{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "foundry_assumption_check", "name": "Foundry mined assumption checks: TioCristian007/SkyFinance", "shortDescription": {"text": "Foundry mined assumption checks: TioCristian007/SkyFinance"}, "fullDescription": {"text": "Comment chain pattern product: assumption_checks\nRepo: TioCristian007/SkyFinance\nThread: TioCristian007/SkyFinance#1\nOutcome: ambiguous_needs_more_evidence\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_weak_supervision, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: TioCristian007/SkyFinance#1\nRepo: TioCristian007/SkyFinance\nThread label: thread_has_human_issue_and_fix_context\nOutcome: ambiguous_needs_more_evidence\nComment count: 1\nLinked commit count: 3\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 2\nLabels: {'security_auth_secret': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'api_or_backend': 2}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-1d6398619ee40928\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"security_auth_secret\",\n    \"polarity"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "medium", "confidence": 0.62, "cwe": "", "owasp": ""}}, {"id": "foundry_auth_guardrail_gap", "name": "Foundry mined security auth guardrail gaps: TioCristian007/SkyFinance", "shortDescription": {"text": "Foundry mined security auth guardrail gaps: TioCristian007/SkyFinance"}, "fullDescription": {"text": "Graph query export: Security/auth changes without enough guardrails\nQuery id: security_auth_guardrail_gaps\nQuery type: motif_query\nIntent: Assumption-check security/auth examples requiring stronger tests or CI.\nMotif: security_auth_without_guardrails\nTraining usage: assumption_check\nGraph gold label: weak_supervision_needs_review\nRepo: TioCristian007/SkyFinance\nThread: TioCristian007/SkyFinance#1\nEvidence:\nGraph motif: Security/auth change without enough guardrails\nMotif id: security_auth_without_guardrails\nPolarity: bad\nTraining usage: assumption_check\nSeverity: critical\nRepo: TioCristian007/SkyFinance\nThread: TioCristian007/SkyFinance#1\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: TioCristian007/SkyFinance#1\nRepo: TioCristian007/SkyFinance\nIssue/PR number: 1\nGraph consistency label: weak_supervision_needs_review\nNodes: 14\nEdges: 20\nNode types: {'commit': 3, 'link_quality': 3, 'pr_file': 2, 'thread': 1, 'repo': 1, 'co"}, "properties": {"scanner": "foundry_dataset", "category": "auth", "severity": "critical", "confidence": 0.78, "cwe": "", "owasp": ""}}, {"id": "scanner-253ce331a7701def", "name": "Possibly dead Python function: capabilities", "shortDescription": {"text": "Possibly dead Python function: capabilities"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ddd73137c8634a9e", "name": "Possibly dead Python function: require_user_id", "shortDescription": {"text": "Possibly dead Python function: require_user_id"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2acf7869693b0c78", "name": "Possibly dead Python function: startup", "shortDescription": {"text": "Possibly dead Python function: startup"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-56fa188b1ef763bf", "name": "Possibly dead Python function: shutdown", "shortDescription": {"text": "Possibly dead Python function: shutdown"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-83d20356e46485ff", "name": "Possibly dead Python function: capabilities", "shortDescription": {"text": "Possibly dead Python function: capabilities"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6baf76586a4c1688", "name": "Possibly dead Python function: capture_request", "shortDescription": {"text": "Possibly dead Python function: capture_request"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a5bdaa4228f7d0b2", "name": "Possibly dead Python function: capabilities", "shortDescription": {"text": "Possibly dead Python function: capabilities"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4b6b2add35a34f79", "name": "Possibly dead Python function: capabilities", "shortDescription": {"text": "Possibly dead Python function: capabilities"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c053ca75d58679e2", "name": "Possibly dead Python function: complete_challenge", "shortDescription": {"text": "Possibly dead Python function: complete_challenge"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-87cc86b94378ebe2", "name": "Stray `console.log` in TS/JS \u2014 frontend/src/components/BankConnect.jsx:266", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/components/BankConnect.jsx:266"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8f34620d6cae87d", "name": "Stray `console.log` in TS/JS \u2014 frontend/src/services/api.js:31", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/services/api.js:31"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0d93460c6b71dfe6", "name": "Stray `console.log` in TS/JS \u2014 backend/server.js:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/server.js:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f8252f32451ca3e", "name": "Stray `console.log` in TS/JS \u2014 backend/scripts/runScheduledSync.js:31", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/scripts/runScheduledSync.js:31"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-257a35f156d54202", "name": "Stray `console.log` in TS/JS \u2014 backend/services/encryptionService.js:102", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/encryptionService.js:102"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5cb70b9a377c4826", "name": "Stray `console.log` in TS/JS \u2014 backend/services/categorizerService.js:231", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/categorizerService.js:231"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-942b38bee0a7cec2", "name": "TODO/FIXME marker in shipping code \u2014 backend/services/financeService.js:280", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 backend/services/financeService.js:280"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ae532b1b249cf5e9", "name": "Stray `console.log` in TS/JS \u2014 backend/services/schedulerService.js:63", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/schedulerService.js:63"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cde49217ddc8ca5b", "name": "Stray `console.log` in TS/JS \u2014 backend/services/categorizationQueueService.js:71", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/categorizationQueueService.js:71"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2bb7895d65aa573e", "name": "Stray `console.log` in TS/JS \u2014 backend/services/ariaService.js:317", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/ariaService.js:317"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f931d60e61a1ad34", "name": "Stray `console.log` in TS/JS \u2014 backend/services/bankSyncService.js:55", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/bankSyncService.js:55"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8c5495f9fedd0a3a", "name": "Dockerfile runs as root: backend-python/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: backend-python/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-09c9f766859045a7", "name": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f66ad88286ca30a", "name": "Dockerfile runs as root: backend/Dockerfile", "shortDescription": {"text": "Dockerfile runs as root: backend/Dockerfile"}, "fullDescription": {"text": "No non-root USER set. Containers running as root expand the blast radius of any vulnerability inside the image."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e5063295643aafac", "name": "Docker base image is tag-pinned but not digest-pinned: node:22-slim", "shortDescription": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-slim"}, "fullDescription": {"text": "Container tags can be retagged upstream. Pin production base images to a reviewed digest (`image@sha256:...`) when reproducibility and supply-chain integrity matter."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43a91666ca33b974", "name": "Insecure pattern 'direct_innerhtml_assignment' in frontend/src/Sky.jsx:1910", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in frontend/src/Sky.jsx:1910"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-777df33a942bc1c6", "name": "Insecure pattern 'insert_adjacent_html' in frontend/src/Sky.jsx:163", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in frontend/src/Sky.jsx:163"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1787fd13f9d48bf8", "name": "Insecure pattern 'insert_adjacent_html' in frontend/src/components/BankConnect.jsx:77", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in frontend/src/components/BankConnect.jsx:77"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f37697bf1fa69215", "name": "Insecure pattern 'insert_adjacent_html' in frontend/src/components/AuthScreen.jsx:106", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in frontend/src/components/AuthScreen.jsx:106"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b334aba343a4e5b2", "name": "Possible secret in backend-python/src/sky/ingestion/contracts.py", "shortDescription": {"text": "Possible secret in backend-python/src/sky/ingestion/contracts.py"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-e9b96784343a9627", "name": "Very large file: frontend/src/Sky.jsx (1991 lines)", "shortDescription": {"text": "Very large file: frontend/src/Sky.jsx (1991 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8988fd75df609d8b", "name": "Very large file: backend-python/src/sky/ingestion/sources/bci_scraper.py (1463 lines)", "shortDescription": {"text": "Very large file: backend-python/src/sky/ingestion/sources/bci_scraper.py (1463 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 116 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 26 placeholder/mock markers across 10 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing ci. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3a36a130e26459b2", "name": "Commented-code block (5 lines) in frontend/src/Sky.jsx:450", "shortDescription": {"text": "Commented-code block (5 lines) in frontend/src/Sky.jsx:450"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a8d7ea8b363ff072", "name": "Commented-code block (5 lines) in frontend/src/App.jsx:4", "shortDescription": {"text": "Commented-code block (5 lines) in frontend/src/App.jsx:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-77663ab3c297df19", "name": "Commented-code block (5 lines) in frontend/src/components/BankConnect.jsx:599", "shortDescription": {"text": "Commented-code block (5 lines) in frontend/src/components/BankConnect.jsx:599"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ab747f4a4ab91249", "name": "Commented-code block (6 lines) in frontend/src/services/api.js:5", "shortDescription": {"text": "Commented-code block (6 lines) in frontend/src/services/api.js:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a8dbea402f454239", "name": "Network/subprocess call without timeout or try/except \u2014 scripts/md_to_pdf.py:139", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/md_to_pdf.py:139"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e6484d2f007455d2", "name": "Commented-code block (6 lines) in backend-python/tests/integration/test_sync_job.py:20", "shortDescription": {"text": "Commented-code block (6 lines) in backend-python/tests/integration/test_sync_job.py:20"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7503429d600cf104", "name": "Legacy-named symbol `bank_encryption_key_v2` in backend-python/scripts/rekey_bank_accounts.py:45", "shortDescription": {"text": "Legacy-named symbol `bank_encryption_key_v2` in backend-python/scripts/rekey_bank_accounts.py:45"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aef09c289f458e05", "name": "Legacy-named symbol `cron_sync_due_deprecated` in backend-python/src/sky/api/routers/internal.py:41", "shortDescription": {"text": "Legacy-named symbol `cron_sync_due_deprecated` in backend-python/src/sky/api/routers/internal.py:41"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0a52b45a8b2a1ea6", "name": "Commented-code block (9 lines) in backend-python/src/sky/ingestion/rate_limiter.py:30", "shortDescription": {"text": "Commented-code block (9 lines) in backend-python/src/sky/ingestion/rate_limiter.py:30"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f19e04d1db2136aa", "name": "Commented-code block (7 lines) in backend-python/src/sky/ingestion/contracts.py:135", "shortDescription": {"text": "Commented-code block (7 lines) in backend-python/src/sky/ingestion/contracts.py:135"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-38291abdad3a509c", "name": "Commented-code block (5 lines) in backend-python/src/sky/ingestion/sources/bci_scraper.py:94", "shortDescription": {"text": "Commented-code block (5 lines) in backend-python/src/sky/ingestion/sources/bci_scraper.py:94"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0109648f6621a5d4", "name": "Commented-code block (6 lines) in backend-python/src/sky/ingestion/sources/falabella_scraper.py:96", "shortDescription": {"text": "Commented-code block (6 lines) in backend-python/src/sky/ingestion/sources/falabella_scraper.py:96"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fe16527cfbd90956", "name": "Commented-code block (12 lines) in backend-python/src/sky/ingestion/sources/bchile_scraper.py:91", "shortDescription": {"text": "Commented-code block (12 lines) in backend-python/src/sky/ingestion/sources/bchile_scraper.py:91"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c51dad15fe55ad32", "name": "Legacy-named symbol `bank_encryption_key_v2` in backend-python/src/sky/core/config.py:127", "shortDescription": {"text": "Legacy-named symbol `bank_encryption_key_v2` in backend-python/src/sky/core/config.py:127"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-87ad0a2524f6e358", "name": "Commented-code block (5 lines) in backend-python/src/sky/core/config.py:133", "shortDescription": {"text": "Commented-code block (5 lines) in backend-python/src/sky/core/config.py:133"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-791a6cf2dc4d9912", "name": "Commented-code block (8 lines) in backend-python/src/sky/core/audit.py:31", "shortDescription": {"text": "Commented-code block (8 lines) in backend-python/src/sky/core/audit.py:31"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-0b62e91f518f5ab3", "name": "Commented-code block (6 lines) in backend-python/src/sky/domain/merchant_feedback.py:41", "shortDescription": {"text": "Commented-code block (6 lines) in backend-python/src/sky/domain/merchant_feedback.py:41"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ff89e9ee875ec33f", "name": "Commented-code block (8 lines) in backend/scripts/runScheduledSync.js:7", "shortDescription": {"text": "Commented-code block (8 lines) in backend/scripts/runScheduledSync.js:7"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-201cb79d4be5673e", "name": "Commented-code block (5 lines) in backend/routes/internal.js:12", "shortDescription": {"text": "Commented-code block (5 lines) in backend/routes/internal.js:12"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-3be1a0b2e7f01878", "name": "Commented-code block (7 lines) in backend/routes/banking.js:6", "shortDescription": {"text": "Commented-code block (7 lines) in backend/routes/banking.js:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-226c8d1dac82756a", "name": "Commented-code block (6 lines) in backend/services/encryptionService.js:6", "shortDescription": {"text": "Commented-code block (6 lines) in backend/services/encryptionService.js:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1eae27f73425b961", "name": "Commented-code block (6 lines) in backend/services/financeService.js:5", "shortDescription": {"text": "Commented-code block (6 lines) in backend/services/financeService.js:5"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c4ecac0b73757ad3", "name": "Commented-code block (8 lines) in backend/services/schedulerService.js:6", "shortDescription": {"text": "Commented-code block (8 lines) in backend/services/schedulerService.js:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d4dc663620921de7", "name": "Commented-code block (5 lines) in backend/services/aiService.js:4", "shortDescription": {"text": "Commented-code block (5 lines) in backend/services/aiService.js:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6764f73c4533c67a", "name": "Commented-code block (7 lines) in backend/services/categorizationQueueService.js:6", "shortDescription": {"text": "Commented-code block (7 lines) in backend/services/categorizationQueueService.js:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-398b2ef5cadd4d86", "name": "Commented-code block (6 lines) in backend/services/ariaService.js:4", "shortDescription": {"text": "Commented-code block (6 lines) in backend/services/ariaService.js:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-173f1c1e1c346f46", "name": "Commented-code block (13 lines) in backend/services/bankSyncService.js:6", "shortDescription": {"text": "Commented-code block (13 lines) in backend/services/bankSyncService.js:6"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8acc4cb3abee6442", "name": "Commented-code block (6 lines) in backend/services/banking.js:4", "shortDescription": {"text": "Commented-code block (6 lines) in backend/services/banking.js:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-214ea6f960e16842", "name": "Commented-code block (5 lines) in backend/services/bankingAdapter.js:11", "shortDescription": {"text": "Commented-code block (5 lines) in backend/services/bankingAdapter.js:11"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1b5a76780c3df9aa", "name": "1 env vars used in code but missing from .env.example", "shortDescription": {"text": "1 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `LOCALAPPDATA`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nbackend-python/scripts/smoke_router.py:source_identifier, backend-python/scripts/smoke_router.py:source_identifier\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-49c98f7cedd9c977", "name": "Near-duplicate function bodies in 4 places", "shortDescription": {"text": "Near-duplicate function bodies in 4 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nbackend-python/src/sky/ingestion/contracts.py:fetch, backend-python/src/sky/ingestion/sources/bci_scraper.py:fetch, backend-python/src/sky/ingestion/sources/falabella_scraper.py:fetch, backend-python/src/sky/ingestion/sources/bchile_scraper.py:fetch\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cb857759801a68c6", "name": "FastAPI POST `fintoc_webhook` without auth dependency \u2014 backend-python/src/sky/api/routers/webhooks.py:12", "shortDescription": {"text": "FastAPI POST `fintoc_webhook` without auth dependency \u2014 backend-python/src/sky/api/routers/webhooks.py:12"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fb2c2bd6e216043b", "name": "FastAPI POST `cron_sync_due` without auth dependency \u2014 backend-python/src/sky/api/routers/internal.py:29", "shortDescription": {"text": "FastAPI POST `cron_sync_due` without auth dependency \u2014 backend-python/src/sky/api/routers/internal.py:29"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7d193ebab08b9f31", "name": "Dangling fetch: GET /summary (frontend/src/services/api.js:76)", "shortDescription": {"text": "Dangling fetch: GET /summary (frontend/src/services/api.js:76)"}, "fullDescription": {"text": "`frontend/src/services/api.js:76` calls `GET /summary` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/summary`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-57b4b8fa49ebde72", "name": "Dangling fetch: GET /transactions?page=${page}&page_size=${page_size} (frontend/src/services/api.js:81)", "shortDescription": {"text": "Dangling fetch: GET /transactions?page=${page}&page_size=${page_size} (frontend/src/services/api.js:81)"}, "fullDescription": {"text": "`frontend/src/services/api.js:81` calls `GET /transactions?page=${page}&page_size=${page_size}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/transactions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-3ccb2b4b1b4942c3", "name": "Dangling fetch: POST /transactions (frontend/src/services/api.js:85)", "shortDescription": {"text": "Dangling fetch: POST /transactions (frontend/src/services/api.js:85)"}, "fullDescription": {"text": "`frontend/src/services/api.js:85` calls `POST /transactions` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/transactions`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4646d8183956a23b", "name": "Dangling fetch: PATCH /transactions/${id} (frontend/src/services/api.js:89)", "shortDescription": {"text": "Dangling fetch: PATCH /transactions/${id} (frontend/src/services/api.js:89)"}, "fullDescription": {"text": "`frontend/src/services/api.js:89` calls `PATCH /transactions/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/transactions/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c7f3a450147614ff", "name": "Dangling fetch: PATCH /transactions/${id}/merchant (frontend/src/services/api.js:96)", "shortDescription": {"text": "Dangling fetch: PATCH /transactions/${id}/merchant (frontend/src/services/api.js:96)"}, "fullDescription": {"text": "`frontend/src/services/api.js:96` calls `PATCH /transactions/${id}/merchant` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/transactions/<p>/merchant`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-be0c3c7969f4f246", "name": "Dangling fetch: DELETE /transactions/${id} (frontend/src/services/api.js:103)", "shortDescription": {"text": "Dangling fetch: DELETE /transactions/${id} (frontend/src/services/api.js:103)"}, "fullDescription": {"text": "`frontend/src/services/api.js:103` calls `DELETE /transactions/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/transactions/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-9b852da4d0977dee", "name": "Dangling fetch: POST /chat (frontend/src/services/api.js:108)", "shortDescription": {"text": "Dangling fetch: POST /chat (frontend/src/services/api.js:108)"}, "fullDescription": {"text": "`frontend/src/services/api.js:108` calls `POST /chat` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/chat`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1b8880cdbba07315", "name": "Dangling fetch: GET /chat/history?limit=${limit} (frontend/src/services/api.js:112)", "shortDescription": {"text": "Dangling fetch: GET /chat/history?limit=${limit} (frontend/src/services/api.js:112)"}, "fullDescription": {"text": "`frontend/src/services/api.js:112` calls `GET /chat/history?limit=${limit}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/chat/history`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ce13bbd4bb873aac", "name": "Dangling fetch: GET /challenges (frontend/src/services/api.js:117)", "shortDescription": {"text": "Dangling fetch: GET /challenges (frontend/src/services/api.js:117)"}, "fullDescription": {"text": "`frontend/src/services/api.js:117` calls `GET /challenges` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/challenges`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-64e8e9e226b9adff", "name": "Dangling fetch: POST /challenges/${id}/activate (frontend/src/services/api.js:121)", "shortDescription": {"text": "Dangling fetch: POST /challenges/${id}/activate (frontend/src/services/api.js:121)"}, "fullDescription": {"text": "`frontend/src/services/api.js:121` calls `POST /challenges/${id}/activate` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/challenges/<p>/activate`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fe4d7bd3f7092bba", "name": "Dangling fetch: POST /challenges/${id}/complete (frontend/src/services/api.js:125)", "shortDescription": {"text": "Dangling fetch: POST /challenges/${id}/complete (frontend/src/services/api.js:125)"}, "fullDescription": {"text": "`frontend/src/services/api.js:125` calls `POST /challenges/${id}/complete` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/challenges/<p>/complete`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7ec517a0d6795c35", "name": "Dangling fetch: POST /simulate (frontend/src/services/api.js:130)", "shortDescription": {"text": "Dangling fetch: POST /simulate (frontend/src/services/api.js:130)"}, "fullDescription": {"text": "`frontend/src/services/api.js:130` calls `POST /simulate` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/simulate`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-abc3cc6dc73ee712", "name": "Dangling fetch: GET /goals (frontend/src/services/api.js:138)", "shortDescription": {"text": "Dangling fetch: GET /goals (frontend/src/services/api.js:138)"}, "fullDescription": {"text": "`frontend/src/services/api.js:138` calls `GET /goals` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/goals`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-134b526e116c59a5", "name": "Dangling fetch: POST /goals (frontend/src/services/api.js:142)", "shortDescription": {"text": "Dangling fetch: POST /goals (frontend/src/services/api.js:142)"}, "fullDescription": {"text": "`frontend/src/services/api.js:142` calls `POST /goals` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/goals`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-fca83cef5198dfea", "name": "Dangling fetch: PATCH /goals/${id} (frontend/src/services/api.js:146)", "shortDescription": {"text": "Dangling fetch: PATCH /goals/${id} (frontend/src/services/api.js:146)"}, "fullDescription": {"text": "`frontend/src/services/api.js:146` calls `PATCH /goals/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/goals/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7d9f085b301eb8ec", "name": "Dangling fetch: DELETE /goals/${id} (frontend/src/services/api.js:150)", "shortDescription": {"text": "Dangling fetch: DELETE /goals/${id} (frontend/src/services/api.js:150)"}, "fullDescription": {"text": "`frontend/src/services/api.js:150` calls `DELETE /goals/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/goals/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0cfdc41eebfe4e67", "name": "Dangling fetch: PATCH /profile (frontend/src/services/api.js:155)", "shortDescription": {"text": "Dangling fetch: PATCH /profile (frontend/src/services/api.js:155)"}, "fullDescription": {"text": "`frontend/src/services/api.js:155` calls `PATCH /profile` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/profile`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-7b050d1366449073", "name": "Dangling fetch: GET /banking/banks (frontend/src/services/api.js:161)", "shortDescription": {"text": "Dangling fetch: GET /banking/banks (frontend/src/services/api.js:161)"}, "fullDescription": {"text": "`frontend/src/services/api.js:161` calls `GET /banking/banks` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/banking/banks`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-8fc2a6839ea70ff9", "name": "Dangling fetch: GET /banking/accounts (frontend/src/services/api.js:165)", "shortDescription": {"text": "Dangling fetch: GET /banking/accounts (frontend/src/services/api.js:165)"}, "fullDescription": {"text": "`frontend/src/services/api.js:165` calls `GET /banking/accounts` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/banking/accounts`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-485d5a25e15ff325", "name": "Dangling fetch: POST /banking/accounts (frontend/src/services/api.js:169)", "shortDescription": {"text": "Dangling fetch: POST /banking/accounts (frontend/src/services/api.js:169)"}, "fullDescription": {"text": "`frontend/src/services/api.js:169` calls `POST /banking/accounts` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/banking/accounts`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d9da2345d3f6459f", "name": "Dangling fetch: POST /banking/sync/${accountId} (frontend/src/services/api.js:176)", "shortDescription": {"text": "Dangling fetch: POST /banking/sync/${accountId} (frontend/src/services/api.js:176)"}, "fullDescription": {"text": "`frontend/src/services/api.js:176` calls `POST /banking/sync/${accountId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/banking/sync/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f653a01d358f4c90", "name": "Dangling fetch: POST /banking/sync-all (frontend/src/services/api.js:180)", "shortDescription": {"text": "Dangling fetch: POST /banking/sync-all (frontend/src/services/api.js:180)"}, "fullDescription": {"text": "`frontend/src/services/api.js:180` calls `POST /banking/sync-all` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/banking/sync-all`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-22250454365e6c46", "name": "Dangling fetch: DELETE /banking/accounts/${accountId} (frontend/src/services/api.js:184)", "shortDescription": {"text": "Dangling fetch: DELETE /banking/accounts/${accountId} (frontend/src/services/api.js:184)"}, "fullDescription": {"text": "`frontend/src/services/api.js:184` calls `DELETE /banking/accounts/${accountId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/banking/accounts/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend-python/src/sky/api/main.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f683b6e8bb1592fe", "name": "Unused endpoint: POST /export-request", "shortDescription": {"text": "Unused endpoint: POST /export-request"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/account.py` declares `POST /export-request` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3f1c5ac307e90ae6", "name": "Unused endpoint: GET /export-request", "shortDescription": {"text": "Unused endpoint: GET /export-request"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/account.py` declares `GET /export-request` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a42fa2f81d4b7e32", "name": "Unused endpoint: GET /export-request/{request_id}", "shortDescription": {"text": "Unused endpoint: GET /export-request/{request_id}"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/account.py` declares `GET /export-request/{request_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-523614e7cfe014ad", "name": "Unused endpoint: GET /banks", "shortDescription": {"text": "Unused endpoint: GET /banks"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/banking.py` declares `GET /banks` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-383442cf4adb1252", "name": "Unused endpoint: POST /sync/{account_id}", "shortDescription": {"text": "Unused endpoint: POST /sync/{account_id}"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/banking.py` declares `POST /sync/{account_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ab7e56c6fbe85d3", "name": "Unused endpoint: POST /sync-all", "shortDescription": {"text": "Unused endpoint: POST /sync-all"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/banking.py` declares `POST /sync-all` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-21c7ff7b8ef22c44", "name": "Unused endpoint: GET /accounts", "shortDescription": {"text": "Unused endpoint: GET /accounts"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/banking.py` declares `GET /accounts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c04406fe463e162f", "name": "Unused endpoint: POST /accounts", "shortDescription": {"text": "Unused endpoint: POST /accounts"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/banking.py` declares `POST /accounts` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ef02d0e1f7da126f", "name": "Unused endpoint: DELETE /accounts/{account_id}", "shortDescription": {"text": "Unused endpoint: DELETE /accounts/{account_id}"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/banking.py` declares `DELETE /accounts/{account_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4756b4c4da7d2088", "name": "Unused endpoint: GET /api/health", "shortDescription": {"text": "Unused endpoint: GET /api/health"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/health.py` declares `GET /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-699ab6284738f549", "name": "Unused endpoint: GET /api/health/deep", "shortDescription": {"text": "Unused endpoint: GET /api/health/deep"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/health.py` declares `GET /api/health/deep` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/goals.py` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-06da2cd01b982905", "name": "Unused endpoint: PATCH /{goal_id}", "shortDescription": {"text": "Unused endpoint: PATCH /{goal_id}"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/goals.py` declares `PATCH /{goal_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-750ef798a989378f", "name": "Unused endpoint: DELETE /{goal_id}", "shortDescription": {"text": "Unused endpoint: DELETE /{goal_id}"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/goals.py` declares `DELETE /{goal_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b671297c83981130", "name": "Unused endpoint: POST /projection", "shortDescription": {"text": "Unused endpoint: POST /projection"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/simulate.py` declares `POST /projection` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-65cb84733062cec2", "name": "Unused endpoint: PATCH /{tx_id}", "shortDescription": {"text": "Unused endpoint: PATCH /{tx_id}"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/transactions.py` declares `PATCH /{tx_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-085213235d638fcd", "name": "Unused endpoint: PATCH /{tx_id}/merchant", "shortDescription": {"text": "Unused endpoint: PATCH /{tx_id}/merchant"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/transactions.py` declares `PATCH /{tx_id}/merchant` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-78caef94e492eeba", "name": "Unused endpoint: DELETE /{tx_id}", "shortDescription": {"text": "Unused endpoint: DELETE /{tx_id}"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/transactions.py` declares `DELETE /{tx_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-183609026a276985", "name": "Unused endpoint: POST /fintoc", "shortDescription": {"text": "Unused endpoint: POST /fintoc"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/webhooks.py` declares `POST /fintoc` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dd19169ed693084c", "name": "Unused endpoint: POST /{challenge_id}/accept", "shortDescription": {"text": "Unused endpoint: POST /{challenge_id}/accept"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/challenges.py` declares `POST /{challenge_id}/accept` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c0cb6e1087bbffa", "name": "Unused endpoint: POST /{challenge_id}/activate", "shortDescription": {"text": "Unused endpoint: POST /{challenge_id}/activate"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/challenges.py` declares `POST /{challenge_id}/activate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-85fea11c856af88d", "name": "Unused endpoint: POST /{challenge_id}/decline", "shortDescription": {"text": "Unused endpoint: POST /{challenge_id}/decline"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/challenges.py` declares `POST /{challenge_id}/decline` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e6163fba2fcdc488", "name": "Unused endpoint: POST /{challenge_id}/complete", "shortDescription": {"text": "Unused endpoint: POST /{challenge_id}/complete"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/challenges.py` declares `POST /{challenge_id}/complete` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d05b1f5adfd3eac", "name": "Unused endpoint: PATCH /", "shortDescription": {"text": "Unused endpoint: PATCH /"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/profile.py` declares `PATCH /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-afc064028ae39ea9", "name": "Unused endpoint: GET /history", "shortDescription": {"text": "Unused endpoint: GET /history"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/chat.py` declares `GET /history` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0b969917809e7cd6", "name": "Unused endpoint: POST /cron/sync-due", "shortDescription": {"text": "Unused endpoint: POST /cron/sync-due"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/internal.py` declares `POST /cron/sync-due` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-201275e8d14c0db7", "name": "Unused endpoint: GET /operator/sync-status", "shortDescription": {"text": "Unused endpoint: GET /operator/sync-status"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/internal.py` declares `GET /operator/sync-status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd1dc91abf32142d", "name": "Unused endpoint: GET /me", "shortDescription": {"text": "Unused endpoint: GET /me"}, "fullDescription": {"text": "`backend-python/src/sky/api/routers/audit.py` declares `GET /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2b92dc87a4256298", "name": "Unused endpoint: USE /api/chat", "shortDescription": {"text": "Unused endpoint: USE /api/chat"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/chat` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bab42d9ce9b7b7d4", "name": "Unused endpoint: USE /api/transactions", "shortDescription": {"text": "Unused endpoint: USE /api/transactions"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/transactions` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-517d7f60c494be2f", "name": "Unused endpoint: USE /api/summary", "shortDescription": {"text": "Unused endpoint: USE /api/summary"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/summary` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00374c3abe79d6d9", "name": "Unused endpoint: USE /api/challenges", "shortDescription": {"text": "Unused endpoint: USE /api/challenges"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/challenges` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-db30a2c591e4bf39", "name": "Unused endpoint: USE /api/simulate", "shortDescription": {"text": "Unused endpoint: USE /api/simulate"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/simulate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7522dc7e4529ffc2", "name": "Unused endpoint: USE /api/goals", "shortDescription": {"text": "Unused endpoint: USE /api/goals"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/goals` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-14dd5ee54e139c2a", "name": "Unused endpoint: USE /api/banking", "shortDescription": {"text": "Unused endpoint: USE /api/banking"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/banking` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e1c89316f317f0ad", "name": "Unused endpoint: USE /api/internal", "shortDescription": {"text": "Unused endpoint: USE /api/internal"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/internal` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a61c112b611f4bb", "name": "Unused endpoint: DELETE /:id", "shortDescription": {"text": "Unused endpoint: DELETE /:id"}, "fullDescription": {"text": "`backend/routes/transactions.js` declares `DELETE /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-17ae4c961edce6d3", "name": "Unused endpoint: POST /:id/activate", "shortDescription": {"text": "Unused endpoint: POST /:id/activate"}, "fullDescription": {"text": "`backend/routes/challenges.js` declares `POST /:id/activate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a005497d5a71980f", "name": "Unused endpoint: POST /:id/complete", "shortDescription": {"text": "Unused endpoint: POST /:id/complete"}, "fullDescription": {"text": "`backend/routes/challenges.js` declares `POST /:id/complete` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-17a818026a0fb6f8", "name": "Unused endpoint: POST /scheduled-sync", "shortDescription": {"text": "Unused endpoint: POST /scheduled-sync"}, "fullDescription": {"text": "`backend/routes/internal.js` declares `POST /scheduled-sync` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-740eae78c4f4ce85", "name": "Unused endpoint: POST /process-queue", "shortDescription": {"text": "Unused endpoint: POST /process-queue"}, "fullDescription": {"text": "`backend/routes/internal.js` declares `POST /process-queue` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5b6dd317aa700414", "name": "Unused endpoint: GET /queue-depth", "shortDescription": {"text": "Unused endpoint: GET /queue-depth"}, "fullDescription": {"text": "`backend/routes/internal.js` declares `GET /queue-depth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8664e7608b8880ea", "name": "Unused endpoint: POST /connect", "shortDescription": {"text": "Unused endpoint: POST /connect"}, "fullDescription": {"text": "`backend/routes/banking.js` declares `POST /connect` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a68f8b446dd2bd2", "name": "Unused endpoint: POST /sync/:id", "shortDescription": {"text": "Unused endpoint: POST /sync/:id"}, "fullDescription": {"text": "`backend/routes/banking.js` declares `POST /sync/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d2a37c2e855bff00", "name": "Unused endpoint: DELETE /accounts/:id", "shortDescription": {"text": "Unused endpoint: DELETE /accounts/:id"}, "fullDescription": {"text": "`backend/routes/banking.js` declares `DELETE /accounts/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5fbc954f63526821", "name": "Unused endpoint: PATCH /:id", "shortDescription": {"text": "Unused endpoint: PATCH /:id"}, "fullDescription": {"text": "`backend/routes/goals.js` declares `PATCH /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/21337"}, "properties": {"repository": "TioCristian007/SkyFinance", "repoUrl": "https://github.com/TioCristian007/SkyFinance", "branch": "main"}, "results": [{"ruleId": "foundry_assumption_check", "level": "warning", "message": {"text": "Foundry mined assumption checks: TioCristian007/SkyFinance"}, "properties": {"repobilityId": 434367, "scanner": "foundry_dataset", "fingerprint": "6babb8b1802685419677ad577cb6a96b5f5f4c6acabbb883b58307faa5d42699", "category": "practices", "severity": "medium", "confidence": 0.62, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "assumption_checks", "synthetic": false, "thread_key": "TioCristian007/SkyFinance#1", "human_labels": ["api_or_backend", "security_auth_secret"], "issue_number": "1", "thread_label": "thread_has_human_issue_and_fix_context", "outcome_label": "ambiguous_needs_more_evidence", "source_backed": true, "max_confidence": 0.757, "repo_full_name": "TioCristian007/SkyFinance", "training_usage": "weak_supervision", "confidence_tier": "weak_supervision", "source_chain_id": "evidence-chain-issue_chain-f9c9285601486788", "helicopter_views": {"graphs": 2, "schemas": 2}, "artifact_families": {"ci": 1, "docs": 3, "schemas": 4}, "source_chain_kind": "issue_chain", "changed_file_count": 2, "source_graph_label": "source_backed_multi_signal_graph", "changed_file_labels": {"api_or_backend": 2}, "linked_commit_count": 3, "helicopter_view_count": 4, "source_artifact_count": 8, "classification_reasons": ["source_graph_has_real_artifacts", "source_graph_has_verification_artifacts", "repo_has_isolated_helicopter_views", "link_quality_weak_supervision", "high_risk_human_feedback_label"], "linked_ci_commit_count": 0, "verification_artifact_count": 5, "design_schema_api_artifact_count": 4}, "text": "Comment chain pattern product: assumption_checks\nRepo: TioCristian007/SkyFinance\nThread: TioCristian007/SkyFinance#1\nOutcome: ambiguous_needs_more_evidence\nThread label: thread_has_human_issue_and_fix_context\nSource graph label: source_backed_multi_signal_graph\nReasons: source_graph_has_real_artifacts, source_graph_has_verification_artifacts, repo_has_isolated_helicopter_views, link_quality_weak_supervision, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: TioCristian007/SkyFinance#1\nRepo: TioCristian007/SkyFinance\nThread label: thread_has_human_issue_and_fix_context\nOutcome: ambiguous_needs_more_evidence\nComment count: 1\nLinked commit count: 3\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 2\nLabels: {'security_auth_secret': 1}\nPolarities: {'bad': 1}\nChanged file labels: {'api_or_backend': 2}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-1d6398619ee40928\",\n    \"kind\": \"pull_request_body\",\n    \"label\": \"security_auth_secret\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/TioCristian007/SkyFinance/pull/1\",\n    \"text\": \"GitHub feedback: security_auth_secret\\nPolarity: bad\\nKind: pull_request_body\\nRepo: TioCristian007/SkyFinance\\nAuthor: TioCristian007 (User)\\nURL: https://github.com/TioCristian007/SkyFinance/pull/1\\nTitle: Implementar scraper BCI con captura de saldoContable\\nBody:\\n- Reemplaza stub vac\u00edo de bci_direct.py con BCIDirectSource completo\\r\\n- Flujo: login \u2192 intercept JWT Bearer \u2192 GET /cuentas \u2192 POST /cuentas-busquedas/por-numero-cuenta por cada cuenta para obtener saldoContable\\r\\n- El balance ven\u00eda N/A porque el endpoint de lista no incluye saldos; hay que pedirlo expl\u00edcitamente con n\u00famero y tipo de cuenta\\r\\n- Agrega test_bci_scraper.py para pruebas manuales end-to-end\"\n  }\n]\nChanged files:\n[\n  {\n    \"id\": \"github-pr-file-file-c0518958f8a11c10\",\n    \"filename\": \"backend-python/scripts/test_bci_scraper.py\",\n    \"label\": \"api_or_backend\",\n    \"status\": \"added\",\n    \"additions\": 108,\n    \"deletions\": 0,\n    \"changes\": 108,\n    \"blob_url\": \"https://github.com/TioCristian007/SkyFinance/blob/f3f6e7c2a02ea29c20894c763c3a8bfb35a2d3b0/backend-python%2Fscripts%2Ftest_bci_scraper.py\"\n  },\n  {\n    \"id\": \"github-pr-file-file-079a2e782d2aa46f\",\n    \"filename\": \"backend-python/src/sky/ingestion/sources/bci_direct.py\",\n    \"label\": \"api_or_backend\",\n    \"status\": \"modified\",\n    \"additions\": 539,\n    \"deletions\": 2,\n    \"changes\": 541,\n    \"blob_url\": \"https://github.com/TioCristian007/SkyFinance/blob/f3f6e7c2a02ea29c20894c763c3a8bfb35a2d3b0/backend-python%2Fsrc%2Fsky%2Fingestion%2Fsources%2Fbci_direct.py\"\n  }\n]\nLinked chain ids:\n[\"evidence-chain-comment_to_commit-6a19077ec9ca216a\"]\nSource graph evidence:\nSource evidence repo graph summary\nRepo: TioCristian007/SkyFinance\nGraph label: source_backed_multi_signal_graph\nNodes: 16\nEdges: 24\nNode types: {\"cooccurrence_profile\": 1, \"github_repo_summary\": 1, \"helicopter_repo_view\": 4, \"repo\": 1, \"source_artifact\": 8, \"so\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/TioCristian007/SkyFinance", "source_id": "comment-chain-pattern-assumption_checks-afbacebfed09d598", "synthetic": false, "gold_label": "", "graph_label": "source_backed_multi_signal_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/assumption_checks/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "TioCristian007/SkyFinance", "source_dataset": "comment_chain_patterns/assumption_checks", "training_usage": "weak_supervision"}}}, {"ruleId": "foundry_auth_guardrail_gap", "level": "error", "message": {"text": "Foundry mined security auth guardrail gaps: TioCristian007/SkyFinance"}, "properties": {"repobilityId": 454965, "scanner": "foundry_dataset", "fingerprint": "dbcd69e8e9fe701c3da30a0042d31cb1b4b15705ac08c53c68528f562149fc74", "category": "auth", "severity": "critical", "confidence": 0.78, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Security/auth changes without enough guardrails", "intent": "Assumption-check security/auth examples requiring stronger tests or CI.", "labels": {"api_or_backend": 2, "generated_provenance": 1, "security_auth_secret": 1, "verification_or_tests": 2, "issue_or_pull_request_thread": 1, "ambiguous_needs_more_evidence": 3, "comment_has_related_commit_context": 1, "thread_has_human_issue_and_fix_context": 2}, "source": "graph_query_export", "motif_id": "security_auth_without_guardrails", "outcomes": {"ambiguous_needs_more_evidence": 6}, "polarity": "bad", "query_id": "security_auth_guardrail_gaps", "severity": "critical", "ci_labels": {}, "synthetic": false, "edge_count": 20, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "thread_touches_file": 2, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "issue_chain_touches_file": 2, "thread_has_comment_chain": 1, "comment_chain_links_commit": 3, "comment_chain_touches_file": 2, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 14, "node_types": {"repo": 1, "commit": 3, "thread": 1, "comment": 1, "pr_file": 2, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "TioCristian007/SkyFinance#1", "issue_number": "1", "quality_tiers": {"weak_supervision": 3}, "repo_full_name": "TioCristian007/SkyFinance", "training_usage": "assumption_check", "source_motif_id": "graph-pattern-motif-thread-3e16bfb0d172d4d8", "graph_gold_label": "weak_supervision_needs_review", "changed_file_labels": {"api_or_backend": 8}}, "text": "Graph query export: Security/auth changes without enough guardrails\nQuery id: security_auth_guardrail_gaps\nQuery type: motif_query\nIntent: Assumption-check security/auth examples requiring stronger tests or CI.\nMotif: security_auth_without_guardrails\nTraining usage: assumption_check\nGraph gold label: weak_supervision_needs_review\nRepo: TioCristian007/SkyFinance\nThread: TioCristian007/SkyFinance#1\nEvidence:\nGraph motif: Security/auth change without enough guardrails\nMotif id: security_auth_without_guardrails\nPolarity: bad\nTraining usage: assumption_check\nSeverity: critical\nRepo: TioCristian007/SkyFinance\nThread: TioCristian007/SkyFinance#1\nGraph gold label: weak_supervision_needs_review\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: TioCristian007/SkyFinance#1\nRepo: TioCristian007/SkyFinance\nIssue/PR number: 1\nGraph consistency label: weak_supervision_needs_review\nNodes: 14\nEdges: 20\nNode types: {'commit': 3, 'link_quality': 3, 'pr_file': 2, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'comment_chain_links_commit': 3, 'chain_has_link_quality': 3, 'thread_touches_file': 2, 'comment_chain_touches_file': 2, 'issue_chain_touches_file': 2, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'ambiguous_needs_more_evidence': 3, 'api_or_backend': 2, 'verification_or_tests': 2, 'thread_has_human_issue_and_fix_context': 2, 'issue_or_pull_request_thread': 1, 'security_auth_secret': 1, 'comment_has_related_commit_context': 1, 'generated_provenance': 1}\nOutcomes: {'ambiguous_needs_more_evidence': 6}\nQuality tiers: {'weak_supervision': 3}\nCI labels: {}\nCurriculum targets:\n- Train auth boundary repair with tests, permission matrices, and secret-handling checks.\n- Keep risky auth changes separate from ordinary bug-fix examples.\nAssumption checks:\n- Are auth/permission paths covered by tests?\n- Are secrets, CORS, or access rules verified rather than summarized?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/TioCristian007/SkyFinance", "source_id": "graph-query-motif_query-b7b042af079852a7", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/security_auth_guardrail_gaps/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "TioCristian007/SkyFinance", "source_dataset": "graph_queries/security_auth_guardrail_gaps", "training_usage": "assumption_check"}}}, {"ruleId": "scanner-253ce331a7701def", "level": "note", "message": {"text": "Possibly dead Python function: capabilities"}, "properties": {"repobilityId": "13d5642ad31c26a8", "scanner": "scanner-primary", "fingerprint": "253ce331a7701def", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-python/scripts/smoke_router.py:71"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ddd73137c8634a9e", "level": "note", "message": {"text": "Possibly dead Python function: require_user_id"}, "properties": {"repobilityId": "7715dcf2390fee93", "scanner": "scanner-primary", "fingerprint": "ddd73137c8634a9e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-python/src/sky/api/deps.py:16"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2acf7869693b0c78", "level": "note", "message": {"text": "Possibly dead Python function: startup"}, "properties": {"repobilityId": "2cdbcf88b35eabc7", "scanner": "scanner-primary", "fingerprint": "2acf7869693b0c78", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-python/src/sky/worker/main.py:33"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-56fa188b1ef763bf", "level": "note", "message": {"text": "Possibly dead Python function: shutdown"}, "properties": {"repobilityId": "c1b7442732df40cc", "scanner": "scanner-primary", "fingerprint": "56fa188b1ef763bf", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-python/src/sky/worker/main.py:56"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-83d20356e46485ff", "level": "note", "message": {"text": "Possibly dead Python function: capabilities"}, "properties": {"repobilityId": "13d5642ad31c26a8", "scanner": "scanner-primary", "fingerprint": "83d20356e46485ff", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-python/src/sky/ingestion/sources/bci_scraper.py:286"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6baf76586a4c1688", "level": "note", "message": {"text": "Possibly dead Python function: capture_request"}, "properties": {"repobilityId": "3e125f76a8dead06", "scanner": "scanner-primary", "fingerprint": "6baf76586a4c1688", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-python/src/sky/ingestion/sources/bci_scraper.py:330"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a5bdaa4228f7d0b2", "level": "note", "message": {"text": "Possibly dead Python function: capabilities"}, "properties": {"repobilityId": "13d5642ad31c26a8", "scanner": "scanner-primary", "fingerprint": "a5bdaa4228f7d0b2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-python/src/sky/ingestion/sources/falabella_scraper.py:64"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4b6b2add35a34f79", "level": "note", "message": {"text": "Possibly dead Python function: capabilities"}, "properties": {"repobilityId": "13d5642ad31c26a8", "scanner": "scanner-primary", "fingerprint": "4b6b2add35a34f79", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-python/src/sky/ingestion/sources/bchile_scraper.py:181"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c053ca75d58679e2", "level": "note", "message": {"text": "Possibly dead Python function: complete_challenge"}, "properties": {"repobilityId": "dc2f60f3e98df701", "scanner": "scanner-primary", "fingerprint": "c053ca75d58679e2", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-python/src/sky/domain/challenges.py:132"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-87cc86b94378ebe2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/components/BankConnect.jsx:266"}, "properties": {"repobilityId": "c91c86d4d5ccc9ce", "scanner": "scanner-primary", "fingerprint": "87cc86b94378ebe2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f8f34620d6cae87d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/services/api.js:31"}, "properties": {"repobilityId": "695d98d98e8ce6f4", "scanner": "scanner-primary", "fingerprint": "f8f34620d6cae87d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0d93460c6b71dfe6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/server.js:41"}, "properties": {"repobilityId": "ec6c625862fd9ddc", "scanner": "scanner-primary", "fingerprint": "0d93460c6b71dfe6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2f8252f32451ca3e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/scripts/runScheduledSync.js:31"}, "properties": {"repobilityId": "b3d0431f6f24727f", "scanner": "scanner-primary", "fingerprint": "2f8252f32451ca3e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-257a35f156d54202", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/encryptionService.js:102"}, "properties": {"repobilityId": "444500a2ee832331", "scanner": "scanner-primary", "fingerprint": "257a35f156d54202", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5cb70b9a377c4826", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/categorizerService.js:231"}, "properties": {"repobilityId": "2a8c1715c6537b30", "scanner": "scanner-primary", "fingerprint": "5cb70b9a377c4826", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-942b38bee0a7cec2", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 backend/services/financeService.js:280"}, "properties": {"repobilityId": "a37703a51142ffca", "scanner": "scanner-primary", "fingerprint": "942b38bee0a7cec2", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-ae532b1b249cf5e9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/schedulerService.js:63"}, "properties": {"repobilityId": "4a3dd6128202488d", "scanner": "scanner-primary", "fingerprint": "ae532b1b249cf5e9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cde49217ddc8ca5b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/categorizationQueueService.js:71"}, "properties": {"repobilityId": "af9088a9671e56e5", "scanner": "scanner-primary", "fingerprint": "cde49217ddc8ca5b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2bb7895d65aa573e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/ariaService.js:317"}, "properties": {"repobilityId": "3874f3a88cf4cc70", "scanner": "scanner-primary", "fingerprint": "2bb7895d65aa573e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f931d60e61a1ad34", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/bankSyncService.js:55"}, "properties": {"repobilityId": "8b1b563854a2ffbc", "scanner": "scanner-primary", "fingerprint": "f931d60e61a1ad34", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8c5495f9fedd0a3a", "level": "warning", "message": {"text": "Dockerfile runs as root: backend-python/Dockerfile"}, "properties": {"repobilityId": "ee9798f0bd86abd4", "scanner": "scanner-primary", "fingerprint": "8c5495f9fedd0a3a", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-09c9f766859045a7", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: python:3.12-slim"}, "properties": {"repobilityId": "89fd250a3062c065", "scanner": "scanner-primary", "fingerprint": "09c9f766859045a7", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-python/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1f66ad88286ca30a", "level": "warning", "message": {"text": "Dockerfile runs as root: backend/Dockerfile"}, "properties": {"repobilityId": "7afd2b0e8a8c9eeb", "scanner": "scanner-primary", "fingerprint": "1f66ad88286ca30a", "layer": "hardware", "severity": "medium", "confidence": 1.0, "tags": ["security", "container"]}}, {"ruleId": "scanner-e5063295643aafac", "level": "note", "message": {"text": "Docker base image is tag-pinned but not digest-pinned: node:22-slim"}, "properties": {"repobilityId": "e2785706b97d526c", "scanner": "scanner-primary", "fingerprint": "e5063295643aafac", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "docker", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/Dockerfile"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-43a91666ca33b974", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in frontend/src/Sky.jsx:1910"}, "properties": {"repobilityId": "fc95dd21361c1d1c", "scanner": "scanner-primary", "fingerprint": "43a91666ca33b974", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/Sky.jsx"}, "region": {"startLine": 1910}}}]}, {"ruleId": "scanner-777df33a942bc1c6", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in frontend/src/Sky.jsx:163"}, "properties": {"repobilityId": "3f42b2cfa3ec35f4", "scanner": "scanner-primary", "fingerprint": "777df33a942bc1c6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/Sky.jsx"}, "region": {"startLine": 163}}}]}, {"ruleId": "scanner-1787fd13f9d48bf8", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in frontend/src/components/BankConnect.jsx:77"}, "properties": {"repobilityId": "f46ef28ab1c20b5d", "scanner": "scanner-primary", "fingerprint": "1787fd13f9d48bf8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/components/BankConnect.jsx"}, "region": {"startLine": 77}}}]}, {"ruleId": "scanner-f37697bf1fa69215", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in frontend/src/components/AuthScreen.jsx:106"}, "properties": {"repobilityId": "f59d7f833865cc90", "scanner": "scanner-primary", "fingerprint": "f37697bf1fa69215", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/components/AuthScreen.jsx"}, "region": {"startLine": 106}}}]}, {"ruleId": "scanner-b334aba343a4e5b2", "level": "error", "message": {"text": "Possible secret in backend-python/src/sky/ingestion/contracts.py"}, "properties": {"repobilityId": "2e8281b2fd22d4fd", "scanner": "scanner-primary", "fingerprint": "b334aba343a4e5b2", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-python/src/sky/ingestion/contracts.py"}, "region": {"startLine": 41}}}]}, {"ruleId": "scanner-e9b96784343a9627", "level": "note", "message": {"text": "Very large file: frontend/src/Sky.jsx (1991 lines)"}, "properties": {"repobilityId": "cb6ebca78c2e664a", "scanner": "scanner-primary", "fingerprint": "e9b96784343a9627", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-8988fd75df609d8b", "level": "note", "message": {"text": "Very large file: backend-python/src/sky/ingestion/sources/bci_scraper.py (1463 lines)"}, "properties": {"repobilityId": "b2651e5d05cf566e", "scanner": "scanner-primary", "fingerprint": "8988fd75df609d8b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "7b443624a4cec5aa", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "8bb89cf4ea07d471", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "1b86fde9fce05632", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "e75931c447b9c873", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "8dae63fa1a0710cc", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "5ad9b97c128e3aaf", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-3a36a130e26459b2", "level": "none", "message": {"text": "Commented-code block (5 lines) in frontend/src/Sky.jsx:450"}, "properties": {"repobilityId": "1576cb7af76ac62c", "scanner": "scanner-primary", "fingerprint": "3a36a130e26459b2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a8d7ea8b363ff072", "level": "none", "message": {"text": "Commented-code block (5 lines) in frontend/src/App.jsx:4"}, "properties": {"repobilityId": "94041b0438bb2eb1", "scanner": "scanner-primary", "fingerprint": "a8d7ea8b363ff072", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-77663ab3c297df19", "level": "none", "message": {"text": "Commented-code block (5 lines) in frontend/src/components/BankConnect.jsx:599"}, "properties": {"repobilityId": "a8f4fb64a8aad64a", "scanner": "scanner-primary", "fingerprint": "77663ab3c297df19", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ab747f4a4ab91249", "level": "none", "message": {"text": "Commented-code block (6 lines) in frontend/src/services/api.js:5"}, "properties": {"repobilityId": "98d2f1a688316593", "scanner": "scanner-primary", "fingerprint": "ab747f4a4ab91249", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-a8dbea402f454239", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 scripts/md_to_pdf.py:139"}, "properties": {"repobilityId": "2e2dc27045647a00", "scanner": "scanner-primary", "fingerprint": "a8dbea402f454239", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e6484d2f007455d2", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend-python/tests/integration/test_sync_job.py:20"}, "properties": {"repobilityId": "5c0968b8f9168c18", "scanner": "scanner-primary", "fingerprint": "e6484d2f007455d2", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7503429d600cf104", "level": "note", "message": {"text": "Legacy-named symbol `bank_encryption_key_v2` in backend-python/scripts/rekey_bank_accounts.py:45"}, "properties": {"repobilityId": "dcf88d129bf32620", "scanner": "scanner-primary", "fingerprint": "7503429d600cf104", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-aef09c289f458e05", "level": "note", "message": {"text": "Legacy-named symbol `cron_sync_due_deprecated` in backend-python/src/sky/api/routers/internal.py:41"}, "properties": {"repobilityId": "9819f287a33378d4", "scanner": "scanner-primary", "fingerprint": "aef09c289f458e05", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-0a52b45a8b2a1ea6", "level": "none", "message": {"text": "Commented-code block (9 lines) in backend-python/src/sky/ingestion/rate_limiter.py:30"}, "properties": {"repobilityId": "d7acaf52167264e3", "scanner": "scanner-primary", "fingerprint": "0a52b45a8b2a1ea6", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f19e04d1db2136aa", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend-python/src/sky/ingestion/contracts.py:135"}, "properties": {"repobilityId": "58bf088aa2712f0a", "scanner": "scanner-primary", "fingerprint": "f19e04d1db2136aa", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-38291abdad3a509c", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend-python/src/sky/ingestion/sources/bci_scraper.py:94"}, "properties": {"repobilityId": "8cf1307c00230ffb", "scanner": "scanner-primary", "fingerprint": "38291abdad3a509c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0109648f6621a5d4", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend-python/src/sky/ingestion/sources/falabella_scraper.py:96"}, "properties": {"repobilityId": "8227506e055a9c15", "scanner": "scanner-primary", "fingerprint": "0109648f6621a5d4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-fe16527cfbd90956", "level": "none", "message": {"text": "Commented-code block (12 lines) in backend-python/src/sky/ingestion/sources/bchile_scraper.py:91"}, "properties": {"repobilityId": "0feb6f54f163e955", "scanner": "scanner-primary", "fingerprint": "fe16527cfbd90956", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c51dad15fe55ad32", "level": "note", "message": {"text": "Legacy-named symbol `bank_encryption_key_v2` in backend-python/src/sky/core/config.py:127"}, "properties": {"repobilityId": "df7547f89b183aa2", "scanner": "scanner-primary", "fingerprint": "c51dad15fe55ad32", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-87ad0a2524f6e358", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend-python/src/sky/core/config.py:133"}, "properties": {"repobilityId": "82cf72b8c37f5f13", "scanner": "scanner-primary", "fingerprint": "87ad0a2524f6e358", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-791a6cf2dc4d9912", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend-python/src/sky/core/audit.py:31"}, "properties": {"repobilityId": "315a1b4e665d3a95", "scanner": "scanner-primary", "fingerprint": "791a6cf2dc4d9912", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-0b62e91f518f5ab3", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend-python/src/sky/domain/merchant_feedback.py:41"}, "properties": {"repobilityId": "810073481435b333", "scanner": "scanner-primary", "fingerprint": "0b62e91f518f5ab3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ff89e9ee875ec33f", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend/scripts/runScheduledSync.js:7"}, "properties": {"repobilityId": "2489a79141297a4d", "scanner": "scanner-primary", "fingerprint": "ff89e9ee875ec33f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-201cb79d4be5673e", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/routes/internal.js:12"}, "properties": {"repobilityId": "4e087958ac53419e", "scanner": "scanner-primary", "fingerprint": "201cb79d4be5673e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-3be1a0b2e7f01878", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend/routes/banking.js:6"}, "properties": {"repobilityId": "86bf815db0089c33", "scanner": "scanner-primary", "fingerprint": "3be1a0b2e7f01878", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-226c8d1dac82756a", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/services/encryptionService.js:6"}, "properties": {"repobilityId": "8ac347834653fdd5", "scanner": "scanner-primary", "fingerprint": "226c8d1dac82756a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1eae27f73425b961", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/services/financeService.js:5"}, "properties": {"repobilityId": "c48472081939d4c1", "scanner": "scanner-primary", "fingerprint": "1eae27f73425b961", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c4ecac0b73757ad3", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend/services/schedulerService.js:6"}, "properties": {"repobilityId": "c0a7d61b2327ee83", "scanner": "scanner-primary", "fingerprint": "c4ecac0b73757ad3", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-d4dc663620921de7", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/services/aiService.js:4"}, "properties": {"repobilityId": "bdaf99263b8fad5f", "scanner": "scanner-primary", "fingerprint": "d4dc663620921de7", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-6764f73c4533c67a", "level": "none", "message": {"text": "Commented-code block (7 lines) in backend/services/categorizationQueueService.js:6"}, "properties": {"repobilityId": "41e75cf839d713d9", "scanner": "scanner-primary", "fingerprint": "6764f73c4533c67a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-398b2ef5cadd4d86", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/services/ariaService.js:4"}, "properties": {"repobilityId": "de70aaf09c10af52", "scanner": "scanner-primary", "fingerprint": "398b2ef5cadd4d86", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-173f1c1e1c346f46", "level": "none", "message": {"text": "Commented-code block (13 lines) in backend/services/bankSyncService.js:6"}, "properties": {"repobilityId": "553fe76a32bfb7bb", "scanner": "scanner-primary", "fingerprint": "173f1c1e1c346f46", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-8acc4cb3abee6442", "level": "none", "message": {"text": "Commented-code block (6 lines) in backend/services/banking.js:4"}, "properties": {"repobilityId": "83496876a8d6016b", "scanner": "scanner-primary", "fingerprint": "8acc4cb3abee6442", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-214ea6f960e16842", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/services/bankingAdapter.js:11"}, "properties": {"repobilityId": "bb2d49290048d145", "scanner": "scanner-primary", "fingerprint": "214ea6f960e16842", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1b5a76780c3df9aa", "level": "none", "message": {"text": "1 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "d04379b337b44a15", "scanner": "scanner-primary", "fingerprint": "1b5a76780c3df9aa", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "324cd5ba5632048e", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "d0ad62c3f3432ce2", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "f9a658581d004dfa", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "5fc5ed2f7b4e5e76", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "cb0a73e4000741ff", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-49c98f7cedd9c977", "level": "note", "message": {"text": "Near-duplicate function bodies in 4 places"}, "properties": {"repobilityId": "15cdacfc40d2e4df", "scanner": "scanner-primary", "fingerprint": "49c98f7cedd9c977", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "fdfe92f61f3df5f8", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-cb857759801a68c6", "level": "error", "message": {"text": "FastAPI POST `fintoc_webhook` without auth dependency \u2014 backend-python/src/sky/api/routers/webhooks.py:12"}, "properties": {"repobilityId": "8f23a3f3660a9b68", "scanner": "scanner-primary", "fingerprint": "cb857759801a68c6", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-python/src/sky/api/routers/webhooks.py"}, "region": {"startLine": 12}}}]}, {"ruleId": "scanner-fb2c2bd6e216043b", "level": "error", "message": {"text": "FastAPI POST `cron_sync_due` without auth dependency \u2014 backend-python/src/sky/api/routers/internal.py:29"}, "properties": {"repobilityId": "83ab53dbde5887d2", "scanner": "scanner-primary", "fingerprint": "fb2c2bd6e216043b", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend-python/src/sky/api/routers/internal.py"}, "region": {"startLine": 29}}}]}, {"ruleId": "scanner-7d193ebab08b9f31", "level": "error", "message": {"text": "Dangling fetch: GET /summary (frontend/src/services/api.js:76)"}, "properties": {"repobilityId": "74d5f0af8e3ab51a", "scanner": "scanner-primary", "fingerprint": "7d193ebab08b9f31", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-57b4b8fa49ebde72", "level": "error", "message": {"text": "Dangling fetch: GET /transactions?page=${page}&page_size=${page_size} (frontend/src/services/api.js:81)"}, "properties": {"repobilityId": "6fd802d1a49ad41d", "scanner": "scanner-primary", "fingerprint": "57b4b8fa49ebde72", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-3ccb2b4b1b4942c3", "level": "error", "message": {"text": "Dangling fetch: POST /transactions (frontend/src/services/api.js:85)"}, "properties": {"repobilityId": "57dc1962a1368403", "scanner": "scanner-primary", "fingerprint": "3ccb2b4b1b4942c3", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-4646d8183956a23b", "level": "error", "message": {"text": "Dangling fetch: PATCH /transactions/${id} (frontend/src/services/api.js:89)"}, "properties": {"repobilityId": "1d0032e9eed4d2c4", "scanner": "scanner-primary", "fingerprint": "4646d8183956a23b", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-c7f3a450147614ff", "level": "error", "message": {"text": "Dangling fetch: PATCH /transactions/${id}/merchant (frontend/src/services/api.js:96)"}, "properties": {"repobilityId": "5688d8a574c511f6", "scanner": "scanner-primary", "fingerprint": "c7f3a450147614ff", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-be0c3c7969f4f246", "level": "error", "message": {"text": "Dangling fetch: DELETE /transactions/${id} (frontend/src/services/api.js:103)"}, "properties": {"repobilityId": "0b388d8ead5a3f86", "scanner": "scanner-primary", "fingerprint": "be0c3c7969f4f246", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-9b852da4d0977dee", "level": "error", "message": {"text": "Dangling fetch: POST /chat (frontend/src/services/api.js:108)"}, "properties": {"repobilityId": "ab61fcfb4c480ae3", "scanner": "scanner-primary", "fingerprint": "9b852da4d0977dee", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-1b8880cdbba07315", "level": "error", "message": {"text": "Dangling fetch: GET /chat/history?limit=${limit} (frontend/src/services/api.js:112)"}, "properties": {"repobilityId": "42768896fe204428", "scanner": "scanner-primary", "fingerprint": "1b8880cdbba07315", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ce13bbd4bb873aac", "level": "error", "message": {"text": "Dangling fetch: GET /challenges (frontend/src/services/api.js:117)"}, "properties": {"repobilityId": "03722615065f53af", "scanner": "scanner-primary", "fingerprint": "ce13bbd4bb873aac", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-64e8e9e226b9adff", "level": "error", "message": {"text": "Dangling fetch: POST /challenges/${id}/activate (frontend/src/services/api.js:121)"}, "properties": {"repobilityId": "13559b6d36a82b1d", "scanner": "scanner-primary", "fingerprint": "64e8e9e226b9adff", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-fe4d7bd3f7092bba", "level": "error", "message": {"text": "Dangling fetch: POST /challenges/${id}/complete (frontend/src/services/api.js:125)"}, "properties": {"repobilityId": "da9859121bcc5d99", "scanner": "scanner-primary", "fingerprint": "fe4d7bd3f7092bba", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7ec517a0d6795c35", "level": "error", "message": {"text": "Dangling fetch: POST /simulate (frontend/src/services/api.js:130)"}, "properties": {"repobilityId": "3f3230e2c6ad4445", "scanner": "scanner-primary", "fingerprint": "7ec517a0d6795c35", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-abc3cc6dc73ee712", "level": "error", "message": {"text": "Dangling fetch: GET /goals (frontend/src/services/api.js:138)"}, "properties": {"repobilityId": "9ad0587489f0daa4", "scanner": "scanner-primary", "fingerprint": "abc3cc6dc73ee712", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-134b526e116c59a5", "level": "error", "message": {"text": "Dangling fetch: POST /goals (frontend/src/services/api.js:142)"}, "properties": {"repobilityId": "b0c59d2809045285", "scanner": "scanner-primary", "fingerprint": "134b526e116c59a5", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-fca83cef5198dfea", "level": "error", "message": {"text": "Dangling fetch: PATCH /goals/${id} (frontend/src/services/api.js:146)"}, "properties": {"repobilityId": "249dbc955515cafc", "scanner": "scanner-primary", "fingerprint": "fca83cef5198dfea", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7d9f085b301eb8ec", "level": "error", "message": {"text": "Dangling fetch: DELETE /goals/${id} (frontend/src/services/api.js:150)"}, "properties": {"repobilityId": "0fde25b567dd9fe4", "scanner": "scanner-primary", "fingerprint": "7d9f085b301eb8ec", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-0cfdc41eebfe4e67", "level": "error", "message": {"text": "Dangling fetch: PATCH /profile (frontend/src/services/api.js:155)"}, "properties": {"repobilityId": "1d223288877d556a", "scanner": "scanner-primary", "fingerprint": "0cfdc41eebfe4e67", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-7b050d1366449073", "level": "error", "message": {"text": "Dangling fetch: GET /banking/banks (frontend/src/services/api.js:161)"}, "properties": {"repobilityId": "1f43726407151b00", "scanner": "scanner-primary", "fingerprint": "7b050d1366449073", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-8fc2a6839ea70ff9", "level": "error", "message": {"text": "Dangling fetch: GET /banking/accounts (frontend/src/services/api.js:165)"}, "properties": {"repobilityId": "1999fcfb6684897b", "scanner": "scanner-primary", "fingerprint": "8fc2a6839ea70ff9", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-485d5a25e15ff325", "level": "error", "message": {"text": "Dangling fetch: POST /banking/accounts (frontend/src/services/api.js:169)"}, "properties": {"repobilityId": "881c6def793a2bdf", "scanner": "scanner-primary", "fingerprint": "485d5a25e15ff325", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-d9da2345d3f6459f", "level": "error", "message": {"text": "Dangling fetch: POST /banking/sync/${accountId} (frontend/src/services/api.js:176)"}, "properties": {"repobilityId": "10556dfdbd5d8f36", "scanner": "scanner-primary", "fingerprint": "d9da2345d3f6459f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-f653a01d358f4c90", "level": "error", "message": {"text": "Dangling fetch: POST /banking/sync-all (frontend/src/services/api.js:180)"}, "properties": {"repobilityId": "0533570d7dd0784f", "scanner": "scanner-primary", "fingerprint": "f653a01d358f4c90", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-22250454365e6c46", "level": "error", "message": {"text": "Dangling fetch: DELETE /banking/accounts/${accountId} (frontend/src/services/api.js:184)"}, "properties": {"repobilityId": "65f1f3ee82923bd5", "scanner": "scanner-primary", "fingerprint": "22250454365e6c46", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "1a027219a9534e23", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f683b6e8bb1592fe", "level": "note", "message": {"text": "Unused endpoint: POST /export-request"}, "properties": {"repobilityId": "a666e42d1e00f3a5", "scanner": "scanner-primary", "fingerprint": "f683b6e8bb1592fe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3f1c5ac307e90ae6", "level": "note", "message": {"text": "Unused endpoint: GET /export-request"}, "properties": {"repobilityId": "744060c4f2edf473", "scanner": "scanner-primary", "fingerprint": "3f1c5ac307e90ae6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a42fa2f81d4b7e32", "level": "note", "message": {"text": "Unused endpoint: GET /export-request/{request_id}"}, "properties": {"repobilityId": "cf12e4f80fddf157", "scanner": "scanner-primary", "fingerprint": "a42fa2f81d4b7e32", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-523614e7cfe014ad", "level": "note", "message": {"text": "Unused endpoint: GET /banks"}, "properties": {"repobilityId": "1353e3722bcca549", "scanner": "scanner-primary", "fingerprint": "523614e7cfe014ad", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-383442cf4adb1252", "level": "note", "message": {"text": "Unused endpoint: POST /sync/{account_id}"}, "properties": {"repobilityId": "ebe43190dfdaad26", "scanner": "scanner-primary", "fingerprint": "383442cf4adb1252", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2ab7e56c6fbe85d3", "level": "note", "message": {"text": "Unused endpoint: POST /sync-all"}, "properties": {"repobilityId": "8d02214d0277af40", "scanner": "scanner-primary", "fingerprint": "2ab7e56c6fbe85d3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-21c7ff7b8ef22c44", "level": "note", "message": {"text": "Unused endpoint: GET /accounts"}, "properties": {"repobilityId": "f84cb73115f94840", "scanner": "scanner-primary", "fingerprint": "21c7ff7b8ef22c44", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c04406fe463e162f", "level": "note", "message": {"text": "Unused endpoint: POST /accounts"}, "properties": {"repobilityId": "4491ef9d5bae45ea", "scanner": "scanner-primary", "fingerprint": "c04406fe463e162f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ef02d0e1f7da126f", "level": "note", "message": {"text": "Unused endpoint: DELETE /accounts/{account_id}"}, "properties": {"repobilityId": "ab09285cc0f19a50", "scanner": "scanner-primary", "fingerprint": "ef02d0e1f7da126f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4756b4c4da7d2088", "level": "note", "message": {"text": "Unused endpoint: GET /api/health"}, "properties": {"repobilityId": "55d46f97338e3fec", "scanner": "scanner-primary", "fingerprint": "4756b4c4da7d2088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-699ab6284738f549", "level": "note", "message": {"text": "Unused endpoint: GET /api/health/deep"}, "properties": {"repobilityId": "ef51cee47565dd23", "scanner": "scanner-primary", "fingerprint": "699ab6284738f549", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "b7881f55471c5f88", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-06da2cd01b982905", "level": "note", "message": {"text": "Unused endpoint: PATCH /{goal_id}"}, "properties": {"repobilityId": "1f50bb8e82c3f677", "scanner": "scanner-primary", "fingerprint": "06da2cd01b982905", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-750ef798a989378f", "level": "note", "message": {"text": "Unused endpoint: DELETE /{goal_id}"}, "properties": {"repobilityId": "556699796fbde25d", "scanner": "scanner-primary", "fingerprint": "750ef798a989378f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b671297c83981130", "level": "note", "message": {"text": "Unused endpoint: POST /projection"}, "properties": {"repobilityId": "434bfb2efe15fc29", "scanner": "scanner-primary", "fingerprint": "b671297c83981130", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-65cb84733062cec2", "level": "note", "message": {"text": "Unused endpoint: PATCH /{tx_id}"}, "properties": {"repobilityId": "64f9c6e629642161", "scanner": "scanner-primary", "fingerprint": "65cb84733062cec2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-085213235d638fcd", "level": "note", "message": {"text": "Unused endpoint: PATCH /{tx_id}/merchant"}, "properties": {"repobilityId": "cef8f4651160072b", "scanner": "scanner-primary", "fingerprint": "085213235d638fcd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-78caef94e492eeba", "level": "note", "message": {"text": "Unused endpoint: DELETE /{tx_id}"}, "properties": {"repobilityId": "4c3f695ada6d421e", "scanner": "scanner-primary", "fingerprint": "78caef94e492eeba", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-183609026a276985", "level": "note", "message": {"text": "Unused endpoint: POST /fintoc"}, "properties": {"repobilityId": "17f42c31e2baafdf", "scanner": "scanner-primary", "fingerprint": "183609026a276985", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dd19169ed693084c", "level": "note", "message": {"text": "Unused endpoint: POST /{challenge_id}/accept"}, "properties": {"repobilityId": "d609dfd2894d86af", "scanner": "scanner-primary", "fingerprint": "dd19169ed693084c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2c0cb6e1087bbffa", "level": "note", "message": {"text": "Unused endpoint: POST /{challenge_id}/activate"}, "properties": {"repobilityId": "075155cf7546acaf", "scanner": "scanner-primary", "fingerprint": "2c0cb6e1087bbffa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-85fea11c856af88d", "level": "note", "message": {"text": "Unused endpoint: POST /{challenge_id}/decline"}, "properties": {"repobilityId": "609dd73261bf59d8", "scanner": "scanner-primary", "fingerprint": "85fea11c856af88d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e6163fba2fcdc488", "level": "note", "message": {"text": "Unused endpoint: POST /{challenge_id}/complete"}, "properties": {"repobilityId": "e386f98a0b3ba626", "scanner": "scanner-primary", "fingerprint": "e6163fba2fcdc488", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6d05b1f5adfd3eac", "level": "note", "message": {"text": "Unused endpoint: PATCH /"}, "properties": {"repobilityId": "9bbd8dac260313de", "scanner": "scanner-primary", "fingerprint": "6d05b1f5adfd3eac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-afc064028ae39ea9", "level": "note", "message": {"text": "Unused endpoint: GET /history"}, "properties": {"repobilityId": "2da60f4cb5658a44", "scanner": "scanner-primary", "fingerprint": "afc064028ae39ea9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0b969917809e7cd6", "level": "note", "message": {"text": "Unused endpoint: POST /cron/sync-due"}, "properties": {"repobilityId": "b5dcd0153a80a3e5", "scanner": "scanner-primary", "fingerprint": "0b969917809e7cd6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-201275e8d14c0db7", "level": "note", "message": {"text": "Unused endpoint: GET /operator/sync-status"}, "properties": {"repobilityId": "8621210532ce7b29", "scanner": "scanner-primary", "fingerprint": "201275e8d14c0db7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd1dc91abf32142d", "level": "note", "message": {"text": "Unused endpoint: GET /me"}, "properties": {"repobilityId": "4c3748fe184ffd13", "scanner": "scanner-primary", "fingerprint": "fd1dc91abf32142d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2b92dc87a4256298", "level": "note", "message": {"text": "Unused endpoint: USE /api/chat"}, "properties": {"repobilityId": "9d872e816eff6150", "scanner": "scanner-primary", "fingerprint": "2b92dc87a4256298", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bab42d9ce9b7b7d4", "level": "note", "message": {"text": "Unused endpoint: USE /api/transactions"}, "properties": {"repobilityId": "85d5a6997470dc88", "scanner": "scanner-primary", "fingerprint": "bab42d9ce9b7b7d4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-517d7f60c494be2f", "level": "note", "message": {"text": "Unused endpoint: USE /api/summary"}, "properties": {"repobilityId": "da67c5a4ebd38efc", "scanner": "scanner-primary", "fingerprint": "517d7f60c494be2f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-00374c3abe79d6d9", "level": "note", "message": {"text": "Unused endpoint: USE /api/challenges"}, "properties": {"repobilityId": "234ad01c44148373", "scanner": "scanner-primary", "fingerprint": "00374c3abe79d6d9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-db30a2c591e4bf39", "level": "note", "message": {"text": "Unused endpoint: USE /api/simulate"}, "properties": {"repobilityId": "f881d185f926adb6", "scanner": "scanner-primary", "fingerprint": "db30a2c591e4bf39", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7522dc7e4529ffc2", "level": "note", "message": {"text": "Unused endpoint: USE /api/goals"}, "properties": {"repobilityId": "c7b1a4f8ba873284", "scanner": "scanner-primary", "fingerprint": "7522dc7e4529ffc2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-14dd5ee54e139c2a", "level": "note", "message": {"text": "Unused endpoint: USE /api/banking"}, "properties": {"repobilityId": "69249d5632c5fa59", "scanner": "scanner-primary", "fingerprint": "14dd5ee54e139c2a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e1c89316f317f0ad", "level": "note", "message": {"text": "Unused endpoint: USE /api/internal"}, "properties": {"repobilityId": "bd3866272d150271", "scanner": "scanner-primary", "fingerprint": "e1c89316f317f0ad", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a61c112b611f4bb", "level": "note", "message": {"text": "Unused endpoint: DELETE /:id"}, "properties": {"repobilityId": "239302400fefb140", "scanner": "scanner-primary", "fingerprint": "7a61c112b611f4bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-17ae4c961edce6d3", "level": "note", "message": {"text": "Unused endpoint: POST /:id/activate"}, "properties": {"repobilityId": "19a47d6b8aa2c992", "scanner": "scanner-primary", "fingerprint": "17ae4c961edce6d3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a005497d5a71980f", "level": "note", "message": {"text": "Unused endpoint: POST /:id/complete"}, "properties": {"repobilityId": "c45167827c65d5c8", "scanner": "scanner-primary", "fingerprint": "a005497d5a71980f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-17a818026a0fb6f8", "level": "note", "message": {"text": "Unused endpoint: POST /scheduled-sync"}, "properties": {"repobilityId": "a4130a24d78d0878", "scanner": "scanner-primary", "fingerprint": "17a818026a0fb6f8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-740eae78c4f4ce85", "level": "note", "message": {"text": "Unused endpoint: POST /process-queue"}, "properties": {"repobilityId": "fcf33993ecbfb7ac", "scanner": "scanner-primary", "fingerprint": "740eae78c4f4ce85", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5b6dd317aa700414", "level": "note", "message": {"text": "Unused endpoint: GET /queue-depth"}, "properties": {"repobilityId": "8e252613145a5c81", "scanner": "scanner-primary", "fingerprint": "5b6dd317aa700414", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8664e7608b8880ea", "level": "note", "message": {"text": "Unused endpoint: POST /connect"}, "properties": {"repobilityId": "cb712203f6227b03", "scanner": "scanner-primary", "fingerprint": "8664e7608b8880ea", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4a68f8b446dd2bd2", "level": "note", "message": {"text": "Unused endpoint: POST /sync/:id"}, "properties": {"repobilityId": "e5d3e90fcc1c0bdb", "scanner": "scanner-primary", "fingerprint": "4a68f8b446dd2bd2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d2a37c2e855bff00", "level": "note", "message": {"text": "Unused endpoint: DELETE /accounts/:id"}, "properties": {"repobilityId": "277791904a624c91", "scanner": "scanner-primary", "fingerprint": "d2a37c2e855bff00", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5fbc954f63526821", "level": "note", "message": {"text": "Unused endpoint: PATCH /:id"}, "properties": {"repobilityId": "94c5c263707ec1a8", "scanner": "scanner-primary", "fingerprint": "5fbc954f63526821", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}