c28317cc5eb", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/commands/pf-tour.md"}, "properties": {"repobilityId": "6fe5a9d8c972d6c0", "scanner": "scanner-primary", "fingerprint": "ca828c28317cc5eb", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/pf-tour.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1ae2da59550f57c5", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .claude/agents/art-director.md"}, "properties": {"repobilityId": "5a114c8a6696e24f", "scanner": "scanner-primary", "fingerprint": "1ae2da59550f57c5", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/agents/art-director.md"}, "region": {"startLine": 119}}}]}, {"ruleId": "scanner-d3b774e32e90b1e2", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/agents/reviewer-edge-hunter.md"}, "properties": {"repobilityId": "76b0ee1c606727ba", "scanner": "scanner-primary", "fingerprint": "d3b774e32e90b1e2", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/agents/reviewer-edge-hunter.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2752e5d45c3d5b29", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/agents/pm.md"}, "properties": {"repobilityId": "17af77c67bbf9c76", "scanner": "scanner-primary", "fingerprint": "2752e5d45c3d5b29", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/agents/pm.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1e2f9b7dcc7a3cfe", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/agents/templates/agent-template-strategic.md"}, "properties": {"repobilityId": "3c88d9d16afeaea1", "scanner": "scanner-primary", "fingerprint": "1e2f9b7dcc7a3cfe", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/agents/templates/agent-template-strategic.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c78e4a85400fabf1", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/settings/usage.md"}, "properties": {"repobilityId": "b7b4159fe10f947d", "scanner": "scanner-primary", "fingerprint": "c78e4a85400fabf1", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/settings/usage.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-735a632f8adbc11c", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/settings/settings.md"}, "properties": {"repobilityId": "7fc50628201070d6", "scanner": "scanner-primary", "fingerprint": "735a632f8adbc11c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/settings/settings.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a3e71733c4b88541", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/demo/demo.md"}, "properties": {"repobilityId": "c2d7235a5f03e421", "scanner": "scanner-primary", "fingerprint": "a3e71733c4b88541", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/demo/demo.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-46fe1bbe8a116689", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/jira/jira.md"}, "properties": {"repobilityId": "7196803673230e07", "scanner": "scanner-primary", "fingerprint": "46fe1bbe8a116689", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/jira/jira.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-054424c61b3eb990", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/jira/usage.md"}, "properties": {"repobilityId": "9150df71c673b692", "scanner": "scanner-primary", "fingerprint": "054424c61b3eb990", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/jira/usage.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f6ca6c162b40105f", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/jira/examples.md"}, "properties": {"repobilityId": "2328306f02835d89", "scanner": "scanner-primary", "fingerprint": "f6ca6c162b40105f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/jira/examples.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b1ca3da86180ddd0", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-theme/usage.md"}, "properties": {"repobilityId": "3f40174b1cdd91e9", "scanner": "scanner-primary", "fingerprint": "b1ca3da86180ddd0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-theme/usage.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c90a55f2d24147ad", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-theme/skill.md"}, "properties": {"repobilityId": "3be64b986c14b80e", "scanner": "scanner-primary", "fingerprint": "c90a55f2d24147ad", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-theme/skill.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-67b82eedc6077e60", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-theme/theme.md"}, "properties": {"repobilityId": "27b3a9430ad64af0", "scanner": "scanner-primary", "fingerprint": "67b82eedc6077e60", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-theme/theme.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2d235e2c5b1c6344", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-theme/examples.md"}, "properties": {"repobilityId": "2e1839786eb5b9f7", "scanner": "scanner-primary", "fingerprint": "2d235e2c5b1c6344", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-theme/examples.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-39c3b1a160c8f84e", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-workflow/usage.md"}, "properties": {"repobilityId": "22b7cfb0105314fc", "scanner": "scanner-primary", "fingerprint": "39c3b1a160c8f84e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-workflow/usage.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5e19ebc3b6b12c9c", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-workflow/skill.md"}, "properties": {"repobilityId": "40cf54ea2ea15036", "scanner": "scanner-primary", "fingerprint": "5e19ebc3b6b12c9c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-workflow/skill.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7c7f3901cbbecc9e", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-workflow/workflow.md"}, "properties": {"repobilityId": "b1c0d74cab755e2e", "scanner": "scanner-primary", "fingerprint": "7c7f3901cbbecc9e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-workflow/workflow.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4692789bc5b18b2f", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .claude/skills/pf-systematic-debugging/systematic-debugging.md"}, "properties": {"repobilityId": "7128f358c2e13fe4", "scanner": "scanner-primary", "fingerprint": "4692789bc5b18b2f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-systematic-debugging/systematic-debugging.md"}, "region": {"startLine": 84}}}]}, {"ruleId": "scanner-541d29ded5d91d6c", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .claude/skills/pf-systematic-debugging/SKILL.md"}, "properties": {"repobilityId": "e300d0b4934ec9cb", "scanner": "scanner-primary", "fingerprint": "541d29ded5d91d6c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-systematic-debugging/SKILL.md"}, "region": {"startLine": 84}}}]}, {"ruleId": "scanner-ef1a5a0b61509e70", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-settings/usage.md"}, "properties": {"repobilityId": "3a46a8e7639d78ff", "scanner": "scanner-primary", "fingerprint": "ef1a5a0b61509e70", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-settings/usage.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-14810bd7ec87709c", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-settings/skill.md"}, "properties": {"repobilityId": "1a7877a6776dd033", "scanner": "scanner-primary", "fingerprint": "14810bd7ec87709c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-settings/skill.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ebcde388387e8c14", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-settings/settings.md"}, "properties": {"repobilityId": "ffd3c818fe4e1bc6", "scanner": "scanner-primary", "fingerprint": "ebcde388387e8c14", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-settings/settings.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6b661db68ef2233b", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/theme/usage.md"}, "properties": {"repobilityId": "04f6635e5102262e", "scanner": "scanner-primary", "fingerprint": "6b661db68ef2233b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/theme/usage.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ea3db862bedae4d3", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/theme/theme.md"}, "properties": {"repobilityId": "3005bb12c7e8052c", "scanner": "scanner-primary", "fingerprint": "ea3db862bedae4d3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/theme/theme.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b323ac03f47e6f57", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/theme/examples.md"}, "properties": {"repobilityId": "88ef4a266b924c78", "scanner": "scanner-primary", "fingerprint": "b323ac03f47e6f57", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/theme/examples.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bc78642104d844fc", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-bc/usage.md"}, "properties": {"repobilityId": "85c1ac64b8a7d78c", "scanner": "scanner-primary", "fingerprint": "bc78642104d844fc", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-bc/usage.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-81160727f176c679", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-bc/skill.md"}, "properties": {"repobilityId": "567df320c9e500b6", "scanner": "scanner-primary", "fingerprint": "81160727f176c679", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-bc/skill.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a2c92fba7af75374", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-bc/bc.md"}, "properties": {"repobilityId": "05d2d85176b8dd2e", "scanner": "scanner-primary", "fingerprint": "a2c92fba7af75374", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-bc/bc.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8bf92b626c8b4017", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-bc/examples.md"}, "properties": {"repobilityId": "8b728f283f7a326d", "scanner": "scanner-primary", "fingerprint": "8bf92b626c8b4017", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-bc/examples.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f90868f21f19a42", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-jira/jira.md"}, "properties": {"repobilityId": "b98fecfddc81e89b", "scanner": "scanner-primary", "fingerprint": "5f90868f21f19a42", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-jira/jira.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-812e9db2696731e1", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-jira/usage.md"}, "properties": {"repobilityId": "fbe08e540fec93ab", "scanner": "scanner-primary", "fingerprint": "812e9db2696731e1", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-jira/usage.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a1cd0034bacaf28c", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-jira/examples.md"}, "properties": {"repobilityId": "7ad3d24e9e84e914", "scanner": "scanner-primary", "fingerprint": "a1cd0034bacaf28c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-jira/examples.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-88bb628c1509aafe", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-jira/SKILL.md"}, "properties": {"repobilityId": "ae1d820a1ea8a243", "scanner": "scanner-primary", "fingerprint": "88bb628c1509aafe", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-jira/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c3df1378ab9b8882", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/yq/yq.md"}, "properties": {"repobilityId": "2ee0661667e0a8da", "scanner": "scanner-primary", "fingerprint": "c3df1378ab9b8882", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/yq/yq.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ffd5fbbb7afd846d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-yq/yq.md"}, "properties": {"repobilityId": "c990e2d4d329720f", "scanner": "scanner-primary", "fingerprint": "ffd5fbbb7afd846d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-yq/yq.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b952479ce3042cec", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-yq/SKILL.md"}, "properties": {"repobilityId": "314d529c4b57d1ab", "scanner": "scanner-primary", "fingerprint": "b952479ce3042cec", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-yq/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-29e57ac346a95903", "level": "warning", "message": {"text": "Agent instruction contains unpinned remote install: .claude/skills/pf-mermaid/mermaid.md"}, "properties": {"repobilityId": "e05a9416ba960937", "scanner": "scanner-primary", "fingerprint": "29e57ac346a95903", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "supply-chain", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-mermaid/mermaid.md"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-d771c68f387131cc", "level": "warning", "message": {"text": "Agent instruction contains unpinned remote install: .claude/skills/pf-mermaid/SKILL.md"}, "properties": {"repobilityId": "32ab7f6488486c2a", "scanner": "scanner-primary", "fingerprint": "d771c68f387131cc", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "supply-chain", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-mermaid/SKILL.md"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-631874a82f75a0a0", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/workflow/usage.md"}, "properties": {"repobilityId": "0a874cc6b246e288", "scanner": "scanner-primary", "fingerprint": "631874a82f75a0a0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/workflow/usage.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3921e35fa76f76d9", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/workflow/workflow.md"}, "properties": {"repobilityId": "12b90416bc29c564", "scanner": "scanner-primary", "fingerprint": "3921e35fa76f76d9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/workflow/workflow.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f3474558b4f5448d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-otel/skill.md"}, "properties": {"repobilityId": "30f7e4c2ccf4d8b1", "scanner": "scanner-primary", "fingerprint": "f3474558b4f5448d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-otel/skill.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ac6fc0cef9119406", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-otel/otel.md"}, "properties": {"repobilityId": "39dec89b5f5aeace", "scanner": "scanner-primary", "fingerprint": "ac6fc0cef9119406", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-otel/otel.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4f215a9571116055", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/pf-demo/demo.md"}, "properties": {"repobilityId": "7251336f56eb4d65", "scanner": "scanner-primary", "fingerprint": "4f215a9571116055", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/pf-demo/demo.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-71fd8e280f04287e", "level": "warning", "message": {"text": "Agent instruction contains unpinned remote install: .claude/skills/mermaid/mermaid.md"}, "properties": {"repobilityId": "7a71854e258b9516", "scanner": "scanner-primary", "fingerprint": "71fd8e280f04287e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "supply-chain", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/mermaid/mermaid.md"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-3a6362f8405fa671", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/bc/usage.md"}, "properties": {"repobilityId": "daa3452b23ef2e08", "scanner": "scanner-primary", "fingerprint": "3a6362f8405fa671", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/bc/usage.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-12f5f2d31d26d940", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/bc/bc.md"}, "properties": {"repobilityId": "ad8324a2363ae66d", "scanner": "scanner-primary", "fingerprint": "12f5f2d31d26d940", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/bc/bc.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-81e69470d5093d56", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/bc/examples.md"}, "properties": {"repobilityId": "48596523e6a321b0", "scanner": "scanner-primary", "fingerprint": "81e69470d5093d56", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/bc/examples.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f67be5ff9c8f780b", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/otel/otel.md"}, "properties": {"repobilityId": "4b19f72b1a99dbe2", "scanner": "scanner-primary", "fingerprint": "f67be5ff9c8f780b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/otel/otel.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0eb4b3cd822f6577", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .claude/skills/systematic-debugging/systematic-debugging.md"}, "properties": {"repobilityId": "8cb22fbea1f80097", "scanner": "scanner-primary", "fingerprint": "0eb4b3cd822f6577", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/systematic-debugging/systematic-debugging.md"}, "region": {"startLine": 84}}}]}, {"ruleId": "scanner-52f69c7702b72357", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/render_pd_audio.py:45"}, "properties": {"repobilityId": "3a0de94f95fa319b", "scanner": "scanner-primary", "fingerprint": "52f69c7702b72357", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b24dc5f9c08b011a", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/render_pd_audio.py:254"}, "properties": {"repobilityId": "234a07064a36fbc3", "scanner": "scanner-primary", "fingerprint": "b24dc5f9c08b011a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-bfcaa0e466f8d991", "level": "note", "message": {"text": "Legacy-named symbol `has_legacy` in scripts/render_common.py:279"}, "properties": {"repobilityId": "047b4985ddb1bba4", "scanner": "scanner-primary", "fingerprint": "bfcaa0e466f8d991", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-606705c1064b91d2", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/render_common.py:376"}, "properties": {"repobilityId": "0057c6e40b13070a", "scanner": "scanner-primary", "fingerprint": "606705c1064b91d2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0a07a4f265c519d4", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/r2_audit.py:126"}, "properties": {"repobilityId": "c41ec0037efb73f7", "scanner": "scanner-primary", "fingerprint": "0a07a4f265c519d4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-b9c292427d39e11f", "level": "note", "message": {"text": "Legacy-named symbol `list_objects_v2` in scripts/r2_pull.py:31"}, "properties": {"repobilityId": "8dd78c3d88194a5c", "scanner": "scanner-primary", "fingerprint": "b9c292427d39e11f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-7d14b2dfe43e82c5", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/grab_stills.py:56"}, "properties": {"repobilityId": "fdff7c290887f318", "scanner": "scanner-primary", "fingerprint": "7d14b2dfe43e82c5", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b849853cbe524c1a", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/generate_r2_preview.py:471"}, "properties": {"repobilityId": "a174a26532bdff0c", "scanner": "scanner-primary", "fingerprint": "b849853cbe524c1a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-fb3d936b402ca340", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/playtest.py:130"}, "properties": {"repobilityId": "3f0f0c7150712684", "scanner": "scanner-primary", "fingerprint": "fb3d936b402ca340", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-17124a6e6684b5fd", "level": "note", "message": {"text": "Legacy-named symbol `list_objects_v2` in scripts/r2_manifest_from_bucket.py:50"}, "properties": {"repobilityId": "d89300ac41b655bb", "scanner": "scanner-primary", "fingerprint": "17124a6e6684b5fd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-4bb3b01f53b2b601", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/playtest_manifest.py:208"}, "properties": {"repobilityId": "32747d3ebf4314d4", "scanner": "scanner-primary", "fingerprint": "4bb3b01f53b2b601", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-22a0841ec3ea44d9", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/render_queue.py:88"}, "properties": {"repobilityId": "a3b010e6eb53923f", "scanner": "scanner-primary", "fingerprint": "22a0841ec3ea44d9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-7fb076987c9f3109", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/playtest_messages.py:321"}, "properties": {"repobilityId": "c952d04494b724a8", "scanner": "scanner-primary", "fingerprint": "7fb076987c9f3109", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-44cda9d6ffcefc36", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/generate_image_sheets.py:217"}, "properties": {"repobilityId": "f2c23ad24c5dfa69", "scanner": "scanner-primary", "fingerprint": "44cda9d6ffcefc36", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-9d958d5bcab6b8d1", "level": "none", "message": {"text": "Commented-code block (7 lines) in scripts/anthropic_usage.py:33"}, "properties": {"repobilityId": "bd831fb16b1f3f47", "scanner": "scanner-primary", "fingerprint": "9d958d5bcab6b8d1", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-2e024a2d52f150b4", "level": "none", "message": {"text": "Commented-code block (10 lines) in scripts/tests/test_r2_audit.py:202"}, "properties": {"repobilityId": "44f367f0593a7438", "scanner": "scanner-primary", "fingerprint": "2e024a2d52f150b4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d95d8cf1cb58bad7", "level": "note", "message": {"text": "Legacy-named symbol `list_objects_v2` in scripts/tests/test_r2_manifest_from_bucket.py:4"}, "properties": {"repobilityId": "3318ed28124adb34", "scanner": "scanner-primary", "fingerprint": "d95d8cf1cb58bad7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-7aa38409644a9a42", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/tests/test_render_pd_audio.py:107"}, "properties": {"repobilityId": "f0b46bcd435d52a5", "scanner": "scanner-primary", "fingerprint": "7aa38409644a9a42", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-250f57e8a1dbd3c5", "level": "none", "message": {"text": "4 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "57584f22b735b5ee", "scanner": "scanner-primary", "fingerprint": "250f57e8a1dbd3c5", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "d8ccfed981e00607", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "eb60df42a5f0fe3f", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}]}]}