{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-faa18553494417e1", "name": "Icon-only button without accessible name \u2014 tools/eslint-plugin-localization/__tests__/no-hardcoded-ui-strings.test.js:38", "shortDescription": {"text": "Icon-only button without accessible name \u2014 tools/eslint-plugin-localization/__tests__/no-hardcoded-ui-strings.test.js:38"}, "fullDescription": {"text": "A `<button>` whose only child is a single glyph or symbol needs `title=` or `aria-label=` so screen readers (and tooltips on hover) work.\n\nWhy: P3 in CHECKLIST.md \u2014 icon-only buttons skipped a title.\nRule id: fq.button.no-label"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 0.85}}, {"id": "scanner-d8dba02e1ba87226", "name": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.17 \u2014 pnpm-lock.yaml", "shortDescription": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.17 \u2014 pnpm-lock.yaml"}, "fullDescription": {"text": "Node.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nThe same as the `hono` core [Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)](https://github.com/honojs/hono/security/advisories/GHSA-wwfh-h76j-fc44).\n\n### Summary\n\nOn Windows hosts, an encoded backslash (`%5C`) in the request path decodes to `\\`, which the Windows path resolver treats as a separator. `serve-static` then resolves a single URL segment such as `admin\\secret.txt` into a nested file under the root and serves it, letting an attacker read static files meant t\n\nPackage: @hono/node-server\nInstalled: 1.19.17\nFixed in: 2.0.5\nSeverity: MEDIUM\nFix: Upgrade @hono/node-server to 2.0.5"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aef9872ebbd2b160", "name": "Agent authority lacks a verifier contract: .github/copilot-instructions.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .github/copilot-instructions.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11b5afed35aa437a", "name": "SkillSpector E1 (data-exfil) in .claude/settings.json", "shortDescription": {"text": "SkillSpector E1 (data-exfil) in .claude/settings.json"}, "fullDescription": {"text": "curl -s -m 3 http://localhost:11434/api/tags)\",\n      \"Bash(echo \\\"EXIT_CODE=$?\\\")\",\n      \"Bash(curl -s -m 3 http://localhost:1234/v1/models)\",\n      \"Bash(curl -s -m 30 http://localhost:1234/v1/chat\n\nData is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.\n\nSkill: unknown\nRule: E1  Category: data-exfil\nSeverity: MEDIUM  Confidence: 0.60\n\nRemediation: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.6}}, {"id": "scanner-6098be30d38c2567", "name": "SkillSpector E1 (data-exfil) in extensions/carte-gouv-fr/src/index.ts", "shortDescription": {"text": "SkillSpector E1 (data-exfil) in extensions/carte-gouv-fr/src/index.ts"}, "fullDescription": {"text": "https://data.geopf.fr/\n\nData is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.\n\nSkill: unknown\nRule: E1  Category: data-exfil\nSeverity: MEDIUM  Confidence: 0.50\n\nRemediation: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 0.5}}, {"id": "scanner-f3321f3de07fb846", "name": "SkillSpector EA3 (excessive-agency) in LICENSE", "shortDescription": {"text": "SkillSpector EA3 (excessive-agency) in LICENSE"}, "fullDescription": {"text": "NOT LIMITED TO\n\nSkill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.\n\nSkill: unknown\nRule: EA3  Category: excessive-agency\nSeverity: LOW  Confidence: 0.70\n\nRemediation: Limit the skill's scope to its documented purpose. Remove instructions that enable the agent to perform actions outside its stated functionality."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.7}}, {"id": "scanner-69b73c741ec69f2c", "name": "SkillSpector EA3 (excessive-agency) in docs/adr/0018-event-driven-rendering-pipeline.md", "shortDescription": {"text": "SkillSpector EA3 (excessive-agency) in docs/adr/0018-event-driven-rendering-pipeline.md"}, "fullDescription": {"text": "not limited to\n\nSkill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.\n\nSkill: unknown\nRule: EA3  Category: excessive-agency\nSeverity: LOW  Confidence: 0.70\n\nRemediation: Limit the skill's scope to its documented purpose. Remove instructions that enable the agent to perform actions outside its stated functionality."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.7}}, {"id": "scanner-e18be84accadb308", "name": "SkillSpector EA3 (excessive-agency) in docs/adr/0019-modular-ressource-localization.md", "shortDescription": {"text": "SkillSpector EA3 (excessive-agency) in docs/adr/0019-modular-ressource-localization.md"}, "fullDescription": {"text": "not limited to\n\nSkill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.\n\nSkill: unknown\nRule: EA3  Category: excessive-agency\nSeverity: LOW  Confidence: 0.70\n\nRemediation: Limit the skill's scope to its documented purpose. Remove instructions that enable the agent to perform actions outside its stated functionality."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.7}}, {"id": "scanner-dc42c6115d6df6a3", "name": "SkillSpector EA3 (excessive-agency) in docs/vision.md", "shortDescription": {"text": "SkillSpector EA3 (excessive-agency) in docs/vision.md"}, "fullDescription": {"text": "Extend functionality\n\nSkill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.\n\nSkill: unknown\nRule: EA3  Category: excessive-agency\nSeverity: LOW  Confidence: 0.75\n\nRemediation: Limit the skill's scope to its documented purpose. Remove instructions that enable the agent to perform actions outside its stated functionality."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.75}}, {"id": "scanner-16317792e0cbff36", "name": "SkillSpector EA3 (excessive-agency) in packages/package-manager/src/package-dependency-resolver.ts", "shortDescription": {"text": "SkillSpector EA3 (excessive-agency) in packages/package-manager/src/package-dependency-resolver.ts"}, "fullDescription": {"text": "handle everything\n\nSkill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.\n\nSkill: unknown\nRule: EA3  Category: excessive-agency\nSeverity: LOW  Confidence: 0.70\n\nRemediation: Limit the skill's scope to its documented purpose. Remove instructions that enable the agent to perform actions outside its stated functionality."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.7}}, {"id": "scanner-49a990162254d52d", "name": "SkillSpector EA3 (excessive-agency) in packages/theme/README.md", "shortDescription": {"text": "SkillSpector EA3 (excessive-agency) in packages/theme/README.md"}, "fullDescription": {"text": "not limited to\n\nSkill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.\n\nSkill: unknown\nRule: EA3  Category: excessive-agency\nSeverity: LOW  Confidence: 0.70\n\nRemediation: Limit the skill's scope to its documented purpose. Remove instructions that enable the agent to perform actions outside its stated functionality."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.7}}, {"id": "scanner-187c16694661c252", "name": "SkillSpector EA3 (excessive-agency) in packages/theme/src/theme-tokens.ts", "shortDescription": {"text": "SkillSpector EA3 (excessive-agency) in packages/theme/src/theme-tokens.ts"}, "fullDescription": {"text": "not limited to\n\nSkill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.\n\nSkill: unknown\nRule: EA3  Category: excessive-agency\nSeverity: LOW  Confidence: 0.70\n\nRemediation: Limit the skill's scope to its documented purpose. Remove instructions that enable the agent to perform actions outside its stated functionality."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.7}}, {"id": "scanner-8723dc5de014aca4", "name": "SkillSpector MP3 (memory-poisoning) in docs/sprints/sprint-022.1-api-foundations.md", "shortDescription": {"text": "SkillSpector MP3 (memory-poisoning) in docs/sprints/sprint-022.1-api-foundations.md"}, "fullDescription": {"text": "reset history\n\nSkill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.\n\nSkill: unknown\nRule: MP3  Category: memory-poisoning\nSeverity: HIGH  Confidence: 0.80\n\nRemediation: Protect agent memory and state from modification by untrusted content. Use read-only memory for critical instructions and validate all state changes."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.8}}, {"id": "scanner-2fe5a7efe99e80f3", "name": "SkillSpector PE3 (priv-esc) in apps/web/src/workbench/pluginSecretStore.ts", "shortDescription": {"text": "SkillSpector PE3 (priv-esc) in apps/web/src/workbench/pluginSecretStore.ts"}, "fullDescription": {"text": "keychain\n\nCode accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.\n\nSkill: unknown\nRule: PE3  Category: priv-esc\nSeverity: HIGH  Confidence: 0.70\n\nRemediation: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.7}}, {"id": "scanner-23d42a74ac9ccb32", "name": "SkillSpector PE3 (priv-esc) in docs/sprints/sprint-023.0-plugin-config-preferences.md", "shortDescription": {"text": "SkillSpector PE3 (priv-esc) in docs/sprints/sprint-023.0-plugin-config-preferences.md"}, "fullDescription": {"text": "keychain\n\nCode accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.\n\nSkill: unknown\nRule: PE3  Category: priv-esc\nSeverity: HIGH  Confidence: 0.70\n\nRemediation: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.7}}, {"id": "scanner-cb1bd0d5c534ee76", "name": "SkillSpector PE3 (priv-esc) in packages/plugin-config/src/configuration-store.ts", "shortDescription": {"text": "SkillSpector PE3 (priv-esc) in packages/plugin-config/src/configuration-store.ts"}, "fullDescription": {"text": "keychain\n\nCode accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.\n\nSkill: unknown\nRule: PE3  Category: priv-esc\nSeverity: HIGH  Confidence: 0.70\n\nRemediation: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.7}}, {"id": "scanner-a7ae807f79649592", "name": "SkillSpector RA1 (rogue-agent) in apps/web/src/extensions/extensionManagement.ts", "shortDescription": {"text": "SkillSpector RA1 (rogue-agent) in apps/web/src/extensions/extensionManagement.ts"}, "fullDescription": {"text": "self-update\n\nSkill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.\n\nSkill: unknown\nRule: RA1  Category: rogue-agent\nSeverity: HIGH  Confidence: 0.90\n\nRemediation: Prevent the skill from modifying its own code, SKILL.md, or configuration files. Treat skill files as read-only at runtime."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.9}}, {"id": "scanner-90bbed042b9f3cd6", "name": "SkillSpector SC1 (supply-chain) in apps/web/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in apps/web/package.json"}, "fullDescription": {"text": "\"@modelcontextprotocol/sdk\": \"^1.29.0\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-53a22588b5e8ec47", "name": "SkillSpector SC1 (supply-chain) in extensions/carte-gouv-fr/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in extensions/carte-gouv-fr/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-0cbe0a9bb4003937", "name": "SkillSpector SC1 (supply-chain) in extensions/example-extension/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in extensions/example-extension/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-1474af525032cfbf", "name": "SkillSpector SC1 (supply-chain) in package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in package.json"}, "fullDescription": {"text": "\"@eslint/js\": \"^10.0.1\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-ff9c7bce6b7f0d91", "name": "SkillSpector SC1 (supply-chain) in packages/ai-engine/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/ai-engine/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-1ce08cc6270fad35", "name": "SkillSpector SC1 (supply-chain) in packages/automation-api/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/automation-api/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-dfa7df10a55487c2", "name": "SkillSpector SC1 (supply-chain) in packages/automation-mcp/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/automation-mcp/package.json"}, "fullDescription": {"text": "\"@modelcontextprotocol/sdk\": \"^1.29.0\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-f3541f8d50db8c42", "name": "SkillSpector SC1 (supply-chain) in packages/building-model/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/building-model/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-1d21f6184c0f0117", "name": "SkillSpector SC1 (supply-chain) in packages/core/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/core/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-4b69c894fcfcde7e", "name": "SkillSpector SC1 (supply-chain) in packages/extension-host/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/extension-host/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-d1daaedb04d5620a", "name": "SkillSpector SC1 (supply-chain) in packages/extension-sdk/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/extension-sdk/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-befad0adce71c5df", "name": "SkillSpector SC1 (supply-chain) in packages/geometry/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/geometry/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-efb8bdfed59b9903", "name": "SkillSpector SC1 (supply-chain) in packages/i18n/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/i18n/package.json"}, "fullDescription": {"text": "\"intl-messageformat\": \"^11.2.12\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-95307821cf316620", "name": "SkillSpector SC1 (supply-chain) in packages/inspector/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/inspector/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-752c7b8c0d98214f", "name": "SkillSpector SC1 (supply-chain) in packages/navigation/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/navigation/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-6e53680721e2e1b1", "name": "SkillSpector SC1 (supply-chain) in packages/package-manager/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/package-manager/package.json"}, "fullDescription": {"text": "\"semver\": \"^7.8.5\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-ed75d4d98f26fa75", "name": "SkillSpector SC1 (supply-chain) in packages/persistence/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/persistence/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-41d97387ccada42a", "name": "SkillSpector SC1 (supply-chain) in packages/plugin-api/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/plugin-api/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-82b4b61cd679663d", "name": "SkillSpector SC1 (supply-chain) in packages/plugin-config/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/plugin-config/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-087394d1427cfb1c", "name": "SkillSpector SC1 (supply-chain) in packages/rendering/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/rendering/package.json"}, "fullDescription": {"text": "\"three\": \"^0.181.1\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-bb611cf0c83b3afd", "name": "SkillSpector SC1 (supply-chain) in packages/resources/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/resources/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-78d49d2a3857f15a", "name": "SkillSpector SC1 (supply-chain) in packages/spatial/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/spatial/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-088e4df87bb1f302", "name": "SkillSpector SC1 (supply-chain) in packages/theme/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/theme/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-9d67517b414e6279", "name": "SkillSpector SC1 (supply-chain) in packages/workbench/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in packages/workbench/package.json"}, "fullDescription": {"text": "\"vitest\": \"^4.1.8\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-f1b156cbc47e662e", "name": "SkillSpector SC1 (supply-chain) in tools/eslint-plugin-localization/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in tools/eslint-plugin-localization/package.json"}, "fullDescription": {"text": "\"eslint\": \"^10.3.0\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-ee22b6a2d0e25cae", "name": "SkillSpector SC1 (supply-chain) in tools/eslint-plugin-theme/package.json", "shortDescription": {"text": "SkillSpector SC1 (supply-chain) in tools/eslint-plugin-theme/package.json"}, "fullDescription": {"text": "\"eslint\": \"^10.3.0\"\n\nDependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.\n\nSkill: unknown\nRule: SC1  Category: supply-chain\nSeverity: LOW  Confidence: 0.40\n\nRemediation: Pin all dependency versions in requirements.txt or pyproject.toml. Use exact versions (==) or compatible ranges. Run pip-audit regularly."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "low", "confidence": 0.4}}, {"id": "scanner-c852ccf9deb6e70b", "name": "SkillSpector SC4 (supply-chain) in apps/web/package.json", "shortDescription": {"text": "SkillSpector SC4 (supply-chain) in apps/web/package.json"}, "fullDescription": {"text": "vite==8.0.12\n\nDependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.\n\nSkill: unknown\nRule: SC4  Category: supply-chain\nSeverity: HIGH  Confidence: 0.80\n\nRemediation: Update the dependency to a patched version that addresses the known CVE. Check OSV (osv.dev) or NVD for details on the vulnerability."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.8}}, {"id": "scanner-f28e5cfcd7afa141", "name": "SkillSpector SC6 (supply-chain) in apps/web/package.json", "shortDescription": {"text": "SkillSpector SC6 (supply-chain) in apps/web/package.json"}, "fullDescription": {"text": "vite\n\nPackage name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.\n\nSkill: unknown\nRule: SC6  Category: supply-chain\nSeverity: HIGH  Confidence: 0.70\n\nRemediation: Verify the package name is correct and not a typosquatting variant. Compare against the official package name on PyPI or npm."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.7}}, {"id": "scanner-75612e1922d1a2e6", "name": "SkillSpector SC6 (supply-chain) in content/ai-demo-provider/package.json", "shortDescription": {"text": "SkillSpector SC6 (supply-chain) in content/ai-demo-provider/package.json"}, "fullDescription": {"text": "label\n\nPackage name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.\n\nSkill: unknown\nRule: SC6  Category: supply-chain\nSeverity: HIGH  Confidence: 0.70\n\nRemediation: Verify the package name is correct and not a typosquatting variant. Compare against the official package name on PyPI or npm."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.7}}, {"id": "scanner-e831f38f77aba2c1", "name": "SkillSpector SC6 (supply-chain) in content/ai-lmstudio-provider/package.json", "shortDescription": {"text": "SkillSpector SC6 (supply-chain) in content/ai-lmstudio-provider/package.json"}, "fullDescription": {"text": "label\n\nPackage name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.\n\nSkill: unknown\nRule: SC6  Category: supply-chain\nSeverity: HIGH  Confidence: 0.70\n\nRemediation: Verify the package name is correct and not a typosquatting variant. Compare against the official package name on PyPI or npm."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.7}}, {"id": "scanner-4a756e3534a5557e", "name": "SkillSpector SC6 (supply-chain) in content/example-extension/package.json", "shortDescription": {"text": "SkillSpector SC6 (supply-chain) in content/example-extension/package.json"}, "fullDescription": {"text": "label\n\nPackage name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.\n\nSkill: unknown\nRule: SC6  Category: supply-chain\nSeverity: HIGH  Confidence: 0.70\n\nRemediation: Verify the package name is correct and not a typosquatting variant. Compare against the official package name on PyPI or npm."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.7}}, {"id": "scanner-a88cbe63ee0eb34a", "name": "SkillSpector P6 (prompt-injection) in packages/package-manager/src/plugin-configuration.ts", "shortDescription": {"text": "SkillSpector P6 (prompt-injection) in packages/package-manager/src/plugin-configuration.ts"}, "fullDescription": {"text": "return rule\n\nSkill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.\n\nSkill: unknown\nRule: P6  Category: prompt-injection\nSeverity: HIGH  Confidence: 0.85\n\nRemediation: Remove any instructions that reveal, print, or output system prompts or internal rules. System instructions should never be exposed to end users."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.85}}, {"id": "scanner-e3447526d13bf19b", "name": "SkillSpector P6 (prompt-injection) in packages/plugin-config/src/preference-validation.ts", "shortDescription": {"text": "SkillSpector P6 (prompt-injection) in packages/plugin-config/src/preference-validation.ts"}, "fullDescription": {"text": "return rule\n\nSkill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.\n\nSkill: unknown\nRule: P6  Category: prompt-injection\nSeverity: HIGH  Confidence: 0.85\n\nRemediation: Remove any instructions that reveal, print, or output system prompts or internal rules. System instructions should never be exposed to end users."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 0.85}}, {"id": "scanner-e637c415447867e4", "name": "Run SkillSpector's LLM-backed analysis in your own pipeline", "shortDescription": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "fullDescription": {"text": "Repobility ran SkillSpector's static rules server-side. The deeper LLM-backed analyzers \u2014 tool-poisoning (TP*), semantic security discovery (SSD*), developer-intent mismatch (SDI*) \u2014 are meant to run on YOUR machine with YOUR model; repobility never sends your code to an LLM. Recipe:\n\n# 1. Install SkillSpector in your own isolated env\npipx install \"skillspector @ git+https://github.com/NVIDIA/SkillSpector.git\"\n\n# 2. Point it at YOUR LLM pipeline (pick one) - your code stays on your machine\nexport SKILLSPECTOR_PROVIDER=anthropic && export ANTHROPIC_API_KEY=sk-ant-...\n# export SKILLSPECTOR_PROVIDER=openai   && export OPENAI_API_KEY=sk-...\n# export SKILLSPECTOR_PROVIDER=openai OPENAI_API_KEY=ollama OPENAI_BASE_URL=http://localhost:11434/v1 SKILLSPECTOR_MODEL=llama3.1:8b\n# export SKILLSPECTOR_PROVIDER=nv_build && export NVIDIA_INFERENCE_KEY=nvapi-...\n\n# 3. Run the LLM-backed scan per skill (omit --no-llm to enable the LLM analyzers)\nskillspector scan . --format sarif --output skillspector-"}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cb639d9a10a47b23", "name": "package.json defines install-time lifecycle scripts", "shortDescription": {"text": "package.json defines install-time lifecycle scripts"}, "fullDescription": {"text": "preinstall/install/postinstall/prepare scripts execute during dependency installation. Review them carefully for network calls, obfuscation, shell execution, or credential access."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-be00c115334307ce", "name": "Very large file: apps/web/src/App.tsx (1261 lines)", "shortDescription": {"text": "Very large file: apps/web/src/App.tsx (1261 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f73c8ff17174db57", "name": "Node manifest has dependencies but no lockfile: apps/web/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ef3ce27fcea2ca2", "name": "Node manifest has dependencies but no lockfile: extensions/carte-gouv-fr/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: extensions/carte-gouv-fr/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec660ae4b7898549", "name": "Node manifest has dependencies but no lockfile: extensions/example-extension/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: extensions/example-extension/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0588e415c04250f0", "name": "Node manifest has dependencies but no lockfile: packages/spatial/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/spatial/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-abdaeeb0b86bd56a", "name": "Node manifest has dependencies but no lockfile: packages/i18n/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/i18n/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ec8786402df3545", "name": "Node manifest has dependencies but no lockfile: packages/rendering/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/rendering/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-038566c48a8f2e78", "name": "Node manifest has dependencies but no lockfile: packages/navigation/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/navigation/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2caa337a56a39957", "name": "Node manifest has dependencies but no lockfile: packages/plugin-api/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/plugin-api/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-82cd173b004539d2", "name": "Node manifest has dependencies but no lockfile: packages/resources/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/resources/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f61a443bf7aac143", "name": "Node manifest has dependencies but no lockfile: packages/extension-host/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/extension-host/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-24a1379c4b883c49", "name": "Node manifest has dependencies but no lockfile: packages/building-model/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/building-model/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-75691449d985e0ee", "name": "Node manifest has dependencies but no lockfile: packages/theme/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/theme/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-20a27c33b1839ed6", "name": "Node manifest has dependencies but no lockfile: packages/workbench/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/workbench/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad2778bbf8021e9d", "name": "Node manifest has dependencies but no lockfile: packages/plugin-config/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/plugin-config/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3321a0ec74fb5c0a", "name": "Node manifest has dependencies but no lockfile: packages/package-manager/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/package-manager/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ae76aef20353f4e", "name": "Node manifest has dependencies but no lockfile: packages/automation-mcp/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/automation-mcp/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cc249ed5e6371854", "name": "Node manifest has dependencies but no lockfile: packages/ai-engine/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/ai-engine/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-31339c4f6d7bc62e", "name": "Node manifest has dependencies but no lockfile: packages/extension-sdk/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/extension-sdk/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1ada30b496643aab", "name": "Node manifest has dependencies but no lockfile: packages/core/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/core/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4d5ce916fb4d7e2", "name": "Node manifest has dependencies but no lockfile: packages/automation-api/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/automation-api/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-721678005439020a", "name": "Node manifest has dependencies but no lockfile: packages/persistence/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/persistence/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e281181b7e23e679", "name": "Node manifest has dependencies but no lockfile: packages/geometry/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/geometry/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-516efb912e6947be", "name": "Node manifest has dependencies but no lockfile: packages/inspector/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/inspector/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-76a355d93b9403fe", "name": "Node manifest has dependencies but no lockfile: tools/eslint-plugin-theme/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: tools/eslint-plugin-theme/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7b645b60c1dd4645", "name": "Node manifest has dependencies but no lockfile: tools/eslint-plugin-localization/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: tools/eslint-plugin-localization/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-705bac266517690b", "name": "Node manifest has dependencies but no lockfile: plugins/measurements/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: plugins/measurements/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 32 placeholder/mock markers across 19 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d018e7f1ff8f1431", "name": "Vulnerable dependency @hono/node-server 1.19.17: GHSA-frvp-7c67-39w9", "shortDescription": {"text": "Vulnerable dependency @hono/node-server 1.19.17: GHSA-frvp-7c67-39w9"}, "fullDescription": {"text": "OSV.dev reports `@hono/node-server` at version `1.19.17` (resolved in `pnpm-lock.yaml`) is affected by GHSA-frvp-7c67-39w9.\nNote: `@hono/node-server` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nNode.js Adapter for Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)\n\nAdvisory: https://osv.dev/vulnerability/GHSA-frvp-7c67-39w9\nFix: upgrade `@hono/node-server` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "medium", "confidence": 0.9}}, {"id": "scanner-0f452baefab70814", "name": "Vulnerable dependency brace-expansion 5.0.6: GHSA-3jxr-9vmj-r5cp", "shortDescription": {"text": "Vulnerable dependency brace-expansion 5.0.6: GHSA-3jxr-9vmj-r5cp"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `5.0.6` (resolved in `pnpm-lock.yaml`) is affected by GHSA-3jxr-9vmj-r5cp (aka CVE-2026-13149).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups\n\nAliases: CVE-2026-13149\nAdvisory: https://osv.dev/vulnerability/GHSA-3jxr-9vmj-r5cp\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-037c11824e840dd1", "name": "Vulnerable dependency brace-expansion 5.0.6: GHSA-mh99-v99m-4gvg", "shortDescription": {"text": "Vulnerable dependency brace-expansion 5.0.6: GHSA-mh99-v99m-4gvg"}, "fullDescription": {"text": "OSV.dev reports `brace-expansion` at version `5.0.6` (resolved in `pnpm-lock.yaml`) is affected by GHSA-mh99-v99m-4gvg (aka CVE-2026-14257).\nNote: `brace-expansion` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nbrace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash\n\nAliases: CVE-2026-14257\nAdvisory: https://osv.dev/vulnerability/GHSA-mh99-v99m-4gvg\nFix: upgrade `brace-expansion` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}, {"id": "scanner-facab9c4db5dfcdb", "name": "Vulnerable dependency postcss 8.5.15: GHSA-r28c-9q8g-f849", "shortDescription": {"text": "Vulnerable dependency postcss 8.5.15: GHSA-r28c-9q8g-f849"}, "fullDescription": {"text": "OSV.dev reports `postcss` at version `8.5.15` (resolved in `pnpm-lock.yaml`) is affected by GHSA-r28c-9q8g-f849.\nNote: `postcss` is a transitive dependency \u2014 pulled in by another package, not declared directly in a manifest.\n\nPostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure\n\nAdvisory: https://osv.dev/vulnerability/GHSA-r28c-9q8g-f849\nFix: upgrade `postcss` past the affected range per the advisory."}, "properties": {"scanner": "scanner-primary", "layer": "dependencies", "severity": "high", "confidence": 0.9}}]}}, "automationDetails": {"id": "repobility/30798"}, "properties": {"repository": "kefrens/archisimple", "repoUrl": "https://github.com/kefrens/archisimple", "branch": "main"}, "results": [{"ruleId": "scanner-faa18553494417e1", "level": "note", "message": {"text": "Icon-only button without accessible name \u2014 tools/eslint-plugin-localization/__tests__/no-hardcoded-ui-strings.test.js:38"}, "properties": {"repobilityId": "a1dffe7147811b66", "scanner": "scanner-primary", "fingerprint": "faa18553494417e1", "layer": "frontend", "severity": "low", "confidence": 0.85, "tags": ["frontend-quality", "fq.button.no-label"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tools/eslint-plugin-localization/__tests__/no-hardcoded-ui-strings.test.js"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-d8dba02e1ba87226", "level": "warning", "message": {"text": "GHSA-frvp-7c67-39w9: @hono/node-server 1.19.17 \u2014 pnpm-lock.yaml"}, "properties": {"repobilityId": "7a7c2342b3c17e8c", "scanner": "scanner-primary", "fingerprint": "d8dba02e1ba87226", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["trivy", "vuln", "GHSA-frvp-7c67-39w9"]}}, {"ruleId": "scanner-aef9872ebbd2b160", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .github/copilot-instructions.md"}, "properties": {"repobilityId": "0f079956bea4eb94", "scanner": "scanner-primary", "fingerprint": "aef9872ebbd2b160", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "agent_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/copilot-instructions.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-11b5afed35aa437a", "level": "warning", "message": {"text": "SkillSpector E1 (data-exfil) in .claude/settings.json"}, "properties": {"repobilityId": "b0802882ae82c8d7", "scanner": "scanner-primary", "fingerprint": "11b5afed35aa437a", "layer": "security", "severity": "medium", "confidence": 0.6, "tags": ["skillspector", "mcp-skill", "data-exfil", "E1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/settings.json"}, "region": {"startLine": 124}}}]}, {"ruleId": "scanner-6098be30d38c2567", "level": "warning", "message": {"text": "SkillSpector E1 (data-exfil) in extensions/carte-gouv-fr/src/index.ts"}, "properties": {"repobilityId": "7daf55ee0b7f1745", "scanner": "scanner-primary", "fingerprint": "6098be30d38c2567", "layer": "security", "severity": "medium", "confidence": 0.5, "tags": ["skillspector", "mcp-skill", "data-exfil", "E1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "extensions/carte-gouv-fr/src/index.ts"}, "region": {"startLine": 37}}}]}, {"ruleId": "scanner-f3321f3de07fb846", "level": "note", "message": {"text": "SkillSpector EA3 (excessive-agency) in LICENSE"}, "properties": {"repobilityId": "1b29968a80e56e5c", "scanner": "scanner-primary", "fingerprint": "f3321f3de07fb846", "layer": "security", "severity": "low", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "excessive-agency", "EA3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "LICENSE"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-69b73c741ec69f2c", "level": "note", "message": {"text": "SkillSpector EA3 (excessive-agency) in docs/adr/0018-event-driven-rendering-pipeline.md"}, "properties": {"repobilityId": "4e317fcdc2b6ae5e", "scanner": "scanner-primary", "fingerprint": "69b73c741ec69f2c", "layer": "security", "severity": "low", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "excessive-agency", "EA3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/adr/0018-event-driven-rendering-pipeline.md"}, "region": {"startLine": 303}}}]}, {"ruleId": "scanner-e18be84accadb308", "level": "note", "message": {"text": "SkillSpector EA3 (excessive-agency) in docs/adr/0019-modular-ressource-localization.md"}, "properties": {"repobilityId": "532f99fa75766c70", "scanner": "scanner-primary", "fingerprint": "e18be84accadb308", "layer": "security", "severity": "low", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "excessive-agency", "EA3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/adr/0019-modular-ressource-localization.md"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-dc42c6115d6df6a3", "level": "note", "message": {"text": "SkillSpector EA3 (excessive-agency) in docs/vision.md"}, "properties": {"repobilityId": "ae856a07b66b442d", "scanner": "scanner-primary", "fingerprint": "dc42c6115d6df6a3", "layer": "security", "severity": "low", "confidence": 0.75, "tags": ["skillspector", "mcp-skill", "excessive-agency", "EA3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/vision.md"}, "region": {"startLine": 129}}}]}, {"ruleId": "scanner-16317792e0cbff36", "level": "note", "message": {"text": "SkillSpector EA3 (excessive-agency) in packages/package-manager/src/package-dependency-resolver.ts"}, "properties": {"repobilityId": "5b3e085ed3c28711", "scanner": "scanner-primary", "fingerprint": "16317792e0cbff36", "layer": "security", "severity": "low", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "excessive-agency", "EA3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/package-manager/src/package-dependency-resolver.ts"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-49a990162254d52d", "level": "note", "message": {"text": "SkillSpector EA3 (excessive-agency) in packages/theme/README.md"}, "properties": {"repobilityId": "658aa6305772948c", "scanner": "scanner-primary", "fingerprint": "49a990162254d52d", "layer": "security", "severity": "low", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "excessive-agency", "EA3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/theme/README.md"}, "region": {"startLine": 38}}}]}, {"ruleId": "scanner-187c16694661c252", "level": "note", "message": {"text": "SkillSpector EA3 (excessive-agency) in packages/theme/src/theme-tokens.ts"}, "properties": {"repobilityId": "1d60c85d43790706", "scanner": "scanner-primary", "fingerprint": "187c16694661c252", "layer": "security", "severity": "low", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "excessive-agency", "EA3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/theme/src/theme-tokens.ts"}, "region": {"startLine": 19}}}]}, {"ruleId": "scanner-8723dc5de014aca4", "level": "error", "message": {"text": "SkillSpector MP3 (memory-poisoning) in docs/sprints/sprint-022.1-api-foundations.md"}, "properties": {"repobilityId": "71fde9a08ca56e23", "scanner": "scanner-primary", "fingerprint": "8723dc5de014aca4", "layer": "security", "severity": "high", "confidence": 0.8, "tags": ["skillspector", "mcp-skill", "memory-poisoning", "MP3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/sprints/sprint-022.1-api-foundations.md"}, "region": {"startLine": 349}}}]}, {"ruleId": "scanner-2fe5a7efe99e80f3", "level": "error", "message": {"text": "SkillSpector PE3 (priv-esc) in apps/web/src/workbench/pluginSecretStore.ts"}, "properties": {"repobilityId": "edc74ab709df921f", "scanner": "scanner-primary", "fingerprint": "2fe5a7efe99e80f3", "layer": "security", "severity": "high", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "priv-esc", "PE3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/src/workbench/pluginSecretStore.ts"}, "region": {"startLine": 8}}}]}, {"ruleId": "scanner-23d42a74ac9ccb32", "level": "error", "message": {"text": "SkillSpector PE3 (priv-esc) in docs/sprints/sprint-023.0-plugin-config-preferences.md"}, "properties": {"repobilityId": "7cadee7aee23a8e5", "scanner": "scanner-primary", "fingerprint": "23d42a74ac9ccb32", "layer": "security", "severity": "high", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "priv-esc", "PE3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/sprints/sprint-023.0-plugin-config-preferences.md"}, "region": {"startLine": 422}}}]}, {"ruleId": "scanner-cb1bd0d5c534ee76", "level": "error", "message": {"text": "SkillSpector PE3 (priv-esc) in packages/plugin-config/src/configuration-store.ts"}, "properties": {"repobilityId": "65e322a36c18781a", "scanner": "scanner-primary", "fingerprint": "cb1bd0d5c534ee76", "layer": "security", "severity": "high", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "priv-esc", "PE3"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/plugin-config/src/configuration-store.ts"}, "region": {"startLine": 34}}}]}, {"ruleId": "scanner-a7ae807f79649592", "level": "error", "message": {"text": "SkillSpector RA1 (rogue-agent) in apps/web/src/extensions/extensionManagement.ts"}, "properties": {"repobilityId": "19ad1c5b2f44ae99", "scanner": "scanner-primary", "fingerprint": "a7ae807f79649592", "layer": "security", "severity": "high", "confidence": 0.9, "tags": ["skillspector", "mcp-skill", "rogue-agent", "RA1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/src/extensions/extensionManagement.ts"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-90bbed042b9f3cd6", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in apps/web/package.json"}, "properties": {"repobilityId": "7b8a0d1fe6ec0f58", "scanner": "scanner-primary", "fingerprint": "90bbed042b9f3cd6", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/package.json"}, "region": {"startLine": 44}}}]}, {"ruleId": "scanner-53a22588b5e8ec47", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in extensions/carte-gouv-fr/package.json"}, "properties": {"repobilityId": "56ddbeb37278e1fc", "scanner": "scanner-primary", "fingerprint": "53a22588b5e8ec47", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "extensions/carte-gouv-fr/package.json"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-0cbe0a9bb4003937", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in extensions/example-extension/package.json"}, "properties": {"repobilityId": "3c8ecd6102938a1d", "scanner": "scanner-primary", "fingerprint": "0cbe0a9bb4003937", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "extensions/example-extension/package.json"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-1474af525032cfbf", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in package.json"}, "properties": {"repobilityId": "3383129e33c8e7f0", "scanner": "scanner-primary", "fingerprint": "1474af525032cfbf", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-ff9c7bce6b7f0d91", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/ai-engine/package.json"}, "properties": {"repobilityId": "295864c93443b834", "scanner": "scanner-primary", "fingerprint": "ff9c7bce6b7f0d91", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/ai-engine/package.json"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-1ce08cc6270fad35", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/automation-api/package.json"}, "properties": {"repobilityId": "03118f1dc526f11d", "scanner": "scanner-primary", "fingerprint": "1ce08cc6270fad35", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/automation-api/package.json"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-dfa7df10a55487c2", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/automation-mcp/package.json"}, "properties": {"repobilityId": "83d3d06ba3aa1b3a", "scanner": "scanner-primary", "fingerprint": "dfa7df10a55487c2", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/automation-mcp/package.json"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-f3541f8d50db8c42", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/building-model/package.json"}, "properties": {"repobilityId": "ebff47efdd0c1a53", "scanner": "scanner-primary", "fingerprint": "f3541f8d50db8c42", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/building-model/package.json"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-1d21f6184c0f0117", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/core/package.json"}, "properties": {"repobilityId": "4611601a809dff81", "scanner": "scanner-primary", "fingerprint": "1d21f6184c0f0117", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/package.json"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-4b69c894fcfcde7e", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/extension-host/package.json"}, "properties": {"repobilityId": "0e3584f3b833e94c", "scanner": "scanner-primary", "fingerprint": "4b69c894fcfcde7e", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/extension-host/package.json"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-d1daaedb04d5620a", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/extension-sdk/package.json"}, "properties": {"repobilityId": "017cd3302bcb8489", "scanner": "scanner-primary", "fingerprint": "d1daaedb04d5620a", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/extension-sdk/package.json"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-befad0adce71c5df", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/geometry/package.json"}, "properties": {"repobilityId": "c9e96e2836472112", "scanner": "scanner-primary", "fingerprint": "befad0adce71c5df", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/geometry/package.json"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-efb8bdfed59b9903", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/i18n/package.json"}, "properties": {"repobilityId": "700ba947e2a69fd5", "scanner": "scanner-primary", "fingerprint": "efb8bdfed59b9903", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/i18n/package.json"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-95307821cf316620", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/inspector/package.json"}, "properties": {"repobilityId": "7297bdf469afd459", "scanner": "scanner-primary", "fingerprint": "95307821cf316620", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/inspector/package.json"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-752c7b8c0d98214f", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/navigation/package.json"}, "properties": {"repobilityId": "d20f2f928cd8fed3", "scanner": "scanner-primary", "fingerprint": "752c7b8c0d98214f", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/navigation/package.json"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-6e53680721e2e1b1", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/package-manager/package.json"}, "properties": {"repobilityId": "3bf9a7e452bfcac4", "scanner": "scanner-primary", "fingerprint": "6e53680721e2e1b1", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/package-manager/package.json"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-ed75d4d98f26fa75", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/persistence/package.json"}, "properties": {"repobilityId": "e92216a463b14988", "scanner": "scanner-primary", "fingerprint": "ed75d4d98f26fa75", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/persistence/package.json"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-41d97387ccada42a", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/plugin-api/package.json"}, "properties": {"repobilityId": "5012dc01111dc328", "scanner": "scanner-primary", "fingerprint": "41d97387ccada42a", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/plugin-api/package.json"}, "region": {"startLine": 20}}}]}, {"ruleId": "scanner-82b4b61cd679663d", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/plugin-config/package.json"}, "properties": {"repobilityId": "adc5b91c8ac481e0", "scanner": "scanner-primary", "fingerprint": "82b4b61cd679663d", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/plugin-config/package.json"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-087394d1427cfb1c", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/rendering/package.json"}, "properties": {"repobilityId": "9c8cc6721d34756d", "scanner": "scanner-primary", "fingerprint": "087394d1427cfb1c", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/rendering/package.json"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-bb611cf0c83b3afd", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/resources/package.json"}, "properties": {"repobilityId": "978bc7512f367b78", "scanner": "scanner-primary", "fingerprint": "bb611cf0c83b3afd", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/resources/package.json"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-78d49d2a3857f15a", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/spatial/package.json"}, "properties": {"repobilityId": "fa5850cef014ab2b", "scanner": "scanner-primary", "fingerprint": "78d49d2a3857f15a", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/spatial/package.json"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-088e4df87bb1f302", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/theme/package.json"}, "properties": {"repobilityId": "b606eef6228801b9", "scanner": "scanner-primary", "fingerprint": "088e4df87bb1f302", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/theme/package.json"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-9d67517b414e6279", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in packages/workbench/package.json"}, "properties": {"repobilityId": "63d20a975941bf5b", "scanner": "scanner-primary", "fingerprint": "9d67517b414e6279", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/workbench/package.json"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-f1b156cbc47e662e", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in tools/eslint-plugin-localization/package.json"}, "properties": {"repobilityId": "c790b2816a175143", "scanner": "scanner-primary", "fingerprint": "f1b156cbc47e662e", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tools/eslint-plugin-localization/package.json"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-ee22b6a2d0e25cae", "level": "note", "message": {"text": "SkillSpector SC1 (supply-chain) in tools/eslint-plugin-theme/package.json"}, "properties": {"repobilityId": "716efb800dc05bce", "scanner": "scanner-primary", "fingerprint": "ee22b6a2d0e25cae", "layer": "security", "severity": "low", "confidence": 0.4, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC1"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tools/eslint-plugin-theme/package.json"}, "region": {"startLine": 13}}}]}, {"ruleId": "scanner-c852ccf9deb6e70b", "level": "error", "message": {"text": "SkillSpector SC4 (supply-chain) in apps/web/package.json"}, "properties": {"repobilityId": "39eb29aa6b174feb", "scanner": "scanner-primary", "fingerprint": "c852ccf9deb6e70b", "layer": "security", "severity": "high", "confidence": 0.8, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC4"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/package.json"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-f28e5cfcd7afa141", "level": "error", "message": {"text": "SkillSpector SC6 (supply-chain) in apps/web/package.json"}, "properties": {"repobilityId": "4e32cd71ce2ae673", "scanner": "scanner-primary", "fingerprint": "f28e5cfcd7afa141", "layer": "security", "severity": "high", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/package.json"}, "region": {"startLine": 67}}}]}, {"ruleId": "scanner-75612e1922d1a2e6", "level": "error", "message": {"text": "SkillSpector SC6 (supply-chain) in content/ai-demo-provider/package.json"}, "properties": {"repobilityId": "17912d2f26672e49", "scanner": "scanner-primary", "fingerprint": "75612e1922d1a2e6", "layer": "security", "severity": "high", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "content/ai-demo-provider/package.json"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-e831f38f77aba2c1", "level": "error", "message": {"text": "SkillSpector SC6 (supply-chain) in content/ai-lmstudio-provider/package.json"}, "properties": {"repobilityId": "37de67aad23b94b1", "scanner": "scanner-primary", "fingerprint": "e831f38f77aba2c1", "layer": "security", "severity": "high", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "content/ai-lmstudio-provider/package.json"}, "region": {"startLine": 21}}}]}, {"ruleId": "scanner-4a756e3534a5557e", "level": "error", "message": {"text": "SkillSpector SC6 (supply-chain) in content/example-extension/package.json"}, "properties": {"repobilityId": "9dd73a097bb11e59", "scanner": "scanner-primary", "fingerprint": "4a756e3534a5557e", "layer": "security", "severity": "high", "confidence": 0.7, "tags": ["skillspector", "mcp-skill", "supply-chain", "SC6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "content/example-extension/package.json"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-a88cbe63ee0eb34a", "level": "error", "message": {"text": "SkillSpector P6 (prompt-injection) in packages/package-manager/src/plugin-configuration.ts"}, "properties": {"repobilityId": "e38b42cfb53409d1", "scanner": "scanner-primary", "fingerprint": "a88cbe63ee0eb34a", "layer": "security", "severity": "high", "confidence": 0.85, "tags": ["skillspector", "mcp-skill", "prompt-injection", "P6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/package-manager/src/plugin-configuration.ts"}, "region": {"startLine": 321}}}]}, {"ruleId": "scanner-e3447526d13bf19b", "level": "error", "message": {"text": "SkillSpector P6 (prompt-injection) in packages/plugin-config/src/preference-validation.ts"}, "properties": {"repobilityId": "d8c8c84dcef2eb9e", "scanner": "scanner-primary", "fingerprint": "e3447526d13bf19b", "layer": "security", "severity": "high", "confidence": 0.85, "tags": ["skillspector", "mcp-skill", "prompt-injection", "P6"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/plugin-config/src/preference-validation.ts"}, "region": {"startLine": 25}}}]}, {"ruleId": "scanner-e637c415447867e4", "level": "none", "message": {"text": "Run SkillSpector's LLM-backed analysis in your own pipeline"}, "properties": {"repobilityId": "1936f198ff5212bf", "scanner": "scanner-primary", "fingerprint": "e637c415447867e4", "layer": "security", "severity": "info", "confidence": 1.0, "tags": ["skillspector", "mcp-skill", "llm-advisory", "ai-coder"]}}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-cb639d9a10a47b23", "level": "note", "message": {"text": "package.json defines install-time lifecycle scripts"}, "properties": {"repobilityId": "b86179956da3a4a8", "scanner": "scanner-primary", "fingerprint": "cb639d9a10a47b23", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "npm", "install-scripts"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-be00c115334307ce", "level": "note", "message": {"text": "Very large file: apps/web/src/App.tsx (1261 lines)"}, "properties": {"repobilityId": "4ccb7d0f033e2f7e", "scanner": "scanner-primary", "fingerprint": "be00c115334307ce", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-f73c8ff17174db57", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "properties": {"repobilityId": "6c1704bf24cf19ac", "scanner": "scanner-primary", "fingerprint": "f73c8ff17174db57", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2ef3ce27fcea2ca2", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: extensions/carte-gouv-fr/package.json"}, "properties": {"repobilityId": "12d30808342b655a", "scanner": "scanner-primary", "fingerprint": "2ef3ce27fcea2ca2", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "extensions/carte-gouv-fr/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ec660ae4b7898549", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: extensions/example-extension/package.json"}, "properties": {"repobilityId": "069c5f582d6e5ab4", "scanner": "scanner-primary", "fingerprint": "ec660ae4b7898549", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "extensions/example-extension/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0588e415c04250f0", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/spatial/package.json"}, "properties": {"repobilityId": "b03cfc1f87e204a8", "scanner": "scanner-primary", "fingerprint": "0588e415c04250f0", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/spatial/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-abdaeeb0b86bd56a", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/i18n/package.json"}, "properties": {"repobilityId": "d914a9bdf5957152", "scanner": "scanner-primary", "fingerprint": "abdaeeb0b86bd56a", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/i18n/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ec8786402df3545", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/rendering/package.json"}, "properties": {"repobilityId": "6a68178793909851", "scanner": "scanner-primary", "fingerprint": "3ec8786402df3545", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/rendering/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-038566c48a8f2e78", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/navigation/package.json"}, "properties": {"repobilityId": "b98ee27c9fd1eaed", "scanner": "scanner-primary", "fingerprint": "038566c48a8f2e78", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/navigation/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2caa337a56a39957", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/plugin-api/package.json"}, "properties": {"repobilityId": "2000985c61032533", "scanner": "scanner-primary", "fingerprint": "2caa337a56a39957", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/plugin-api/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-82cd173b004539d2", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/resources/package.json"}, "properties": {"repobilityId": "190c40b73af1da47", "scanner": "scanner-primary", "fingerprint": "82cd173b004539d2", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/resources/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f61a443bf7aac143", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/extension-host/package.json"}, "properties": {"repobilityId": "1b834216da6a50af", "scanner": "scanner-primary", "fingerprint": "f61a443bf7aac143", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/extension-host/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-24a1379c4b883c49", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/building-model/package.json"}, "properties": {"repobilityId": "be4487c27a726b51", "scanner": "scanner-primary", "fingerprint": "24a1379c4b883c49", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/building-model/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-75691449d985e0ee", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/theme/package.json"}, "properties": {"repobilityId": "c8b2e44d39efe820", "scanner": "scanner-primary", "fingerprint": "75691449d985e0ee", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/theme/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-20a27c33b1839ed6", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/workbench/package.json"}, "properties": {"repobilityId": "8821f3969d32a21f", "scanner": "scanner-primary", "fingerprint": "20a27c33b1839ed6", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/workbench/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ad2778bbf8021e9d", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/plugin-config/package.json"}, "properties": {"repobilityId": "5d172ac707d917ca", "scanner": "scanner-primary", "fingerprint": "ad2778bbf8021e9d", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/plugin-config/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3321a0ec74fb5c0a", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/package-manager/package.json"}, "properties": {"repobilityId": "83a955c8b1ce9ddc", "scanner": "scanner-primary", "fingerprint": "3321a0ec74fb5c0a", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/package-manager/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1ae76aef20353f4e", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/automation-mcp/package.json"}, "properties": {"repobilityId": "09965f869ba2b695", "scanner": "scanner-primary", "fingerprint": "1ae76aef20353f4e", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/automation-mcp/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-cc249ed5e6371854", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/ai-engine/package.json"}, "properties": {"repobilityId": "4f08c7b2c5e3b082", "scanner": "scanner-primary", "fingerprint": "cc249ed5e6371854", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/ai-engine/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-31339c4f6d7bc62e", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/extension-sdk/package.json"}, "properties": {"repobilityId": "81e4d8b3b7ac7664", "scanner": "scanner-primary", "fingerprint": "31339c4f6d7bc62e", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/extension-sdk/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1ada30b496643aab", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/core/package.json"}, "properties": {"repobilityId": "8640e46be7e3f9b2", "scanner": "scanner-primary", "fingerprint": "1ada30b496643aab", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b4d5ce916fb4d7e2", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/automation-api/package.json"}, "properties": {"repobilityId": "0893ae8a8ad6280d", "scanner": "scanner-primary", "fingerprint": "b4d5ce916fb4d7e2", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/automation-api/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-721678005439020a", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/persistence/package.json"}, "properties": {"repobilityId": "0620706eff76de3f", "scanner": "scanner-primary", "fingerprint": "721678005439020a", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/persistence/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e281181b7e23e679", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/geometry/package.json"}, "properties": {"repobilityId": "5e216d17123b008b", "scanner": "scanner-primary", "fingerprint": "e281181b7e23e679", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/geometry/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-516efb912e6947be", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/inspector/package.json"}, "properties": {"repobilityId": "cbecd12907da6d88", "scanner": "scanner-primary", "fingerprint": "516efb912e6947be", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/inspector/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-76a355d93b9403fe", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: tools/eslint-plugin-theme/package.json"}, "properties": {"repobilityId": "747c39fbb44639a3", "scanner": "scanner-primary", "fingerprint": "76a355d93b9403fe", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tools/eslint-plugin-theme/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7b645b60c1dd4645", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: tools/eslint-plugin-localization/package.json"}, "properties": {"repobilityId": "268f54e3610b3c42", "scanner": "scanner-primary", "fingerprint": "7b645b60c1dd4645", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "tools/eslint-plugin-localization/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-705bac266517690b", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: plugins/measurements/package.json"}, "properties": {"repobilityId": "bc1adea72d91d4fd", "scanner": "scanner-primary", "fingerprint": "705bac266517690b", "layer": "dependencies", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "plugins/measurements/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "bd1008f55d41f992", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "a6f5fd32a26a3d23", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "659590ebf362a773", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-d018e7f1ff8f1431", "level": "warning", "message": {"text": "Vulnerable dependency @hono/node-server 1.19.17: GHSA-frvp-7c67-39w9"}, "properties": {"repobilityId": "d9be4cad8cc3ea85", "scanner": "scanner-primary", "fingerprint": "d018e7f1ff8f1431", "layer": "dependencies", "severity": "medium", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-frvp-7c67-39w9", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0f452baefab70814", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 5.0.6: GHSA-3jxr-9vmj-r5cp"}, "properties": {"repobilityId": "d33b0db2b7d6b674", "scanner": "scanner-primary", "fingerprint": "0f452baefab70814", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-3jxr-9vmj-r5cp", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-037c11824e840dd1", "level": "error", "message": {"text": "Vulnerable dependency brace-expansion 5.0.6: GHSA-mh99-v99m-4gvg"}, "properties": {"repobilityId": "b18bc07c3b6811f7", "scanner": "scanner-primary", "fingerprint": "037c11824e840dd1", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-mh99-v99m-4gvg", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-facab9c4db5dfcdb", "level": "error", "message": {"text": "Vulnerable dependency postcss 8.5.15: GHSA-r28c-9q8g-f849"}, "properties": {"repobilityId": "70c61f72b039c17c", "scanner": "scanner-primary", "fingerprint": "facab9c4db5dfcdb", "layer": "dependencies", "severity": "high", "confidence": 0.9, "tags": ["dependency", "sca", "osv", "GHSA-r28c-9q8g-f849", "transitive"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "pnpm-lock.yaml"}, "region": {"startLine": 1}}}]}]}]}