{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-4d135fcd3d1aaa50", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/github-connect.tsx:174", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/github-connect.tsx:174"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d8deba02398b1621", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/transcription-panel.tsx:85", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/transcription-panel.tsx:85"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c03d745dc701bda2", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/google-drive-connect.tsx:241", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/google-drive-connect.tsx:241"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8066ed9b9cf6d053", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/views/ChatTab.tsx:171", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/views/ChatTab.tsx:171"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-38e691ddd2b6b954", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/views/settings/ConnectionsTab.tsx:382", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/views/settings/ConnectionsTab.tsx:382"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c2e4175ee9fef6d4", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/views/settings/VaultTab.tsx:232", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/views/settings/VaultTab.tsx:232"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-54eafa974209d844", "name": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/views/settings/CostsTab.tsx:102", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/views/settings/CostsTab.tsx:102"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-72fd79796c1c2fd1", "name": "Stray `console.log` in TS/JS \u2014 packages/server/src/ingestQueue.ts:95", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/server/src/ingestQueue.ts:95"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-398acbc007e7ce75", "name": "Stray `console.log` in TS/JS \u2014 packages/server/src/transcribe.ts:194", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/server/src/transcribe.ts:194"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d005e5a34f8ea163", "name": "Stray `console.log` in TS/JS \u2014 packages/server/src/runtime.ts:347", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/server/src/runtime.ts:347"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-657d21074b6ab41f", "name": "Stray `console.log` in TS/JS \u2014 packages/server/src/main.ts:24", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/server/src/main.ts:24"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6855ccb1d3e3f599", "name": "Stray `console.log` in TS/JS \u2014 packages/server/src/app.ts:608", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/server/src/app.ts:608"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9db2dbf4591f983a", "name": "Stray `console.log` in TS/JS \u2014 packages/server/src/taskJobQueue.ts:80", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/server/src/taskJobQueue.ts:80"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9668f9173fedb0c5", "name": "Stray `console.log` in TS/JS \u2014 packages/server/src/testHarness.ts:68", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/server/src/testHarness.ts:68"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6df8b33b550889c4", "name": "Stray `console.log` in TS/JS \u2014 packages/core/src/cli.ts:106", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/core/src/cli.ts:106"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d63da3583b14afc0", "name": "Dockerfile runs as root: Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-835eae4c7f17a2f8", "name": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-48771ffe2767b2f2", "name": "Dockerfile runs as root: apps/site/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: apps/site/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d5c188687a36da32", "name": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5b47368a4740bd23", "name": "Docker base image is tag-pinned but not digest-pinned: nginx:alpine", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: nginx:alpine"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3a44a6ba7414614b", "name": "Dockerfile runs as root: services/x-mcp/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: services/x-mcp/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4d5d7527f8ec28ba", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd69fc03fe1738b6", "name": "Insecure pattern 'node_child_process' in scripts/backlog-monitor.mjs:25", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/backlog-monitor.mjs:25"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-61d9937e86a15f7d", "name": "Insecure pattern 'node_child_process' in scripts/fanout-codex.mjs:6", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/fanout-codex.mjs:6"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fd85bacffedf360e", "name": "Insecure pattern 'node_child_process' in packages/server/src/transcribe.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in packages/server/src/transcribe.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0a45925b626bacb3", "name": "Insecure pattern 'node_child_process' in packages/core/src/ops/search.ts:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in packages/core/src/ops/search.ts:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c902715ef34c50ef", "name": "Very large file: packages/core/src/llm/aisdk.ts (886 lines)", "shortDescription": {"text": "Very large file: packages/core/src/llm/aisdk.ts (886 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-482d2261cd0f01ce", "name": "Node manifest has dependencies but no lockfile: apps/site/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/site/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a9eb7dc7c6e3880", "name": "Node manifest has dependencies but no lockfile: apps/web/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b739f2f2be1d714d", "name": "Node manifest has dependencies but no lockfile: packages/server/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/server/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28e92806c0db3cd2", "name": "Node manifest has dependencies but no lockfile: packages/core/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/core/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 48 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 28 placeholder/mock markers across 15 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d79c4077342a7d0", "name": "Runtime service client appears to use placeholder configuration", "shortDescription": {"text": "Runtime service client appears to use placeholder configuration"}, "fullDescription": {"text": "A runtime source file appears to wire Supabase/Firebase/AI/payment-style clients to placeholder URLs, keys, or fallback values. In the Fable corpus this often means the UI/API shape is present while the backend service is not actually configured."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2c5f98b152cddb6d", "name": "Agent authority lacks a verifier contract: .claude/launch.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/launch.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e9299fdf25c27842", "name": "Commented-code block (5 lines) in scripts/backlog-monitor.mjs:9", "shortDescription": {"text": "Commented-code block (5 lines) in scripts/backlog-monitor.mjs:9"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-40fb9095d5e359ee", "name": "Commented-code block (6 lines) in scripts/fanout-codex.mjs:725", "shortDescription": {"text": "Commented-code block (6 lines) in scripts/fanout-codex.mjs:725"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-95accc9c4f6bf551", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/server/src/transcribe.ts:195", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/server/src/transcribe.ts:195"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ec64581ace75b5b6", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/server/src/githubApp.ts:61", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/server/src/githubApp.ts:61"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bf3abff3c3ef41d0", "name": "Commented-code block (5 lines) in packages/server/src/openrouterModels.ts:30", "shortDescription": {"text": "Commented-code block (5 lines) in packages/server/src/openrouterModels.ts:30"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-185ae2bafae1fb8d", "name": "Commented-code block (7 lines) in packages/server/src/app.ts:520", "shortDescription": {"text": "Commented-code block (7 lines) in packages/server/src/app.ts:520"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e64b6f5b2b78625a", "name": "Commented-code block (9 lines) in packages/server/src/whatsappGateway.ts:581", "shortDescription": {"text": "Commented-code block (9 lines) in packages/server/src/whatsappGateway.ts:581"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3419c0674502b102", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/core/src/backlog.ts:39", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/core/src/backlog.ts:39"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-411cb2ab8ba02a8c", "name": "Commented-code block (7 lines) in packages/core/src/taskingPolicy.ts:30", "shortDescription": {"text": "Commented-code block (7 lines) in packages/core/src/taskingPolicy.ts:30"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c15273508419db60", "name": "Commented-code block (5 lines) in packages/core/src/engine/engine.ts:114", "shortDescription": {"text": "Commented-code block (5 lines) in packages/core/src/engine/engine.ts:114"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-26420c179824d543", "name": "49 env vars used in code but missing from .env.example", "shortDescription": {"text": "49 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `ANTHROPIC_API_KEY`, `GH_TOKEN`, `GITHUB_TOKEN`, `GROQ_API_KEY`, `HOME`, `NODE_ENV`, `OPENAI_API_KEY`, `OPENROUTER_API_KEY` + 41 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a32e40e7c4aa6e60", "name": "Dangling fetch: POST /mcp (packages/server/test/health.test.ts:35)", "shortDescription": {"text": "Dangling fetch: POST /mcp (packages/server/test/health.test.ts:35)"}, "fullDescription": {"text": "`packages/server/test/health.test.ts:35` calls `POST /mcp` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/mcp`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4e6f02476dbbce9e", "name": "Dangling fetch: POST /mcp (packages/server/test/oauth.test.ts:48)", "shortDescription": {"text": "Dangling fetch: POST /mcp (packages/server/test/oauth.test.ts:48)"}, "fullDescription": {"text": "`packages/server/test/oauth.test.ts:48` calls `POST /mcp` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/mcp`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1b31e31a7f2e1495", "name": "Dangling fetch: POST /mcp (packages/server/test/oauth.test.ts:120)", "shortDescription": {"text": "Dangling fetch: POST /mcp (packages/server/test/oauth.test.ts:120)"}, "fullDescription": {"text": "`packages/server/test/oauth.test.ts:120` calls `POST /mcp` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/mcp`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bc09d803f7999de8", "name": "Dangling fetch: POST https://api.github.com/app-manifests/${encodeURIComponent(code)}/conversions (packages/server/src/g", "shortDescription": {"text": "Dangling fetch: POST https://api.github.com/app-manifests/${encodeURIComponent(code)}/conversions (packages/server/src/githubApp.ts:61)"}, "fullDescription": {"text": "`packages/server/src/githubApp.ts:61` calls `POST https://api.github.com/app-manifests/${encodeURIComponent(code)}/conversions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/app-manifests/<p>/conversions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1805edc699438356", "name": "Dangling fetch: POST https://api.github.com/app/installations/${installationId}/access_tokens (packages/server/src/githu", "shortDescription": {"text": "Dangling fetch: POST https://api.github.com/app/installations/${installationId}/access_tokens (packages/server/src/githubApp.ts:106)"}, "fullDescription": {"text": "`packages/server/src/githubApp.ts:106` calls `POST https://api.github.com/app/installations/${installationId}/access_tokens` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/app/installations/<p>/access_tokens`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-226e34ded8238c96", "name": "Dangling fetch: GET https://api.github.com/installation/repositories?per_page=100&page=${page} (packages/server/src/gith", "shortDescription": {"text": "Dangling fetch: GET https://api.github.com/installation/repositories?per_page=100&page=${page} (packages/server/src/githubApp.ts:134)"}, "fullDescription": {"text": "`packages/server/src/githubApp.ts:134` calls `GET https://api.github.com/installation/repositories?per_page=100&page=${page}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/installation/repositories`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3257fd4ec8d37f4a", "name": "Dangling fetch: GET https://api.github.com${path} (packages/server/src/githubApp.ts:233)", "shortDescription": {"text": "Dangling fetch: GET https://api.github.com${path} (packages/server/src/githubApp.ts:233)"}, "fullDescription": {"text": "`packages/server/src/githubApp.ts:233` calls `GET https://api.github.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a5f9d8264ec2941a", "name": "Dangling fetch: GET https://api.github.com${path} (packages/server/src/runtime.ts:170)", "shortDescription": {"text": "Dangling fetch: GET https://api.github.com${path} (packages/server/src/runtime.ts:170)"}, "fullDescription": {"text": "`packages/server/src/runtime.ts:170` calls `GET https://api.github.com${path}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-679501217821dcd9", "name": "Dangling fetch: GET https://api.github.com/repos/${repo} (packages/server/src/runtime.ts:384)", "shortDescription": {"text": "Dangling fetch: GET https://api.github.com/repos/${repo} (packages/server/src/runtime.ts:384)"}, "fullDescription": {"text": "`packages/server/src/runtime.ts:384` calls `GET https://api.github.com/repos/${repo}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/api.github.com/repos/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c45bbd30453077bb", "name": "Dangling fetch: GET /files (packages/server/src/drive.ts:142)", "shortDescription": {"text": "Dangling fetch: GET /files (packages/server/src/drive.ts:142)"}, "fullDescription": {"text": "`packages/server/src/drive.ts:142` calls `GET /files` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/files`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5f5ad218707fb7f3", "name": "Dangling fetch: GET /files/${encodeURIComponent(fileId)} (packages/server/src/drive.ts:155)", "shortDescription": {"text": "Dangling fetch: GET /files/${encodeURIComponent(fileId)} (packages/server/src/drive.ts:155)"}, "fullDescription": {"text": "`packages/server/src/drive.ts:155` calls `GET /files/${encodeURIComponent(fileId)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/files/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-45bbd6d9bfb5a7e3", "name": "Dangling fetch: GET /files/${encodeURIComponent(fileId)} (packages/server/src/drive.ts:161)", "shortDescription": {"text": "Dangling fetch: GET /files/${encodeURIComponent(fileId)} (packages/server/src/drive.ts:161)"}, "fullDescription": {"text": "`packages/server/src/drive.ts:161` calls `GET /files/${encodeURIComponent(fileId)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/files/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1ff31f44d38b2740", "name": "Dangling fetch: GET /files/${encodeURIComponent(fileId)}/export (packages/server/src/drive.ts:167)", "shortDescription": {"text": "Dangling fetch: GET /files/${encodeURIComponent(fileId)}/export (packages/server/src/drive.ts:167)"}, "fullDescription": {"text": "`packages/server/src/drive.ts:167` calls `GET /files/${encodeURIComponent(fileId)}/export` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/files/<p>/export`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e6778686b28597d5", "name": "Dangling fetch: GET /files/${encodeURIComponent(folderId)} (packages/server/src/drive.ts:173)", "shortDescription": {"text": "Dangling fetch: GET /files/${encodeURIComponent(folderId)} (packages/server/src/drive.ts:173)"}, "fullDescription": {"text": "`packages/server/src/drive.ts:173` calls `GET /files/${encodeURIComponent(folderId)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/files/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-b0c8f62c9e2e2647", "name": "Dangling fetch: POST /files (packages/server/src/drive.ts:185)", "shortDescription": {"text": "Dangling fetch: POST /files (packages/server/src/drive.ts:185)"}, "fullDescription": {"text": "`packages/server/src/drive.ts:185` calls `POST /files` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/files`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f83d4fdd8f7fe423", "name": "Dangling fetch: GET /files/${encodeURIComponent(fileId)} (packages/server/src/drive.ts:195)", "shortDescription": {"text": "Dangling fetch: GET /files/${encodeURIComponent(fileId)} (packages/server/src/drive.ts:195)"}, "fullDescription": {"text": "`packages/server/src/drive.ts:195` calls `GET /files/${encodeURIComponent(fileId)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/files/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-bd6c228599944045", "name": "Dangling fetch: GET /files/${encodeURIComponent(fileId)} (packages/server/src/drive.ts:197)", "shortDescription": {"text": "Dangling fetch: GET /files/${encodeURIComponent(fileId)} (packages/server/src/drive.ts:197)"}, "fullDescription": {"text": "`packages/server/src/drive.ts:197` calls `GET /files/${encodeURIComponent(fileId)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/files/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d5a39262ac205120", "name": "Unused endpoint: POST /api/auth/logout", "shortDescription": {"text": "Unused endpoint: POST /api/auth/logout"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/auth/logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8073f7bf758f6d0", "name": "Unused endpoint: USE /api/*", "shortDescription": {"text": "Unused endpoint: USE /api/*"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `USE /api/*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6520d32db325720c", "name": "Unused endpoint: POST /api/settings/test-github", "shortDescription": {"text": "Unused endpoint: POST /api/settings/test-github"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/settings/test-github` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0cfa3889bbe0b967", "name": "Unused endpoint: POST /api/settings/test-llm", "shortDescription": {"text": "Unused endpoint: POST /api/settings/test-llm"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/settings/test-llm` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b3907ca4b538990c", "name": "Unused endpoint: POST /api/settings/test-drive", "shortDescription": {"text": "Unused endpoint: POST /api/settings/test-drive"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/settings/test-drive` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f96d534a56f1d72", "name": "Unused endpoint: GET /api/transcription/status", "shortDescription": {"text": "Unused endpoint: GET /api/transcription/status"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/transcription/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fc1b277b0121f00f", "name": "Unused endpoint: GET /api/transcription/models", "shortDescription": {"text": "Unused endpoint: GET /api/transcription/models"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/transcription/models` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-acf20c76290d2c5e", "name": "Unused endpoint: GET /api/ingest/jobs", "shortDescription": {"text": "Unused endpoint: GET /api/ingest/jobs"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/ingest/jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4639279572afd0f9", "name": "Unused endpoint: POST /api/ingest/jobs/:id/retry", "shortDescription": {"text": "Unused endpoint: POST /api/ingest/jobs/:id/retry"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/ingest/jobs/:id/retry` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d2fa81ed13d28e8", "name": "Unused endpoint: POST /api/ingest/jobs/:id/cancel", "shortDescription": {"text": "Unused endpoint: POST /api/ingest/jobs/:id/cancel"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/ingest/jobs/:id/cancel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d6e854271dfe2f06", "name": "Unused endpoint: GET /api/tasks/jobs", "shortDescription": {"text": "Unused endpoint: GET /api/tasks/jobs"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/tasks/jobs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-65aaf12e035d3cf1", "name": "Unused endpoint: GET /api/tasks/jobs/:id", "shortDescription": {"text": "Unused endpoint: GET /api/tasks/jobs/:id"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/tasks/jobs/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-60e78a867a1a28c9", "name": "Unused endpoint: GET /api/usage", "shortDescription": {"text": "Unused endpoint: GET /api/usage"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/usage` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-47fd9d939fce100b", "name": "Unused endpoint: GET /api/telegram/status", "shortDescription": {"text": "Unused endpoint: GET /api/telegram/status"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/telegram/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-31c2deae76d68879", "name": "Unused endpoint: PUT /api/telegram/settings", "shortDescription": {"text": "Unused endpoint: PUT /api/telegram/settings"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `PUT /api/telegram/settings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f59f097b10c2bb3", "name": "Unused endpoint: POST /api/whatsapp/pair", "shortDescription": {"text": "Unused endpoint: POST /api/whatsapp/pair"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/whatsapp/pair` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7321666daf0ebe62", "name": "Unused endpoint: POST /api/whatsapp/disconnect", "shortDescription": {"text": "Unused endpoint: POST /api/whatsapp/disconnect"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/whatsapp/disconnect` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f2d0983504d1fed", "name": "Unused endpoint: GET /api/token", "shortDescription": {"text": "Unused endpoint: GET /api/token"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3c7fa5bc7fb600d6", "name": "Unused endpoint: POST /api/connections/revoke", "shortDescription": {"text": "Unused endpoint: POST /api/connections/revoke"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/connections/revoke` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6dccb2ca654ffc58", "name": "Unused endpoint: GET /api/vault", "shortDescription": {"text": "Unused endpoint: GET /api/vault"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/vault` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8251dbcba2d56355", "name": "Unused endpoint: POST /api/vault/sync", "shortDescription": {"text": "Unused endpoint: POST /api/vault/sync"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/vault/sync` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f7119a004ccea43d", "name": "Unused endpoint: POST /api/vault/reclone", "shortDescription": {"text": "Unused endpoint: POST /api/vault/reclone"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/vault/reclone` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-708229ec52744ff7", "name": "Unused endpoint: GET /api/vault/lint", "shortDescription": {"text": "Unused endpoint: GET /api/vault/lint"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/vault/lint` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1e15e342cb480b79", "name": "Unused endpoint: POST /api/vault/clean-slate", "shortDescription": {"text": "Unused endpoint: POST /api/vault/clean-slate"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/vault/clean-slate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-853429f6d13f6c04", "name": "Unused endpoint: GET /api/github/app/status", "shortDescription": {"text": "Unused endpoint: GET /api/github/app/status"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/github/app/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5a3fd51ea50b1b46", "name": "Unused endpoint: GET /api/github/app/callback", "shortDescription": {"text": "Unused endpoint: GET /api/github/app/callback"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/github/app/callback` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-df2653f9c8317d7f", "name": "Unused endpoint: GET /api/github/repos", "shortDescription": {"text": "Unused endpoint: GET /api/github/repos"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/github/repos` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b27cae650b33f7af", "name": "Unused endpoint: POST /api/github/app/disconnect", "shortDescription": {"text": "Unused endpoint: POST /api/github/app/disconnect"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/github/app/disconnect` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-77775a20faff184d", "name": "Unused endpoint: POST /api/store", "shortDescription": {"text": "Unused endpoint: POST /api/store"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/store` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-88ce831cd15f9c9c", "name": "Unused endpoint: POST /api/notify", "shortDescription": {"text": "Unused endpoint: POST /api/notify"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/notify` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e56d69b4f1ceed1e", "name": "Unused endpoint: GET /api/chat/history", "shortDescription": {"text": "Unused endpoint: GET /api/chat/history"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/chat/history` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0570b113beec4178", "name": "Unused endpoint: DELETE /api/chat", "shortDescription": {"text": "Unused endpoint: DELETE /api/chat"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `DELETE /api/chat` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-511c1c43ab4fc9cf", "name": "Unused endpoint: POST /api/work", "shortDescription": {"text": "Unused endpoint: POST /api/work"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `POST /api/work` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2205760646975fb8", "name": "Unused endpoint: GET /api/search", "shortDescription": {"text": "Unused endpoint: GET /api/search"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/search` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-edcc9ba55a2f486f", "name": "Unused endpoint: GET /api/note", "shortDescription": {"text": "Unused endpoint: GET /api/note"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `GET /api/note` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-efbc80312c5027b5", "name": "Unused endpoint: ALL /mcp", "shortDescription": {"text": "Unused endpoint: ALL /mcp"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `ALL /mcp` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3abf952b8d28d710", "name": "Unused endpoint: USE /*", "shortDescription": {"text": "Unused endpoint: USE /*"}, "fullDescription": {"text": "`packages/server/src/app.ts` declares `USE /*` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/23584"}, "properties": {"repository": "zenod-ai/zenod", "repoUrl": "https://github.com/zenod-ai/zenod", "branch": "main"}, "results": [{"ruleId": "scanner-4d135fcd3d1aaa50", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/github-connect.tsx:174"}, "properties": {"repobilityId": "2233a6b4557b66cd", "scanner": "scanner-primary", "fingerprint": "4d135fcd3d1aaa50", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-d8deba02398b1621", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/transcription-panel.tsx:85"}, "properties": {"repobilityId": "65e09c2a07d18f15", "scanner": "scanner-primary", "fingerprint": "d8deba02398b1621", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-c03d745dc701bda2", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/components/google-drive-connect.tsx:241"}, "properties": {"repobilityId": "adf864eb11ea3864", "scanner": "scanner-primary", "fingerprint": "c03d745dc701bda2", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-8066ed9b9cf6d053", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/views/ChatTab.tsx:171"}, "properties": {"repobilityId": "20c69119670dfddd", "scanner": "scanner-primary", "fingerprint": "8066ed9b9cf6d053", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-38e691ddd2b6b954", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/views/settings/ConnectionsTab.tsx:382"}, "properties": {"repobilityId": "8413511e31af97f4", "scanner": "scanner-primary", "fingerprint": "38e691ddd2b6b954", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-c2e4175ee9fef6d4", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/views/settings/VaultTab.tsx:232"}, "properties": {"repobilityId": "4e68d7c5b8a5635b", "scanner": "scanner-primary", "fingerprint": "c2e4175ee9fef6d4", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-54eafa974209d844", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 apps/web/src/views/settings/CostsTab.tsx:102"}, "properties": {"repobilityId": "042142653950c894", "scanner": "scanner-primary", "fingerprint": "54eafa974209d844", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-72fd79796c1c2fd1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/server/src/ingestQueue.ts:95"}, "properties": {"repobilityId": "863d321adca786e7", "scanner": "scanner-primary", "fingerprint": "72fd79796c1c2fd1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-398acbc007e7ce75", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/server/src/transcribe.ts:194"}, "properties": {"repobilityId": "f6d2e33ffd57dfa0", "scanner": "scanner-primary", "fingerprint": "398acbc007e7ce75", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d005e5a34f8ea163", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/server/src/runtime.ts:347"}, "properties": {"repobilityId": "709c7bbb4f5a8f55", "scanner": "scanner-primary", "fingerprint": "d005e5a34f8ea163", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-657d21074b6ab41f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/server/src/main.ts:24"}, "properties": {"repobilityId": "2c8f9bc915352ab0", "scanner": "scanner-primary", "fingerprint": "657d21074b6ab41f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6855ccb1d3e3f599", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/server/src/app.ts:608"}, "properties": {"repobilityId": "7306ea4edf235862", "scanner": "scanner-primary", "fingerprint": "6855ccb1d3e3f599", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9db2dbf4591f983a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/server/src/taskJobQueue.ts:80"}, "properties": {"repobilityId": "8c20da7c87c5551f", "scanner": "scanner-primary", "fingerprint": "9db2dbf4591f983a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9668f9173fedb0c5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/server/src/testHarness.ts:68"}, "properties": {"repobilityId": "bf74cc61a3069acf", "scanner": "scanner-primary", "fingerprint": "9668f9173fedb0c5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6df8b33b550889c4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/core/src/cli.ts:106"}, "properties": {"repobilityId": "488a17576ff7071f", "scanner": "scanner-primary", "fingerprint": "6df8b33b550889c4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d63da3583b14afc0", "level": "warning", "message": {"text": "Dockerfile runs as root: Dockerfile"}, "properties": {"repobilityId": "a2ed1bd120e507db", "scanner": "scanner-primary", "fingerprint": "d63da3583b14afc0", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-835eae4c7f17a2f8", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "properties": {"repobilityId": "fbf5c1e082efe5be", "scanner": "scanner-primary", "fingerprint": "835eae4c7f17a2f8", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 2}}}]}, {"ruleId": "scanner-835eae4c7f17a2f8", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "properties": {"repobilityId": "e1d34649daa99565", "scanner": "scanner-primary", "fingerprint": "835eae4c7f17a2f8", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 22}}}]}, {"ruleId": "scanner-835eae4c7f17a2f8", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "properties": {"repobilityId": "604ceee76c9b7800", "scanner": "scanner-primary", "fingerprint": "835eae4c7f17a2f8", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "Dockerfile"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-48771ffe2767b2f2", "level": "warning", "message": {"text": "Dockerfile runs as root: apps/site/Dockerfile"}, "properties": {"repobilityId": "60b6ea1aeeda7a27", "scanner": "scanner-primary", "fingerprint": "48771ffe2767b2f2", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-d5c188687a36da32", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-alpine"}, "properties": {"repobilityId": "6c749d71c63b961c", "scanner": "scanner-primary", "fingerprint": "d5c188687a36da32", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/site/Dockerfile"}, "region": {"startLine": 5}}}]}, {"ruleId": "scanner-5b47368a4740bd23", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: nginx:alpine"}, "properties": {"repobilityId": "a7ba1d41cfcb8c1f", "scanner": "scanner-primary", "fingerprint": "5b47368a4740bd23", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/site/Dockerfile"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-3a44a6ba7414614b", "level": "warning", "message": {"text": "Dockerfile runs as root: services/x-mcp/Dockerfile"}, "properties": {"repobilityId": "a6e51b17baa02660", "scanner": "scanner-primary", "fingerprint": "3a44a6ba7414614b", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-4d5d7527f8ec28ba", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "ba72fa80f867f168", "scanner": "scanner-primary", "fingerprint": "4d5d7527f8ec28ba", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "services/x-mcp/Dockerfile"}, "region": {"startLine": 12}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-cd69fc03fe1738b6", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/backlog-monitor.mjs:25"}, "properties": {"repobilityId": "a44e0aae36b39b64", "scanner": "scanner-primary", "fingerprint": "cd69fc03fe1738b6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/backlog-monitor.mjs"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-61d9937e86a15f7d", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/fanout-codex.mjs:6"}, "properties": {"repobilityId": "ebe68bb611682ced", "scanner": "scanner-primary", "fingerprint": "61d9937e86a15f7d", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/fanout-codex.mjs"}, "region": {"startLine": 6}}}]}, {"ruleId": "scanner-fd85bacffedf360e", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in packages/server/src/transcribe.ts:1"}, "properties": {"repobilityId": "be620fcb784e5080", "scanner": "scanner-primary", "fingerprint": "fd85bacffedf360e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/server/src/transcribe.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0a45925b626bacb3", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in packages/core/src/ops/search.ts:1"}, "properties": {"repobilityId": "7e8e86d6f53825a1", "scanner": "scanner-primary", "fingerprint": "0a45925b626bacb3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/src/ops/search.ts"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c902715ef34c50ef", "level": "note", "message": {"text": "Very large file: packages/core/src/llm/aisdk.ts (886 lines)"}, "properties": {"repobilityId": "c84d7c3ed4a500da", "scanner": "scanner-primary", "fingerprint": "c902715ef34c50ef", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-482d2261cd0f01ce", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/site/package.json"}, "properties": {"repobilityId": "c3d7a4cdb0728e9e", "scanner": "scanner-primary", "fingerprint": "482d2261cd0f01ce", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/site/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4a9eb7dc7c6e3880", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "properties": {"repobilityId": "6c1704bf24cf19ac", "scanner": "scanner-primary", "fingerprint": "4a9eb7dc7c6e3880", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b739f2f2be1d714d", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/server/package.json"}, "properties": {"repobilityId": "d7cb4fafc3b292b2", "scanner": "scanner-primary", "fingerprint": "b739f2f2be1d714d", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/server/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-28e92806c0db3cd2", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/core/package.json"}, "properties": {"repobilityId": "8640e46be7e3f9b2", "scanner": "scanner-primary", "fingerprint": "28e92806c0db3cd2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "49006d4158eb103c", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "5f9cbbb97ac94ade", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-9d79c4077342a7d0", "level": "warning", "message": {"text": "Runtime service client appears to use placeholder configuration"}, "properties": {"repobilityId": "885bfb1672e8d963", "scanner": "scanner-primary", "fingerprint": "9d79c4077342a7d0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "runtime-config", "service-client", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "db76b348545be86f", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "47989fa38c8a3e2f", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "3559841200e96348", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "c73dfd2bbf7b6bb8", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-2c5f98b152cddb6d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/launch.json"}, "properties": {"repobilityId": "0de48c0f4ab303d8", "scanner": "scanner-primary", "fingerprint": "2c5f98b152cddb6d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/launch.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e9299fdf25c27842", "level": "none", "message": {"text": "Commented-code block (5 lines) in scripts/backlog-monitor.mjs:9"}, "properties": {"repobilityId": "3f344cf2d235c730", "scanner": "scanner-primary", "fingerprint": "e9299fdf25c27842", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-40fb9095d5e359ee", "level": "none", "message": {"text": "Commented-code block (6 lines) in scripts/fanout-codex.mjs:725"}, "properties": {"repobilityId": "f33a0f39c3812a58", "scanner": "scanner-primary", "fingerprint": "40fb9095d5e359ee", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-95accc9c4f6bf551", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/server/src/transcribe.ts:195"}, "properties": {"repobilityId": "29d84eca47cf54d8", "scanner": "scanner-primary", "fingerprint": "95accc9c4f6bf551", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ec64581ace75b5b6", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/server/src/githubApp.ts:61"}, "properties": {"repobilityId": "12e22e5cb903805c", "scanner": "scanner-primary", "fingerprint": "ec64581ace75b5b6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-bf3abff3c3ef41d0", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/server/src/openrouterModels.ts:30"}, "properties": {"repobilityId": "bebf13d6b81efd15", "scanner": "scanner-primary", "fingerprint": "bf3abff3c3ef41d0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-185ae2bafae1fb8d", "level": "none", "message": {"text": "Commented-code block (7 lines) in packages/server/src/app.ts:520"}, "properties": {"repobilityId": "aa8c6b1bc4f7eec9", "scanner": "scanner-primary", "fingerprint": "185ae2bafae1fb8d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e64b6f5b2b78625a", "level": "none", "message": {"text": "Commented-code block (9 lines) in packages/server/src/whatsappGateway.ts:581"}, "properties": {"repobilityId": "8332ee784131e205", "scanner": "scanner-primary", "fingerprint": "e64b6f5b2b78625a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3419c0674502b102", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/core/src/backlog.ts:39"}, "properties": {"repobilityId": "ddac5f1b30c6a82a", "scanner": "scanner-primary", "fingerprint": "3419c0674502b102", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-411cb2ab8ba02a8c", "level": "none", "message": {"text": "Commented-code block (7 lines) in packages/core/src/taskingPolicy.ts:30"}, "properties": {"repobilityId": "9e7324dc4280f9e8", "scanner": "scanner-primary", "fingerprint": "411cb2ab8ba02a8c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c15273508419db60", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/core/src/engine/engine.ts:114"}, "properties": {"repobilityId": "5480030782d2498b", "scanner": "scanner-primary", "fingerprint": "c15273508419db60", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-26420c179824d543", "level": "note", "message": {"text": "49 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "804c38b408877986", "scanner": "scanner-primary", "fingerprint": "26420c179824d543", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-a32e40e7c4aa6e60", "level": "error", "message": {"text": "Dangling fetch: POST /mcp (packages/server/test/health.test.ts:35)"}, "properties": {"repobilityId": "03a4e39f18b609d5", "scanner": "scanner-primary", "fingerprint": "a32e40e7c4aa6e60", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4e6f02476dbbce9e", "level": "error", "message": {"text": "Dangling fetch: POST /mcp (packages/server/test/oauth.test.ts:48)"}, "properties": {"repobilityId": "b38ab23bb7ee92f6", "scanner": "scanner-primary", "fingerprint": "4e6f02476dbbce9e", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-1b31e31a7f2e1495", "level": "error", "message": {"text": "Dangling fetch: POST /mcp (packages/server/test/oauth.test.ts:120)"}, "properties": {"repobilityId": "e2b0eaf02a913e4b", "scanner": "scanner-primary", "fingerprint": "1b31e31a7f2e1495", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-bc09d803f7999de8", "level": "error", "message": {"text": "Dangling fetch: POST https://api.github.com/app-manifests/${encodeURIComponent(code)}/conversions (packages/server/src/githubApp.ts:61)"}, "properties": {"repobilityId": "473a2b3fa5302851", "scanner": "scanner-primary", "fingerprint": "bc09d803f7999de8", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-1805edc699438356", "level": "error", "message": {"text": "Dangling fetch: POST https://api.github.com/app/installations/${installationId}/access_tokens (packages/server/src/githubApp.ts:106)"}, "properties": {"repobilityId": "2edcea7f5501cb98", "scanner": "scanner-primary", "fingerprint": "1805edc699438356", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-226e34ded8238c96", "level": "error", "message": {"text": "Dangling fetch: GET https://api.github.com/installation/repositories?per_page=100&page=${page} (packages/server/src/githubApp.ts:134)"}, "properties": {"repobilityId": "54644ec6ba8b94b9", "scanner": "scanner-primary", "fingerprint": "226e34ded8238c96", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-3257fd4ec8d37f4a", "level": "error", "message": {"text": "Dangling fetch: GET https://api.github.com${path} (packages/server/src/githubApp.ts:233)"}, "properties": {"repobilityId": "16a8c46de00bbd0d", "scanner": "scanner-primary", "fingerprint": "3257fd4ec8d37f4a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a5f9d8264ec2941a", "level": "error", "message": {"text": "Dangling fetch: GET https://api.github.com${path} (packages/server/src/runtime.ts:170)"}, "properties": {"repobilityId": "edbadb66e237f680", "scanner": "scanner-primary", "fingerprint": "a5f9d8264ec2941a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-679501217821dcd9", "level": "error", "message": {"text": "Dangling fetch: GET https://api.github.com/repos/${repo} (packages/server/src/runtime.ts:384)"}, "properties": {"repobilityId": "41852f5977cca5a2", "scanner": "scanner-primary", "fingerprint": "679501217821dcd9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-c45bbd30453077bb", "level": "error", "message": {"text": "Dangling fetch: GET /files (packages/server/src/drive.ts:142)"}, "properties": {"repobilityId": "3acb2272a79eea07", "scanner": "scanner-primary", "fingerprint": "c45bbd30453077bb", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5f5ad218707fb7f3", "level": "error", "message": {"text": "Dangling fetch: GET /files/${encodeURIComponent(fileId)} (packages/server/src/drive.ts:155)"}, "properties": {"repobilityId": "c56141c4989cb377", "scanner": "scanner-primary", "fingerprint": "5f5ad218707fb7f3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-45bbd6d9bfb5a7e3", "level": "error", "message": {"text": "Dangling fetch: GET /files/${encodeURIComponent(fileId)} (packages/server/src/drive.ts:161)"}, "properties": {"repobilityId": "2067eb7943fccd49", "scanner": "scanner-primary", "fingerprint": "45bbd6d9bfb5a7e3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-1ff31f44d38b2740", "level": "error", "message": {"text": "Dangling fetch: GET /files/${encodeURIComponent(fileId)}/export (packages/server/src/drive.ts:167)"}, "properties": {"repobilityId": "8f003ae49d5bfa69", "scanner": "scanner-primary", "fingerprint": "1ff31f44d38b2740", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-e6778686b28597d5", "level": "error", "message": {"text": "Dangling fetch: GET /files/${encodeURIComponent(folderId)} (packages/server/src/drive.ts:173)"}, "properties": {"repobilityId": "6e4e5ce05a2b4c62", "scanner": "scanner-primary", "fingerprint": "e6778686b28597d5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-b0c8f62c9e2e2647", "level": "error", "message": {"text": "Dangling fetch: POST /files (packages/server/src/drive.ts:185)"}, "properties": {"repobilityId": "2a9a0ee0bf22bb31", "scanner": "scanner-primary", "fingerprint": "b0c8f62c9e2e2647", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-f83d4fdd8f7fe423", "level": "error", "message": {"text": "Dangling fetch: GET /files/${encodeURIComponent(fileId)} (packages/server/src/drive.ts:195)"}, "properties": {"repobilityId": "4f6a4fc192351442", "scanner": "scanner-primary", "fingerprint": "f83d4fdd8f7fe423", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-bd6c228599944045", "level": "error", "message": {"text": "Dangling fetch: GET /files/${encodeURIComponent(fileId)} (packages/server/src/drive.ts:197)"}, "properties": {"repobilityId": "84b236a6bdf301b1", "scanner": "scanner-primary", "fingerprint": "bd6c228599944045", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-d5a39262ac205120", "level": "note", "message": {"text": "Unused endpoint: POST /api/auth/logout"}, "properties": {"repobilityId": "eafb5b97c8e7933e", "scanner": "scanner-primary", "fingerprint": "d5a39262ac205120", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b8073f7bf758f6d0", "level": "note", "message": {"text": "Unused endpoint: USE /api/*"}, "properties": {"repobilityId": "0bbe568da4b4d3f9", "scanner": "scanner-primary", "fingerprint": "b8073f7bf758f6d0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6520d32db325720c", "level": "note", "message": {"text": "Unused endpoint: POST /api/settings/test-github"}, "properties": {"repobilityId": "e8911878985b1671", "scanner": "scanner-primary", "fingerprint": "6520d32db325720c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0cfa3889bbe0b967", "level": "note", "message": {"text": "Unused endpoint: POST /api/settings/test-llm"}, "properties": {"repobilityId": "a2983199272e7eed", "scanner": "scanner-primary", "fingerprint": "0cfa3889bbe0b967", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b3907ca4b538990c", "level": "note", "message": {"text": "Unused endpoint: POST /api/settings/test-drive"}, "properties": {"repobilityId": "f7d33afecddcd7a2", "scanner": "scanner-primary", "fingerprint": "b3907ca4b538990c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2f96d534a56f1d72", "level": "note", "message": {"text": "Unused endpoint: GET /api/transcription/status"}, "properties": {"repobilityId": "3afcf7d662f17ddd", "scanner": "scanner-primary", "fingerprint": "2f96d534a56f1d72", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fc1b277b0121f00f", "level": "note", "message": {"text": "Unused endpoint: GET /api/transcription/models"}, "properties": {"repobilityId": "95e5081b3b77dcf9", "scanner": "scanner-primary", "fingerprint": "fc1b277b0121f00f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-acf20c76290d2c5e", "level": "note", "message": {"text": "Unused endpoint: GET /api/ingest/jobs"}, "properties": {"repobilityId": "483a2ded2fec4734", "scanner": "scanner-primary", "fingerprint": "acf20c76290d2c5e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4639279572afd0f9", "level": "note", "message": {"text": "Unused endpoint: POST /api/ingest/jobs/:id/retry"}, "properties": {"repobilityId": "38379f12de60e8a1", "scanner": "scanner-primary", "fingerprint": "4639279572afd0f9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6d2fa81ed13d28e8", "level": "note", "message": {"text": "Unused endpoint: POST /api/ingest/jobs/:id/cancel"}, "properties": {"repobilityId": "0569b9560b6ace88", "scanner": "scanner-primary", "fingerprint": "6d2fa81ed13d28e8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d6e854271dfe2f06", "level": "note", "message": {"text": "Unused endpoint: GET /api/tasks/jobs"}, "properties": {"repobilityId": "c9be11403dd0c256", "scanner": "scanner-primary", "fingerprint": "d6e854271dfe2f06", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-65aaf12e035d3cf1", "level": "note", "message": {"text": "Unused endpoint: GET /api/tasks/jobs/:id"}, "properties": {"repobilityId": "e6448ce93e894b91", "scanner": "scanner-primary", "fingerprint": "65aaf12e035d3cf1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-60e78a867a1a28c9", "level": "note", "message": {"text": "Unused endpoint: GET /api/usage"}, "properties": {"repobilityId": "900c86f2a4abf08a", "scanner": "scanner-primary", "fingerprint": "60e78a867a1a28c9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-47fd9d939fce100b", "level": "note", "message": {"text": "Unused endpoint: GET /api/telegram/status"}, "properties": {"repobilityId": "97e9449c807d81cc", "scanner": "scanner-primary", "fingerprint": "47fd9d939fce100b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-31c2deae76d68879", "level": "note", "message": {"text": "Unused endpoint: PUT /api/telegram/settings"}, "properties": {"repobilityId": "cc30ac839c31613f", "scanner": "scanner-primary", "fingerprint": "31c2deae76d68879", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7f59f097b10c2bb3", "level": "note", "message": {"text": "Unused endpoint: POST /api/whatsapp/pair"}, "properties": {"repobilityId": "5b6a037df221f14d", "scanner": "scanner-primary", "fingerprint": "7f59f097b10c2bb3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7321666daf0ebe62", "level": "note", "message": {"text": "Unused endpoint: POST /api/whatsapp/disconnect"}, "properties": {"repobilityId": "06d49f9c7bafd39b", "scanner": "scanner-primary", "fingerprint": "7321666daf0ebe62", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2f2d0983504d1fed", "level": "note", "message": {"text": "Unused endpoint: GET /api/token"}, "properties": {"repobilityId": "94e291703a133606", "scanner": "scanner-primary", "fingerprint": "2f2d0983504d1fed", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3c7fa5bc7fb600d6", "level": "note", "message": {"text": "Unused endpoint: POST /api/connections/revoke"}, "properties": {"repobilityId": "b333bc9bff4eb6d1", "scanner": "scanner-primary", "fingerprint": "3c7fa5bc7fb600d6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6dccb2ca654ffc58", "level": "note", "message": {"text": "Unused endpoint: GET /api/vault"}, "properties": {"repobilityId": "f50199e8df65d63b", "scanner": "scanner-primary", "fingerprint": "6dccb2ca654ffc58", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8251dbcba2d56355", "level": "note", "message": {"text": "Unused endpoint: POST /api/vault/sync"}, "properties": {"repobilityId": "42792687739a6574", "scanner": "scanner-primary", "fingerprint": "8251dbcba2d56355", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f7119a004ccea43d", "level": "note", "message": {"text": "Unused endpoint: POST /api/vault/reclone"}, "properties": {"repobilityId": "a5a6fde02a5d50a7", "scanner": "scanner-primary", "fingerprint": "f7119a004ccea43d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-708229ec52744ff7", "level": "note", "message": {"text": "Unused endpoint: GET /api/vault/lint"}, "properties": {"repobilityId": "365c3ce7ffcd83d0", "scanner": "scanner-primary", "fingerprint": "708229ec52744ff7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1e15e342cb480b79", "level": "note", "message": {"text": "Unused endpoint: POST /api/vault/clean-slate"}, "properties": {"repobilityId": "76f49a949a6b1c9a", "scanner": "scanner-primary", "fingerprint": "1e15e342cb480b79", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-853429f6d13f6c04", "level": "note", "message": {"text": "Unused endpoint: GET /api/github/app/status"}, "properties": {"repobilityId": "4436e7ccd37be177", "scanner": "scanner-primary", "fingerprint": "853429f6d13f6c04", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5a3fd51ea50b1b46", "level": "note", "message": {"text": "Unused endpoint: GET /api/github/app/callback"}, "properties": {"repobilityId": "c45463b5d65482a2", "scanner": "scanner-primary", "fingerprint": "5a3fd51ea50b1b46", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-df2653f9c8317d7f", "level": "note", "message": {"text": "Unused endpoint: GET /api/github/repos"}, "properties": {"repobilityId": "a76e6cf8fac8e1b2", "scanner": "scanner-primary", "fingerprint": "df2653f9c8317d7f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b27cae650b33f7af", "level": "note", "message": {"text": "Unused endpoint: POST /api/github/app/disconnect"}, "properties": {"repobilityId": "5fcc8077102f5d54", "scanner": "scanner-primary", "fingerprint": "b27cae650b33f7af", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-77775a20faff184d", "level": "note", "message": {"text": "Unused endpoint: POST /api/store"}, "properties": {"repobilityId": "d33470a3f220f621", "scanner": "scanner-primary", "fingerprint": "77775a20faff184d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-88ce831cd15f9c9c", "level": "note", "message": {"text": "Unused endpoint: POST /api/notify"}, "properties": {"repobilityId": "16e3d7d8bbd0be61", "scanner": "scanner-primary", "fingerprint": "88ce831cd15f9c9c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e56d69b4f1ceed1e", "level": "note", "message": {"text": "Unused endpoint: GET /api/chat/history"}, "properties": {"repobilityId": "0e40c572ae132a96", "scanner": "scanner-primary", "fingerprint": "e56d69b4f1ceed1e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0570b113beec4178", "level": "note", "message": {"text": "Unused endpoint: DELETE /api/chat"}, "properties": {"repobilityId": "e22744514445ff75", "scanner": "scanner-primary", "fingerprint": "0570b113beec4178", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-511c1c43ab4fc9cf", "level": "note", "message": {"text": "Unused endpoint: POST /api/work"}, "properties": {"repobilityId": "485d16f9edd19af7", "scanner": "scanner-primary", "fingerprint": "511c1c43ab4fc9cf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2205760646975fb8", "level": "note", "message": {"text": "Unused endpoint: GET /api/search"}, "properties": {"repobilityId": "19665eccaf68ae35", "scanner": "scanner-primary", "fingerprint": "2205760646975fb8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-edcc9ba55a2f486f", "level": "note", "message": {"text": "Unused endpoint: GET /api/note"}, "properties": {"repobilityId": "0e02a67cbf2f118d", "scanner": "scanner-primary", "fingerprint": "edcc9ba55a2f486f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-efbc80312c5027b5", "level": "note", "message": {"text": "Unused endpoint: ALL /mcp"}, "properties": {"repobilityId": "aef5bae2649014e9", "scanner": "scanner-primary", "fingerprint": "efbc80312c5027b5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3abf952b8d28d710", "level": "note", "message": {"text": "Unused endpoint: USE /*"}, "properties": {"repobilityId": "dc411cc51d72613c", "scanner": "scanner-primary", "fingerprint": "3abf952b8d28d710", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}