{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-4abe16dd28c10add", "name": "Possibly dead Python function: handler", "shortDescription": {"text": "Possibly dead Python function: handler"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8366d0d506b65df9", "name": "Stray `console.log` in TS/JS \u2014 server.js:268", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server.js:268"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-14d99ede2ce03512", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/layout/Sidebar.jsx:118", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/layout/Sidebar.jsx:118"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8a8cf67e52c6ad97", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/red-teaming/LogEntry.jsx:67", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/red-teaming/LogEntry.jsx:67"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ad089cc83edf2fee", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/PromptTelemetryDrawer.jsx:98", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/PromptTelemetryDrawer.jsx:98"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-117665a3714a455b", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/PipelineTraceV2.jsx:381", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/PipelineTraceV2.jsx:381"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ad49fc5ee18526a4", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/ModelSelector.jsx:154", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/ModelSelector.jsx:154"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fe3fcf0c3672e7e6", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/ResendWidget.jsx:19", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/ResendWidget.jsx:19"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-adc205aebbe0c581", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/TelemetrySidebar.jsx:201", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/TelemetrySidebar.jsx:201"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b71a0dc5d088a2e4", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/AttackCategory.jsx:44", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/AttackCategory.jsx:44"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-57067f6db42fdb86", "name": "\"active\" state uses light bg in a dark theme \u2014 src/components/model-scanning/ScannerPanel.jsx:67", "shortDescription": {"text": "\"active\" state uses light bg in a dark theme \u2014 src/components/model-scanning/ScannerPanel.jsx:67"}, "fullDescription": {"text": "A ternary like `active ? 'bg-white' : '...'` (or bg-gray-100/200) on a dark theme produces jarring white pills. Use a dark-emphasized active state instead \u2014 border + ring or slightly brighter dark bg. Example: `active ? 'bg-gray-800 border-gray-500 ring-1 ring-blue-500/30' : '\u2026'`.\n\nWhy: P-E in CHECKLIST.md \u2014 light bg in a dark theme is a class of regression.\nRule id: fq.active-light-bg"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa0a3bd39f4b99b2", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/model-scanning/VulnerabilityReport.jsx:29", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/model-scanning/VulnerabilityReport.jsx:29"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3060f3e4832c82c3", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/model-scanning/ModelCard.jsx:38", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/model-scanning/ModelCard.jsx:38"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1a9bf6225a62f18b", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/observability/TraceDrawer.jsx:138", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/observability/TraceDrawer.jsx:138"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ecc4c14db6aebfea", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/observability/TraceTable.jsx:71", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/observability/TraceTable.jsx:71"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2dedf123ae7f287e", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/observability/KpiStrip.jsx:47", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/observability/KpiStrip.jsx:47"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-527b2f9bb22e8639", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/sidebar/NavItem.jsx:108", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/sidebar/NavItem.jsx:108"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-33a38a17a57b2b3f", "name": "`truncate` class without `title=` for hover reveal \u2014 src/views/RedTeamingView.jsx:426", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/views/RedTeamingView.jsx:426"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cb6bbe0475d8be50", "name": "`truncate` class without `title=` for hover reveal \u2014 src/views/ModelScanningView.jsx:250", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/views/ModelScanningView.jsx:250"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1dffdaa6b664aaf5", "name": "`truncate` class without `title=` for hover reveal \u2014 src/views/ReleaseNotesView.jsx:572", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/views/ReleaseNotesView.jsx:572"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-af6c2609f275011d", "name": "Privileged port 10 in use", "shortDescription": {"text": "Privileged port 10 in use"}, "fullDescription": {"text": "Port 10 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8aa5ed116187f20d", "name": "Insecure pattern 'cors_wildcard' in scanner_server.py:49", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in scanner_server.py:49"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2eb0d3b944c09be2", "name": "Insecure pattern 'node_child_process' in server.js:16", "shortDescription": {"text": "Insecure pattern 'node_child_process' in server.js:16"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b24069be1fe44413", "name": "Insecure pattern 'cors_wildcard' in server.js:23", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in server.js:23"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3c421ce42668ca94", "name": "Insecure pattern 'cors_wildcard' in scanner_app.py:218", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in scanner_app.py:218"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-34a96f1555369678", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/AIRS-Claude-Code-Hooks-Guide.html:1767", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/AIRS-Claude-Code-Hooks-Guide.html:1767"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0da5ed3464b07080", "name": "Insecure pattern 'cors_wildcard' in mcp-server/mcp_server.py:38", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in mcp-server/mcp_server.py:38"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6a3111b368302910", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/hooks-guide.html:1779", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/hooks-guide.html:1779"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-093130ad9f658ea5", "name": "Possible secret in src/views/DeveloperCornerView.jsx", "shortDescription": {"text": "Possible secret in src/views/DeveloperCornerView.jsx"}, "fullDescription": {"text": "Detected pattern matching generic_api_key. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-57f3e5e27d5004f2", "name": "Very large file: server.js (1522 lines)", "shortDescription": {"text": "Very large file: server.js (1522 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e23cd6f6b12c53b0", "name": "Very large file: src/components/api-intercept/TelemetrySidebar.jsx (1155 lines)", "shortDescription": {"text": "Very large file: src/components/api-intercept/TelemetrySidebar.jsx (1155 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d81ee0703486e813", "name": "Very large file: src/views/McpSecurityView.jsx (1675 lines)", "shortDescription": {"text": "Very large file: src/views/McpSecurityView.jsx (1675 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 77 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 50 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 40 placeholder/mock markers across 18 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: ci, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing ci, tests. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4004576abd1755a6", "name": "Commented-code block (6 lines) in portkey-routes.js:19", "shortDescription": {"text": "Commented-code block (6 lines) in portkey-routes.js:19"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-46ce50b70b701c42", "name": "Commented-code block (5 lines) in server.js:29", "shortDescription": {"text": "Commented-code block (5 lines) in server.js:29"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6fa4cfedf4d77eef", "name": "`fetch()` without try/.catch or AbortSignal \u2014 server.js:94", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server.js:94"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-448d36d9f043dc13", "name": "Network/subprocess call without timeout or try/except \u2014 scanner_app.py:159", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scanner_app.py:159"}, "fullDescription": {"text": "`requests.post(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-83ed7ab86e7f43a6", "name": "Commented-code block (5 lines) in src/components/api-intercept/PipelineTraceV2.jsx:5", "shortDescription": {"text": "Commented-code block (5 lines) in src/components/api-intercept/PipelineTraceV2.jsx:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6222e8ed208bd839", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/hooks/useObservability.js:32", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/hooks/useObservability.js:32"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d3f25650b0f606b", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/DeveloperCornerView.jsx:231", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/DeveloperCornerView.jsx:231"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9b4d5ad427afbd09", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/ObservabilityView.jsx:334", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/ObservabilityView.jsx:334"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-21d07f53f2032a3d", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/RedTeamingView.jsx:100", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/RedTeamingView.jsx:100"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7d4a8099f5ab9e11", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/ModelScanningView.jsx:156", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/ModelScanningView.jsx:156"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-030da566069872e9", "name": "15 env vars used in code but missing from .env.example", "shortDescription": {"text": "15 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `AWS_SESSION_TOKEN`, `AZURE_OPENAI_API_KEY`, `AZURE_OPENAI_API_VERSION`, `AZURE_OPENAI_DEPLOYMENT`, `AZURE_OPENAI_ENDPOINT`, `BEDROCK_REGION`, `CHATBOT_API_KEY`, `HF_SCAN_GROUP_UUID` + 7 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f76d463f37b6f66", "name": "FastAPI POST `scan_model` without auth dependency \u2014 scanner_app.py:1296", "shortDescription": {"text": "FastAPI POST `scan_model` without auth dependency \u2014 scanner_app.py:1296"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d2348376df2ee9a8", "name": "FastAPI POST `read_file` without auth dependency \u2014 mcp-server/mcp_server.py:72", "shortDescription": {"text": "FastAPI POST `read_file` without auth dependency \u2014 mcp-server/mcp_server.py:72"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d8a06abb9b3d6b3e", "name": "FastAPI POST `web_fetch` without auth dependency \u2014 mcp-server/mcp_server.py:106", "shortDescription": {"text": "FastAPI POST `web_fetch` without auth dependency \u2014 mcp-server/mcp_server.py:106"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3861fbb98c229aef", "name": "FastAPI POST `execute_code` without auth dependency \u2014 mcp-server/mcp_server.py:139", "shortDescription": {"text": "FastAPI POST `execute_code` without auth dependency \u2014 mcp-server/mcp_server.py:139"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-22bb7cf4f8b86d72", "name": "FastAPI POST `get_memory` without auth dependency \u2014 mcp-server/mcp_server.py:173", "shortDescription": {"text": "FastAPI POST `get_memory` without auth dependency \u2014 mcp-server/mcp_server.py:173"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6c17508ea3b1277b", "name": "FastAPI POST `set_memory` without auth dependency \u2014 mcp-server/mcp_server.py:184", "shortDescription": {"text": "FastAPI POST `set_memory` without auth dependency \u2014 mcp-server/mcp_server.py:184"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6c5005449600a7e8", "name": "Dangling fetch: POST https://api.portkey.ai/v1/chat/completions (portkey-routes.js:139)", "shortDescription": {"text": "Dangling fetch: POST https://api.portkey.ai/v1/chat/completions (portkey-routes.js:139)"}, "fullDescription": {"text": "`portkey-routes.js:139` calls `POST https://api.portkey.ai/v1/chat/completions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.portkey.ai/v1/chat/completions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-020c9983abc35f35", "name": "Dangling fetch: POST https://auth.apps.paloaltonetworks.com/oauth2/access_token (server.js:642)", "shortDescription": {"text": "Dangling fetch: POST https://auth.apps.paloaltonetworks.com/oauth2/access_token (server.js:642)"}, "fullDescription": {"text": "`server.js:642` calls `POST https://auth.apps.paloaltonetworks.com/oauth2/access_token` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/auth.apps.paloaltonetworks.com/oauth2/access_token`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cb25b3e2a5395c41", "name": "Dangling fetch: GET http://localhost:${scannerPort}/ (server.js:746)", "shortDescription": {"text": "Dangling fetch: GET http://localhost:${scannerPort}/ (server.js:746)"}, "fullDescription": {"text": "`server.js:746` calls `GET http://localhost:${scannerPort}/` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/localhost:/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-11c33d8c7617b0ad", "name": "Dangling fetch: GET http://ip-api.com/json/${ip}?fields=country,regionName,city,status (server.js:1406)", "shortDescription": {"text": "Dangling fetch: GET http://ip-api.com/json/${ip}?fields=country,regionName,city,status (server.js:1406)"}, "fullDescription": {"text": "`server.js:1406` calls `GET http://ip-api.com/json/${ip}?fields=country,regionName,city,status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/ip-api.com/json/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-33d511f892785b28", "name": "Dangling fetch: GET http://localhost:${PORT}/api/health (server.js:1491)", "shortDescription": {"text": "Dangling fetch: GET http://localhost:${PORT}/api/health (server.js:1491)"}, "fullDescription": {"text": "`server.js:1491` calls `GET http://localhost:${PORT}/api/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/http:/localhost:/<p>/api/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-89a32c8808ba95ad", "name": "Dangling fetch: GET /api/models/${provider} (src/components/api-intercept/ModelSelector.jsx:67)", "shortDescription": {"text": "Dangling fetch: GET /api/models/${provider} (src/components/api-intercept/ModelSelector.jsx:67)"}, "fullDescription": {"text": "`src/components/api-intercept/ModelSelector.jsx:67` calls `GET /api/models/${provider}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/models/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-35bea63c7a5e670b", "name": "Dangling fetch: POST /api/gateway/chat (src/hooks/usePortkeyChat.js:35)", "shortDescription": {"text": "Dangling fetch: POST /api/gateway/chat (src/hooks/usePortkeyChat.js:35)"}, "fullDescription": {"text": "`src/hooks/usePortkeyChat.js:35` calls `POST /api/gateway/chat` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/gateway/chat`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-800e73ee25067e1f", "name": "Dangling fetch: GET /api/gateway/health (src/views/LlmGatewayView.jsx:19)", "shortDescription": {"text": "Dangling fetch: GET /api/gateway/health (src/views/LlmGatewayView.jsx:19)"}, "fullDescription": {"text": "`src/views/LlmGatewayView.jsx:19` calls `GET /api/gateway/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/gateway/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4de25c83ff1717dc", "name": "Dangling fetch: POST /api/gateway/compare (src/views/llm-gateway/LiveDemoTab.jsx:67)", "shortDescription": {"text": "Dangling fetch: POST /api/gateway/compare (src/views/llm-gateway/LiveDemoTab.jsx:67)"}, "fullDescription": {"text": "`src/views/llm-gateway/LiveDemoTab.jsx:67` calls `POST /api/gateway/compare` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/gateway/compare`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f0e8d6447adbf7dd", "name": "Dangling fetch: GET /api/gateway/configs (src/views/llm-gateway/LiveDemoTab.jsx:118)", "shortDescription": {"text": "Dangling fetch: GET /api/gateway/configs (src/views/llm-gateway/LiveDemoTab.jsx:118)"}, "fullDescription": {"text": "`src/views/llm-gateway/LiveDemoTab.jsx:118` calls `GET /api/gateway/configs` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/gateway/configs`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-30d2f18eaf17b039", "name": "Dangling fetch: GET /api/gateway/health (src/views/llm-gateway/components/PortkeyStatusStrip.jsx:15)", "shortDescription": {"text": "Dangling fetch: GET /api/gateway/health (src/views/llm-gateway/components/PortkeyStatusStrip.jsx:15)"}, "fullDescription": {"text": "`src/views/llm-gateway/components/PortkeyStatusStrip.jsx:15` calls `GET /api/gateway/health` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/gateway/health`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-08079b4ac0c96a17", "name": "Dangling fetch: GET /api/gateway/configs (src/views/llm-gateway/components/PortkeyStatusStrip.jsx:16)", "shortDescription": {"text": "Dangling fetch: GET /api/gateway/configs (src/views/llm-gateway/components/PortkeyStatusStrip.jsx:16)"}, "fullDescription": {"text": "`src/views/llm-gateway/components/PortkeyStatusStrip.jsx:16` calls `GET /api/gateway/configs` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/gateway/configs`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-697b7b6b27c74e73", "name": "Dangling fetch: GET /api/gateway/models (src/views/llm-gateway/components/ModelPicker.jsx:13)", "shortDescription": {"text": "Dangling fetch: GET /api/gateway/models (src/views/llm-gateway/components/ModelPicker.jsx:13)"}, "fullDescription": {"text": "`src/views/llm-gateway/components/ModelPicker.jsx:13` calls `GET /api/gateway/models` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/gateway/models`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`scanner_server.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e9c7dbaad9cd31ba", "name": "Unused endpoint: POST /tools/read_file", "shortDescription": {"text": "Unused endpoint: POST /tools/read_file"}, "fullDescription": {"text": "`mcp-server/mcp_server.py` declares `POST /tools/read_file` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1c439b69b412541d", "name": "Unused endpoint: POST /tools/web_fetch", "shortDescription": {"text": "Unused endpoint: POST /tools/web_fetch"}, "fullDescription": {"text": "`mcp-server/mcp_server.py` declares `POST /tools/web_fetch` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fe23c95893c097c8", "name": "Unused endpoint: POST /tools/execute_code", "shortDescription": {"text": "Unused endpoint: POST /tools/execute_code"}, "fullDescription": {"text": "`mcp-server/mcp_server.py` declares `POST /tools/execute_code` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30dba86f511f8b1f", "name": "Unused endpoint: POST /tools/get_memory", "shortDescription": {"text": "Unused endpoint: POST /tools/get_memory"}, "fullDescription": {"text": "`mcp-server/mcp_server.py` declares `POST /tools/get_memory` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f60ff37cc8b6a2b1", "name": "Unused endpoint: POST /tools/set_memory", "shortDescription": {"text": "Unused endpoint: POST /tools/set_memory"}, "fullDescription": {"text": "`mcp-server/mcp_server.py` declares `POST /tools/set_memory` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-65dcdfe977c2b64d", "name": "Unused endpoint: GET /configs", "shortDescription": {"text": "Unused endpoint: GET /configs"}, "fullDescription": {"text": "`portkey-routes.js` declares `GET /configs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ab9bf5db6820af4", "name": "Unused endpoint: GET /models", "shortDescription": {"text": "Unused endpoint: GET /models"}, "fullDescription": {"text": "`portkey-routes.js` declares `GET /models` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5cf10967b5fa0cac", "name": "Unused endpoint: POST /compare", "shortDescription": {"text": "Unused endpoint: POST /compare"}, "fullDescription": {"text": "`portkey-routes.js` declares `POST /compare` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-451248ea1ad93dfa", "name": "Unused endpoint: USE /api/gateway", "shortDescription": {"text": "Unused endpoint: USE /api/gateway"}, "fullDescription": {"text": "`server.js` declares `USE /api/gateway` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d2517f9eafc5297", "name": "Unused endpoint: POST /api/chat", "shortDescription": {"text": "Unused endpoint: POST /api/chat"}, "fullDescription": {"text": "`server.js` declares `POST /api/chat` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8558a3e567f3dec4", "name": "Unused endpoint: POST /api/redteam/proxy", "shortDescription": {"text": "Unused endpoint: POST /api/redteam/proxy"}, "fullDescription": {"text": "`server.js` declares `POST /api/redteam/proxy` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-36ee702aa60140ed", "name": "Unused endpoint: GET /api/models/vertex", "shortDescription": {"text": "Unused endpoint: GET /api/models/vertex"}, "fullDescription": {"text": "`server.js` declares `GET /api/models/vertex` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-27c29caf2dd5ef86", "name": "Unused endpoint: GET /api/models/bedrock", "shortDescription": {"text": "Unused endpoint: GET /api/models/bedrock"}, "fullDescription": {"text": "`server.js` declares `GET /api/models/bedrock` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eefc0fc77a0374cc", "name": "Unused endpoint: GET /api/models/azure", "shortDescription": {"text": "Unused endpoint: GET /api/models/azure"}, "fullDescription": {"text": "`server.js` declares `GET /api/models/azure` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-14ed042b32520e5c", "name": "Unused endpoint: GET /api/redteam/targets/:id", "shortDescription": {"text": "Unused endpoint: GET /api/redteam/targets/:id"}, "fullDescription": {"text": "`server.js` declares `GET /api/redteam/targets/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-55efa1a4bf548e16", "name": "Unused endpoint: GET /api/redteam/scan", "shortDescription": {"text": "Unused endpoint: GET /api/redteam/scan"}, "fullDescription": {"text": "`server.js` declares `GET /api/redteam/scan` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-77ad3df22d4135a8", "name": "Unused endpoint: POST /api/cot", "shortDescription": {"text": "Unused endpoint: POST /api/cot"}, "fullDescription": {"text": "`server.js` declares `POST /api/cot` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4756b4c4da7d2088", "name": "Unused endpoint: GET /api/health", "shortDescription": {"text": "Unused endpoint: GET /api/health"}, "fullDescription": {"text": "`server.js` declares `GET /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43680dc9ac9e1af0", "name": "Unused endpoint: GET /api/release-notes", "shortDescription": {"text": "Unused endpoint: GET /api/release-notes"}, "fullDescription": {"text": "`server.js` declares `GET /api/release-notes` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/19285"}, "properties": {"repository": "sergeiudo/sudo-airs-demo-portal", "repoUrl": "https://github.com/sergeiudo/sudo-airs-demo-portal", "branch": "main"}, "results": [{"ruleId": "scanner-4abe16dd28c10add", "level": "note", "message": {"text": "Possibly dead Python function: handler"}, "properties": {"repobilityId": "bd219af3bd678eef", "scanner": "scanner-primary", "fingerprint": "4abe16dd28c10add", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "aws-chatbot-target/handler.py:26"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8366d0d506b65df9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server.js:268"}, "properties": {"repobilityId": "a9deebb5fdc93edc", "scanner": "scanner-primary", "fingerprint": "8366d0d506b65df9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-14d99ede2ce03512", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/layout/Sidebar.jsx:118"}, "properties": {"repobilityId": "86cc1d7e19f26a28", "scanner": "scanner-primary", "fingerprint": "14d99ede2ce03512", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-8a8cf67e52c6ad97", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/red-teaming/LogEntry.jsx:67"}, "properties": {"repobilityId": "45c545d8b4777ad0", "scanner": "scanner-primary", "fingerprint": "8a8cf67e52c6ad97", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-ad089cc83edf2fee", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/PromptTelemetryDrawer.jsx:98"}, "properties": {"repobilityId": "ac36cace702a3bde", "scanner": "scanner-primary", "fingerprint": "ad089cc83edf2fee", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-117665a3714a455b", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/PipelineTraceV2.jsx:381"}, "properties": {"repobilityId": "0c3b78071fef9e12", "scanner": "scanner-primary", "fingerprint": "117665a3714a455b", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-ad49fc5ee18526a4", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/ModelSelector.jsx:154"}, "properties": {"repobilityId": "da8bdc26cb8989c6", "scanner": "scanner-primary", "fingerprint": "ad49fc5ee18526a4", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-fe3fcf0c3672e7e6", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/ResendWidget.jsx:19"}, "properties": {"repobilityId": "9f646109f336009d", "scanner": "scanner-primary", "fingerprint": "fe3fcf0c3672e7e6", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-adc205aebbe0c581", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/TelemetrySidebar.jsx:201"}, "properties": {"repobilityId": "c5c76e4c070e33cc", "scanner": "scanner-primary", "fingerprint": "adc205aebbe0c581", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-b71a0dc5d088a2e4", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/api-intercept/AttackCategory.jsx:44"}, "properties": {"repobilityId": "06de07d231982383", "scanner": "scanner-primary", "fingerprint": "b71a0dc5d088a2e4", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-57067f6db42fdb86", "level": "note", "message": {"text": "\"active\" state uses light bg in a dark theme \u2014 src/components/model-scanning/ScannerPanel.jsx:67"}, "properties": {"repobilityId": "d1e7c88254058ef9", "scanner": "scanner-primary", "fingerprint": "57067f6db42fdb86", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.active-light-bg"]}}, {"ruleId": "scanner-aa0a3bd39f4b99b2", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/model-scanning/VulnerabilityReport.jsx:29"}, "properties": {"repobilityId": "5ee7190a2150a0a8", "scanner": "scanner-primary", "fingerprint": "aa0a3bd39f4b99b2", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-3060f3e4832c82c3", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/model-scanning/ModelCard.jsx:38"}, "properties": {"repobilityId": "4860e8e416325d2e", "scanner": "scanner-primary", "fingerprint": "3060f3e4832c82c3", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-1a9bf6225a62f18b", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/observability/TraceDrawer.jsx:138"}, "properties": {"repobilityId": "9c7bf9b1eb0f4135", "scanner": "scanner-primary", "fingerprint": "1a9bf6225a62f18b", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-ecc4c14db6aebfea", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/observability/TraceTable.jsx:71"}, "properties": {"repobilityId": "de52f98c7d63cbcf", "scanner": "scanner-primary", "fingerprint": "ecc4c14db6aebfea", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-2dedf123ae7f287e", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/observability/KpiStrip.jsx:47"}, "properties": {"repobilityId": "1b3828ba8a670f3d", "scanner": "scanner-primary", "fingerprint": "2dedf123ae7f287e", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-527b2f9bb22e8639", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/sidebar/NavItem.jsx:108"}, "properties": {"repobilityId": "ef2bea31790993d9", "scanner": "scanner-primary", "fingerprint": "527b2f9bb22e8639", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-33a38a17a57b2b3f", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/views/RedTeamingView.jsx:426"}, "properties": {"repobilityId": "4b5578dbdbf1babd", "scanner": "scanner-primary", "fingerprint": "33a38a17a57b2b3f", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-cb6bbe0475d8be50", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/views/ModelScanningView.jsx:250"}, "properties": {"repobilityId": "622dd376747d5a38", "scanner": "scanner-primary", "fingerprint": "cb6bbe0475d8be50", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-1dffdaa6b664aaf5", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/views/ReleaseNotesView.jsx:572"}, "properties": {"repobilityId": "cfe524c5a2cd47af", "scanner": "scanner-primary", "fingerprint": "1dffdaa6b664aaf5", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-af6c2609f275011d", "level": "warning", "message": {"text": "Privileged port 10 in use"}, "properties": {"repobilityId": "735372d6b5594915", "scanner": "scanner-primary", "fingerprint": "af6c2609f275011d", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "setup-slack-notify.sh"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8aa5ed116187f20d", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in scanner_server.py:49"}, "properties": {"repobilityId": "e90a4a6d9a2bf704", "scanner": "scanner-primary", "fingerprint": "8aa5ed116187f20d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scanner_server.py"}, "region": {"startLine": 49}}}]}, {"ruleId": "scanner-2eb0d3b944c09be2", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in server.js:16"}, "properties": {"repobilityId": "23f3ba0b6e438ed3", "scanner": "scanner-primary", "fingerprint": "2eb0d3b944c09be2", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "server.js"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-b24069be1fe44413", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in server.js:23"}, "properties": {"repobilityId": "0d9bca6c0839725e", "scanner": "scanner-primary", "fingerprint": "b24069be1fe44413", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "server.js"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-3c421ce42668ca94", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in scanner_app.py:218"}, "properties": {"repobilityId": "1ceeea33d1c7057c", "scanner": "scanner-primary", "fingerprint": "3c421ce42668ca94", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scanner_app.py"}, "region": {"startLine": 218}}}]}, {"ruleId": "scanner-34a96f1555369678", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/AIRS-Claude-Code-Hooks-Guide.html:1767"}, "properties": {"repobilityId": "8684094b287f2bb1", "scanner": "scanner-primary", "fingerprint": "34a96f1555369678", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/AIRS-Claude-Code-Hooks-Guide.html"}, "region": {"startLine": 1767}}}]}, {"ruleId": "scanner-0da5ed3464b07080", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in mcp-server/mcp_server.py:38"}, "properties": {"repobilityId": "428112b7b63659cf", "scanner": "scanner-primary", "fingerprint": "0da5ed3464b07080", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mcp-server/mcp_server.py"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-6a3111b368302910", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/hooks-guide.html:1779"}, "properties": {"repobilityId": "36ee55ae0d80a260", "scanner": "scanner-primary", "fingerprint": "6a3111b368302910", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/hooks-guide.html"}, "region": {"startLine": 1779}}}]}, {"ruleId": "scanner-093130ad9f658ea5", "level": "error", "message": {"text": "Possible secret in src/views/DeveloperCornerView.jsx"}, "properties": {"repobilityId": "65706e0833ce8467", "scanner": "scanner-primary", "fingerprint": "093130ad9f658ea5", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/views/DeveloperCornerView.jsx"}, "region": {"startLine": 470}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-57f3e5e27d5004f2", "level": "note", "message": {"text": "Very large file: server.js (1522 lines)"}, "properties": {"repobilityId": "1479ba50e708c5c1", "scanner": "scanner-primary", "fingerprint": "57f3e5e27d5004f2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-e23cd6f6b12c53b0", "level": "note", "message": {"text": "Very large file: src/components/api-intercept/TelemetrySidebar.jsx (1155 lines)"}, "properties": {"repobilityId": "6d23083f5a54e93a", "scanner": "scanner-primary", "fingerprint": "e23cd6f6b12c53b0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-d81ee0703486e813", "level": "note", "message": {"text": "Very large file: src/views/McpSecurityView.jsx (1675 lines)"}, "properties": {"repobilityId": "c2bcb44c1a22063c", "scanner": "scanner-primary", "fingerprint": "d81ee0703486e813", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "1845f7ccfd642e0a", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "15923421638eae53", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "51b3e626b40f29fe", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "3232824dbc0816ea", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "ff60c00db218d6e8", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "d90d449f47529acc", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "ee5c24abe4ba7cb5", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-4004576abd1755a6", "level": "none", "message": {"text": "Commented-code block (6 lines) in portkey-routes.js:19"}, "properties": {"repobilityId": "12201e3a896124a8", "scanner": "scanner-primary", "fingerprint": "4004576abd1755a6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-46ce50b70b701c42", "level": "none", "message": {"text": "Commented-code block (5 lines) in server.js:29"}, "properties": {"repobilityId": "37c0c697410f3ff3", "scanner": "scanner-primary", "fingerprint": "46ce50b70b701c42", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6fa4cfedf4d77eef", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 server.js:94"}, "properties": {"repobilityId": "cf73aeb32f3642fb", "scanner": "scanner-primary", "fingerprint": "6fa4cfedf4d77eef", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-448d36d9f043dc13", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scanner_app.py:159"}, "properties": {"repobilityId": "383043358dbca21b", "scanner": "scanner-primary", "fingerprint": "448d36d9f043dc13", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-83ed7ab86e7f43a6", "level": "none", "message": {"text": "Commented-code block (5 lines) in src/components/api-intercept/PipelineTraceV2.jsx:5"}, "properties": {"repobilityId": "10ff381489deb3d7", "scanner": "scanner-primary", "fingerprint": "83ed7ab86e7f43a6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6222e8ed208bd839", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/hooks/useObservability.js:32"}, "properties": {"repobilityId": "53498e1fa8ac8135", "scanner": "scanner-primary", "fingerprint": "6222e8ed208bd839", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-2d3f25650b0f606b", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/DeveloperCornerView.jsx:231"}, "properties": {"repobilityId": "b5e3837797b0fc8b", "scanner": "scanner-primary", "fingerprint": "2d3f25650b0f606b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-9b4d5ad427afbd09", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/ObservabilityView.jsx:334"}, "properties": {"repobilityId": "94bb038a72017d66", "scanner": "scanner-primary", "fingerprint": "9b4d5ad427afbd09", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-21d07f53f2032a3d", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/RedTeamingView.jsx:100"}, "properties": {"repobilityId": "c9f15926f42536c6", "scanner": "scanner-primary", "fingerprint": "21d07f53f2032a3d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-7d4a8099f5ab9e11", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/views/ModelScanningView.jsx:156"}, "properties": {"repobilityId": "1a2ac045f1d9988a", "scanner": "scanner-primary", "fingerprint": "7d4a8099f5ab9e11", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-030da566069872e9", "level": "note", "message": {"text": "15 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "0519c1c0e8c1f8e4", "scanner": "scanner-primary", "fingerprint": "030da566069872e9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-1f76d463f37b6f66", "level": "error", "message": {"text": "FastAPI POST `scan_model` without auth dependency \u2014 scanner_app.py:1296"}, "properties": {"repobilityId": "f9785a85168196cc", "scanner": "scanner-primary", "fingerprint": "1f76d463f37b6f66", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scanner_app.py"}, "region": {"startLine": 1296}}}]}, {"ruleId": "scanner-d2348376df2ee9a8", "level": "error", "message": {"text": "FastAPI POST `read_file` without auth dependency \u2014 mcp-server/mcp_server.py:72"}, "properties": {"repobilityId": "3d2b05cc1a3f0492", "scanner": "scanner-primary", "fingerprint": "d2348376df2ee9a8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mcp-server/mcp_server.py"}, "region": {"startLine": 72}}}]}, {"ruleId": "scanner-d8a06abb9b3d6b3e", "level": "error", "message": {"text": "FastAPI POST `web_fetch` without auth dependency \u2014 mcp-server/mcp_server.py:106"}, "properties": {"repobilityId": "be1d7d688f61ba8d", "scanner": "scanner-primary", "fingerprint": "d8a06abb9b3d6b3e", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mcp-server/mcp_server.py"}, "region": {"startLine": 106}}}]}, {"ruleId": "scanner-3861fbb98c229aef", "level": "error", "message": {"text": "FastAPI POST `execute_code` without auth dependency \u2014 mcp-server/mcp_server.py:139"}, "properties": {"repobilityId": "aeb4382e9db01800", "scanner": "scanner-primary", "fingerprint": "3861fbb98c229aef", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mcp-server/mcp_server.py"}, "region": {"startLine": 139}}}]}, {"ruleId": "scanner-22bb7cf4f8b86d72", "level": "error", "message": {"text": "FastAPI POST `get_memory` without auth dependency \u2014 mcp-server/mcp_server.py:173"}, "properties": {"repobilityId": "f84e85ce8368a177", "scanner": "scanner-primary", "fingerprint": "22bb7cf4f8b86d72", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mcp-server/mcp_server.py"}, "region": {"startLine": 173}}}]}, {"ruleId": "scanner-6c17508ea3b1277b", "level": "error", "message": {"text": "FastAPI POST `set_memory` without auth dependency \u2014 mcp-server/mcp_server.py:184"}, "properties": {"repobilityId": "554f8f35ce51d3ca", "scanner": "scanner-primary", "fingerprint": "6c17508ea3b1277b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "mcp-server/mcp_server.py"}, "region": {"startLine": 184}}}]}, {"ruleId": "scanner-6c5005449600a7e8", "level": "error", "message": {"text": "Dangling fetch: POST https://api.portkey.ai/v1/chat/completions (portkey-routes.js:139)"}, "properties": {"repobilityId": "e9a2a655402e5495", "scanner": "scanner-primary", "fingerprint": "6c5005449600a7e8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-020c9983abc35f35", "level": "error", "message": {"text": "Dangling fetch: POST https://auth.apps.paloaltonetworks.com/oauth2/access_token (server.js:642)"}, "properties": {"repobilityId": "3c10f1f52ee2a2eb", "scanner": "scanner-primary", "fingerprint": "020c9983abc35f35", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-cb25b3e2a5395c41", "level": "error", "message": {"text": "Dangling fetch: GET http://localhost:${scannerPort}/ (server.js:746)"}, "properties": {"repobilityId": "c5df98d1894b873a", "scanner": "scanner-primary", "fingerprint": "cb25b3e2a5395c41", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-11c33d8c7617b0ad", "level": "error", "message": {"text": "Dangling fetch: GET http://ip-api.com/json/${ip}?fields=country,regionName,city,status (server.js:1406)"}, "properties": {"repobilityId": "9424e640182544f0", "scanner": "scanner-primary", "fingerprint": "11c33d8c7617b0ad", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-33d511f892785b28", "level": "error", "message": {"text": "Dangling fetch: GET http://localhost:${PORT}/api/health (server.js:1491)"}, "properties": {"repobilityId": "3a49bf7dc73162ce", "scanner": "scanner-primary", "fingerprint": "33d511f892785b28", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-89a32c8808ba95ad", "level": "error", "message": {"text": "Dangling fetch: GET /api/models/${provider} (src/components/api-intercept/ModelSelector.jsx:67)"}, "properties": {"repobilityId": "5227788526621e0f", "scanner": "scanner-primary", "fingerprint": "89a32c8808ba95ad", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-35bea63c7a5e670b", "level": "error", "message": {"text": "Dangling fetch: POST /api/gateway/chat (src/hooks/usePortkeyChat.js:35)"}, "properties": {"repobilityId": "74064c27260b4554", "scanner": "scanner-primary", "fingerprint": "35bea63c7a5e670b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-800e73ee25067e1f", "level": "error", "message": {"text": "Dangling fetch: GET /api/gateway/health (src/views/LlmGatewayView.jsx:19)"}, "properties": {"repobilityId": "82dc9e4cda2a7915", "scanner": "scanner-primary", "fingerprint": "800e73ee25067e1f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-4de25c83ff1717dc", "level": "error", "message": {"text": "Dangling fetch: POST /api/gateway/compare (src/views/llm-gateway/LiveDemoTab.jsx:67)"}, "properties": {"repobilityId": "00ad7bc64adb5de9", "scanner": "scanner-primary", "fingerprint": "4de25c83ff1717dc", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-f0e8d6447adbf7dd", "level": "error", "message": {"text": "Dangling fetch: GET /api/gateway/configs (src/views/llm-gateway/LiveDemoTab.jsx:118)"}, "properties": {"repobilityId": "e9c1c8f24ede1368", "scanner": "scanner-primary", "fingerprint": "f0e8d6447adbf7dd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-30d2f18eaf17b039", "level": "error", "message": {"text": "Dangling fetch: GET /api/gateway/health (src/views/llm-gateway/components/PortkeyStatusStrip.jsx:15)"}, "properties": {"repobilityId": "e5097481cfbc9fd8", "scanner": "scanner-primary", "fingerprint": "30d2f18eaf17b039", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-08079b4ac0c96a17", "level": "error", "message": {"text": "Dangling fetch: GET /api/gateway/configs (src/views/llm-gateway/components/PortkeyStatusStrip.jsx:16)"}, "properties": {"repobilityId": "fa253e557bf58425", "scanner": "scanner-primary", "fingerprint": "08079b4ac0c96a17", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-697b7b6b27c74e73", "level": "error", "message": {"text": "Dangling fetch: GET /api/gateway/models (src/views/llm-gateway/components/ModelPicker.jsx:13)"}, "properties": {"repobilityId": "4b1f0610fd38be30", "scanner": "scanner-primary", "fingerprint": "697b7b6b27c74e73", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "a362fd2d4ed1a4d3", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e9c7dbaad9cd31ba", "level": "note", "message": {"text": "Unused endpoint: POST /tools/read_file"}, "properties": {"repobilityId": "33fa5c118b511ab8", "scanner": "scanner-primary", "fingerprint": "e9c7dbaad9cd31ba", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1c439b69b412541d", "level": "note", "message": {"text": "Unused endpoint: POST /tools/web_fetch"}, "properties": {"repobilityId": "8bc02e411652c939", "scanner": "scanner-primary", "fingerprint": "1c439b69b412541d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fe23c95893c097c8", "level": "note", "message": {"text": "Unused endpoint: POST /tools/execute_code"}, "properties": {"repobilityId": "0d8b97aa10d81abb", "scanner": "scanner-primary", "fingerprint": "fe23c95893c097c8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-30dba86f511f8b1f", "level": "note", "message": {"text": "Unused endpoint: POST /tools/get_memory"}, "properties": {"repobilityId": "a2c0efd33a2d4006", "scanner": "scanner-primary", "fingerprint": "30dba86f511f8b1f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f60ff37cc8b6a2b1", "level": "note", "message": {"text": "Unused endpoint: POST /tools/set_memory"}, "properties": {"repobilityId": "6d7ee906443a33f8", "scanner": "scanner-primary", "fingerprint": "f60ff37cc8b6a2b1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-65dcdfe977c2b64d", "level": "note", "message": {"text": "Unused endpoint: GET /configs"}, "properties": {"repobilityId": "fb9ed627acd6b45d", "scanner": "scanner-primary", "fingerprint": "65dcdfe977c2b64d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2ab9bf5db6820af4", "level": "note", "message": {"text": "Unused endpoint: GET /models"}, "properties": {"repobilityId": "4d446b1b53b5d84c", "scanner": "scanner-primary", "fingerprint": "2ab9bf5db6820af4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5cf10967b5fa0cac", "level": "note", "message": {"text": "Unused endpoint: POST /compare"}, "properties": {"repobilityId": "5beea3d49bc59700", "scanner": "scanner-primary", "fingerprint": "5cf10967b5fa0cac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-451248ea1ad93dfa", "level": "note", "message": {"text": "Unused endpoint: USE /api/gateway"}, "properties": {"repobilityId": "13aa970757208daf", "scanner": "scanner-primary", "fingerprint": "451248ea1ad93dfa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9d2517f9eafc5297", "level": "note", "message": {"text": "Unused endpoint: POST /api/chat"}, "properties": {"repobilityId": "79ec3a715c2a37cb", "scanner": "scanner-primary", "fingerprint": "9d2517f9eafc5297", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8558a3e567f3dec4", "level": "note", "message": {"text": "Unused endpoint: POST /api/redteam/proxy"}, "properties": {"repobilityId": "cd5f5f77fea6e3d9", "scanner": "scanner-primary", "fingerprint": "8558a3e567f3dec4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-36ee702aa60140ed", "level": "note", "message": {"text": "Unused endpoint: GET /api/models/vertex"}, "properties": {"repobilityId": "aade0d7075d86d2d", "scanner": "scanner-primary", "fingerprint": "36ee702aa60140ed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-27c29caf2dd5ef86", "level": "note", "message": {"text": "Unused endpoint: GET /api/models/bedrock"}, "properties": {"repobilityId": "2e1c42ebc3dd603e", "scanner": "scanner-primary", "fingerprint": "27c29caf2dd5ef86", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-eefc0fc77a0374cc", "level": "note", "message": {"text": "Unused endpoint: GET /api/models/azure"}, "properties": {"repobilityId": "b3c5ac2fccce7a7d", "scanner": "scanner-primary", "fingerprint": "eefc0fc77a0374cc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-14ed042b32520e5c", "level": "note", "message": {"text": "Unused endpoint: GET /api/redteam/targets/:id"}, "properties": {"repobilityId": "809643b684cbde25", "scanner": "scanner-primary", "fingerprint": "14ed042b32520e5c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-55efa1a4bf548e16", "level": "note", "message": {"text": "Unused endpoint: GET /api/redteam/scan"}, "properties": {"repobilityId": "7b8b35af3ba53ac9", "scanner": "scanner-primary", "fingerprint": "55efa1a4bf548e16", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-77ad3df22d4135a8", "level": "note", "message": {"text": "Unused endpoint: POST /api/cot"}, "properties": {"repobilityId": "498bf5cf75500dac", "scanner": "scanner-primary", "fingerprint": "77ad3df22d4135a8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4756b4c4da7d2088", "level": "note", "message": {"text": "Unused endpoint: GET /api/health"}, "properties": {"repobilityId": "98e09bb8fcd7909b", "scanner": "scanner-primary", "fingerprint": "4756b4c4da7d2088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-43680dc9ac9e1af0", "level": "note", "message": {"text": "Unused endpoint: GET /api/release-notes"}, "properties": {"repobilityId": "5140ae8129bd544c", "scanner": "scanner-primary", "fingerprint": "43680dc9ac9e1af0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}