{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-85f3447bf2b08705", "name": "Insecure pattern 'cors_wildcard' in .claude/skills/aick-health-check/SKILL.md:290", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in .claude/skills/aick-health-check/SKILL.md:290"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-247ac42715a87c26", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-python@v5 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-000fbbef08cf2571", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/setup-python@v5 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 44 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-122f91b7f2906dc4", "name": "Agent authority lacks a verifier contract: .claude/settings.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/settings.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-57e3a2d6cd643a4f", "name": "Agent authority lacks a verifier contract: .claude/SECURITY.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/SECURITY.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-76a91aa6fb69c1ab", "name": "Agent instruction contains unpinned remote install: .claude/SECURITY.md", "shortDescription": {"text": "Agent instruction contains unpinned remote install: .claude/SECURITY.md"}, "fullDescription": {"text": "Remote install commands in agent instructions are a supply-chain risk, especially when an agent can execute shell commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7966b860a5a74d5a", "name": "Agent authority lacks a verifier contract: .claude/docs/troubleshooting.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/docs/troubleshooting.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-74cbb8cfabcbef5e", "name": "Agent authority lacks a verifier contract: .claude/docs/version-management.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/docs/version-management.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-28829a88ac0b1ea0", "name": "Agent authority lacks a verifier contract: .claude/templates/TEMPLATE-ENGINE.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/templates/TEMPLATE-ENGINE.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-967ab14ddb28e469", "name": "Agent authority lacks a verifier contract: .claude/templates/protocols/ai-crew-kit-cleanup.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/templates/protocols/ai-crew-kit-cleanup.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4f2e41644f384f93", "name": "Agent authority lacks a verifier contract: .claude/skills/aick-merge-pr/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-merge-pr/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c96bbb409e60e9b6", "name": "Agent authority lacks a verifier contract: .claude/skills/aick-plan/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-plan/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5d76e08680098fee", "name": "Agent authority lacks a verifier contract: .claude/skills/aick-backlog/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-backlog/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-90811cb4e4be8c3e", "name": "Agent authority lacks a verifier contract: .claude/skills/aick-status/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-status/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d75640a567877706", "name": "Agent authority lacks a verifier contract: .claude/skills/aick-fix/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-fix/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ca1121f9afbaac95", "name": "Agent authority lacks a verifier contract: .claude/skills/aick-create/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-create/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bfca5189f9a7647f", "name": "Agent authority lacks a verifier contract: .claude/skills/aick-validate/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-validate/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d2485c4bae3bf98c", "name": "Agent authority lacks a verifier contract: .claude/skills/aick-report/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-report/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2f555923860e373e", "name": "Agent authority lacks a verifier contract: .claude/skills/aick-upgrade/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-upgrade/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9fbb55923120c950", "name": "Agent authority lacks a verifier contract: .claude/skills/aick-feature/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-feature/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3b449120c03f017b", "name": "Agent authority lacks a verifier contract: .claude/skills/aick-review/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-review/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-501eefc8d41716f9", "name": "Agent authority lacks a verifier contract: .claude/skills/aick-retro/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-retro/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1cd51301bfed4059", "name": "Agent authority lacks a verifier contract: .claude/schemas/backlog.schema.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/schemas/backlog.schema.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-95f21a96cf6a7ae6", "name": "Agent instruction contains unpinned remote install: .claude/schemas/project.schema.json", "shortDescription": {"text": "Agent instruction contains unpinned remote install: .claude/schemas/project.schema.json"}, "fullDescription": {"text": "Remote install commands in agent instructions are a supply-chain risk, especially when an agent can execute shell commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b84ca39c0e3d934b", "name": "Agent authority lacks a verifier contract: .claude/schemas/migrations.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/schemas/migrations.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-89b7749406dc74f2", "name": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/README.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/README.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c584b20d537a9f6f", "name": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/negative/missing-command.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/negative/missing-command.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a5456f5f590d29b4", "name": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/negative/timeout-out-of-range.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/negative/timeout-out-of-range.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d7c2c88a399f00f5", "name": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/negative/additional-property.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/negative/additional-property.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-182f39c53b4a2a09", "name": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/negative/unknown-event.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/negative/unknown-event.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9cc72a99810c90b5", "name": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/positive/v2-full-hooks.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/positive/v2-full-hooks.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-58a80d5815f142e4", "name": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/positive/v2-future-events.json", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/positive/v2-future-events.json"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f2f87adb32a03847", "name": "Agent authority lacks a verifier contract: .claude/domains/_base/checklists/architecture.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/domains/_base/checklists/architecture.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-94371658e8841c9d", "name": "Agent authority lacks a verifier contract: .claude/domains/_base/checklists/security-basic.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/domains/_base/checklists/security-basic.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-008bbabd29643815", "name": "Agent instruction/config may expose a secret: .claude/domains/_base/conventions/deployment.md", "shortDescription": {"text": "Agent instruction/config may expose a secret: .claude/domains/_base/conventions/deployment.md"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-81b4a000ce8dfcea", "name": "Agent instruction/config may expose a secret: .claude/domains/_base/conventions/cache.md", "shortDescription": {"text": "Agent instruction/config may expose a secret: .claude/domains/_base/conventions/cache.md"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1df31e7bd8ea795f", "name": "Agent authority lacks a verifier contract: .claude/domains/_base/conventions/python-patterns.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/domains/_base/conventions/python-patterns.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3cb86acacb8dbc10", "name": "Agent authority lacks a verifier contract: .claude/domains/_base/conventions/message-queue.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/domains/_base/conventions/message-queue.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6f0292f8cce0b020", "name": "Agent authority lacks a verifier contract: .claude/domains/_base/conventions/logging.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/domains/_base/conventions/logging.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9dacee157edd1cc", "name": "Agent authority lacks a verifier contract: .claude/domains/general/README.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/domains/general/README.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0a280570127e363b", "name": "Agent authority lacks a verifier contract: .claude/domains/general/docs/getting-started.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/domains/general/docs/getting-started.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b912251a5be1e2c3", "name": "Agent authority lacks a verifier contract: examples/merge-gate-demo/CLAUDE.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: examples/merge-gate-demo/CLAUDE.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-59ddfee925921081", "name": "Legacy-named symbol `app_v2` in tests/skill_init/test_sanitization.py:26", "shortDescription": {"text": "Legacy-named symbol `app_v2` in tests/skill_init/test_sanitization.py:26"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4d4899bc125ad08e", "name": "Commented-code block (7 lines) in tests/skill_init/test_schema_compliance.py:251", "shortDescription": {"text": "Commented-code block (7 lines) in tests/skill_init/test_schema_compliance.py:251"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/22639"}, "properties": {"repository": "wejsa/ai-crew-kit", "repoUrl": "https://github.com/wejsa/ai-crew-kit", "branch": "main"}, "results": [{"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-85f3447bf2b08705", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in .claude/skills/aick-health-check/SKILL.md:290"}, "properties": {"repobilityId": "690ee3d756f4cc56", "scanner": "scanner-primary", "fingerprint": "85f3447bf2b08705", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/aick-health-check/SKILL.md"}, "region": {"startLine": 290}}}]}, {"ruleId": "scanner-247ac42715a87c26", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "6aeb5819cdbb391c", "scanner": "scanner-primary", "fingerprint": "247ac42715a87c26", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/schema-validation.yml"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-000fbbef08cf2571", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b20f929169d530e8", "scanner": "scanner-primary", "fingerprint": "000fbbef08cf2571", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/aick-init-tests.yml"}, "region": {"startLine": 33}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "155ef27938290141", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "90dc54b43a01b197", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "a57f301bafe15d91", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-122f91b7f2906dc4", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/settings.json"}, "properties": {"repobilityId": "a2967269048b6a9d", "scanner": "scanner-primary", "fingerprint": "122f91b7f2906dc4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/settings.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-57e3a2d6cd643a4f", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/SECURITY.md"}, "properties": {"repobilityId": "235cd8d4c07a93df", "scanner": "scanner-primary", "fingerprint": "57e3a2d6cd643a4f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/SECURITY.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-76a91aa6fb69c1ab", "level": "warning", "message": {"text": "Agent instruction contains unpinned remote install: .claude/SECURITY.md"}, "properties": {"repobilityId": "8fa74e683bef6ea9", "scanner": "scanner-primary", "fingerprint": "76a91aa6fb69c1ab", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "supply-chain", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/SECURITY.md"}, "region": {"startLine": 22}}}]}, {"ruleId": "scanner-7966b860a5a74d5a", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/docs/troubleshooting.md"}, "properties": {"repobilityId": "8a9b2cfbcd609634", "scanner": "scanner-primary", "fingerprint": "7966b860a5a74d5a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/docs/troubleshooting.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-74cbb8cfabcbef5e", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/docs/version-management.md"}, "properties": {"repobilityId": "5abfc53034ec0b93", "scanner": "scanner-primary", "fingerprint": "74cbb8cfabcbef5e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/docs/version-management.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-28829a88ac0b1ea0", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/templates/TEMPLATE-ENGINE.md"}, "properties": {"repobilityId": "1061d0ad8f6108c8", "scanner": "scanner-primary", "fingerprint": "28829a88ac0b1ea0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/templates/TEMPLATE-ENGINE.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-967ab14ddb28e469", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/templates/protocols/ai-crew-kit-cleanup.md"}, "properties": {"repobilityId": "7daeb3a040ca5a16", "scanner": "scanner-primary", "fingerprint": "967ab14ddb28e469", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/templates/protocols/ai-crew-kit-cleanup.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4f2e41644f384f93", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-merge-pr/SKILL.md"}, "properties": {"repobilityId": "788d7decc46aa71b", "scanner": "scanner-primary", "fingerprint": "4f2e41644f384f93", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/aick-merge-pr/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c96bbb409e60e9b6", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-plan/SKILL.md"}, "properties": {"repobilityId": "f36e82b9aa57d158", "scanner": "scanner-primary", "fingerprint": "c96bbb409e60e9b6", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/aick-plan/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5d76e08680098fee", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-backlog/SKILL.md"}, "properties": {"repobilityId": "0f0a05fcc30c28b4", "scanner": "scanner-primary", "fingerprint": "5d76e08680098fee", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/aick-backlog/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-90811cb4e4be8c3e", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-status/SKILL.md"}, "properties": {"repobilityId": "4d0caf64df46704c", "scanner": "scanner-primary", "fingerprint": "90811cb4e4be8c3e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/aick-status/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d75640a567877706", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-fix/SKILL.md"}, "properties": {"repobilityId": "b36298171d12e414", "scanner": "scanner-primary", "fingerprint": "d75640a567877706", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/aick-fix/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ca1121f9afbaac95", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-create/SKILL.md"}, "properties": {"repobilityId": "793038ed69be7709", "scanner": "scanner-primary", "fingerprint": "ca1121f9afbaac95", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/aick-create/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-bfca5189f9a7647f", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-validate/SKILL.md"}, "properties": {"repobilityId": "1da5f116f5c74ab3", "scanner": "scanner-primary", "fingerprint": "bfca5189f9a7647f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/aick-validate/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d2485c4bae3bf98c", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-report/SKILL.md"}, "properties": {"repobilityId": "a3f79b8e3dbd147a", "scanner": "scanner-primary", "fingerprint": "d2485c4bae3bf98c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/aick-report/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2f555923860e373e", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-upgrade/SKILL.md"}, "properties": {"repobilityId": "7726c7d2cfde0f9f", "scanner": "scanner-primary", "fingerprint": "2f555923860e373e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/aick-upgrade/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9fbb55923120c950", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-feature/SKILL.md"}, "properties": {"repobilityId": "610166a45f9b9946", "scanner": "scanner-primary", "fingerprint": "9fbb55923120c950", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/aick-feature/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3b449120c03f017b", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-review/SKILL.md"}, "properties": {"repobilityId": "001f517ea78f08fc", "scanner": "scanner-primary", "fingerprint": "3b449120c03f017b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/aick-review/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-501eefc8d41716f9", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/aick-retro/SKILL.md"}, "properties": {"repobilityId": "c53f277bfa6b60fd", "scanner": "scanner-primary", "fingerprint": "501eefc8d41716f9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/aick-retro/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1cd51301bfed4059", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/schemas/backlog.schema.json"}, "properties": {"repobilityId": "9fd277b63bf1d30a", "scanner": "scanner-primary", "fingerprint": "1cd51301bfed4059", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/schemas/backlog.schema.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-95f21a96cf6a7ae6", "level": "warning", "message": {"text": "Agent instruction contains unpinned remote install: .claude/schemas/project.schema.json"}, "properties": {"repobilityId": "6ad5340de6b0c06c", "scanner": "scanner-primary", "fingerprint": "95f21a96cf6a7ae6", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "supply-chain", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/schemas/project.schema.json"}, "region": {"startLine": 486}}}]}, {"ruleId": "scanner-b84ca39c0e3d934b", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/schemas/migrations.json"}, "properties": {"repobilityId": "9797907ae6b44c2d", "scanner": "scanner-primary", "fingerprint": "b84ca39c0e3d934b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/schemas/migrations.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-89b7749406dc74f2", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/README.md"}, "properties": {"repobilityId": "bdc7eae7e6b4cf09", "scanner": "scanner-primary", "fingerprint": "89b7749406dc74f2", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/schemas/fixtures/README.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-c584b20d537a9f6f", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/negative/missing-command.json"}, "properties": {"repobilityId": "7b917049c115a0ca", "scanner": "scanner-primary", "fingerprint": "c584b20d537a9f6f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/schemas/fixtures/negative/missing-command.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-a5456f5f590d29b4", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/negative/timeout-out-of-range.json"}, "properties": {"repobilityId": "931ef0b9ff9a2fa5", "scanner": "scanner-primary", "fingerprint": "a5456f5f590d29b4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/schemas/fixtures/negative/timeout-out-of-range.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d7c2c88a399f00f5", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/negative/additional-property.json"}, "properties": {"repobilityId": "e303ca129676b8e6", "scanner": "scanner-primary", "fingerprint": "d7c2c88a399f00f5", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/schemas/fixtures/negative/additional-property.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-182f39c53b4a2a09", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/negative/unknown-event.json"}, "properties": {"repobilityId": "311428fbd084766b", "scanner": "scanner-primary", "fingerprint": "182f39c53b4a2a09", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/schemas/fixtures/negative/unknown-event.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9cc72a99810c90b5", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/positive/v2-full-hooks.json"}, "properties": {"repobilityId": "87d9857c06f86766", "scanner": "scanner-primary", "fingerprint": "9cc72a99810c90b5", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/schemas/fixtures/positive/v2-full-hooks.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-58a80d5815f142e4", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/schemas/fixtures/positive/v2-future-events.json"}, "properties": {"repobilityId": "874e97d338e39bf8", "scanner": "scanner-primary", "fingerprint": "58a80d5815f142e4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/schemas/fixtures/positive/v2-future-events.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f2f87adb32a03847", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/domains/_base/checklists/architecture.md"}, "properties": {"repobilityId": "bec0be0a6252b728", "scanner": "scanner-primary", "fingerprint": "f2f87adb32a03847", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/domains/_base/checklists/architecture.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-94371658e8841c9d", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/domains/_base/checklists/security-basic.md"}, "properties": {"repobilityId": "bc2d72d09a374adb", "scanner": "scanner-primary", "fingerprint": "94371658e8841c9d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/domains/_base/checklists/security-basic.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-008bbabd29643815", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .claude/domains/_base/conventions/deployment.md"}, "properties": {"repobilityId": "e8c0070faa4212f7", "scanner": "scanner-primary", "fingerprint": "008bbabd29643815", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/domains/_base/conventions/deployment.md"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-81b4a000ce8dfcea", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .claude/domains/_base/conventions/cache.md"}, "properties": {"repobilityId": "b30c4aec341f4b41", "scanner": "scanner-primary", "fingerprint": "81b4a000ce8dfcea", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/domains/_base/conventions/cache.md"}, "region": {"startLine": 44}}}]}, {"ruleId": "scanner-1df31e7bd8ea795f", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/domains/_base/conventions/python-patterns.md"}, "properties": {"repobilityId": "575cb4c16db1d1f2", "scanner": "scanner-primary", "fingerprint": "1df31e7bd8ea795f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/domains/_base/conventions/python-patterns.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3cb86acacb8dbc10", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/domains/_base/conventions/message-queue.md"}, "properties": {"repobilityId": "6929a8a994dcd212", "scanner": "scanner-primary", "fingerprint": "3cb86acacb8dbc10", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/domains/_base/conventions/message-queue.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-6f0292f8cce0b020", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/domains/_base/conventions/logging.md"}, "properties": {"repobilityId": "5d960501ccde94af", "scanner": "scanner-primary", "fingerprint": "6f0292f8cce0b020", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/domains/_base/conventions/logging.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b9dacee157edd1cc", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/domains/general/README.md"}, "properties": {"repobilityId": "4727b0d062d868d5", "scanner": "scanner-primary", "fingerprint": "b9dacee157edd1cc", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/domains/general/README.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0a280570127e363b", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/domains/general/docs/getting-started.md"}, "properties": {"repobilityId": "3f59fa9a9a031976", "scanner": "scanner-primary", "fingerprint": "0a280570127e363b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/domains/general/docs/getting-started.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b912251a5be1e2c3", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: examples/merge-gate-demo/CLAUDE.md"}, "properties": {"repobilityId": "7024becb955e2edf", "scanner": "scanner-primary", "fingerprint": "b912251a5be1e2c3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "examples/merge-gate-demo/CLAUDE.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-59ddfee925921081", "level": "note", "message": {"text": "Legacy-named symbol `app_v2` in tests/skill_init/test_sanitization.py:26"}, "properties": {"repobilityId": "289361e08b9f4087", "scanner": "scanner-primary", "fingerprint": "59ddfee925921081", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-4d4899bc125ad08e", "level": "none", "message": {"text": "Commented-code block (7 lines) in tests/skill_init/test_schema_compliance.py:251"}, "properties": {"repobilityId": "eca0131534efce47", "scanner": "scanner-primary", "fingerprint": "4d4899bc125ad08e", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}]}]}