{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-4250f27b77b233a1", "name": "Possibly dead Python function: process_bind_param", "shortDescription": {"text": "Possibly dead Python function: process_bind_param"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9050077d807d4c15", "name": "Possibly dead Python function: process_result_value", "shortDescription": {"text": "Possibly dead Python function: process_result_value"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4d84ac1eaed2a81c", "name": "Possibly dead Python function: require_auth", "shortDescription": {"text": "Possibly dead Python function: require_auth"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b3765e2172fd686", "name": "Possibly dead Python function: execute_tool", "shortDescription": {"text": "Possibly dead Python function: execute_tool"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb8278230b41859a", "name": "Possibly dead Python function: build_prompt", "shortDescription": {"text": "Possibly dead Python function: build_prompt"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c355752e2f0005ec", "name": "Possibly dead Python function: build_prompt_with_example", "shortDescription": {"text": "Possibly dead Python function: build_prompt_with_example"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9fe3bbe372bc431f", "name": "`dangerouslySetInnerHTML` used in a React component \u2014 frontend/src/components/layout/ThemeProvider.tsx:67", "shortDescription": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 frontend/src/components/layout/ThemeProvider.tsx:67"}, "fullDescription": {"text": "Open XSS surface unless the input is provably trusted. Replace with explicit JSX or sanitize via a vetted library.\n\nWhy: OWASP basics. Already partially flagged by the security analyzer.\nRule id: fq.dangerous-html"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1c5fa7d7d07734fd", "name": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/app/library/page.tsx:535", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/app/library/page.tsx:535"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-12fdf869b7e65afe", "name": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/app/digest/page.tsx:404", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/app/digest/page.tsx:404"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-006294a4a30d7c31", "name": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/app/reports/page.tsx:79", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/app/reports/page.tsx:79"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9d60fc7eedf84e03", "name": "Insecure pattern 'dangerous_innerhtml' in frontend/src/components/layout/ThemeProvider.tsx:67", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in frontend/src/components/layout/ThemeProvider.tsx:67"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6b526b2b739aedd1", "name": "Insecure pattern 'document_write' in frontend/src/app/debate/page.tsx:227", "shortDescription": {"text": "Insecure pattern 'document_write' in frontend/src/app/debate/page.tsx:227"}, "fullDescription": {"text": "Found a known-risky pattern (document_write). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bb63f919bf0adfe4", "name": "Insecure pattern 'eval_used' in .claude/security-patterns.yaml:15", "shortDescription": {"text": "Insecure pattern 'eval_used' in .claude/security-patterns.yaml:15"}, "fullDescription": {"text": "Found a known-risky pattern (eval_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-90b4c99bd715872f", "name": "Insecure pattern 'exec_used' in .claude/security-patterns.yaml:15", "shortDescription": {"text": "Insecure pattern 'exec_used' in .claude/security-patterns.yaml:15"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b56c72de5f8b5bfb", "name": "Insecure pattern 'dangerous_innerhtml' in .claude/security-patterns.yaml:25", "shortDescription": {"text": "Insecure pattern 'dangerous_innerhtml' in .claude/security-patterns.yaml:25"}, "fullDescription": {"text": "Found a known-risky pattern (dangerous_innerhtml). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "2 test file(s) for 88 source file(s) (ratio 0.02). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 99 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 47 placeholder/mock markers across 10 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, ci. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4bbb690cc82f103d", "name": "Agent authority lacks a verifier contract: .claude/security-patterns.yaml", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/security-patterns.yaml"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a5cf0919ef3e6186", "name": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/lib/api.ts:29", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/lib/api.ts:29"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1048ce4dafb478ef", "name": "Commented-code block (5 lines) in backend/services/anthropic_client.py:14", "shortDescription": {"text": "Commented-code block (5 lines) in backend/services/anthropic_client.py:14"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-00cfd8998e0b1ad8", "name": "Commented-code block (5 lines) in backend/evals/eval_being_specific.py:145", "shortDescription": {"text": "Commented-code block (5 lines) in backend/evals/eval_being_specific.py:145"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-9195295a5f5a4410", "name": "Commented-code block (5 lines) in backend/evals/eval_prompt_versions.py:67", "shortDescription": {"text": "Commented-code block (5 lines) in backend/evals/eval_prompt_versions.py:67"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1b5a76780c3df9aa", "name": "1 env vars used in code but missing from .env.example", "shortDescription": {"text": "1 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `NEXT_PUBLIC_API_URL`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nbackend/routers/reports.py:generate_report, backend/routers/reports.py:create_draft\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e6f7b7e0b738667b", "name": "FastAPI POST `generate_report` without auth dependency \u2014 backend/routers/reports.py:18", "shortDescription": {"text": "FastAPI POST `generate_report` without auth dependency \u2014 backend/routers/reports.py:18"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cb2003ffe8e119ae", "name": "FastAPI POST `create_draft` without auth dependency \u2014 backend/routers/reports.py:54", "shortDescription": {"text": "FastAPI POST `create_draft` without auth dependency \u2014 backend/routers/reports.py:54"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0ca0ed8447ffa957", "name": "FastAPI PATCH `update_report` without auth dependency \u2014 backend/routers/reports.py:82", "shortDescription": {"text": "FastAPI PATCH `update_report` without auth dependency \u2014 backend/routers/reports.py:82"}, "fullDescription": {"text": "`@router.patch` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-35b949835fe8bbb7", "name": "FastAPI DELETE `delete_report` without auth dependency \u2014 backend/routers/reports.py:162", "shortDescription": {"text": "FastAPI DELETE `delete_report` without auth dependency \u2014 backend/routers/reports.py:162"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a3c234cb55e9afaf", "name": "FastAPI POST `start_debate` without auth dependency \u2014 backend/routers/debate.py:26", "shortDescription": {"text": "FastAPI POST `start_debate` without auth dependency \u2014 backend/routers/debate.py:26"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-94f27d8bc8bc2e7d", "name": "FastAPI DELETE `delete_debate` without auth dependency \u2014 backend/routers/debate.py:103", "shortDescription": {"text": "FastAPI DELETE `delete_debate` without auth dependency \u2014 backend/routers/debate.py:103"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9ea3cea2a12b975c", "name": "FastAPI PUT `save_settings_endpoint` without auth dependency \u2014 backend/routers/digest.py:91", "shortDescription": {"text": "FastAPI PUT `save_settings_endpoint` without auth dependency \u2014 backend/routers/digest.py:91"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e6997fc7c2a91a24", "name": "FastAPI POST `send_now` without auth dependency \u2014 backend/routers/digest.py:131", "shortDescription": {"text": "FastAPI POST `send_now` without auth dependency \u2014 backend/routers/digest.py:131"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f638522596797ef8", "name": "FastAPI POST `start_research` without auth dependency \u2014 backend/routers/research.py:20", "shortDescription": {"text": "FastAPI POST `start_research` without auth dependency \u2014 backend/routers/research.py:20"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a3a12b95a7478fcd", "name": "FastAPI POST `save_session_to_library` without auth dependency \u2014 backend/routers/research.py:86", "shortDescription": {"text": "FastAPI POST `save_session_to_library` without auth dependency \u2014 backend/routers/research.py:86"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e216894a21416e4d", "name": "FastAPI DELETE `delete_session` without auth dependency \u2014 backend/routers/research.py:128", "shortDescription": {"text": "FastAPI DELETE `delete_session` without auth dependency \u2014 backend/routers/research.py:128"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4b1ca6d80502db39", "name": "FastAPI DELETE `delete_reminder` without auth dependency \u2014 backend/routers/reminders.py:17", "shortDescription": {"text": "FastAPI DELETE `delete_reminder` without auth dependency \u2014 backend/routers/reminders.py:17"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-964c7f1c1ae6e4a7", "name": "FastAPI PUT `save_model_settings` without auth dependency \u2014 backend/routers/settings.py:46", "shortDescription": {"text": "FastAPI PUT `save_model_settings` without auth dependency \u2014 backend/routers/settings.py:46"}, "fullDescription": {"text": "`@router.put` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e48ce27bb42a9797", "name": "FastAPI POST `upload_document` without auth dependency \u2014 backend/routers/documents.py:185", "shortDescription": {"text": "FastAPI POST `upload_document` without auth dependency \u2014 backend/routers/documents.py:185"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ea8b425ab7936a70", "name": "FastAPI POST `ingest_url` without auth dependency \u2014 backend/routers/documents.py:225", "shortDescription": {"text": "FastAPI POST `ingest_url` without auth dependency \u2014 backend/routers/documents.py:225"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-798dd12897d6f667", "name": "FastAPI POST `assign_folder` without auth dependency \u2014 backend/routers/documents.py:299", "shortDescription": {"text": "FastAPI POST `assign_folder` without auth dependency \u2014 backend/routers/documents.py:299"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d02aeb9a64e4cfb2", "name": "FastAPI POST `rename_folder` without auth dependency \u2014 backend/routers/documents.py:315", "shortDescription": {"text": "FastAPI POST `rename_folder` without auth dependency \u2014 backend/routers/documents.py:315"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8cadd50b7de1e113", "name": "FastAPI DELETE `delete_document` without auth dependency \u2014 backend/routers/documents.py:333", "shortDescription": {"text": "FastAPI DELETE `delete_document` without auth dependency \u2014 backend/routers/documents.py:333"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e125452985810e41", "name": "FastAPI POST `ask_documents` without auth dependency \u2014 backend/routers/documents.py:356", "shortDescription": {"text": "FastAPI POST `ask_documents` without auth dependency \u2014 backend/routers/documents.py:356"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d10c5de3452398b1", "name": "FastAPI POST `start_analysis` without auth dependency \u2014 backend/routers/analysis.py:15", "shortDescription": {"text": "FastAPI POST `start_analysis` without auth dependency \u2014 backend/routers/analysis.py:15"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-efb6774b3ea7909b", "name": "FastAPI DELETE `delete_analysis` without auth dependency \u2014 backend/routers/analysis.py:87", "shortDescription": {"text": "FastAPI DELETE `delete_analysis` without auth dependency \u2014 backend/routers/analysis.py:87"}, "fullDescription": {"text": "`@router.delete` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9a42c0215252d31b", "name": "Dangling fetch: POST /api/research/start (frontend/src/lib/api.ts:83)", "shortDescription": {"text": "Dangling fetch: POST /api/research/start (frontend/src/lib/api.ts:83)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:83` calls `POST /api/research/start` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/research/start`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b4ecf0e9f30e5839", "name": "Dangling fetch: GET /api/research/ (frontend/src/lib/api.ts:87)", "shortDescription": {"text": "Dangling fetch: GET /api/research/ (frontend/src/lib/api.ts:87)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:87` calls `GET /api/research/` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/research`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7b56a44b0cb488a6", "name": "Dangling fetch: GET /api/research/${id} (frontend/src/lib/api.ts:88)", "shortDescription": {"text": "Dangling fetch: GET /api/research/${id} (frontend/src/lib/api.ts:88)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:88` calls `GET /api/research/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/research/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-27192fbba6152d61", "name": "Dangling fetch: DELETE /api/research/${id} (frontend/src/lib/api.ts:90)", "shortDescription": {"text": "Dangling fetch: DELETE /api/research/${id} (frontend/src/lib/api.ts:90)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:90` calls `DELETE /api/research/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/research/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-715dcf1947f80360", "name": "Dangling fetch: POST /api/research/${sessionId}/save-to-library (frontend/src/lib/api.ts:94)", "shortDescription": {"text": "Dangling fetch: POST /api/research/${sessionId}/save-to-library (frontend/src/lib/api.ts:94)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:94` calls `POST /api/research/${sessionId}/save-to-library` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/research/<p>/save-to-library`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-62b8cb1d32453ca7", "name": "Dangling fetch: POST /api/documents/ingest-url (frontend/src/lib/api.ts:110)", "shortDescription": {"text": "Dangling fetch: POST /api/documents/ingest-url (frontend/src/lib/api.ts:110)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:110` calls `POST /api/documents/ingest-url` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/documents/ingest-url`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-877cd736ac0b8e8d", "name": "Dangling fetch: GET /api/documents/${id} (frontend/src/lib/api.ts:116)", "shortDescription": {"text": "Dangling fetch: GET /api/documents/${id} (frontend/src/lib/api.ts:116)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:116` calls `GET /api/documents/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/documents/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-688609a90fd386a8", "name": "Dangling fetch: DELETE /api/documents/${id} (frontend/src/lib/api.ts:118)", "shortDescription": {"text": "Dangling fetch: DELETE /api/documents/${id} (frontend/src/lib/api.ts:118)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:118` calls `DELETE /api/documents/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/documents/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8ff1642eb9dc2686", "name": "Dangling fetch: POST /api/documents/assign-folder (frontend/src/lib/api.ts:120)", "shortDescription": {"text": "Dangling fetch: POST /api/documents/assign-folder (frontend/src/lib/api.ts:120)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:120` calls `POST /api/documents/assign-folder` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/documents/assign-folder`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8f67094f7ef25d95", "name": "Dangling fetch: POST /api/documents/rename-folder (frontend/src/lib/api.ts:125)", "shortDescription": {"text": "Dangling fetch: POST /api/documents/rename-folder (frontend/src/lib/api.ts:125)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:125` calls `POST /api/documents/rename-folder` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/documents/rename-folder`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-80149cd02be330a2", "name": "Dangling fetch: POST /api/reports/draft (frontend/src/lib/api.ts:139)", "shortDescription": {"text": "Dangling fetch: POST /api/reports/draft (frontend/src/lib/api.ts:139)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:139` calls `POST /api/reports/draft` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/reports/draft`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-24b71833513403ab", "name": "Dangling fetch: GET /api/reports/ (frontend/src/lib/api.ts:143)", "shortDescription": {"text": "Dangling fetch: GET /api/reports/ (frontend/src/lib/api.ts:143)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:143` calls `GET /api/reports/` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/reports`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-88925f3d414010ec", "name": "Dangling fetch: GET /api/reports/${id} (frontend/src/lib/api.ts:144)", "shortDescription": {"text": "Dangling fetch: GET /api/reports/${id} (frontend/src/lib/api.ts:144)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:144` calls `GET /api/reports/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/reports/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-93135ab4ac5c8c5e", "name": "Dangling fetch: PATCH /api/reports/${id} (frontend/src/lib/api.ts:146)", "shortDescription": {"text": "Dangling fetch: PATCH /api/reports/${id} (frontend/src/lib/api.ts:146)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:146` calls `PATCH /api/reports/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/reports/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c96e64fe3d175b2b", "name": "Dangling fetch: DELETE /api/reports/${id} (frontend/src/lib/api.ts:151)", "shortDescription": {"text": "Dangling fetch: DELETE /api/reports/${id} (frontend/src/lib/api.ts:151)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:151` calls `DELETE /api/reports/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/reports/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d432b3a3d053b79b", "name": "Dangling fetch: GET /api/analysis/ (frontend/src/lib/api.ts:157)", "shortDescription": {"text": "Dangling fetch: GET /api/analysis/ (frontend/src/lib/api.ts:157)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:157` calls `GET /api/analysis/` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/analysis`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b043edd673436ac4", "name": "Dangling fetch: GET /api/analysis/${id} (frontend/src/lib/api.ts:158)", "shortDescription": {"text": "Dangling fetch: GET /api/analysis/${id} (frontend/src/lib/api.ts:158)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:158` calls `GET /api/analysis/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/analysis/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ce97b31301de3312", "name": "Dangling fetch: DELETE /api/analysis/${id} (frontend/src/lib/api.ts:160)", "shortDescription": {"text": "Dangling fetch: DELETE /api/analysis/${id} (frontend/src/lib/api.ts:160)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:160` calls `DELETE /api/analysis/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/analysis/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4840dc6cc9399119", "name": "Dangling fetch: GET /api/settings/models (frontend/src/lib/api.ts:165)", "shortDescription": {"text": "Dangling fetch: GET /api/settings/models (frontend/src/lib/api.ts:165)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:165` calls `GET /api/settings/models` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/models`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e4d7d5422861ed1a", "name": "Dangling fetch: PUT /api/settings/models (frontend/src/lib/api.ts:178)", "shortDescription": {"text": "Dangling fetch: PUT /api/settings/models (frontend/src/lib/api.ts:178)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:178` calls `PUT /api/settings/models` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/settings/models`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-747b23a077db0ff2", "name": "Dangling fetch: DELETE /api/reminders/${id} (frontend/src/lib/api.ts:196)", "shortDescription": {"text": "Dangling fetch: DELETE /api/reminders/${id} (frontend/src/lib/api.ts:196)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:196` calls `DELETE /api/reminders/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/reminders/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6da592eebb52e3ef", "name": "Dangling fetch: GET /api/auth/status (frontend/src/lib/api.ts:200)", "shortDescription": {"text": "Dangling fetch: GET /api/auth/status (frontend/src/lib/api.ts:200)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:200` calls `GET /api/auth/status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/status`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5825ea91d441c71f", "name": "Dangling fetch: POST /api/auth/login (frontend/src/lib/api.ts:202)", "shortDescription": {"text": "Dangling fetch: POST /api/auth/login (frontend/src/lib/api.ts:202)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:202` calls `POST /api/auth/login` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/login`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3bfd1e6fee22adf1", "name": "Dangling fetch: POST /api/digest/send-now (frontend/src/lib/api.ts:210)", "shortDescription": {"text": "Dangling fetch: POST /api/digest/send-now (frontend/src/lib/api.ts:210)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:210` calls `POST /api/digest/send-now` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/digest/send-now`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-076d3b1bfd1c2796", "name": "Dangling fetch: GET /api/digest/status (frontend/src/lib/api.ts:217)", "shortDescription": {"text": "Dangling fetch: GET /api/digest/status (frontend/src/lib/api.ts:217)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:217` calls `GET /api/digest/status` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/digest/status`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b8033a4bf2293e9a", "name": "Dangling fetch: GET /api/digest/settings (frontend/src/lib/api.ts:228)", "shortDescription": {"text": "Dangling fetch: GET /api/digest/settings (frontend/src/lib/api.ts:228)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:228` calls `GET /api/digest/settings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/digest/settings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-58382b84d4b162a0", "name": "Dangling fetch: PUT /api/digest/settings (frontend/src/lib/api.ts:245)", "shortDescription": {"text": "Dangling fetch: PUT /api/digest/settings (frontend/src/lib/api.ts:245)"}, "fullDescription": {"text": "`frontend/src/lib/api.ts:245` calls `PUT /api/digest/settings` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/digest/settings`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-970eb92d6ec2bfaa", "name": "Unused endpoint: POST /generate", "shortDescription": {"text": "Unused endpoint: POST /generate"}, "fullDescription": {"text": "`backend/routers/reports.py` declares `POST /generate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7e30280ac6f566cd", "name": "Unused endpoint: GET /template/{report_type}", "shortDescription": {"text": "Unused endpoint: GET /template/{report_type}"}, "fullDescription": {"text": "`backend/routers/reports.py` declares `GET /template/{report_type}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-29d17450d20db711", "name": "Unused endpoint: POST /draft", "shortDescription": {"text": "Unused endpoint: POST /draft"}, "fullDescription": {"text": "`backend/routers/reports.py` declares `POST /draft` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend/routers/reports.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6f606e1e29a7ef82", "name": "Unused endpoint: GET /{report_id}", "shortDescription": {"text": "Unused endpoint: GET /{report_id}"}, "fullDescription": {"text": "`backend/routers/reports.py` declares `GET /{report_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bc72b2c1e1abc7b8", "name": "Unused endpoint: PATCH /{report_id}", "shortDescription": {"text": "Unused endpoint: PATCH /{report_id}"}, "fullDescription": {"text": "`backend/routers/reports.py` declares `PATCH /{report_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f44d37b218815ac", "name": "Unused endpoint: GET /{report_id}/export", "shortDescription": {"text": "Unused endpoint: GET /{report_id}/export"}, "fullDescription": {"text": "`backend/routers/reports.py` declares `GET /{report_id}/export` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-772e19875f5f1469", "name": "Unused endpoint: DELETE /{report_id}", "shortDescription": {"text": "Unused endpoint: DELETE /{report_id}"}, "fullDescription": {"text": "`backend/routers/reports.py` declares `DELETE /{report_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`backend/routers/auth.py` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a13a7e97aeacf55f", "name": "Unused endpoint: POST /start", "shortDescription": {"text": "Unused endpoint: POST /start"}, "fullDescription": {"text": "`backend/routers/debate.py` declares `POST /start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-da1da8bd83699e0b", "name": "Unused endpoint: GET /{debate_id}/stream", "shortDescription": {"text": "Unused endpoint: GET /{debate_id}/stream"}, "fullDescription": {"text": "`backend/routers/debate.py` declares `GET /{debate_id}/stream` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9b6b3ebade0a4f9e", "name": "Unused endpoint: GET /{debate_id}", "shortDescription": {"text": "Unused endpoint: GET /{debate_id}"}, "fullDescription": {"text": "`backend/routers/debate.py` declares `GET /{debate_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a6f6a8cb58233691", "name": "Unused endpoint: DELETE /{debate_id}", "shortDescription": {"text": "Unused endpoint: DELETE /{debate_id}"}, "fullDescription": {"text": "`backend/routers/debate.py` declares `DELETE /{debate_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-512ccb0fd0b230ba", "name": "Unused endpoint: GET /settings", "shortDescription": {"text": "Unused endpoint: GET /settings"}, "fullDescription": {"text": "`backend/routers/digest.py` declares `GET /settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1cf2ed60cbbf2375", "name": "Unused endpoint: PUT /settings", "shortDescription": {"text": "Unused endpoint: PUT /settings"}, "fullDescription": {"text": "`backend/routers/digest.py` declares `PUT /settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d8be6d8780c450bb", "name": "Unused endpoint: POST /send-now", "shortDescription": {"text": "Unused endpoint: POST /send-now"}, "fullDescription": {"text": "`backend/routers/digest.py` declares `POST /send-now` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3a3f32d20186df2d", "name": "Unused endpoint: GET /{session_id}/stream", "shortDescription": {"text": "Unused endpoint: GET /{session_id}/stream"}, "fullDescription": {"text": "`backend/routers/research.py` declares `GET /{session_id}/stream` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-af24049c13127ae7", "name": "Unused endpoint: GET /{session_id}", "shortDescription": {"text": "Unused endpoint: GET /{session_id}"}, "fullDescription": {"text": "`backend/routers/research.py` declares `GET /{session_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-46a71b9e5675be00", "name": "Unused endpoint: POST /{session_id}/save-to-library", "shortDescription": {"text": "Unused endpoint: POST /{session_id}/save-to-library"}, "fullDescription": {"text": "`backend/routers/research.py` declares `POST /{session_id}/save-to-library` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-173ad25a6a1cb443", "name": "Unused endpoint: DELETE /{session_id}", "shortDescription": {"text": "Unused endpoint: DELETE /{session_id}"}, "fullDescription": {"text": "`backend/routers/research.py` declares `DELETE /{session_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-83dd8a48703de15f", "name": "Unused endpoint: DELETE /{reminder_id}", "shortDescription": {"text": "Unused endpoint: DELETE /{reminder_id}"}, "fullDescription": {"text": "`backend/routers/reminders.py` declares `DELETE /{reminder_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ab9bf5db6820af4", "name": "Unused endpoint: GET /models", "shortDescription": {"text": "Unused endpoint: GET /models"}, "fullDescription": {"text": "`backend/routers/settings.py` declares `GET /models` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ca0a4ab49c30f35", "name": "Unused endpoint: PUT /models", "shortDescription": {"text": "Unused endpoint: PUT /models"}, "fullDescription": {"text": "`backend/routers/settings.py` declares `PUT /models` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6236b283b79811b8", "name": "Unused endpoint: POST /upload", "shortDescription": {"text": "Unused endpoint: POST /upload"}, "fullDescription": {"text": "`backend/routers/documents.py` declares `POST /upload` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4282e8f5dc08008", "name": "Unused endpoint: POST /ingest-url", "shortDescription": {"text": "Unused endpoint: POST /ingest-url"}, "fullDescription": {"text": "`backend/routers/documents.py` declares `POST /ingest-url` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-14ca9451df2c5dcc", "name": "Unused endpoint: GET /{doc_id}", "shortDescription": {"text": "Unused endpoint: GET /{doc_id}"}, "fullDescription": {"text": "`backend/routers/documents.py` declares `GET /{doc_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e8f52efc7cf66b77", "name": "Unused endpoint: POST /assign-folder", "shortDescription": {"text": "Unused endpoint: POST /assign-folder"}, "fullDescription": {"text": "`backend/routers/documents.py` declares `POST /assign-folder` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0e1f788a818bccab", "name": "Unused endpoint: POST /rename-folder", "shortDescription": {"text": "Unused endpoint: POST /rename-folder"}, "fullDescription": {"text": "`backend/routers/documents.py` declares `POST /rename-folder` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e96576fde6078449", "name": "Unused endpoint: DELETE /{doc_id}", "shortDescription": {"text": "Unused endpoint: DELETE /{doc_id}"}, "fullDescription": {"text": "`backend/routers/documents.py` declares `DELETE /{doc_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8e1fadad2500f063", "name": "Unused endpoint: POST /ask", "shortDescription": {"text": "Unused endpoint: POST /ask"}, "fullDescription": {"text": "`backend/routers/documents.py` declares `POST /ask` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-26d3bb1589d06372", "name": "Unused endpoint: GET /{analysis_id}", "shortDescription": {"text": "Unused endpoint: GET /{analysis_id}"}, "fullDescription": {"text": "`backend/routers/analysis.py` declares `GET /{analysis_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9e91dee9605e46a9", "name": "Unused endpoint: GET /{analysis_id}/export", "shortDescription": {"text": "Unused endpoint: GET /{analysis_id}/export"}, "fullDescription": {"text": "`backend/routers/analysis.py` declares `GET /{analysis_id}/export` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cf23a02b5866451b", "name": "Unused endpoint: DELETE /{analysis_id}", "shortDescription": {"text": "Unused endpoint: DELETE /{analysis_id}"}, "fullDescription": {"text": "`backend/routers/analysis.py` declares `DELETE /{analysis_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/18670"}, "properties": {"repository": "ryokoralston/ai-research-policy-app", "repoUrl": "https://github.com/ryokoralston/ai-research-policy-app", "branch": "main"}, "results": [{"ruleId": "scanner-4250f27b77b233a1", "level": "note", "message": {"text": "Possibly dead Python function: process_bind_param"}, "properties": {"repobilityId": "a51428934072abb6", "scanner": "scanner-primary", "fingerprint": "4250f27b77b233a1", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/services/secret_crypto.py:89"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9050077d807d4c15", "level": "note", "message": {"text": "Possibly dead Python function: process_result_value"}, "properties": {"repobilityId": "2b4ef95eaf3928de", "scanner": "scanner-primary", "fingerprint": "9050077d807d4c15", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/services/secret_crypto.py:94"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4d84ac1eaed2a81c", "level": "note", "message": {"text": "Possibly dead Python function: require_auth"}, "properties": {"repobilityId": "d7855475dea79341", "scanner": "scanner-primary", "fingerprint": "4d84ac1eaed2a81c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/services/auth.py:52"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3b3765e2172fd686", "level": "note", "message": {"text": "Possibly dead Python function: execute_tool"}, "properties": {"repobilityId": "0e530e8ee3947a19", "scanner": "scanner-primary", "fingerprint": "3b3765e2172fd686", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/services/rag_service.py:141"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-eb8278230b41859a", "level": "note", "message": {"text": "Possibly dead Python function: build_prompt"}, "properties": {"repobilityId": "4db34c79c09c2eab", "scanner": "scanner-primary", "fingerprint": "eb8278230b41859a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/evals/eval_research_queries.py:113"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c355752e2f0005ec", "level": "note", "message": {"text": "Possibly dead Python function: build_prompt_with_example"}, "properties": {"repobilityId": "e8f6dbf4bbd88605", "scanner": "scanner-primary", "fingerprint": "c355752e2f0005ec", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/evals/eval_research_queries.py:126"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9fe3bbe372bc431f", "level": "warning", "message": {"text": "`dangerouslySetInnerHTML` used in a React component \u2014 frontend/src/components/layout/ThemeProvider.tsx:67"}, "properties": {"repobilityId": "8690c1d717e17be7", "scanner": "scanner-primary", "fingerprint": "9fe3bbe372bc431f", "layer": "frontend", "severity": "medium", "confidence": 1.0, "tags": ["frontend-quality", "fq.dangerous-html"]}}, {"ruleId": "scanner-1c5fa7d7d07734fd", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/app/library/page.tsx:535"}, "properties": {"repobilityId": "80ed60ad3dcf1d08", "scanner": "scanner-primary", "fingerprint": "1c5fa7d7d07734fd", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-12fdf869b7e65afe", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/app/digest/page.tsx:404"}, "properties": {"repobilityId": "7ddfe1e888430e66", "scanner": "scanner-primary", "fingerprint": "12fdf869b7e65afe", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-006294a4a30d7c31", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/app/reports/page.tsx:79"}, "properties": {"repobilityId": "5084e6ffaba1e083", "scanner": "scanner-primary", "fingerprint": "006294a4a30d7c31", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-9d60fc7eedf84e03", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in frontend/src/components/layout/ThemeProvider.tsx:67"}, "properties": {"repobilityId": "4ed73a2de355a5ca", "scanner": "scanner-primary", "fingerprint": "9d60fc7eedf84e03", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/components/layout/ThemeProvider.tsx"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-6b526b2b739aedd1", "level": "note", "message": {"text": "Insecure pattern 'document_write' in frontend/src/app/debate/page.tsx:227"}, "properties": {"repobilityId": "0334cc91c21be3e4", "scanner": "scanner-primary", "fingerprint": "6b526b2b739aedd1", "layer": "security", "severity": "low", "confidence": 1.0, "tags": ["owasp", "document_write"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/app/debate/page.tsx"}, "region": {"startLine": 227}}}]}, {"ruleId": "scanner-bb63f919bf0adfe4", "level": "error", "message": {"text": "Insecure pattern 'eval_used' in .claude/security-patterns.yaml:15"}, "properties": {"repobilityId": "31da1e1a72a9b3da", "scanner": "scanner-primary", "fingerprint": "bb63f919bf0adfe4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "eval_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/security-patterns.yaml"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-90b4c99bd715872f", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in .claude/security-patterns.yaml:15"}, "properties": {"repobilityId": "5c0242da9db8393b", "scanner": "scanner-primary", "fingerprint": "90b4c99bd715872f", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/security-patterns.yaml"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-b56c72de5f8b5bfb", "level": "warning", "message": {"text": "Insecure pattern 'dangerous_innerhtml' in .claude/security-patterns.yaml:25"}, "properties": {"repobilityId": "af26b73b47fe5dcb", "scanner": "scanner-primary", "fingerprint": "b56c72de5f8b5bfb", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "dangerous_innerhtml"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/security-patterns.yaml"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "c9de21d2bd96d32d", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "0e7e6dcdf05e9065", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "60f4dfa064ab63ef", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "5810a7db637459d1", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "b970f902fb935565", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "2b191f8f5dbdd815", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "df706bc952a41205", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "c87e20edaf05ed6f", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-4bbb690cc82f103d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/security-patterns.yaml"}, "properties": {"repobilityId": "0c639596e0799699", "scanner": "scanner-primary", "fingerprint": "4bbb690cc82f103d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/security-patterns.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a5cf0919ef3e6186", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/lib/api.ts:29"}, "properties": {"repobilityId": "08f5e502d2e8fcb0", "scanner": "scanner-primary", "fingerprint": "a5cf0919ef3e6186", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-1048ce4dafb478ef", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/services/anthropic_client.py:14"}, "properties": {"repobilityId": "58bf18935beb6e23", "scanner": "scanner-primary", "fingerprint": "1048ce4dafb478ef", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-00cfd8998e0b1ad8", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/evals/eval_being_specific.py:145"}, "properties": {"repobilityId": "0d888b05a99cb007", "scanner": "scanner-primary", "fingerprint": "00cfd8998e0b1ad8", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-9195295a5f5a4410", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/evals/eval_prompt_versions.py:67"}, "properties": {"repobilityId": "b6cb8872eab2afb0", "scanner": "scanner-primary", "fingerprint": "9195295a5f5a4410", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1b5a76780c3df9aa", "level": "none", "message": {"text": "1 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "d04379b337b44a15", "scanner": "scanner-primary", "fingerprint": "1b5a76780c3df9aa", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "aab4d2378be2b42f", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-e6f7b7e0b738667b", "level": "error", "message": {"text": "FastAPI POST `generate_report` without auth dependency \u2014 backend/routers/reports.py:18"}, "properties": {"repobilityId": "c62803ef3828780c", "scanner": "scanner-primary", "fingerprint": "e6f7b7e0b738667b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/reports.py"}, "region": {"startLine": 18}}}]}, {"ruleId": "scanner-cb2003ffe8e119ae", "level": "error", "message": {"text": "FastAPI POST `create_draft` without auth dependency \u2014 backend/routers/reports.py:54"}, "properties": {"repobilityId": "20c8992acf3a1cd7", "scanner": "scanner-primary", "fingerprint": "cb2003ffe8e119ae", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/reports.py"}, "region": {"startLine": 54}}}]}, {"ruleId": "scanner-0ca0ed8447ffa957", "level": "error", "message": {"text": "FastAPI PATCH `update_report` without auth dependency \u2014 backend/routers/reports.py:82"}, "properties": {"repobilityId": "b7c806e30b6c296a", "scanner": "scanner-primary", "fingerprint": "0ca0ed8447ffa957", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/reports.py"}, "region": {"startLine": 82}}}]}, {"ruleId": "scanner-35b949835fe8bbb7", "level": "error", "message": {"text": "FastAPI DELETE `delete_report` without auth dependency \u2014 backend/routers/reports.py:162"}, "properties": {"repobilityId": "48bf279b3d951288", "scanner": "scanner-primary", "fingerprint": "35b949835fe8bbb7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/reports.py"}, "region": {"startLine": 162}}}]}, {"ruleId": "scanner-a3c234cb55e9afaf", "level": "error", "message": {"text": "FastAPI POST `start_debate` without auth dependency \u2014 backend/routers/debate.py:26"}, "properties": {"repobilityId": "e59a37e755938b29", "scanner": "scanner-primary", "fingerprint": "a3c234cb55e9afaf", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/debate.py"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-94f27d8bc8bc2e7d", "level": "error", "message": {"text": "FastAPI DELETE `delete_debate` without auth dependency \u2014 backend/routers/debate.py:103"}, "properties": {"repobilityId": "e82b11cebec2514e", "scanner": "scanner-primary", "fingerprint": "94f27d8bc8bc2e7d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/debate.py"}, "region": {"startLine": 103}}}]}, {"ruleId": "scanner-9ea3cea2a12b975c", "level": "error", "message": {"text": "FastAPI PUT `save_settings_endpoint` without auth dependency \u2014 backend/routers/digest.py:91"}, "properties": {"repobilityId": "99d8cb9142357596", "scanner": "scanner-primary", "fingerprint": "9ea3cea2a12b975c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/digest.py"}, "region": {"startLine": 91}}}]}, {"ruleId": "scanner-e6997fc7c2a91a24", "level": "error", "message": {"text": "FastAPI POST `send_now` without auth dependency \u2014 backend/routers/digest.py:131"}, "properties": {"repobilityId": "58ae44040c7358b3", "scanner": "scanner-primary", "fingerprint": "e6997fc7c2a91a24", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/digest.py"}, "region": {"startLine": 131}}}]}, {"ruleId": "scanner-f638522596797ef8", "level": "error", "message": {"text": "FastAPI POST `start_research` without auth dependency \u2014 backend/routers/research.py:20"}, "properties": {"repobilityId": "24c6003e108b00b3", "scanner": "scanner-primary", "fingerprint": "f638522596797ef8", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/research.py"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-a3a12b95a7478fcd", "level": "error", "message": {"text": "FastAPI POST `save_session_to_library` without auth dependency \u2014 backend/routers/research.py:86"}, "properties": {"repobilityId": "d3f887c73f8b9ba3", "scanner": "scanner-primary", "fingerprint": "a3a12b95a7478fcd", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/research.py"}, "region": {"startLine": 86}}}]}, {"ruleId": "scanner-e216894a21416e4d", "level": "error", "message": {"text": "FastAPI DELETE `delete_session` without auth dependency \u2014 backend/routers/research.py:128"}, "properties": {"repobilityId": "3e01e2c75f89a1bd", "scanner": "scanner-primary", "fingerprint": "e216894a21416e4d", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/research.py"}, "region": {"startLine": 128}}}]}, {"ruleId": "scanner-4b1ca6d80502db39", "level": "error", "message": {"text": "FastAPI DELETE `delete_reminder` without auth dependency \u2014 backend/routers/reminders.py:17"}, "properties": {"repobilityId": "aca755a720141b2d", "scanner": "scanner-primary", "fingerprint": "4b1ca6d80502db39", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/reminders.py"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-964c7f1c1ae6e4a7", "level": "error", "message": {"text": "FastAPI PUT `save_model_settings` without auth dependency \u2014 backend/routers/settings.py:46"}, "properties": {"repobilityId": "0f13a09b8180a268", "scanner": "scanner-primary", "fingerprint": "964c7f1c1ae6e4a7", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/settings.py"}, "region": {"startLine": 46}}}]}, {"ruleId": "scanner-e48ce27bb42a9797", "level": "error", "message": {"text": "FastAPI POST `upload_document` without auth dependency \u2014 backend/routers/documents.py:185"}, "properties": {"repobilityId": "3762f205b5e3f8aa", "scanner": "scanner-primary", "fingerprint": "e48ce27bb42a9797", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/documents.py"}, "region": {"startLine": 185}}}]}, {"ruleId": "scanner-ea8b425ab7936a70", "level": "error", "message": {"text": "FastAPI POST `ingest_url` without auth dependency \u2014 backend/routers/documents.py:225"}, "properties": {"repobilityId": "a352853775168ee6", "scanner": "scanner-primary", "fingerprint": "ea8b425ab7936a70", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/documents.py"}, "region": {"startLine": 225}}}]}, {"ruleId": "scanner-798dd12897d6f667", "level": "error", "message": {"text": "FastAPI POST `assign_folder` without auth dependency \u2014 backend/routers/documents.py:299"}, "properties": {"repobilityId": "fa91fad3e1c96e71", "scanner": "scanner-primary", "fingerprint": "798dd12897d6f667", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/documents.py"}, "region": {"startLine": 299}}}]}, {"ruleId": "scanner-d02aeb9a64e4cfb2", "level": "error", "message": {"text": "FastAPI POST `rename_folder` without auth dependency \u2014 backend/routers/documents.py:315"}, "properties": {"repobilityId": "cd13cba5428810f9", "scanner": "scanner-primary", "fingerprint": "d02aeb9a64e4cfb2", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/documents.py"}, "region": {"startLine": 315}}}]}, {"ruleId": "scanner-8cadd50b7de1e113", "level": "error", "message": {"text": "FastAPI DELETE `delete_document` without auth dependency \u2014 backend/routers/documents.py:333"}, "properties": {"repobilityId": "093347ec092f01fd", "scanner": "scanner-primary", "fingerprint": "8cadd50b7de1e113", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/documents.py"}, "region": {"startLine": 333}}}]}, {"ruleId": "scanner-e125452985810e41", "level": "error", "message": {"text": "FastAPI POST `ask_documents` without auth dependency \u2014 backend/routers/documents.py:356"}, "properties": {"repobilityId": "31831d92c01d4957", "scanner": "scanner-primary", "fingerprint": "e125452985810e41", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/documents.py"}, "region": {"startLine": 356}}}]}, {"ruleId": "scanner-d10c5de3452398b1", "level": "error", "message": {"text": "FastAPI POST `start_analysis` without auth dependency \u2014 backend/routers/analysis.py:15"}, "properties": {"repobilityId": "7553e14d8b0747da", "scanner": "scanner-primary", "fingerprint": "d10c5de3452398b1", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/analysis.py"}, "region": {"startLine": 15}}}]}, {"ruleId": "scanner-efb6774b3ea7909b", "level": "error", "message": {"text": "FastAPI DELETE `delete_analysis` without auth dependency \u2014 backend/routers/analysis.py:87"}, "properties": {"repobilityId": "2ba374436a81a4f7", "scanner": "scanner-primary", "fingerprint": "efb6774b3ea7909b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/routers/analysis.py"}, "region": {"startLine": 87}}}]}, {"ruleId": "scanner-9a42c0215252d31b", "level": "error", "message": {"text": "Dangling fetch: POST /api/research/start (frontend/src/lib/api.ts:83)"}, "properties": {"repobilityId": "f88612eff2cb9b93", "scanner": "scanner-primary", "fingerprint": "9a42c0215252d31b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-b4ecf0e9f30e5839", "level": "error", "message": {"text": "Dangling fetch: GET /api/research/ (frontend/src/lib/api.ts:87)"}, "properties": {"repobilityId": "6efc910428f0ebf4", "scanner": "scanner-primary", "fingerprint": "b4ecf0e9f30e5839", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7b56a44b0cb488a6", "level": "error", "message": {"text": "Dangling fetch: GET /api/research/${id} (frontend/src/lib/api.ts:88)"}, "properties": {"repobilityId": "b314986a477303a3", "scanner": "scanner-primary", "fingerprint": "7b56a44b0cb488a6", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-27192fbba6152d61", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/research/${id} (frontend/src/lib/api.ts:90)"}, "properties": {"repobilityId": "0d4296672882294f", "scanner": "scanner-primary", "fingerprint": "27192fbba6152d61", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-715dcf1947f80360", "level": "error", "message": {"text": "Dangling fetch: POST /api/research/${sessionId}/save-to-library (frontend/src/lib/api.ts:94)"}, "properties": {"repobilityId": "977846e47c55e9b8", "scanner": "scanner-primary", "fingerprint": "715dcf1947f80360", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-62b8cb1d32453ca7", "level": "error", "message": {"text": "Dangling fetch: POST /api/documents/ingest-url (frontend/src/lib/api.ts:110)"}, "properties": {"repobilityId": "1c1aee70f9fa0fad", "scanner": "scanner-primary", "fingerprint": "62b8cb1d32453ca7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-877cd736ac0b8e8d", "level": "error", "message": {"text": "Dangling fetch: GET /api/documents/${id} (frontend/src/lib/api.ts:116)"}, "properties": {"repobilityId": "8e1261bd7c504b14", "scanner": "scanner-primary", "fingerprint": "877cd736ac0b8e8d", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-688609a90fd386a8", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/documents/${id} (frontend/src/lib/api.ts:118)"}, "properties": {"repobilityId": "6916e12d02ab96ca", "scanner": "scanner-primary", "fingerprint": "688609a90fd386a8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-8ff1642eb9dc2686", "level": "error", "message": {"text": "Dangling fetch: POST /api/documents/assign-folder (frontend/src/lib/api.ts:120)"}, "properties": {"repobilityId": "6266d14ea843a7f6", "scanner": "scanner-primary", "fingerprint": "8ff1642eb9dc2686", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-8f67094f7ef25d95", "level": "error", "message": {"text": "Dangling fetch: POST /api/documents/rename-folder (frontend/src/lib/api.ts:125)"}, "properties": {"repobilityId": "b66bec39e5e79dcc", "scanner": "scanner-primary", "fingerprint": "8f67094f7ef25d95", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-80149cd02be330a2", "level": "error", "message": {"text": "Dangling fetch: POST /api/reports/draft (frontend/src/lib/api.ts:139)"}, "properties": {"repobilityId": "6860ff6972d5f280", "scanner": "scanner-primary", "fingerprint": "80149cd02be330a2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-24b71833513403ab", "level": "error", "message": {"text": "Dangling fetch: GET /api/reports/ (frontend/src/lib/api.ts:143)"}, "properties": {"repobilityId": "2a76861eba2a9dce", "scanner": "scanner-primary", "fingerprint": "24b71833513403ab", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-88925f3d414010ec", "level": "error", "message": {"text": "Dangling fetch: GET /api/reports/${id} (frontend/src/lib/api.ts:144)"}, "properties": {"repobilityId": "4bc83028e563d656", "scanner": "scanner-primary", "fingerprint": "88925f3d414010ec", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-93135ab4ac5c8c5e", "level": "error", "message": {"text": "Dangling fetch: PATCH /api/reports/${id} (frontend/src/lib/api.ts:146)"}, "properties": {"repobilityId": "e161f1b527ac9bb5", "scanner": "scanner-primary", "fingerprint": "93135ab4ac5c8c5e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-c96e64fe3d175b2b", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/reports/${id} (frontend/src/lib/api.ts:151)"}, "properties": {"repobilityId": "fcc6e1d543740405", "scanner": "scanner-primary", "fingerprint": "c96e64fe3d175b2b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-d432b3a3d053b79b", "level": "error", "message": {"text": "Dangling fetch: GET /api/analysis/ (frontend/src/lib/api.ts:157)"}, "properties": {"repobilityId": "5341ce69310319ec", "scanner": "scanner-primary", "fingerprint": "d432b3a3d053b79b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-b043edd673436ac4", "level": "error", "message": {"text": "Dangling fetch: GET /api/analysis/${id} (frontend/src/lib/api.ts:158)"}, "properties": {"repobilityId": "ca1ac87f160cb6c5", "scanner": "scanner-primary", "fingerprint": "b043edd673436ac4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ce97b31301de3312", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/analysis/${id} (frontend/src/lib/api.ts:160)"}, "properties": {"repobilityId": "451f31d1c00b6976", "scanner": "scanner-primary", "fingerprint": "ce97b31301de3312", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4840dc6cc9399119", "level": "error", "message": {"text": "Dangling fetch: GET /api/settings/models (frontend/src/lib/api.ts:165)"}, "properties": {"repobilityId": "7d1425075181d5ae", "scanner": "scanner-primary", "fingerprint": "4840dc6cc9399119", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-e4d7d5422861ed1a", "level": "error", "message": {"text": "Dangling fetch: PUT /api/settings/models (frontend/src/lib/api.ts:178)"}, "properties": {"repobilityId": "7d9ce2c8fb30777e", "scanner": "scanner-primary", "fingerprint": "e4d7d5422861ed1a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-747b23a077db0ff2", "level": "error", "message": {"text": "Dangling fetch: DELETE /api/reminders/${id} (frontend/src/lib/api.ts:196)"}, "properties": {"repobilityId": "95ec581570d4055d", "scanner": "scanner-primary", "fingerprint": "747b23a077db0ff2", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-6da592eebb52e3ef", "level": "error", "message": {"text": "Dangling fetch: GET /api/auth/status (frontend/src/lib/api.ts:200)"}, "properties": {"repobilityId": "bb7c5e5960876312", "scanner": "scanner-primary", "fingerprint": "6da592eebb52e3ef", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5825ea91d441c71f", "level": "error", "message": {"text": "Dangling fetch: POST /api/auth/login (frontend/src/lib/api.ts:202)"}, "properties": {"repobilityId": "56a9b5e30b6b9f8e", "scanner": "scanner-primary", "fingerprint": "5825ea91d441c71f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3bfd1e6fee22adf1", "level": "error", "message": {"text": "Dangling fetch: POST /api/digest/send-now (frontend/src/lib/api.ts:210)"}, "properties": {"repobilityId": "75715ce142b29a71", "scanner": "scanner-primary", "fingerprint": "3bfd1e6fee22adf1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-076d3b1bfd1c2796", "level": "error", "message": {"text": "Dangling fetch: GET /api/digest/status (frontend/src/lib/api.ts:217)"}, "properties": {"repobilityId": "e56d6730ee5066ee", "scanner": "scanner-primary", "fingerprint": "076d3b1bfd1c2796", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-b8033a4bf2293e9a", "level": "error", "message": {"text": "Dangling fetch: GET /api/digest/settings (frontend/src/lib/api.ts:228)"}, "properties": {"repobilityId": "d58eae68ee8d309d", "scanner": "scanner-primary", "fingerprint": "b8033a4bf2293e9a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-58382b84d4b162a0", "level": "error", "message": {"text": "Dangling fetch: PUT /api/digest/settings (frontend/src/lib/api.ts:245)"}, "properties": {"repobilityId": "52326d7d95117ce5", "scanner": "scanner-primary", "fingerprint": "58382b84d4b162a0", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-970eb92d6ec2bfaa", "level": "note", "message": {"text": "Unused endpoint: POST /generate"}, "properties": {"repobilityId": "29adac5e66ee2ee8", "scanner": "scanner-primary", "fingerprint": "970eb92d6ec2bfaa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7e30280ac6f566cd", "level": "note", "message": {"text": "Unused endpoint: GET /template/{report_type}"}, "properties": {"repobilityId": "d42f31d12f71ca78", "scanner": "scanner-primary", "fingerprint": "7e30280ac6f566cd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-29d17450d20db711", "level": "note", "message": {"text": "Unused endpoint: POST /draft"}, "properties": {"repobilityId": "5dd1038fd0f50baa", "scanner": "scanner-primary", "fingerprint": "29d17450d20db711", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "1d107575ae8702f8", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6f606e1e29a7ef82", "level": "note", "message": {"text": "Unused endpoint: GET /{report_id}"}, "properties": {"repobilityId": "15a1a871a0f78401", "scanner": "scanner-primary", "fingerprint": "6f606e1e29a7ef82", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bc72b2c1e1abc7b8", "level": "note", "message": {"text": "Unused endpoint: PATCH /{report_id}"}, "properties": {"repobilityId": "69b6730e50b65a8f", "scanner": "scanner-primary", "fingerprint": "bc72b2c1e1abc7b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8f44d37b218815ac", "level": "note", "message": {"text": "Unused endpoint: GET /{report_id}/export"}, "properties": {"repobilityId": "05b3217a5338ced6", "scanner": "scanner-primary", "fingerprint": "8f44d37b218815ac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-772e19875f5f1469", "level": "note", "message": {"text": "Unused endpoint: DELETE /{report_id}"}, "properties": {"repobilityId": "50349b2df9b58c19", "scanner": "scanner-primary", "fingerprint": "772e19875f5f1469", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "8b9d76c682d772e8", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a13a7e97aeacf55f", "level": "note", "message": {"text": "Unused endpoint: POST /start"}, "properties": {"repobilityId": "46f47c3c7774a60d", "scanner": "scanner-primary", "fingerprint": "a13a7e97aeacf55f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-da1da8bd83699e0b", "level": "note", "message": {"text": "Unused endpoint: GET /{debate_id}/stream"}, "properties": {"repobilityId": "88a3298c62707bc6", "scanner": "scanner-primary", "fingerprint": "da1da8bd83699e0b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9b6b3ebade0a4f9e", "level": "note", "message": {"text": "Unused endpoint: GET /{debate_id}"}, "properties": {"repobilityId": "271b8cb3ab95ffb3", "scanner": "scanner-primary", "fingerprint": "9b6b3ebade0a4f9e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a6f6a8cb58233691", "level": "note", "message": {"text": "Unused endpoint: DELETE /{debate_id}"}, "properties": {"repobilityId": "f0c047ac9aea939d", "scanner": "scanner-primary", "fingerprint": "a6f6a8cb58233691", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-512ccb0fd0b230ba", "level": "note", "message": {"text": "Unused endpoint: GET /settings"}, "properties": {"repobilityId": "9d5291770d2b3eb9", "scanner": "scanner-primary", "fingerprint": "512ccb0fd0b230ba", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1cf2ed60cbbf2375", "level": "note", "message": {"text": "Unused endpoint: PUT /settings"}, "properties": {"repobilityId": "f267f580374e89c6", "scanner": "scanner-primary", "fingerprint": "1cf2ed60cbbf2375", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d8be6d8780c450bb", "level": "note", "message": {"text": "Unused endpoint: POST /send-now"}, "properties": {"repobilityId": "e0dd8451314d55f6", "scanner": "scanner-primary", "fingerprint": "d8be6d8780c450bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3a3f32d20186df2d", "level": "note", "message": {"text": "Unused endpoint: GET /{session_id}/stream"}, "properties": {"repobilityId": "9117582211de1299", "scanner": "scanner-primary", "fingerprint": "3a3f32d20186df2d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-af24049c13127ae7", "level": "note", "message": {"text": "Unused endpoint: GET /{session_id}"}, "properties": {"repobilityId": "a5e905960497d20c", "scanner": "scanner-primary", "fingerprint": "af24049c13127ae7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-46a71b9e5675be00", "level": "note", "message": {"text": "Unused endpoint: POST /{session_id}/save-to-library"}, "properties": {"repobilityId": "282554d1f53c06ba", "scanner": "scanner-primary", "fingerprint": "46a71b9e5675be00", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-173ad25a6a1cb443", "level": "note", "message": {"text": "Unused endpoint: DELETE /{session_id}"}, "properties": {"repobilityId": "8961f372b61db04b", "scanner": "scanner-primary", "fingerprint": "173ad25a6a1cb443", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-83dd8a48703de15f", "level": "note", "message": {"text": "Unused endpoint: DELETE /{reminder_id}"}, "properties": {"repobilityId": "ee7562dbaa7768c2", "scanner": "scanner-primary", "fingerprint": "83dd8a48703de15f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2ab9bf5db6820af4", "level": "note", "message": {"text": "Unused endpoint: GET /models"}, "properties": {"repobilityId": "d15212473f299a75", "scanner": "scanner-primary", "fingerprint": "2ab9bf5db6820af4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7ca0a4ab49c30f35", "level": "note", "message": {"text": "Unused endpoint: PUT /models"}, "properties": {"repobilityId": "2e367802539ac77c", "scanner": "scanner-primary", "fingerprint": "7ca0a4ab49c30f35", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6236b283b79811b8", "level": "note", "message": {"text": "Unused endpoint: POST /upload"}, "properties": {"repobilityId": "0c682075274ff1e1", "scanner": "scanner-primary", "fingerprint": "6236b283b79811b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b4282e8f5dc08008", "level": "note", "message": {"text": "Unused endpoint: POST /ingest-url"}, "properties": {"repobilityId": "c30588bd95f27410", "scanner": "scanner-primary", "fingerprint": "b4282e8f5dc08008", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-14ca9451df2c5dcc", "level": "note", "message": {"text": "Unused endpoint: GET /{doc_id}"}, "properties": {"repobilityId": "72bcd7e9b1640b4b", "scanner": "scanner-primary", "fingerprint": "14ca9451df2c5dcc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e8f52efc7cf66b77", "level": "note", "message": {"text": "Unused endpoint: POST /assign-folder"}, "properties": {"repobilityId": "8577abab118d97ac", "scanner": "scanner-primary", "fingerprint": "e8f52efc7cf66b77", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0e1f788a818bccab", "level": "note", "message": {"text": "Unused endpoint: POST /rename-folder"}, "properties": {"repobilityId": "3c464c404850bdb8", "scanner": "scanner-primary", "fingerprint": "0e1f788a818bccab", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e96576fde6078449", "level": "note", "message": {"text": "Unused endpoint: DELETE /{doc_id}"}, "properties": {"repobilityId": "68debcba7fd20d3c", "scanner": "scanner-primary", "fingerprint": "e96576fde6078449", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8e1fadad2500f063", "level": "note", "message": {"text": "Unused endpoint: POST /ask"}, "properties": {"repobilityId": "73d771f5f09e3f71", "scanner": "scanner-primary", "fingerprint": "8e1fadad2500f063", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-26d3bb1589d06372", "level": "note", "message": {"text": "Unused endpoint: GET /{analysis_id}"}, "properties": {"repobilityId": "729c38a67fffa065", "scanner": "scanner-primary", "fingerprint": "26d3bb1589d06372", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9e91dee9605e46a9", "level": "note", "message": {"text": "Unused endpoint: GET /{analysis_id}/export"}, "properties": {"repobilityId": "0803f33b157f0a0f", "scanner": "scanner-primary", "fingerprint": "9e91dee9605e46a9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cf23a02b5866451b", "level": "note", "message": {"text": "Unused endpoint: DELETE /{analysis_id}"}, "properties": {"repobilityId": "4eb104093266f1ab", "scanner": "scanner-primary", "fingerprint": "cf23a02b5866451b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}