{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-49a89c05aba81e59", "name": "Possibly dead Python function: verify_token", "shortDescription": {"text": "Possibly dead Python function: verify_token"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dc82b1411aecaf98", "name": "Possibly dead Python function: daily_generate", "shortDescription": {"text": "Possibly dead Python function: daily_generate"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-943eda0966666fe1", "name": "Stray `console.log` in TS/JS \u2014 src/server.js:780", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 src/server.js:780"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-79e654736ad59e30", "name": "Insecure pattern 'direct_innerhtml_assignment' in dashboard.html:149", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in dashboard.html:149"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-98e7529390fb314c", "name": "Insecure pattern 'direct_innerhtml_assignment' in subasta.html:165", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in subasta.html:165"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8e1c089dc69818e5", "name": "Insecure pattern 'direct_innerhtml_assignment' in council-scumm.html:2971", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in council-scumm.html:2971"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-295ca421bb549511", "name": "Insecure pattern 'direct_innerhtml_assignment' in teamwork.js:98", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in teamwork.js:98"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5dde93395e8e73b1", "name": "Insecure pattern 'direct_outerhtml_assignment' in teamwork.js:1110", "shortDescription": {"text": "Insecure pattern 'direct_outerhtml_assignment' in teamwork.js:1110"}, "fullDescription": {"text": "Found a known-risky pattern (direct_outerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cbe651325ca8c4c0", "name": "Insecure pattern 'insert_adjacent_html' in teamwork.js:1111", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in teamwork.js:1111"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-36fd5c46251b6e68", "name": "Insecure pattern 'node_child_process' in src/server.js:4", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/server.js:4"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-91274f11ef3c130e", "name": "Insecure pattern 'cors_wildcard' in src/server.js:34", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in src/server.js:34"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bb23e184d4ab7dd0", "name": "Insecure pattern 'node_child_process' in src/ssh-exec.js:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in src/ssh-exec.js:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-02d49222c4652189", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/app.js:227", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/app.js:227"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aae6acbd918ceee7", "name": "Insecure pattern 'direct_innerhtml_assignment' in docs/teamwork.js:98", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/teamwork.js:98"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-edb6f2e74079c15b", "name": "Insecure pattern 'direct_outerhtml_assignment' in docs/teamwork.js:1110", "shortDescription": {"text": "Insecure pattern 'direct_outerhtml_assignment' in docs/teamwork.js:1110"}, "fullDescription": {"text": "Found a known-risky pattern (direct_outerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1a4235c90db3686f", "name": "Insecure pattern 'insert_adjacent_html' in docs/teamwork.js:1111", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in docs/teamwork.js:1111"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c0c15880c09b9a37", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/game.html:822", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/game.html:822"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eb87e70844b461a4", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/dashboard.html:149", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/dashboard.html:149"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9d836a8d63690979", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/app.js:227", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/app.js:227"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-16680f61495adb3c", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/council-scumm.html:2760", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/council-scumm.html:2760"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-480315510b26b657", "name": "Insecure pattern 'direct_innerhtml_assignment' in public/teamwork.js:98", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/teamwork.js:98"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-945d6a255d8b41f3", "name": "Insecure pattern 'direct_outerhtml_assignment' in public/teamwork.js:1110", "shortDescription": {"text": "Insecure pattern 'direct_outerhtml_assignment' in public/teamwork.js:1110"}, "fullDescription": {"text": "Found a known-risky pattern (direct_outerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-24217d92a3954625", "name": "Insecure pattern 'insert_adjacent_html' in public/teamwork.js:1111", "shortDescription": {"text": "Insecure pattern 'insert_adjacent_html' in public/teamwork.js:1111"}, "fullDescription": {"text": "Found a known-risky pattern (insert_adjacent_html). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e4f658c0c00de0d4", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-448d8837178ae57a", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-dee1707abc5f72ce", "name": "Very large file: council-api.py (3863 lines)", "shortDescription": {"text": "Very large file: council-api.py (3863 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6cef8fbbaeb0cd15", "name": "Very large file: src/ssh-exec.js (2012 lines)", "shortDescription": {"text": "Very large file: src/ssh-exec.js (2012 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 14 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 30 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-11825279136b53a3", "name": "CI is configured but no tests are detected", "shortDescription": {"text": "CI is configured but no tests are detected"}, "fullDescription": {"text": "A CI pipeline exists, but the scan found no test files to gate. Opus labeled this generated-code pattern as config theater: release machinery exists, but it has little behavioral signal."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, tests. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f6f127bc7ff99d0d", "name": "Commented-code block (5 lines) in council-api.py:3225", "shortDescription": {"text": "Commented-code block (5 lines) in council-api.py:3225"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e3cae6631ef9f0fb", "name": "Blocking `time.sleep(...)` inside `async def yar_task_action` \u2014 council-api.py:1666", "shortDescription": {"text": "Blocking `time.sleep(...)` inside `async def yar_task_action` \u2014 council-api.py:1666"}, "fullDescription": {"text": "Sync I/O inside an async function blocks the event loop. While `time.sleep(...)` is running, *all* other coroutines on this loop are paused \u2014 silent throughput collapse under concurrency. Use the async equivalent (`httpx.AsyncClient`, `asyncio.sleep`, `aiofiles`) or wrap with `await asyncio.to_thread(...)`."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f0a1a1500a2faf1b", "name": "Blocking `time.sleep(...)` inside `async def yar_create_task` \u2014 council-api.py:1756", "shortDescription": {"text": "Blocking `time.sleep(...)` inside `async def yar_create_task` \u2014 council-api.py:1756"}, "fullDescription": {"text": "Sync I/O inside an async function blocks the event loop. While `time.sleep(...)` is running, *all* other coroutines on this loop are paused \u2014 silent throughput collapse under concurrency. Use the async equivalent (`httpx.AsyncClient`, `asyncio.sleep`, `aiofiles`) or wrap with `await asyncio.to_thread(...)`."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "high", "confidence": 1.0}}, {"id": "scanner-4399e611ca130956", "name": "Blocking `time.sleep(...)` inside `async def yar_projects` \u2014 council-api.py:1845", "shortDescription": {"text": "Blocking `time.sleep(...)` inside `async def yar_projects` \u2014 council-api.py:1845"}, "fullDescription": {"text": "Sync I/O inside an async function blocks the event loop. While `time.sleep(...)` is running, *all* other coroutines on this loop are paused \u2014 silent throughput collapse under concurrency. Use the async equivalent (`httpx.AsyncClient`, `asyncio.sleep`, `aiofiles`) or wrap with `await asyncio.to_thread(...)`."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d9df571a9e033c4e", "name": "`fetch()` without try/.catch or AbortSignal \u2014 tools/yarig-tasks-sync.mjs:69", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 tools/yarig-tasks-sync.mjs:69"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7d5f5468c7bbe3aa", "name": "`fetch()` without try/.catch or AbortSignal \u2014 tools/chatgpt-crear-worker.mjs:227", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 tools/chatgpt-crear-worker.mjs:227"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-49cb2735c5ba5925", "name": "`fetch()` without try/.catch or AbortSignal \u2014 docs/app.js:241", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 docs/app.js:241"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-fe4b8c779d6b891f", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/app.js:241", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/app.js:241"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2c8c249bb380e427", "name": "`fetch()` without try/.catch or AbortSignal \u2014 public/new-member.js:783", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/new-member.js:783"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\ncouncil-api.py:agent_ask_anthropic, council-api.py:agent_ask\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be46ea126aa5d8dc", "name": "Near-duplicate function bodies in 3 places", "shortDescription": {"text": "Near-duplicate function bodies in 3 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\ncouncil-api.py:yar_projects, council-api.py:prepare_yar_login_session, council-api.py:yar_logout_session\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f01b2d966144047", "name": "FastAPI POST `tube_import_to_stock` without auth dependency \u2014 council-api.py:2657", "shortDescription": {"text": "FastAPI POST `tube_import_to_stock` without auth dependency \u2014 council-api.py:2657"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a88eb0f0b0087653", "name": "FastAPI POST `council_import_to_stock` without auth dependency \u2014 council-api.py:2664", "shortDescription": {"text": "FastAPI POST `council_import_to_stock` without auth dependency \u2014 council-api.py:2664"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1e72a768a45c04d0", "name": "FastAPI POST `council_presentar` without auth dependency \u2014 council-api.py:2757", "shortDescription": {"text": "FastAPI POST `council_presentar` without auth dependency \u2014 council-api.py:2757"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-d2293b08285fedca", "name": "Dangling fetch: POST https://catbox.moe/user/api.php (tools/chatgpt-crear-worker.mjs:249)", "shortDescription": {"text": "Dangling fetch: POST https://catbox.moe/user/api.php (tools/chatgpt-crear-worker.mjs:249)"}, "fullDescription": {"text": "`tools/chatgpt-crear-worker.mjs:249` calls `POST https://catbox.moe/user/api.php` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/catbox.moe/user/api.php`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6ffe94decf053e92", "name": "Dangling fetch: POST /api/machines/${id}/sync (docs/app.js:241)", "shortDescription": {"text": "Dangling fetch: POST /api/machines/${id}/sync (docs/app.js:241)"}, "fullDescription": {"text": "`docs/app.js:241` calls `POST /api/machines/${id}/sync` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/machines/<p>/sync`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-0389ce91177d55bc", "name": "Dangling fetch: POST /api/machines/${id}/sync (public/app.js:241)", "shortDescription": {"text": "Dangling fetch: POST /api/machines/${id}/sync (public/app.js:241)"}, "fullDescription": {"text": "`public/app.js:241` calls `POST /api/machines/${id}/sync` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/machines/<p>/sync`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-cdf55e1978312c93", "name": "Dangling fetch: GET /api/machines (public/app.js:391)", "shortDescription": {"text": "Dangling fetch: GET /api/machines (public/app.js:391)"}, "fullDescription": {"text": "`public/app.js:391` calls `GET /api/machines` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/machines`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-6c2240c9c0c0db5f", "name": "Dangling fetch: GET /api/machines (public/new-member.js:773)", "shortDescription": {"text": "Dangling fetch: GET /api/machines (public/new-member.js:773)"}, "fullDescription": {"text": "`public/new-member.js:773` calls `GET /api/machines` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/machines`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-a1acad1cd80a3774", "name": "Dangling fetch: POST /api/machines (public/new-member.js:814)", "shortDescription": {"text": "Dangling fetch: POST /api/machines (public/new-member.js:814)"}, "fullDescription": {"text": "`public/new-member.js:814` calls `POST /api/machines` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/machines`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`council-api.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f92704cbd397bfc", "name": "Unused endpoint: POST /api/council/ask", "shortDescription": {"text": "Unused endpoint: POST /api/council/ask"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/ask` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a3bbccadab42ff9", "name": "Unused endpoint: POST /api/council/ask-one", "shortDescription": {"text": "Unused endpoint: POST /api/council/ask-one"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/ask-one` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-19b67e35e86b5e49", "name": "Unused endpoint: GET /api/council/models", "shortDescription": {"text": "Unused endpoint: GET /api/council/models"}, "fullDescription": {"text": "`council-api.py` declares `GET /api/council/models` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-20762f55ae30d23e", "name": "Unused endpoint: GET /api/council/yar-context", "shortDescription": {"text": "Unused endpoint: GET /api/council/yar-context"}, "fullDescription": {"text": "`council-api.py` declares `GET /api/council/yar-context` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dbc3d12378f72d7f", "name": "Unused endpoint: GET /api/council/yar-status", "shortDescription": {"text": "Unused endpoint: GET /api/council/yar-status"}, "fullDescription": {"text": "`council-api.py` declares `GET /api/council/yar-status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9199c8f280170e9f", "name": "Unused endpoint: GET /api/council/diario", "shortDescription": {"text": "Unused endpoint: GET /api/council/diario"}, "fullDescription": {"text": "`council-api.py` declares `GET /api/council/diario` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fa1696c948425c1a", "name": "Unused endpoint: POST /api/council/diario/append", "shortDescription": {"text": "Unused endpoint: POST /api/council/diario/append"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/diario/append` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2956d5e291df3f38", "name": "Unused endpoint: POST /api/council/yar-context", "shortDescription": {"text": "Unused endpoint: POST /api/council/yar-context"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/yar-context` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9298b6a3dad575ee", "name": "Unused endpoint: POST /api/council/yar-sync", "shortDescription": {"text": "Unused endpoint: POST /api/council/yar-sync"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/yar-sync` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6afe83744e1f2c8c", "name": "Unused endpoint: POST /api/council/yar-task-action", "shortDescription": {"text": "Unused endpoint: POST /api/council/yar-task-action"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/yar-task-action` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cb948bf622f595b2", "name": "Unused endpoint: POST /api/council/yar-create-task", "shortDescription": {"text": "Unused endpoint: POST /api/council/yar-create-task"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/yar-create-task` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1426472d6bf4f1ac", "name": "Unused endpoint: POST /api/council/yar-projects", "shortDescription": {"text": "Unused endpoint: POST /api/council/yar-projects"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/yar-projects` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bc77f8456aa71839", "name": "Unused endpoint: POST /api/council/yar-login", "shortDescription": {"text": "Unused endpoint: POST /api/council/yar-login"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/yar-login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-26305e6cf85c23eb", "name": "Unused endpoint: POST /api/council/yar-logout", "shortDescription": {"text": "Unused endpoint: POST /api/council/yar-logout"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/yar-logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5309efb2fffd3f30", "name": "Unused endpoint: POST /api/council/analyze-youtube", "shortDescription": {"text": "Unused endpoint: POST /api/council/analyze-youtube"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/analyze-youtube` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6e1f8a2cdde864d7", "name": "Unused endpoint: POST /api/council/importar-video", "shortDescription": {"text": "Unused endpoint: POST /api/council/importar-video"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/importar-video` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6c88d7aa408598d2", "name": "Unused endpoint: GET /api/council/importar-video/{job_id}", "shortDescription": {"text": "Unused endpoint: GET /api/council/importar-video/{job_id}"}, "fullDescription": {"text": "`council-api.py` declares `GET /api/council/importar-video/{job_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d7e602d330639ee", "name": "Unused endpoint: POST /tube/import-to-stock", "shortDescription": {"text": "Unused endpoint: POST /tube/import-to-stock"}, "fullDescription": {"text": "`council-api.py` declares `POST /tube/import-to-stock` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-04812e2fc625a12d", "name": "Unused endpoint: POST /api/council/import-to-stock", "shortDescription": {"text": "Unused endpoint: POST /api/council/import-to-stock"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/import-to-stock` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7754aa0e3a033e1a", "name": "Unused endpoint: GET /api/council/health", "shortDescription": {"text": "Unused endpoint: GET /api/council/health"}, "fullDescription": {"text": "`council-api.py` declares `GET /api/council/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e9df9b4fd7e95e2", "name": "Unused endpoint: GET /api/council/budget", "shortDescription": {"text": "Unused endpoint: GET /api/council/budget"}, "fullDescription": {"text": "`council-api.py` declares `GET /api/council/budget` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d103efb870294ad4", "name": "Unused endpoint: GET /api/council/presentation", "shortDescription": {"text": "Unused endpoint: GET /api/council/presentation"}, "fullDescription": {"text": "`council-api.py` declares `GET /api/council/presentation` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-79f862eb0fc07801", "name": "Unused endpoint: POST /api/council/presentar", "shortDescription": {"text": "Unused endpoint: POST /api/council/presentar"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/presentar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-153dfcba90277e42", "name": "Unused endpoint: GET /api/council/daily", "shortDescription": {"text": "Unused endpoint: GET /api/council/daily"}, "fullDescription": {"text": "`council-api.py` declares `GET /api/council/daily` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d758434173103e9e", "name": "Unused endpoint: POST /api/council/leer", "shortDescription": {"text": "Unused endpoint: POST /api/council/leer"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/leer` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4f889d434a7ea445", "name": "Unused endpoint: GET /api/council/entrenar/{gen}", "shortDescription": {"text": "Unused endpoint: GET /api/council/entrenar/{gen}"}, "fullDescription": {"text": "`council-api.py` declares `GET /api/council/entrenar/{gen}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7779e106647f6603", "name": "Unused endpoint: GET /api/council/entrenar/{gen}/{persona}", "shortDescription": {"text": "Unused endpoint: GET /api/council/entrenar/{gen}/{persona}"}, "fullDescription": {"text": "`council-api.py` declares `GET /api/council/entrenar/{gen}/{persona}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e601d0eb3ebaf700", "name": "Unused endpoint: POST /api/council/entrenar/{gen}/{persona}/merge", "shortDescription": {"text": "Unused endpoint: POST /api/council/entrenar/{gen}/{persona}/merge"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/entrenar/{gen}/{persona}/merge` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3b83a5b27a64dafb", "name": "Unused endpoint: POST /api/council/crear", "shortDescription": {"text": "Unused endpoint: POST /api/council/crear"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/crear` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7706fd61bce8fcaa", "name": "Unused endpoint: GET /api/council/crear/{job_id}", "shortDescription": {"text": "Unused endpoint: GET /api/council/crear/{job_id}"}, "fullDescription": {"text": "`council-api.py` declares `GET /api/council/crear/{job_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f2dde124a06b8827", "name": "Unused endpoint: GET /api/council/crear-pending", "shortDescription": {"text": "Unused endpoint: GET /api/council/crear-pending"}, "fullDescription": {"text": "`council-api.py` declares `GET /api/council/crear-pending` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fe84d7565876de98", "name": "Unused endpoint: POST /api/council/crear/claim", "shortDescription": {"text": "Unused endpoint: POST /api/council/crear/claim"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/crear/claim` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba82c07b90d90532", "name": "Unused endpoint: POST /api/council/crear/{job_id}/result", "shortDescription": {"text": "Unused endpoint: POST /api/council/crear/{job_id}/result"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/crear/{job_id}/result` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ce57176a2c9999f", "name": "Unused endpoint: POST /api/council/crear/{job_id}/error", "shortDescription": {"text": "Unused endpoint: POST /api/council/crear/{job_id}/error"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/crear/{job_id}/error` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-798db72bb5cb539d", "name": "Unused endpoint: POST /api/council/hackeo", "shortDescription": {"text": "Unused endpoint: POST /api/council/hackeo"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/hackeo` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-12ba89726fbca3fb", "name": "Unused endpoint: POST /api/council/hackeo/stop", "shortDescription": {"text": "Unused endpoint: POST /api/council/hackeo/stop"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/hackeo/stop` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d28abc942d91cd0a", "name": "Unused endpoint: POST /api/council/hackeo/discover-macs", "shortDescription": {"text": "Unused endpoint: POST /api/council/hackeo/discover-macs"}, "fullDescription": {"text": "`council-api.py` declares `POST /api/council/hackeo/discover-macs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/25147"}, "properties": {"repository": "csilvasantin/32.-ConsejoAdmiraNextGame", "repoUrl": "https://github.com/csilvasantin/32.-ConsejoAdmiraNextGame", "branch": "main"}, "results": [{"ruleId": "scanner-49a89c05aba81e59", "level": "note", "message": {"text": "Possibly dead Python function: verify_token"}, "properties": {"repobilityId": "6a5c4adccfca0a15", "scanner": "scanner-primary", "fingerprint": "49a89c05aba81e59", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "council-api.py:743"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dc82b1411aecaf98", "level": "note", "message": {"text": "Possibly dead Python function: daily_generate"}, "properties": {"repobilityId": "d2dceb4f7ffb35c6", "scanner": "scanner-primary", "fingerprint": "dc82b1411aecaf98", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "council-api.py:3121"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-943eda0966666fe1", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 src/server.js:780"}, "properties": {"repobilityId": "51ec0d6adae748e2", "scanner": "scanner-primary", "fingerprint": "943eda0966666fe1", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-79e654736ad59e30", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in dashboard.html:149"}, "properties": {"repobilityId": "3cddbad051d0bcc9", "scanner": "scanner-primary", "fingerprint": "79e654736ad59e30", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "dashboard.html"}, "region": {"startLine": 149}}}]}, {"ruleId": "scanner-98e7529390fb314c", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in subasta.html:165"}, "properties": {"repobilityId": "343ce8bb0fc3eb1a", "scanner": "scanner-primary", "fingerprint": "98e7529390fb314c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "subasta.html"}, "region": {"startLine": 165}}}]}, {"ruleId": "scanner-8e1c089dc69818e5", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in council-scumm.html:2971"}, "properties": {"repobilityId": "d49b539164d9c4b5", "scanner": "scanner-primary", "fingerprint": "8e1c089dc69818e5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "council-scumm.html"}, "region": {"startLine": 2971}}}]}, {"ruleId": "scanner-295ca421bb549511", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in teamwork.js:98"}, "properties": {"repobilityId": "0c37dd9ac0771ee5", "scanner": "scanner-primary", "fingerprint": "295ca421bb549511", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "teamwork.js"}, "region": {"startLine": 98}}}]}, {"ruleId": "scanner-5dde93395e8e73b1", "level": "warning", "message": {"text": "Insecure pattern 'direct_outerhtml_assignment' in teamwork.js:1110"}, "properties": {"repobilityId": "ce8b781a19956c64", "scanner": "scanner-primary", "fingerprint": "5dde93395e8e73b1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_outerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "teamwork.js"}, "region": {"startLine": 1110}}}]}, {"ruleId": "scanner-cbe651325ca8c4c0", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in teamwork.js:1111"}, "properties": {"repobilityId": "3aa91b2753b2cc18", "scanner": "scanner-primary", "fingerprint": "cbe651325ca8c4c0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "teamwork.js"}, "region": {"startLine": 1111}}}]}, {"ruleId": "scanner-36fd5c46251b6e68", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/server.js:4"}, "properties": {"repobilityId": "ecd1c02e6625591a", "scanner": "scanner-primary", "fingerprint": "36fd5c46251b6e68", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/server.js"}, "region": {"startLine": 4}}}]}, {"ruleId": "scanner-91274f11ef3c130e", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in src/server.js:34"}, "properties": {"repobilityId": "d45a416ef266a21a", "scanner": "scanner-primary", "fingerprint": "91274f11ef3c130e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/server.js"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-bb23e184d4ab7dd0", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in src/ssh-exec.js:1"}, "properties": {"repobilityId": "6e5641fdf4c5a07d", "scanner": "scanner-primary", "fingerprint": "bb23e184d4ab7dd0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "src/ssh-exec.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-02d49222c4652189", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/app.js:227"}, "properties": {"repobilityId": "5c1ec0cc9ba6fd66", "scanner": "scanner-primary", "fingerprint": "02d49222c4652189", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/app.js"}, "region": {"startLine": 227}}}]}, {"ruleId": "scanner-aae6acbd918ceee7", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in docs/teamwork.js:98"}, "properties": {"repobilityId": "c4facc0d33b80668", "scanner": "scanner-primary", "fingerprint": "aae6acbd918ceee7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/teamwork.js"}, "region": {"startLine": 98}}}]}, {"ruleId": "scanner-edb6f2e74079c15b", "level": "warning", "message": {"text": "Insecure pattern 'direct_outerhtml_assignment' in docs/teamwork.js:1110"}, "properties": {"repobilityId": "1ab26176f3e28ab4", "scanner": "scanner-primary", "fingerprint": "edb6f2e74079c15b", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_outerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/teamwork.js"}, "region": {"startLine": 1110}}}]}, {"ruleId": "scanner-1a4235c90db3686f", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in docs/teamwork.js:1111"}, "properties": {"repobilityId": "467773e1df6df777", "scanner": "scanner-primary", "fingerprint": "1a4235c90db3686f", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/teamwork.js"}, "region": {"startLine": 1111}}}]}, {"ruleId": "scanner-c0c15880c09b9a37", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/game.html:822"}, "properties": {"repobilityId": "ad5aa18e9cabee69", "scanner": "scanner-primary", "fingerprint": "c0c15880c09b9a37", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/game.html"}, "region": {"startLine": 822}}}]}, {"ruleId": "scanner-eb87e70844b461a4", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/dashboard.html:149"}, "properties": {"repobilityId": "547954c10b03e6e3", "scanner": "scanner-primary", "fingerprint": "eb87e70844b461a4", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/dashboard.html"}, "region": {"startLine": 149}}}]}, {"ruleId": "scanner-9d836a8d63690979", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/app.js:227"}, "properties": {"repobilityId": "5192b9054ebe3f07", "scanner": "scanner-primary", "fingerprint": "9d836a8d63690979", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/app.js"}, "region": {"startLine": 227}}}]}, {"ruleId": "scanner-16680f61495adb3c", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/council-scumm.html:2760"}, "properties": {"repobilityId": "6b34e13a47237559", "scanner": "scanner-primary", "fingerprint": "16680f61495adb3c", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/council-scumm.html"}, "region": {"startLine": 2760}}}]}, {"ruleId": "scanner-480315510b26b657", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in public/teamwork.js:98"}, "properties": {"repobilityId": "0dee722640b52047", "scanner": "scanner-primary", "fingerprint": "480315510b26b657", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/teamwork.js"}, "region": {"startLine": 98}}}]}, {"ruleId": "scanner-945d6a255d8b41f3", "level": "warning", "message": {"text": "Insecure pattern 'direct_outerhtml_assignment' in public/teamwork.js:1110"}, "properties": {"repobilityId": "73054dcaff631a47", "scanner": "scanner-primary", "fingerprint": "945d6a255d8b41f3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_outerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/teamwork.js"}, "region": {"startLine": 1110}}}]}, {"ruleId": "scanner-24217d92a3954625", "level": "warning", "message": {"text": "Insecure pattern 'insert_adjacent_html' in public/teamwork.js:1111"}, "properties": {"repobilityId": "4ed6d6d9ab434b7d", "scanner": "scanner-primary", "fingerprint": "24217d92a3954625", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "insert_adjacent_html"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "public/teamwork.js"}, "region": {"startLine": 1111}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-e4f658c0c00de0d4", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "0fb8c24a130cdd0a", "scanner": "scanner-primary", "fingerprint": "e4f658c0c00de0d4", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/pages.yml"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-e4f658c0c00de0d4", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "38cf1c8b667d348e", "scanner": "scanner-primary", "fingerprint": "e4f658c0c00de0d4", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/pages.yml"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-e4f658c0c00de0d4", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "7b2f6f2d816930a2", "scanner": "scanner-primary", "fingerprint": "e4f658c0c00de0d4", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/pages.yml"}, "region": {"startLine": 70}}}]}, {"ruleId": "scanner-e4f658c0c00de0d4", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "25e1fa3783e7cb32", "scanner": "scanner-primary", "fingerprint": "e4f658c0c00de0d4", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/pages.yml"}, "region": {"startLine": 76}}}]}, {"ruleId": "scanner-448d8837178ae57a", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "13af6451e15656fc", "scanner": "scanner-primary", "fingerprint": "448d8837178ae57a", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/pages.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-dee1707abc5f72ce", "level": "note", "message": {"text": "Very large file: council-api.py (3863 lines)"}, "properties": {"repobilityId": "992d6eafbfcfe93d", "scanner": "scanner-primary", "fingerprint": "dee1707abc5f72ce", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6cef8fbbaeb0cd15", "level": "note", "message": {"text": "Very large file: src/ssh-exec.js (2012 lines)"}, "properties": {"repobilityId": "691b1462c29d35e2", "scanner": "scanner-primary", "fingerprint": "6cef8fbbaeb0cd15", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "8a0e629812eac5b7", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "587c4a9664c3ec3e", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-11825279136b53a3", "level": "warning", "message": {"text": "CI is configured but no tests are detected"}, "properties": {"repobilityId": "0a04d79c78123658", "scanner": "scanner-primary", "fingerprint": "11825279136b53a3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "ci", "config-theater", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "d125f4a0e7824b49", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "45e30fb895ca40a1", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-f6f127bc7ff99d0d", "level": "none", "message": {"text": "Commented-code block (5 lines) in council-api.py:3225"}, "properties": {"repobilityId": "0afb1da292726018", "scanner": "scanner-primary", "fingerprint": "f6f127bc7ff99d0d", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e3cae6631ef9f0fb", "level": "error", "message": {"text": "Blocking `time.sleep(...)` inside `async def yar_task_action` \u2014 council-api.py:1666"}, "properties": {"repobilityId": "8c90392a82514941", "scanner": "scanner-primary", "fingerprint": "e3cae6631ef9f0fb", "layer": "quality", "severity": "high", "confidence": 1.0, "tags": ["integrity", "sync-io-in-async", "performance"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "council-api.py"}, "region": {"startLine": 1666}}}]}, {"ruleId": "scanner-f0a1a1500a2faf1b", "level": "error", "message": {"text": "Blocking `time.sleep(...)` inside `async def yar_create_task` \u2014 council-api.py:1756"}, "properties": {"repobilityId": "817ac0fdda8d9dd8", "scanner": "scanner-primary", "fingerprint": "f0a1a1500a2faf1b", "layer": "quality", "severity": "high", "confidence": 1.0, "tags": ["integrity", "sync-io-in-async", "performance"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "council-api.py"}, "region": {"startLine": 1756}}}]}, {"ruleId": "scanner-4399e611ca130956", "level": "error", "message": {"text": "Blocking `time.sleep(...)` inside `async def yar_projects` \u2014 council-api.py:1845"}, "properties": {"repobilityId": "0b5a78a126469beb", "scanner": "scanner-primary", "fingerprint": "4399e611ca130956", "layer": "quality", "severity": "high", "confidence": 1.0, "tags": ["integrity", "sync-io-in-async", "performance"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "council-api.py"}, "region": {"startLine": 1845}}}]}, {"ruleId": "scanner-d9df571a9e033c4e", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 tools/yarig-tasks-sync.mjs:69"}, "properties": {"repobilityId": "b2b04b429855ce16", "scanner": "scanner-primary", "fingerprint": "d9df571a9e033c4e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-7d5f5468c7bbe3aa", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 tools/chatgpt-crear-worker.mjs:227"}, "properties": {"repobilityId": "3ee45495c6dd2efa", "scanner": "scanner-primary", "fingerprint": "7d5f5468c7bbe3aa", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-49cb2735c5ba5925", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 docs/app.js:241"}, "properties": {"repobilityId": "32719865e526e5ed", "scanner": "scanner-primary", "fingerprint": "49cb2735c5ba5925", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-fe4b8c779d6b891f", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/app.js:241"}, "properties": {"repobilityId": "0fd13caf4674f843", "scanner": "scanner-primary", "fingerprint": "fe4b8c779d6b891f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-2c8c249bb380e427", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 public/new-member.js:783"}, "properties": {"repobilityId": "22843f327fcdd73a", "scanner": "scanner-primary", "fingerprint": "2c8c249bb380e427", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "d173c5ef8e70fb1f", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-be46ea126aa5d8dc", "level": "note", "message": {"text": "Near-duplicate function bodies in 3 places"}, "properties": {"repobilityId": "c967da1d4e87b762", "scanner": "scanner-primary", "fingerprint": "be46ea126aa5d8dc", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "b4e6c84d21d4d4f9", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-7f01b2d966144047", "level": "error", "message": {"text": "FastAPI POST `tube_import_to_stock` without auth dependency \u2014 council-api.py:2657"}, "properties": {"repobilityId": "3f25a34586121445", "scanner": "scanner-primary", "fingerprint": "7f01b2d966144047", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "council-api.py"}, "region": {"startLine": 2657}}}]}, {"ruleId": "scanner-a88eb0f0b0087653", "level": "error", "message": {"text": "FastAPI POST `council_import_to_stock` without auth dependency \u2014 council-api.py:2664"}, "properties": {"repobilityId": "1a68d59315c5585e", "scanner": "scanner-primary", "fingerprint": "a88eb0f0b0087653", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "council-api.py"}, "region": {"startLine": 2664}}}]}, {"ruleId": "scanner-1e72a768a45c04d0", "level": "error", "message": {"text": "FastAPI POST `council_presentar` without auth dependency \u2014 council-api.py:2757"}, "properties": {"repobilityId": "60dec0a1cbfe01aa", "scanner": "scanner-primary", "fingerprint": "1e72a768a45c04d0", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "council-api.py"}, "region": {"startLine": 2757}}}]}, {"ruleId": "scanner-d2293b08285fedca", "level": "error", "message": {"text": "Dangling fetch: POST https://catbox.moe/user/api.php (tools/chatgpt-crear-worker.mjs:249)"}, "properties": {"repobilityId": "aca4357268ba2b07", "scanner": "scanner-primary", "fingerprint": "d2293b08285fedca", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-6ffe94decf053e92", "level": "error", "message": {"text": "Dangling fetch: POST /api/machines/${id}/sync (docs/app.js:241)"}, "properties": {"repobilityId": "4f939915ea04d793", "scanner": "scanner-primary", "fingerprint": "6ffe94decf053e92", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-0389ce91177d55bc", "level": "error", "message": {"text": "Dangling fetch: POST /api/machines/${id}/sync (public/app.js:241)"}, "properties": {"repobilityId": "871613ebfa7e9442", "scanner": "scanner-primary", "fingerprint": "0389ce91177d55bc", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-cdf55e1978312c93", "level": "error", "message": {"text": "Dangling fetch: GET /api/machines (public/app.js:391)"}, "properties": {"repobilityId": "b7215db502d18322", "scanner": "scanner-primary", "fingerprint": "cdf55e1978312c93", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-6c2240c9c0c0db5f", "level": "error", "message": {"text": "Dangling fetch: GET /api/machines (public/new-member.js:773)"}, "properties": {"repobilityId": "ff919d9888839898", "scanner": "scanner-primary", "fingerprint": "6c2240c9c0c0db5f", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-a1acad1cd80a3774", "level": "error", "message": {"text": "Dangling fetch: POST /api/machines (public/new-member.js:814)"}, "properties": {"repobilityId": "ad3af96c13ce3025", "scanner": "scanner-primary", "fingerprint": "a1acad1cd80a3774", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "c72cbe42a2736961", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7f92704cbd397bfc", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/ask"}, "properties": {"repobilityId": "dc934a4b13078bc0", "scanner": "scanner-primary", "fingerprint": "7f92704cbd397bfc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4a3bbccadab42ff9", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/ask-one"}, "properties": {"repobilityId": "1542b9cb56ea42f6", "scanner": "scanner-primary", "fingerprint": "4a3bbccadab42ff9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-19b67e35e86b5e49", "level": "note", "message": {"text": "Unused endpoint: GET /api/council/models"}, "properties": {"repobilityId": "2611e2bba7a4d3be", "scanner": "scanner-primary", "fingerprint": "19b67e35e86b5e49", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-20762f55ae30d23e", "level": "note", "message": {"text": "Unused endpoint: GET /api/council/yar-context"}, "properties": {"repobilityId": "f2ee73beddd59eed", "scanner": "scanner-primary", "fingerprint": "20762f55ae30d23e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dbc3d12378f72d7f", "level": "note", "message": {"text": "Unused endpoint: GET /api/council/yar-status"}, "properties": {"repobilityId": "ff6f6e15b8f3500d", "scanner": "scanner-primary", "fingerprint": "dbc3d12378f72d7f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9199c8f280170e9f", "level": "note", "message": {"text": "Unused endpoint: GET /api/council/diario"}, "properties": {"repobilityId": "d0b9b1058d98b22a", "scanner": "scanner-primary", "fingerprint": "9199c8f280170e9f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fa1696c948425c1a", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/diario/append"}, "properties": {"repobilityId": "55de3cec80742f1e", "scanner": "scanner-primary", "fingerprint": "fa1696c948425c1a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2956d5e291df3f38", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/yar-context"}, "properties": {"repobilityId": "55e14900575b593a", "scanner": "scanner-primary", "fingerprint": "2956d5e291df3f38", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9298b6a3dad575ee", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/yar-sync"}, "properties": {"repobilityId": "cdfbcca17c40b943", "scanner": "scanner-primary", "fingerprint": "9298b6a3dad575ee", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6afe83744e1f2c8c", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/yar-task-action"}, "properties": {"repobilityId": "2f0cc19e719c1bf1", "scanner": "scanner-primary", "fingerprint": "6afe83744e1f2c8c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cb948bf622f595b2", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/yar-create-task"}, "properties": {"repobilityId": "e90f6f06293daa86", "scanner": "scanner-primary", "fingerprint": "cb948bf622f595b2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1426472d6bf4f1ac", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/yar-projects"}, "properties": {"repobilityId": "7e3f6978c80ed116", "scanner": "scanner-primary", "fingerprint": "1426472d6bf4f1ac", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-bc77f8456aa71839", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/yar-login"}, "properties": {"repobilityId": "7885988683ed3551", "scanner": "scanner-primary", "fingerprint": "bc77f8456aa71839", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-26305e6cf85c23eb", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/yar-logout"}, "properties": {"repobilityId": "b925515315f48547", "scanner": "scanner-primary", "fingerprint": "26305e6cf85c23eb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5309efb2fffd3f30", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/analyze-youtube"}, "properties": {"repobilityId": "be3aab21e4dcfa1b", "scanner": "scanner-primary", "fingerprint": "5309efb2fffd3f30", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6e1f8a2cdde864d7", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/importar-video"}, "properties": {"repobilityId": "913b3232c16ac3ab", "scanner": "scanner-primary", "fingerprint": "6e1f8a2cdde864d7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6c88d7aa408598d2", "level": "note", "message": {"text": "Unused endpoint: GET /api/council/importar-video/{job_id}"}, "properties": {"repobilityId": "b77c1559ff8296df", "scanner": "scanner-primary", "fingerprint": "6c88d7aa408598d2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8d7e602d330639ee", "level": "note", "message": {"text": "Unused endpoint: POST /tube/import-to-stock"}, "properties": {"repobilityId": "3750cc39b87f398f", "scanner": "scanner-primary", "fingerprint": "8d7e602d330639ee", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-04812e2fc625a12d", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/import-to-stock"}, "properties": {"repobilityId": "495acc7d2fdac199", "scanner": "scanner-primary", "fingerprint": "04812e2fc625a12d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7754aa0e3a033e1a", "level": "note", "message": {"text": "Unused endpoint: GET /api/council/health"}, "properties": {"repobilityId": "09dfa9ec6d91725f", "scanner": "scanner-primary", "fingerprint": "7754aa0e3a033e1a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3e9df9b4fd7e95e2", "level": "note", "message": {"text": "Unused endpoint: GET /api/council/budget"}, "properties": {"repobilityId": "1fe713c2ad311fc7", "scanner": "scanner-primary", "fingerprint": "3e9df9b4fd7e95e2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d103efb870294ad4", "level": "note", "message": {"text": "Unused endpoint: GET /api/council/presentation"}, "properties": {"repobilityId": "4fd44b6fbb15e72a", "scanner": "scanner-primary", "fingerprint": "d103efb870294ad4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-79f862eb0fc07801", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/presentar"}, "properties": {"repobilityId": "f416ef659b467130", "scanner": "scanner-primary", "fingerprint": "79f862eb0fc07801", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-153dfcba90277e42", "level": "note", "message": {"text": "Unused endpoint: GET /api/council/daily"}, "properties": {"repobilityId": "c33074f3150f81c7", "scanner": "scanner-primary", "fingerprint": "153dfcba90277e42", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d758434173103e9e", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/leer"}, "properties": {"repobilityId": "66cfeed3db46c631", "scanner": "scanner-primary", "fingerprint": "d758434173103e9e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4f889d434a7ea445", "level": "note", "message": {"text": "Unused endpoint: GET /api/council/entrenar/{gen}"}, "properties": {"repobilityId": "a56baa11e04b3b73", "scanner": "scanner-primary", "fingerprint": "4f889d434a7ea445", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7779e106647f6603", "level": "note", "message": {"text": "Unused endpoint: GET /api/council/entrenar/{gen}/{persona}"}, "properties": {"repobilityId": "c0ca23ca74d2f5e6", "scanner": "scanner-primary", "fingerprint": "7779e106647f6603", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e601d0eb3ebaf700", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/entrenar/{gen}/{persona}/merge"}, "properties": {"repobilityId": "43add9c000461a22", "scanner": "scanner-primary", "fingerprint": "e601d0eb3ebaf700", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3b83a5b27a64dafb", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/crear"}, "properties": {"repobilityId": "2f58ce9365dafc2e", "scanner": "scanner-primary", "fingerprint": "3b83a5b27a64dafb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7706fd61bce8fcaa", "level": "note", "message": {"text": "Unused endpoint: GET /api/council/crear/{job_id}"}, "properties": {"repobilityId": "2b5cedd8145ca121", "scanner": "scanner-primary", "fingerprint": "7706fd61bce8fcaa", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f2dde124a06b8827", "level": "note", "message": {"text": "Unused endpoint: GET /api/council/crear-pending"}, "properties": {"repobilityId": "80c42e5e250ccdb0", "scanner": "scanner-primary", "fingerprint": "f2dde124a06b8827", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fe84d7565876de98", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/crear/claim"}, "properties": {"repobilityId": "82b53a8d1ef82dfc", "scanner": "scanner-primary", "fingerprint": "fe84d7565876de98", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ba82c07b90d90532", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/crear/{job_id}/result"}, "properties": {"repobilityId": "fd41877fbaa8a9b3", "scanner": "scanner-primary", "fingerprint": "ba82c07b90d90532", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1ce57176a2c9999f", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/crear/{job_id}/error"}, "properties": {"repobilityId": "54b2a69f65e4acb4", "scanner": "scanner-primary", "fingerprint": "1ce57176a2c9999f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-798db72bb5cb539d", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/hackeo"}, "properties": {"repobilityId": "b921ad925bd90cf7", "scanner": "scanner-primary", "fingerprint": "798db72bb5cb539d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-12ba89726fbca3fb", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/hackeo/stop"}, "properties": {"repobilityId": "982c9ec35be38a6e", "scanner": "scanner-primary", "fingerprint": "12ba89726fbca3fb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d28abc942d91cd0a", "level": "note", "message": {"text": "Unused endpoint: POST /api/council/hackeo/discover-macs"}, "properties": {"repobilityId": "2c0f98bb8f86bbe4", "scanner": "scanner-primary", "fingerprint": "d28abc942d91cd0a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}