{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "foundry_unresolved_feedback", "name": "Foundry mined unresolved feedback: TheMorpheus407/morphcook", "shortDescription": {"text": "Foundry mined unresolved feedback: TheMorpheus407/morphcook"}, "fullDescription": {"text": "Graph query export: Human feedback without linked fix evidence\nQuery id: unresolved_feedback\nQuery type: motif_query\nIntent: Negative/unresolved examples that should not be hallucinated into fixes.\nMotif: unlinked_feedback_needs_evidence\nTraining usage: negative_or_unresolved\nGraph gold label: needs_more_evidence\nRepo: TheMorpheus407/morphcook\nThread: TheMorpheus407/morphcook#2\nEvidence:\nGraph motif: Human feedback exists without a linked fix\nMotif id: unlinked_feedback_needs_evidence\nPolarity: bad\nTraining usage: negative_or_unresolved\nSeverity: medium\nRepo: TheMorpheus407/morphcook\nThread: TheMorpheus407/morphcook#2\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: TheMorpheus407/morphcook#2\nRepo: TheMorpheus407/morphcook\nIssue/PR number: 2\nGraph consistency label: needs_more_evidence\nNodes: 9\nEdges: 11\nNode types: {'link_quality': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "medium", "confidence": 0.7, "cwe": "", "owasp": ""}}, {"id": "foundry_bad_chain", "name": "Foundry mined bad chains: TheMorpheus407/morphcook", "shortDescription": {"text": "Foundry mined bad chains: TheMorpheus407/morphcook"}, "fullDescription": {"text": "Comment chain pattern product: bad_chains\nRepo: TheMorpheus407/morphcook\nThread: TheMorpheus407/morphcook#2\nOutcome: not_resolved_or_not_observed\nThread label: thread_has_human_issue_without_fix_context\nSource graph label: source_artifact_without_verification_graph\nReasons: source_graph_has_real_artifacts, link_quality_unresolved\nChain evidence:\nIssue/PR evidence chain: TheMorpheus407/morphcook#2\nRepo: TheMorpheus407/morphcook\nThread label: thread_has_human_issue_without_fix_context\nOutcome: not_resolved_or_not_observed\nComment count: 1\nLinked commit count: 0\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 0\nLabels: {'agent_instruction_gap': 1}\nPolarities: {'bad': 1}\nChanged file labels: {}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-1b32777c2db19a27\",\n    \"kind\": \"issue_body\",\n    \"label\": \"agent_instruction_gap\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/TheMorpheus407/morphcook/issues/2\",\n    \"text\": \"GitHub feedback: agent_instruction_gap\\nPola"}, "properties": {"scanner": "foundry_dataset", "category": "practices", "severity": "high", "confidence": 0.84, "cwe": "", "owasp": ""}}, {"id": "foundry_auth_guardrail_gap", "name": "Foundry mined security auth guardrail gaps: TheMorpheus407/morphcook", "shortDescription": {"text": "Foundry mined security auth guardrail gaps: TheMorpheus407/morphcook"}, "fullDescription": {"text": "Graph query export: Security/auth changes without enough guardrails\nQuery id: security_auth_guardrail_gaps\nQuery type: motif_query\nIntent: Assumption-check security/auth examples requiring stronger tests or CI.\nMotif: security_auth_without_guardrails\nTraining usage: assumption_check\nGraph gold label: needs_more_evidence\nRepo: TheMorpheus407/morphcook\nThread: TheMorpheus407/morphcook#1\nEvidence:\nGraph motif: Security/auth change without enough guardrails\nMotif id: security_auth_without_guardrails\nPolarity: bad\nTraining usage: assumption_check\nSeverity: critical\nRepo: TheMorpheus407/morphcook\nThread: TheMorpheus407/morphcook#1\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: TheMorpheus407/morphcook#1\nRepo: TheMorpheus407/morphcook\nIssue/PR number: 1\nGraph consistency label: needs_more_evidence\nNodes: 12\nEdges: 16\nNode types: {'link_quality': 4, 'comment': 2, 'comment_chain': 2, 'thread': 1, 'repo': 1, 'issue_chain': 1, 'fix_outcome':"}, "properties": {"scanner": "foundry_dataset", "category": "auth", "severity": "critical", "confidence": 0.78, "cwe": "", "owasp": ""}}, {"id": "scanner-084e655634455d1c", "name": "Possibly dead Python function: key", "shortDescription": {"text": "Possibly dead Python function: key"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9710c8d059e53154", "name": "No frontend routes/components detected", "shortDescription": {"text": "No frontend routes/components detected"}, "fullDescription": {"text": "No React/Vue/Next routes were found. This is fine for backend-only repos."}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f56dc12786a58ba7", "name": "Very large file: claude-fable-5/pipeline/wave4_lattice.py (1712 lines)", "shortDescription": {"text": "Very large file: claude-fable-5/pipeline/wave4_lattice.py (1712 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 4 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 43 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: ci, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1e8c89b93925169a", "name": "Network/subprocess call without timeout or try/except \u2014 claude-fable-5/deploy/publish_play.py:60", "shortDescription": {"text": "Network/subprocess call without timeout or try/except \u2014 claude-fable-5/deploy/publish_play.py:60"}, "fullDescription": {"text": "`subprocess.run(...)` here lacks both a `timeout=` arg and an enclosing try/except. This is exactly the class of bug that took down our git-clone earlier (HTTP/2 stream cancel surfaced as a fatal). Add a `timeout=` and wrap in try/except, or use a wrapper that retries."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f4e4ec947ab57569", "name": "Legacy-named symbol `ing_copy` in claude-fable-5/pipeline/wave4_lattice.py:1473", "shortDescription": {"text": "Legacy-named symbol `ing_copy` in claude-fable-5/pipeline/wave4_lattice.py:1473"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c04133e54348533", "name": "Near-duplicate function bodies in 2 places", "shortDescription": {"text": "Near-duplicate function bodies in 2 places"}, "fullDescription": {"text": "Functions with the same first-5-line body hash:\nclaude-fable-5/pipeline/wave4_lattice.py:walk, claude-fable-5/pipeline/wave4_lattice.py:walk\n\nThis is *the* AI-coder failure mode (4\u00d7 more duplication in vibe-coded repos \u2014 see https://jw.hn/ai-code-hygiene). Consolidate or document why they're separate."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/21128"}, "properties": {"repository": "TheMorpheus407/morphcook", "repoUrl": "https://github.com/TheMorpheus407/morphcook", "branch": "main"}, "results": [{"ruleId": "foundry_unresolved_feedback", "level": "warning", "message": {"text": "Foundry mined unresolved feedback: TheMorpheus407/morphcook"}, "properties": {"repobilityId": 361634, "scanner": "foundry_dataset", "fingerprint": "64a0a76f9658deae35a1ecf10d6efecb8d6d756e96895bcd62d528b044d4004c", "category": "practices", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback without linked fix evidence", "intent": "Negative/unresolved examples that should not be hallucinated into fixes.", "labels": {"agent_instruction_gap": 1, "issue_or_pull_request_thread": 1, "not_resolved_or_not_observed": 3, "human_reported_issue_no_linked_fix": 1, "thread_has_human_issue_without_fix_context": 2}, "source": "graph_query_export", "motif_id": "unlinked_feedback_needs_evidence", "outcomes": {"not_resolved_or_not_observed": 6}, "polarity": "bad", "query_id": "unresolved_feedback", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 11, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 1, "thread_has_comment": 1, "chain_has_link_quality": 3, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "thread_has_comment_chain": 1, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 1}, "node_count": 9, "node_types": {"repo": 1, "thread": 1, "comment": 1, "fix_outcome": 1, "issue_chain": 1, "link_quality": 3, "comment_chain": 1}, "query_type": "motif_query", "thread_key": "TheMorpheus407/morphcook#2", "issue_number": "2", "quality_tiers": {"unresolved": 3}, "repo_full_name": "TheMorpheus407/morphcook", "training_usage": "negative_or_unresolved", "source_motif_id": "graph-pattern-motif-thread-a886b9480dc0dc9c", "graph_gold_label": "needs_more_evidence", "changed_file_labels": {}}, "text": "Graph query export: Human feedback without linked fix evidence\nQuery id: unresolved_feedback\nQuery type: motif_query\nIntent: Negative/unresolved examples that should not be hallucinated into fixes.\nMotif: unlinked_feedback_needs_evidence\nTraining usage: negative_or_unresolved\nGraph gold label: needs_more_evidence\nRepo: TheMorpheus407/morphcook\nThread: TheMorpheus407/morphcook#2\nEvidence:\nGraph motif: Human feedback exists without a linked fix\nMotif id: unlinked_feedback_needs_evidence\nPolarity: bad\nTraining usage: negative_or_unresolved\nSeverity: medium\nRepo: TheMorpheus407/morphcook\nThread: TheMorpheus407/morphcook#2\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: TheMorpheus407/morphcook#2\nRepo: TheMorpheus407/morphcook\nIssue/PR number: 2\nGraph consistency label: needs_more_evidence\nNodes: 9\nEdges: 11\nNode types: {'link_quality': 3, 'thread': 1, 'repo': 1, 'comment': 1, 'comment_chain': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 3, 'repo_has_thread': 1, 'thread_has_comment': 1, 'thread_has_comment_chain': 1, 'comment_has_chain': 1, 'thread_has_issue_chain': 1, 'issue_chain_has_comment_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'not_resolved_or_not_observed': 3, 'thread_has_human_issue_without_fix_context': 2, 'issue_or_pull_request_thread': 1, 'agent_instruction_gap': 1, 'human_reported_issue_no_linked_fix': 1}\nOutcomes: {'not_resolved_or_not_observed': 6}\nQuality tiers: {'unresolved': 3}\nCI labels: {}\nCurriculum targets:\n- Teach models to preserve unresolved human feedback instead of hallucinating fixes.\n- Build issue-to-regression examples where no accepted fix exists yet.\nAssumption checks:\n- Can a commit be linked by issue number, SHA, changed path, or time window?\n- If no link exists, is this explicitly labelled unresolved?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/TheMorpheus407/morphcook", "source_id": "graph-query-motif_query-e14dafb6fcfad349", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/unresolved_feedback/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "TheMorpheus407/morphcook", "source_dataset": "graph_queries/unresolved_feedback", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_unresolved_feedback", "level": "warning", "message": {"text": "Foundry mined unresolved feedback: TheMorpheus407/morphcook"}, "properties": {"repobilityId": 361633, "scanner": "foundry_dataset", "fingerprint": "b67be7c81d3b19b608a2fd2bd99c2494183caa0eef6fa6cdebc6569f9883b62e", "category": "practices", "severity": "medium", "confidence": 0.7, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Human feedback without linked fix evidence", "intent": "Negative/unresolved examples that should not be hallucinated into fixes.", "labels": {"security_auth_secret": 1, "human_feedback_general": 1, "unlinked_human_feedback": 1, "issue_or_pull_request_thread": 1, "not_resolved_or_not_observed": 3, "ambiguous_needs_more_evidence": 1, "human_reported_issue_no_linked_fix": 1, "thread_has_human_issue_without_fix_context": 2}, "source": "graph_query_export", "motif_id": "unlinked_feedback_needs_evidence", "outcomes": {"not_resolved_or_not_observed": 6, "ambiguous_needs_more_evidence": 2}, "polarity": "bad", "query_id": "unresolved_feedback", "severity": "medium", "ci_labels": {}, "synthetic": false, "edge_count": 16, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 2, "thread_has_comment": 2, "chain_has_link_quality": 4, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "thread_has_comment_chain": 2, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 2}, "node_count": 12, "node_types": {"repo": 1, "thread": 1, "comment": 2, "fix_outcome": 1, "issue_chain": 1, "link_quality": 4, "comment_chain": 2}, "query_type": "motif_query", "thread_key": "TheMorpheus407/morphcook#1", "issue_number": "1", "quality_tiers": {"unresolved": 4}, "repo_full_name": "TheMorpheus407/morphcook", "training_usage": "negative_or_unresolved", "source_motif_id": "graph-pattern-motif-thread-fe624d4ac757880a", "graph_gold_label": "needs_more_evidence", "changed_file_labels": {}}, "text": "Graph query export: Human feedback without linked fix evidence\nQuery id: unresolved_feedback\nQuery type: motif_query\nIntent: Negative/unresolved examples that should not be hallucinated into fixes.\nMotif: unlinked_feedback_needs_evidence\nTraining usage: negative_or_unresolved\nGraph gold label: needs_more_evidence\nRepo: TheMorpheus407/morphcook\nThread: TheMorpheus407/morphcook#1\nEvidence:\nGraph motif: Human feedback exists without a linked fix\nMotif id: unlinked_feedback_needs_evidence\nPolarity: bad\nTraining usage: negative_or_unresolved\nSeverity: medium\nRepo: TheMorpheus407/morphcook\nThread: TheMorpheus407/morphcook#1\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: TheMorpheus407/morphcook#1\nRepo: TheMorpheus407/morphcook\nIssue/PR number: 1\nGraph consistency label: needs_more_evidence\nNodes: 12\nEdges: 16\nNode types: {'link_quality': 4, 'comment': 2, 'comment_chain': 2, 'thread': 1, 'repo': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 4, 'thread_has_comment': 2, 'thread_has_comment_chain': 2, 'comment_has_chain': 2, 'issue_chain_has_comment_chain': 2, 'repo_has_thread': 1, 'thread_has_issue_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'not_resolved_or_not_observed': 3, 'thread_has_human_issue_without_fix_context': 2, 'issue_or_pull_request_thread': 1, 'security_auth_secret': 1, 'human_feedback_general': 1, 'human_reported_issue_no_linked_fix': 1, 'unlinked_human_feedback': 1, 'ambiguous_needs_more_evidence': 1}\nOutcomes: {'not_resolved_or_not_observed': 6, 'ambiguous_needs_more_evidence': 2}\nQuality tiers: {'unresolved': 4}\nCI labels: {}\nCurriculum targets:\n- Teach models to preserve unresolved human feedback instead of hallucinating fixes.\n- Build issue-to-regression examples where no accepted fix exists yet.\nAssumption checks:\n- Can a commit be linked by issue number, SHA, changed path, or time window?\n- If no link exists, is this explicitly labelled unresolved?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/TheMorpheus407/morphcook", "source_id": "graph-query-motif_query-cdec616636979c40", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/unresolved_feedback/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "TheMorpheus407/morphcook", "source_dataset": "graph_queries/unresolved_feedback", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_bad_chain", "level": "error", "message": {"text": "Foundry mined bad chains: TheMorpheus407/morphcook"}, "properties": {"repobilityId": 316591, "scanner": "foundry_dataset", "fingerprint": "147956bd246c9480eab6adc6d10c8ccde6a935bd6d981ef3907db93fee911dc7", "category": "practices", "severity": "high", "confidence": 0.84, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "bad_chains", "synthetic": false, "thread_key": "TheMorpheus407/morphcook#2", "human_labels": ["agent_instruction_gap"], "issue_number": "2", "thread_label": "thread_has_human_issue_without_fix_context", "outcome_label": "not_resolved_or_not_observed", "source_backed": true, "max_confidence": 0.0, "repo_full_name": "TheMorpheus407/morphcook", "training_usage": "negative_or_unresolved", "confidence_tier": "unresolved", "source_chain_id": "evidence-chain-issue_chain-89dd8e2c57a7209a", "helicopter_views": {}, "artifact_families": {"docs": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 0, "source_graph_label": "source_artifact_without_verification_graph", "changed_file_labels": {}, "linked_commit_count": 0, "helicopter_view_count": 0, "source_artifact_count": 1, "classification_reasons": ["source_graph_has_real_artifacts", "link_quality_unresolved"], "linked_ci_commit_count": 0, "verification_artifact_count": 0, "design_schema_api_artifact_count": 0}, "text": "Comment chain pattern product: bad_chains\nRepo: TheMorpheus407/morphcook\nThread: TheMorpheus407/morphcook#2\nOutcome: not_resolved_or_not_observed\nThread label: thread_has_human_issue_without_fix_context\nSource graph label: source_artifact_without_verification_graph\nReasons: source_graph_has_real_artifacts, link_quality_unresolved\nChain evidence:\nIssue/PR evidence chain: TheMorpheus407/morphcook#2\nRepo: TheMorpheus407/morphcook\nThread label: thread_has_human_issue_without_fix_context\nOutcome: not_resolved_or_not_observed\nComment count: 1\nLinked commit count: 0\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 0\nLabels: {'agent_instruction_gap': 1}\nPolarities: {'bad': 1}\nChanged file labels: {}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-1b32777c2db19a27\",\n    \"kind\": \"issue_body\",\n    \"label\": \"agent_instruction_gap\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/TheMorpheus407/morphcook/issues/2\",\n    \"text\": \"GitHub feedback: agent_instruction_gap\\nPolarity: bad\\nKind: issue_body\\nRepo: TheMorpheus407/morphcook\\nAuthor: timjonaswechler (User)\\nURL: https://github.com/TheMorpheus407/morphcook/issues/2\\nTitle: Question about the future direction of MorphCook\\nBody:\\n   Hey,\\n\\n   first of all: I really like the idea behind MorphCook, and the Claude Fable 5 version looks especially strong.\\n\\n   Before throwing an idea into the room, I wanted to ask first: is this repository mainly meant to stay a test/model-comparison repo, or do you plan to continue developing MorphCook further?\\n\\n   If you do plan to continue it, one thought came to mind immediately. My girlfriend is often looking for recipes and trying to plan around preferences, restrictions, and everyday constraints.\\n\\n   That made me wonder how MorphCook could work for people who want to use it, but do not want to or cannot rebuild the app themselves.\\n\\n   I don\u2019t have a concrete proposal yet. I\u2019d mostly be curious to hear your opinion on whether that direction would make sense for the project.\"\n  }\n]\nChanged files:\n[]\nLinked chain ids:\n[\"evidence-chain-comment_to_commit-81a525833ede10cc\"]\nSource graph evidence:\nSource evidence repo graph summary\nRepo: TheMorpheus407/morphcook\nGraph label: source_artifact_without_verification_graph\nNodes: 5\nEdges: 6\nNode types: {\"cooccurrence_profile\": 1, \"github_repo_summary\": 1, \"repo\": 1, \"source_artifact\": 1, \"source_bundle\": 1}\nEdge types: {\"artifact_needs_claim_verification\": 1, \"repo_has_cooccurrence_profile\": 1, \"repo_has_github_evidence_summary\": 1, \"repo_has_source_artifact\": 1, \"repo_has_source_bundle\": 1, \"source_bundle_uses_cooccurrence_profile\": 1}\nArtifact families: {\"docs\": 1}\nHelicopter views: {}\nBundle labels: {\"source_backed_security_guardrail_bundle\": 1}\nCo-occurrence labels: {\"security_guardrail_cluster\": 1}", "source": "foundry_mined_dataset", "repo_url": "https://github.com/TheMorpheus407/morphcook", "source_id": "comment-chain-pattern-bad_chains-c6e12b3463157467", "synthetic": false, "gold_label": "", "graph_label": "source_artifact_without_verification_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/bad_chains/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "TheMorpheus407/morphcook", "source_dataset": "comment_chain_patterns/bad_chains", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_bad_chain", "level": "error", "message": {"text": "Foundry mined bad chains: TheMorpheus407/morphcook"}, "properties": {"repobilityId": 316590, "scanner": "foundry_dataset", "fingerprint": "f8ae77519d377255b5121ac4ba24947e7c2f0bf78706b96d08d8f64a7a0e6feb", "category": "practices", "severity": "high", "confidence": 0.84, "triageState": "open", "verdict": "confirmed", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "comment_chain_pattern_product", "source": "comment_chain_pattern_miner", "product": "bad_chains", "synthetic": false, "thread_key": "TheMorpheus407/morphcook#1", "human_labels": ["human_feedback_general", "security_auth_secret"], "issue_number": "1", "thread_label": "thread_has_human_issue_without_fix_context", "outcome_label": "not_resolved_or_not_observed", "source_backed": true, "max_confidence": 0.0, "repo_full_name": "TheMorpheus407/morphcook", "training_usage": "negative_or_unresolved", "confidence_tier": "unresolved", "source_chain_id": "evidence-chain-issue_chain-75bd5e62c2004571", "helicopter_views": {}, "artifact_families": {"docs": 1}, "source_chain_kind": "issue_chain", "changed_file_count": 0, "source_graph_label": "source_artifact_without_verification_graph", "changed_file_labels": {}, "linked_commit_count": 0, "helicopter_view_count": 0, "source_artifact_count": 1, "classification_reasons": ["source_graph_has_real_artifacts", "link_quality_unresolved", "high_risk_human_feedback_label"], "linked_ci_commit_count": 0, "verification_artifact_count": 0, "design_schema_api_artifact_count": 0}, "text": "Comment chain pattern product: bad_chains\nRepo: TheMorpheus407/morphcook\nThread: TheMorpheus407/morphcook#1\nOutcome: not_resolved_or_not_observed\nThread label: thread_has_human_issue_without_fix_context\nSource graph label: source_artifact_without_verification_graph\nReasons: source_graph_has_real_artifacts, link_quality_unresolved, high_risk_human_feedback_label\nChain evidence:\nIssue/PR evidence chain: TheMorpheus407/morphcook#1\nRepo: TheMorpheus407/morphcook\nThread label: thread_has_human_issue_without_fix_context\nOutcome: not_resolved_or_not_observed\nComment count: 2\nLinked commit count: 0\nLinked CI commit count: 0\nLinked CI labels: {}\nChanged file count: 0\nLabels: {'security_auth_secret': 1, 'human_feedback_general': 1}\nPolarities: {'bad': 1, 'neutral': 1}\nChanged file labels: {}\nExamples:\n[\n  {\n    \"id\": \"github-feedback-comment-262df01a56f94fdb\",\n    \"kind\": \"issue_body\",\n    \"label\": \"security_auth_secret\",\n    \"polarity\": \"bad\",\n    \"url\": \"https://github.com/TheMorpheus407/morphcook/issues/1\",\n    \"text\": \"GitHub feedback: security_auth_secret\\nPolarity: bad\\nKind: issue_body\\nRepo: TheMorpheus407/morphcook\\nAuthor: ananta888 (User)\\nURL: https://github.com/TheMorpheus407/morphcook/issues/1\\nTitle: Gedanke zu KI-Benchmarks, Brownfield-Projekten und Safety-Grenzen\\nBody:\\nHi Morpheus,\\n \\nspannender Test, vor allem weil du mit einer klaren `SPEC.md` arbeitest und alle Modelle gegen dieselbe Ausgangslage laufen l\u00e4sst.\\n\\nIch glaube aber, dass daneben noch ein zweiter Benchmark-Typ extrem wichtig w\u00e4re: nicht nur Greenfield, also \u201ebaue ein neues Projekt aus einer m\u00f6glichst guten Spec\u201c, sondern Brownfield.\\n\\nAlso z. B.:\\n\\n* bestehendes gr\u00f6\u00dferes Repository\\n* vorhandene Architektur und Altentscheidungen\\n* vorhandene Tests\\n* konkrete Fehleranalyse\\n* gezielte Weiterentwicklung\\n* m\u00f6glichst wenig unn\u00f6tiger Umbau\\n* Kontext muss aus dem Projekt selbst korrekt gezogen werden\\n\\nGenau da trennt sich meiner Erfahrung nach sehr stark, welches Modell oder Agentensystem praktisch wirklich n\u00fctzlich ist. Ein neues Projekt aus einer perfekten Spec zu erzeugen ist interessant, aber mein Alltag ist eher: vorhandenes Projekt verstehen, sinnvolle Stellen finden, nichts kaputtmachen, Tests beachten und kleine saubere \u00c4nderung\"\n  },\n  {\n    \"id\": \"github-feedback-comment-80803f65449a8bbb\",\n    \"kind\": \"issue_comment\",\n    \"label\": \"human_feedback_general\",\n    \"polarity\": \"neutral\",\n    \"url\": \"https://github.com/TheMorpheus407/morphcook/issues/1#issuecomment-4672384136\",\n    \"text\": \"GitHub feedback: human_feedback_general\\nPolarity: neutral\\nKind: issue_comment\\nRepo: TheMorpheus407/morphcook\\nAuthor: ananta888 (User)\\nURL: https://github.com/TheMorpheus407/morphcook/issues/1#issuecomment-4672384136\\nTitle: \\nBody:\\nMein Favorit als weiterentwicklungs Test-Projekt ist Keycloak am besten das Frontend das mal sch\u00f6nner machen das ist ne Aufgabe :-) - das ist dann wohl nicht nur f\u00fcr mich n\u00fctzlich.\"\n  }\n]\nChanged files:\n[]\nLinked\n[truncated by importer]", "source": "foundry_mined_dataset", "repo_url": "https://github.com/TheMorpheus407/morphcook", "source_id": "comment-chain-pattern-bad_chains-c972be3b3d5a1ffe", "synthetic": false, "gold_label": "", "graph_label": "source_artifact_without_verification_graph", "source_path": "/data/distillate/foundry_data/comment_chain_patterns/bad_chains/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "TheMorpheus407/morphcook", "source_dataset": "comment_chain_patterns/bad_chains", "training_usage": "negative_or_unresolved"}}}, {"ruleId": "foundry_auth_guardrail_gap", "level": "error", "message": {"text": "Foundry mined security auth guardrail gaps: TheMorpheus407/morphcook"}, "properties": {"repobilityId": 332228, "scanner": "foundry_dataset", "fingerprint": "c3e7f56cfb9220dbfc16e0150ec20c3a9b924226e865ff27dcc3744d197a1288", "category": "auth", "severity": "critical", "confidence": 0.78, "triageState": "open", "verdict": "needs_review", "isResolved": false, "reason": "Imported from mined Foundry/Fable5 evidence with real GitHub/source provenance. Review source_id before acting.", "evidence": {"meta": {"kind": "graph_query_record", "title": "Security/auth changes without enough guardrails", "intent": "Assumption-check security/auth examples requiring stronger tests or CI.", "labels": {"security_auth_secret": 1, "human_feedback_general": 1, "unlinked_human_feedback": 1, "issue_or_pull_request_thread": 1, "not_resolved_or_not_observed": 3, "ambiguous_needs_more_evidence": 1, "human_reported_issue_no_linked_fix": 1, "thread_has_human_issue_without_fix_context": 2}, "source": "graph_query_export", "motif_id": "security_auth_without_guardrails", "outcomes": {"not_resolved_or_not_observed": 6, "ambiguous_needs_more_evidence": 2}, "polarity": "bad", "query_id": "security_auth_guardrail_gaps", "severity": "critical", "ci_labels": {}, "synthetic": false, "edge_count": 16, "edge_types": {"repo_has_thread": 1, "comment_has_chain": 2, "thread_has_comment": 2, "chain_has_link_quality": 4, "thread_has_fix_outcome": 1, "thread_has_issue_chain": 1, "thread_has_comment_chain": 2, "issue_chain_has_fix_outcome": 1, "issue_chain_has_comment_chain": 2}, "node_count": 12, "node_types": {"repo": 1, "thread": 1, "comment": 2, "fix_outcome": 1, "issue_chain": 1, "link_quality": 4, "comment_chain": 2}, "query_type": "motif_query", "thread_key": "TheMorpheus407/morphcook#1", "issue_number": "1", "quality_tiers": {"unresolved": 4}, "repo_full_name": "TheMorpheus407/morphcook", "training_usage": "assumption_check", "source_motif_id": "graph-pattern-motif-thread-5ce4440af37d75f9", "graph_gold_label": "needs_more_evidence", "changed_file_labels": {}}, "text": "Graph query export: Security/auth changes without enough guardrails\nQuery id: security_auth_guardrail_gaps\nQuery type: motif_query\nIntent: Assumption-check security/auth examples requiring stronger tests or CI.\nMotif: security_auth_without_guardrails\nTraining usage: assumption_check\nGraph gold label: needs_more_evidence\nRepo: TheMorpheus407/morphcook\nThread: TheMorpheus407/morphcook#1\nEvidence:\nGraph motif: Security/auth change without enough guardrails\nMotif id: security_auth_without_guardrails\nPolarity: bad\nTraining usage: assumption_check\nSeverity: critical\nRepo: TheMorpheus407/morphcook\nThread: TheMorpheus407/morphcook#1\nGraph gold label: needs_more_evidence\nThread graph evidence:\nGitHub issue/PR evidence subgraph\nThread: TheMorpheus407/morphcook#1\nRepo: TheMorpheus407/morphcook\nIssue/PR number: 1\nGraph consistency label: needs_more_evidence\nNodes: 12\nEdges: 16\nNode types: {'link_quality': 4, 'comment': 2, 'comment_chain': 2, 'thread': 1, 'repo': 1, 'issue_chain': 1, 'fix_outcome': 1}\nEdge types: {'chain_has_link_quality': 4, 'thread_has_comment': 2, 'thread_has_comment_chain': 2, 'comment_has_chain': 2, 'issue_chain_has_comment_chain': 2, 'repo_has_thread': 1, 'thread_has_issue_chain': 1, 'thread_has_fix_outcome': 1, 'issue_chain_has_fix_outcome': 1}\nLabels: {'not_resolved_or_not_observed': 3, 'thread_has_human_issue_without_fix_context': 2, 'issue_or_pull_request_thread': 1, 'security_auth_secret': 1, 'human_feedback_general': 1, 'human_reported_issue_no_linked_fix': 1, 'unlinked_human_feedback': 1, 'ambiguous_needs_more_evidence': 1}\nOutcomes: {'not_resolved_or_not_observed': 6, 'ambiguous_needs_more_evidence': 2}\nQuality tiers: {'unresolved': 4}\nCI labels: {}\nCurriculum targets:\n- Train auth boundary repair with tests, permission matrices, and secret-handling checks.\n- Keep risky auth changes separate from ordinary bug-fix examples.\nAssumption checks:\n- Are auth/permission paths covered by tests?\n- Are secrets, CORS, or access rules verified rather than summarized?", "source": "foundry_mined_dataset", "repo_url": "https://github.com/TheMorpheus407/morphcook", "source_id": "graph-query-motif_query-00cfe637bf5c52ef", "synthetic": false, "gold_label": "", "graph_label": "", "source_path": "/data/distillate/foundry_data/graph_queries/security_auth_guardrail_gaps/shard-0.jsonl", "bundle_label": "", "priority_band": "", "priority_score": 0, "repo_full_name": "TheMorpheus407/morphcook", "source_dataset": "graph_queries/security_auth_guardrail_gaps", "training_usage": "assumption_check"}}}, {"ruleId": "scanner-084e655634455d1c", "level": "note", "message": {"text": "Possibly dead Python function: key"}, "properties": {"repobilityId": "82ad9f64418e6fec", "scanner": "scanner-primary", "fingerprint": "084e655634455d1c", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "claude-fable-5/pipeline/wave4_lattice.py:608"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9710c8d059e53154", "level": "none", "message": {"text": "No frontend routes/components detected"}, "properties": {"repobilityId": "44ca61485762e494", "scanner": "scanner-primary", "fingerprint": "9710c8d059e53154", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-f56dc12786a58ba7", "level": "note", "message": {"text": "Very large file: claude-fable-5/pipeline/wave4_lattice.py (1712 lines)"}, "properties": {"repobilityId": "7b70e6fc16066601", "scanner": "scanner-primary", "fingerprint": "f56dc12786a58ba7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "c7519650e46b0704", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "41e02d6868ec9378", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "ee22ed54586afd92", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "263444e75cea3848", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "93ecbf32f5f72a06", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-1e8c89b93925169a", "level": "warning", "message": {"text": "Network/subprocess call without timeout or try/except \u2014 claude-fable-5/deploy/publish_play.py:60"}, "properties": {"repobilityId": "d2a6e1899b2195c4", "scanner": "scanner-primary", "fingerprint": "1e8c89b93925169a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f4e4ec947ab57569", "level": "note", "message": {"text": "Legacy-named symbol `ing_copy` in claude-fable-5/pipeline/wave4_lattice.py:1473"}, "properties": {"repobilityId": "52bf1eac4a37e849", "scanner": "scanner-primary", "fingerprint": "f4e4ec947ab57569", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "296d5130cdfff9b2", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "22374fd0df719319", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}, {"ruleId": "scanner-2c04133e54348533", "level": "note", "message": {"text": "Near-duplicate function bodies in 2 places"}, "properties": {"repobilityId": "09cdde4f1beb9cec", "scanner": "scanner-primary", "fingerprint": "2c04133e54348533", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "duplicate", "dry"]}}]}]}