{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-96c2762a6a73a623", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/index.ts:196", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/index.ts:196"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9b3cf1e8d8e0687a", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/middleware/tracing.ts:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/middleware/tracing.ts:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fb14b24aa7fa5431", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/routes/builder.ts:568", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/routes/builder.ts:568"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e722c31c289fb129", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/routes/clerk-webhook.ts:158", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/routes/clerk-webhook.ts:158"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e16f6cb0f14e8f17", "name": "TODO/FIXME marker in shipping code \u2014 packages/sandbox/src/tasks/eval/llm-judge.ts:28", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 packages/sandbox/src/tasks/eval/llm-judge.ts:28"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-a14fdfee8e43cc86", "name": "Stray `console.log` in TS/JS \u2014 packages/core/src/db/apply-sql.cli.ts:29", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/core/src/db/apply-sql.cli.ts:29"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4511f1fef6766d5e", "name": "Stray `console.log` in TS/JS \u2014 packages/core/src/graph/coverage.cli.ts:58", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/core/src/graph/coverage.cli.ts:58"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-54b06dc8d51048c7", "name": "Stray `console.log` in TS/JS \u2014 packages/core/src/graph/embed.cli.ts:32", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/core/src/graph/embed.cli.ts:32"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e13bbe1769d9aed7", "name": "Stray `console.log` in TS/JS \u2014 packages/core/src/graph/seed.cli.ts:17", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/core/src/graph/seed.cli.ts:17"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-21b0e45958c9edad", "name": "Stray `console.log` in TS/JS \u2014 packages/core/src/llm/LLMAbstraction.ts:88", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/core/src/llm/LLMAbstraction.ts:88"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-657d7a966c97d685", "name": "Stray `console.log` in TS/JS \u2014 packages/evals/src/runner.ts:169", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/evals/src/runner.ts:169"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ec47c2da9e0833e", "name": "Stray `console.log` in TS/JS \u2014 packages/evals/src/validation-bench.ts:328", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 packages/evals/src/validation-bench.ts:328"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1e9968eff7bdba57", "name": "Stray `console.log` in TS/JS \u2014 .github/skills/export-audit-pack/scripts/export.ts:37", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 .github/skills/export-audit-pack/scripts/export.ts:37"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-af17890d6e2737be", "name": "Stray `console.log` in TS/JS \u2014 .github/skills/verify-trace-chain/scripts/verify.ts:14", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 .github/skills/verify-trace-chain/scripts/verify.ts:14"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d2bf667c9d571d46", "name": "TODO/FIXME marker in shipping code \u2014 .github/skills/create-process/assets/agent-template.ts:11", "shortDescription": {"text": "TODO/FIXME marker in shipping code \u2014 .github/skills/create-process/assets/agent-template.ts:11"}, "fullDescription": {"text": "Track in /reviews or /issues, not as a code comment that rots.\n\nWhy: Drift control \u2014 shouldn't be the same as Quality TODO scanner.\nRule id: fq.todo-marker"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-8403c08ef4c07bb5", "name": "Stray `console.log` in TS/JS \u2014 .github/skills/run-compliance-check/scripts/check-coverage.ts:28", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 .github/skills/run-compliance-check/scripts/check-coverage.ts:28"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c694fb21645bd8b", "name": "Stray `console.log` in TS/JS \u2014 .github/skills/seed-regulations/scripts/validate-yaml.ts:58", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 .github/skills/seed-regulations/scripts/validate-yaml.ts:58"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-075ac34699dbaa3f", "name": "Privileged port 10 in use", "shortDescription": {"text": "Privileged port 10 in use"}, "fullDescription": {"text": "Port 10 is privileged (<1024). Make sure the service runs with the right caps or front it with a non-privileged port via a load balancer."}, "properties": {"scanner": "scanner-primary", "layer": "network", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e891e3d2a48990a1", "name": "Insecure pattern 'cors_wildcard' in apps/api/serve-lite.mjs:66", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in apps/api/serve-lite.mjs:66"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-af71d53e23eac6c8", "name": "Insecure pattern 'direct_innerhtml_assignment' in apps/api/src/services/AgentBundler.ts:253", "shortDescription": {"text": "Insecure pattern 'direct_innerhtml_assignment' in apps/api/src/services/AgentBundler.ts:253"}, "fullDescription": {"text": "Found a known-risky pattern (direct_innerhtml_assignment). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0096d36ad20926e8", "name": "Possible secret in packages/mcp-server/scripts/smoke.mjs", "shortDescription": {"text": "Possible secret in packages/mcp-server/scripts/smoke.mjs"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-200c4602cb0221c5", "name": "Insecure pattern 'node_child_process' in packages/mcp-server/scripts/smoke.mjs:11", "shortDescription": {"text": "Insecure pattern 'node_child_process' in packages/mcp-server/scripts/smoke.mjs:11"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-65aa740cba4a4a73", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5d2dba911b3e3517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/upload-artifact@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-27924aa79fa4a517", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-48fb8ac0ffe1b092", "name": "GitHub Action is tag-pinned rather than SHA-pinned", "shortDescription": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "fullDescription": {"text": "actions/checkout@v4 can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "low", "confidence": 1.0}}, {"id": "scanner-139b11d10599a9c4", "name": "GitHub Action tracks a moving branch", "shortDescription": {"text": "GitHub Action tracks a moving branch"}, "fullDescription": {"text": "aquasecurity/trivy-action@master can move without a code change in this repo. Pin third-party actions to a reviewed 40-character commit SHA."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e5b8e6d3f2b30391", "name": "GitHub Actions workflow grants broad write permissions", "shortDescription": {"text": "GitHub Actions workflow grants broad write permissions"}, "fullDescription": {"text": "CI tokens with write permissions increase blast radius when an action, dependency, or PR workflow is compromised. Prefer job-level least-privilege permissions."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f112cb87ef05f4cf", "name": "Very large file: apps/web/src/lib/psurDocuments.ts (1131 lines)", "shortDescription": {"text": "Very large file: apps/web/src/lib/psurDocuments.ts (1131 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ba49967cf0b0efe7", "name": "Very large file: apps/web/src/pages/ProcessDesigner.tsx (2042 lines)", "shortDescription": {"text": "Very large file: apps/web/src/pages/ProcessDesigner.tsx (2042 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-edfde1549cdf4308", "name": "Very large file: apps/web/src/pages/Sandbox.tsx (1920 lines)", "shortDescription": {"text": "Very large file: apps/web/src/pages/Sandbox.tsx (1920 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ada82e818b0aefd3", "name": "Very large file: apps/web/src/pages/PsurDemo.tsx (2263 lines)", "shortDescription": {"text": "Very large file: apps/web/src/pages/PsurDemo.tsx (2263 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea3b5e389d8c9c0f", "name": "Low test-to-source ratio", "shortDescription": {"text": "Low test-to-source ratio"}, "fullDescription": {"text": "32 tests / 252 src (ratio 0.13)."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b06b8d86f24c77f9", "name": "Node manifest has dependencies but no lockfile: apps/api/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/api/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a9eb7dc7c6e3880", "name": "Node manifest has dependencies but no lockfile: apps/web/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8cad527fa7b2fdd7", "name": "Node manifest has dependencies but no lockfile: packages/sandbox/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/sandbox/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28e92806c0db3cd2", "name": "Node manifest has dependencies but no lockfile: packages/core/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/core/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7eb3bf44d969a4e1", "name": "Node manifest has dependencies but no lockfile: packages/evals/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/evals/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 133 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 27 placeholder/mock markers across 18 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing lockfile. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1824f43a23904319", "name": "Agent instruction contains unpinned remote install: .claude/commands/goal-publish-mcp.md", "shortDescription": {"text": "Agent instruction contains unpinned remote install: .claude/commands/goal-publish-mcp.md"}, "fullDescription": {"text": "Remote install commands in agent instructions are a supply-chain risk, especially when an agent can execute shell commands."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-80e352046295c6a4", "name": "Commented-code block (6 lines) in apps/api/src/index.ts:162", "shortDescription": {"text": "Commented-code block (6 lines) in apps/api/src/index.ts:162"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-f9969136b2edef74", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/psur.test.ts:248", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/psur.test.ts:248"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e77de2c3d67a964c", "name": "Commented-code block (5 lines) in apps/api/src/routes/managed-agents.ts:173", "shortDescription": {"text": "Commented-code block (5 lines) in apps/api/src/routes/managed-agents.ts:173"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-485a7486c916d937", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/builder.test.ts:352", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/builder.test.ts:352"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-79fbdb9ca8f7c5c4", "name": "Commented-code block (5 lines) in apps/api/src/routes/psur.ts:396", "shortDescription": {"text": "Commented-code block (5 lines) in apps/api/src/routes/psur.ts:396"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-7cf706f7c69b2e2c", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/workspace.test.ts:201", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/workspace.test.ts:201"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-713c2f6d53fe2bd9", "name": "Commented-code block (6 lines) in apps/api/src/routes/builder.ts:412", "shortDescription": {"text": "Commented-code block (6 lines) in apps/api/src/routes/builder.ts:412"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-ccc2445df8fe4d57", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/sandbox.test.ts:144", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/sandbox.test.ts:144"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3aa546a6adae2556", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/traces.test.ts:86", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/traces.test.ts:86"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b6da3446d8da0580", "name": "Commented-code block (5 lines) in apps/api/src/routes/clerk-webhook.ts:12", "shortDescription": {"text": "Commented-code block (5 lines) in apps/api/src/routes/clerk-webhook.ts:12"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-666063d532949853", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/services/AgentBundler.ts:203", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/services/AgentBundler.ts:203"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f5b6b328881b5463", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/lib/queryClient.ts:68", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/lib/queryClient.ts:68"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c9194db6a17a9dcb", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/pages/PsurDemo.tsx:208", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/pages/PsurDemo.tsx:208"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0ae0507d83b98182", "name": "Commented-code block (5 lines) in packages/core/src/agents/BaseGroundedAgent.ts:74", "shortDescription": {"text": "Commented-code block (5 lines) in packages/core/src/agents/BaseGroundedAgent.ts:74"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-c2cdaf6da03f88ef", "name": "Commented-code block (5 lines) in packages/core/src/db/schema.ts:453", "shortDescription": {"text": "Commented-code block (5 lines) in packages/core/src/db/schema.ts:453"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-4b80f34ce98ef6f0", "name": "Commented-code block (6 lines) in packages/core/src/graph/GraphSeeder.ts:98", "shortDescription": {"text": "Commented-code block (6 lines) in packages/core/src/graph/GraphSeeder.ts:98"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-75818801ee2810ec", "name": "Commented-code block (7 lines) in packages/core/src/graph/types.ts:109", "shortDescription": {"text": "Commented-code block (7 lines) in packages/core/src/graph/types.ts:109"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-37b0d5c20fdb19dd", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/core/src/llm/providers/GenericProvider.ts:50", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/core/src/llm/providers/GenericProvider.ts:50"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-836d214f86d62353", "name": "`fetch()` without try/.catch or AbortSignal \u2014 packages/core/src/llm/providers/DeepSeekProvider.ts:55", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/core/src/llm/providers/DeepSeekProvider.ts:55"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b0b5e7cb1208a7cd", "name": "13 env vars used in code but missing from .env.example", "shortDescription": {"text": "13 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `API_URL`, `DEEPSEEK_API_KEY`, `EMBEDDING_PROVIDER`, `FILE_STORE_PATH`, `LOG_LEVEL`, `MANAGED_AGENTS_MODEL`, `MCP_MAX_RESPONSE_BYTES`, `MCP_URL` + 5 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ee8e83033be6be0e", "name": "Frontend route `/app/sandbox/:taskId` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/app/sandbox/:taskId` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9c7753083de896c", "name": "Frontend route `/app/trails/:id` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/app/trails/:id` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f5af48edf1c1df4", "name": "Frontend route `/app/trails` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/app/trails` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a30e97e5b3f0c1a8", "name": "Frontend route `/app/*` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/app/*` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b1cea81df8fa1d86", "name": "Unused endpoint: USE /api/clerk-webhook", "shortDescription": {"text": "Unused endpoint: USE /api/clerk-webhook"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `USE /api/clerk-webhook` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-44f28055eb716379", "name": "Unused endpoint: USE /ready", "shortDescription": {"text": "Unused endpoint: USE /ready"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `USE /ready` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d88bf633f398006", "name": "Unused endpoint: GET /api/graph/stats", "shortDescription": {"text": "Unused endpoint: GET /api/graph/stats"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `GET /api/graph/stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dde3adb27bf7eebe", "name": "Unused endpoint: USE /api", "shortDescription": {"text": "Unused endpoint: USE /api"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `USE /api` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-962186af7cd159b9", "name": "Unused endpoint: USE /api/psur", "shortDescription": {"text": "Unused endpoint: USE /api/psur"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `USE /api/psur` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6b11d62e5e5c482b", "name": "Unused endpoint: USE /api/graph", "shortDescription": {"text": "Unused endpoint: USE /api/graph"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `USE /api/graph` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-55125999d15d30ae", "name": "Unused endpoint: USE /api/traces", "shortDescription": {"text": "Unused endpoint: USE /api/traces"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `USE /api/traces` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d1c6d1d11f461711", "name": "Unused endpoint: USE /api/api-keys", "shortDescription": {"text": "Unused endpoint: USE /api/api-keys"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `USE /api/api-keys` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50d9d80b509ac18d", "name": "Unused endpoint: USE /api/sandbox", "shortDescription": {"text": "Unused endpoint: USE /api/sandbox"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `USE /api/sandbox` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6cd3f7afb94e8b8f", "name": "Unused endpoint: USE /api/builder", "shortDescription": {"text": "Unused endpoint: USE /api/builder"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `USE /api/builder` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1afa00d06cb7e7d5", "name": "Unused endpoint: USE /api/usage", "shortDescription": {"text": "Unused endpoint: USE /api/usage"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `USE /api/usage` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f29e8d5ce947efbb", "name": "Unused endpoint: USE /api/workspace", "shortDescription": {"text": "Unused endpoint: USE /api/workspace"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `USE /api/workspace` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f81b49bb89fa3006", "name": "Unused endpoint: USE /api/validate-draft", "shortDescription": {"text": "Unused endpoint: USE /api/validate-draft"}, "fullDescription": {"text": "`apps/api/src/index.ts` declares `USE /api/validate-draft` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd0e06afbaab19b3", "name": "Unused endpoint: GET /tasks", "shortDescription": {"text": "Unused endpoint: GET /tasks"}, "fullDescription": {"text": "`apps/api/src/routes/sandbox.ts` declares `GET /tasks` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4d2b27fe30e2e2c2", "name": "Unused endpoint: GET /tasks/:id", "shortDescription": {"text": "Unused endpoint: GET /tasks/:id"}, "fullDescription": {"text": "`apps/api/src/routes/sandbox.ts` declares `GET /tasks/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f6786e723a23903c", "name": "Unused endpoint: POST /tasks/:id/run", "shortDescription": {"text": "Unused endpoint: POST /tasks/:id/run"}, "fullDescription": {"text": "`apps/api/src/routes/sandbox.ts` declares `POST /tasks/:id/run` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-275993b4e45208e5", "name": "Unused endpoint: GET /runs/:runId/stream", "shortDescription": {"text": "Unused endpoint: GET /runs/:runId/stream"}, "fullDescription": {"text": "`apps/api/src/routes/sandbox.ts` declares `GET /runs/:runId/stream` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd5f43776a3755fc", "name": "Unused endpoint: GET /runs/recent", "shortDescription": {"text": "Unused endpoint: GET /runs/recent"}, "fullDescription": {"text": "`apps/api/src/routes/sandbox.ts` declares `GET /runs/recent` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a9c351022ff0983", "name": "Unused endpoint: GET /runs/:runId/result", "shortDescription": {"text": "Unused endpoint: GET /runs/:runId/result"}, "fullDescription": {"text": "`apps/api/src/routes/sandbox.ts` declares `GET /runs/:runId/result` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ddbb94d0d606421e", "name": "Unused endpoint: GET /runs/:runId/trace", "shortDescription": {"text": "Unused endpoint: GET /runs/:runId/trace"}, "fullDescription": {"text": "`apps/api/src/routes/sandbox.ts` declares `GET /runs/:runId/trace` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e4be0e9456fdc2b4", "name": "Unused endpoint: GET /runs/:runId/trace/verify", "shortDescription": {"text": "Unused endpoint: GET /runs/:runId/trace/verify"}, "fullDescription": {"text": "`apps/api/src/routes/sandbox.ts` declares `GET /runs/:runId/trace/verify` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a2e4c1c7d468070", "name": "Unused endpoint: GET /runs/:runId/audit-pack", "shortDescription": {"text": "Unused endpoint: GET /runs/:runId/audit-pack"}, "fullDescription": {"text": "`apps/api/src/routes/sandbox.ts` declares `GET /runs/:runId/audit-pack` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-abe36e0d2e7b63c9", "name": "Unused endpoint: POST /runs/:runId/judge", "shortDescription": {"text": "Unused endpoint: POST /runs/:runId/judge"}, "fullDescription": {"text": "`apps/api/src/routes/sandbox.ts` declares `POST /runs/:runId/judge` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8c16eb1659ee9897", "name": "Unused endpoint: GET /tasks/:id/download", "shortDescription": {"text": "Unused endpoint: GET /tasks/:id/download"}, "fullDescription": {"text": "`apps/api/src/routes/sandbox.ts` declares `GET /tasks/:id/download` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`apps/api/src/routes/readiness.ts` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c2584bcef569ae26", "name": "Unused endpoint: POST /agents/:id/deploy", "shortDescription": {"text": "Unused endpoint: POST /agents/:id/deploy"}, "fullDescription": {"text": "`apps/api/src/routes/managed-agents.ts` declares `POST /agents/:id/deploy` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28362816735f463c", "name": "Unused endpoint: POST /agents/:id/runs", "shortDescription": {"text": "Unused endpoint: POST /agents/:id/runs"}, "fullDescription": {"text": "`apps/api/src/routes/managed-agents.ts` declares `POST /agents/:id/runs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8dcc3675973e7474", "name": "Unused endpoint: GET /agents/:id/runs", "shortDescription": {"text": "Unused endpoint: GET /agents/:id/runs"}, "fullDescription": {"text": "`apps/api/src/routes/managed-agents.ts` declares `GET /agents/:id/runs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c9b8229e40690bb9", "name": "Unused endpoint: GET /agents/:id/runs/:runId", "shortDescription": {"text": "Unused endpoint: GET /agents/:id/runs/:runId"}, "fullDescription": {"text": "`apps/api/src/routes/managed-agents.ts` declares `GET /agents/:id/runs/:runId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ad79d9b65733f752", "name": "Unused endpoint: POST /agents/:id/runs/:runId/save", "shortDescription": {"text": "Unused endpoint: POST /agents/:id/runs/:runId/save"}, "fullDescription": {"text": "`apps/api/src/routes/managed-agents.ts` declares `POST /agents/:id/runs/:runId/save` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-92e4fb1a8c310c5d", "name": "Unused endpoint: GET /agents/:id/runs/:runId/stream", "shortDescription": {"text": "Unused endpoint: GET /agents/:id/runs/:runId/stream"}, "fullDescription": {"text": "`apps/api/src/routes/managed-agents.ts` declares `GET /agents/:id/runs/:runId/stream` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`apps/api/src/routes/validate-draft.ts` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-10c14b30d098b8b6", "name": "Unused endpoint: GET /:processInstanceId", "shortDescription": {"text": "Unused endpoint: GET /:processInstanceId"}, "fullDescription": {"text": "`apps/api/src/routes/traces.ts` declares `GET /:processInstanceId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3d8d3b89d66eecdb", "name": "Unused endpoint: GET /:processInstanceId/verify", "shortDescription": {"text": "Unused endpoint: GET /:processInstanceId/verify"}, "fullDescription": {"text": "`apps/api/src/routes/traces.ts` declares `GET /:processInstanceId/verify` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b30638f97b764f09", "name": "Unused endpoint: GET /:processInstanceId/export.jsonl", "shortDescription": {"text": "Unused endpoint: GET /:processInstanceId/export.jsonl"}, "fullDescription": {"text": "`apps/api/src/routes/traces.ts` declares `GET /:processInstanceId/export.jsonl` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c41b5a0ddeb29b1", "name": "Unused endpoint: GET /:processInstanceId/export.dot", "shortDescription": {"text": "Unused endpoint: GET /:processInstanceId/export.dot"}, "fullDescription": {"text": "`apps/api/src/routes/traces.ts` declares `GET /:processInstanceId/export.dot` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-339f9dd69037b797", "name": "Unused endpoint: GET /:processInstanceId/audit-report", "shortDescription": {"text": "Unused endpoint: GET /:processInstanceId/audit-report"}, "fullDescription": {"text": "`apps/api/src/routes/traces.ts` declares `GET /:processInstanceId/audit-report` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4ac3174931f5a7e8", "name": "Unused endpoint: GET /:processInstanceId/audit-pack", "shortDescription": {"text": "Unused endpoint: GET /:processInstanceId/audit-pack"}, "fullDescription": {"text": "`apps/api/src/routes/traces.ts` declares `GET /:processInstanceId/audit-pack` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ab45f4d06595901", "name": "Unused endpoint: GET /obligations", "shortDescription": {"text": "Unused endpoint: GET /obligations"}, "fullDescription": {"text": "`apps/api/src/routes/graph.ts` declares `GET /obligations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2b38bd6a95a90406", "name": "Unused endpoint: GET /obligations/:id", "shortDescription": {"text": "Unused endpoint: GET /obligations/:id"}, "fullDescription": {"text": "`apps/api/src/routes/graph.ts` declares `GET /obligations/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-502c83fb6274eae0", "name": "Unused endpoint: GET /obligations/:id/explain", "shortDescription": {"text": "Unused endpoint: GET /obligations/:id/explain"}, "fullDescription": {"text": "`apps/api/src/routes/graph.ts` declares `GET /obligations/:id/explain` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa8ee0adbe1e9daf", "name": "Unused endpoint: POST /obligations", "shortDescription": {"text": "Unused endpoint: POST /obligations"}, "fullDescription": {"text": "`apps/api/src/routes/graph.ts` declares `POST /obligations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9ea480e0c5b1a862", "name": "Unused endpoint: DELETE /obligations/:id", "shortDescription": {"text": "Unused endpoint: DELETE /obligations/:id"}, "fullDescription": {"text": "`apps/api/src/routes/graph.ts` declares `DELETE /obligations/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1bb3714794b14146", "name": "Unused endpoint: POST /query", "shortDescription": {"text": "Unused endpoint: POST /query"}, "fullDescription": {"text": "`apps/api/src/routes/graph.ts` declares `POST /query` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e1590f41fc76e5b", "name": "Unused endpoint: POST /compliance-check", "shortDescription": {"text": "Unused endpoint: POST /compliance-check"}, "fullDescription": {"text": "`apps/api/src/routes/graph.ts` declares `POST /compliance-check` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7bf655151935db1a", "name": "Unused endpoint: POST /schedule-cadence", "shortDescription": {"text": "Unused endpoint: POST /schedule-cadence"}, "fullDescription": {"text": "`apps/api/src/routes/graph.ts` declares `POST /schedule-cadence` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6f43d8ef9e363507", "name": "Unused endpoint: POST /evidence-map", "shortDescription": {"text": "Unused endpoint: POST /evidence-map"}, "fullDescription": {"text": "`apps/api/src/routes/graph.ts` declares `POST /evidence-map` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-09b021c60df86e61", "name": "Unused endpoint: POST /explain-path", "shortDescription": {"text": "Unused endpoint: POST /explain-path"}, "fullDescription": {"text": "`apps/api/src/routes/graph.ts` declares `POST /explain-path` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6af224edb292ca8f", "name": "Unused endpoint: GET /process-types", "shortDescription": {"text": "Unused endpoint: GET /process-types"}, "fullDescription": {"text": "`apps/api/src/routes/graph.ts` declares `GET /process-types` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd8dc4599ec52a08", "name": "Unused endpoint: GET /stats", "shortDescription": {"text": "Unused endpoint: GET /stats"}, "fullDescription": {"text": "`apps/api/src/routes/graph.ts` declares `GET /stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/19879"}, "properties": {"repository": "Smarticus81/grkbSamarticusv1", "repoUrl": "https://github.com/Smarticus81/grkbSamarticusv1", "branch": "main"}, "results": [{"ruleId": "scanner-96c2762a6a73a623", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/index.ts:196"}, "properties": {"repobilityId": "a178156af585d748", "scanner": "scanner-primary", "fingerprint": "96c2762a6a73a623", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9b3cf1e8d8e0687a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/middleware/tracing.ts:19"}, "properties": {"repobilityId": "f3e0374414656393", "scanner": "scanner-primary", "fingerprint": "9b3cf1e8d8e0687a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fb14b24aa7fa5431", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/routes/builder.ts:568"}, "properties": {"repobilityId": "67671442aa934f39", "scanner": "scanner-primary", "fingerprint": "fb14b24aa7fa5431", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e722c31c289fb129", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/routes/clerk-webhook.ts:158"}, "properties": {"repobilityId": "0a200bb113ca5e6c", "scanner": "scanner-primary", "fingerprint": "e722c31c289fb129", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e16f6cb0f14e8f17", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 packages/sandbox/src/tasks/eval/llm-judge.ts:28"}, "properties": {"repobilityId": "42bf51c321e8655b", "scanner": "scanner-primary", "fingerprint": "e16f6cb0f14e8f17", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-a14fdfee8e43cc86", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/core/src/db/apply-sql.cli.ts:29"}, "properties": {"repobilityId": "2e309689e4a82597", "scanner": "scanner-primary", "fingerprint": "a14fdfee8e43cc86", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4511f1fef6766d5e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/core/src/graph/coverage.cli.ts:58"}, "properties": {"repobilityId": "cafbb14a83b8e9da", "scanner": "scanner-primary", "fingerprint": "4511f1fef6766d5e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-54b06dc8d51048c7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/core/src/graph/embed.cli.ts:32"}, "properties": {"repobilityId": "21fd3431da60143e", "scanner": "scanner-primary", "fingerprint": "54b06dc8d51048c7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e13bbe1769d9aed7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/core/src/graph/seed.cli.ts:17"}, "properties": {"repobilityId": "1ea1f997000532cd", "scanner": "scanner-primary", "fingerprint": "e13bbe1769d9aed7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-21b0e45958c9edad", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/core/src/llm/LLMAbstraction.ts:88"}, "properties": {"repobilityId": "6ff63971f86c4884", "scanner": "scanner-primary", "fingerprint": "21b0e45958c9edad", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-657d7a966c97d685", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/evals/src/runner.ts:169"}, "properties": {"repobilityId": "2b9e328ef79dc90a", "scanner": "scanner-primary", "fingerprint": "657d7a966c97d685", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2ec47c2da9e0833e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 packages/evals/src/validation-bench.ts:328"}, "properties": {"repobilityId": "b08eb3f911362d31", "scanner": "scanner-primary", "fingerprint": "2ec47c2da9e0833e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1e9968eff7bdba57", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 .github/skills/export-audit-pack/scripts/export.ts:37"}, "properties": {"repobilityId": "0a282f4d12ee6fa6", "scanner": "scanner-primary", "fingerprint": "1e9968eff7bdba57", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-af17890d6e2737be", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 .github/skills/verify-trace-chain/scripts/verify.ts:14"}, "properties": {"repobilityId": "1b6e973415775f90", "scanner": "scanner-primary", "fingerprint": "af17890d6e2737be", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d2bf667c9d571d46", "level": "none", "message": {"text": "TODO/FIXME marker in shipping code \u2014 .github/skills/create-process/assets/agent-template.ts:11"}, "properties": {"repobilityId": "facb97563b258ea3", "scanner": "scanner-primary", "fingerprint": "d2bf667c9d571d46", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.todo-marker"]}}, {"ruleId": "scanner-8403c08ef4c07bb5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 .github/skills/run-compliance-check/scripts/check-coverage.ts:28"}, "properties": {"repobilityId": "355cf2835ea5c5d7", "scanner": "scanner-primary", "fingerprint": "8403c08ef4c07bb5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5c694fb21645bd8b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 .github/skills/seed-regulations/scripts/validate-yaml.ts:58"}, "properties": {"repobilityId": "6647acd2f9b679a7", "scanner": "scanner-primary", "fingerprint": "5c694fb21645bd8b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-075ac34699dbaa3f", "level": "warning", "message": {"text": "Privileged port 10 in use"}, "properties": {"repobilityId": "735372d6b5594915", "scanner": "scanner-primary", "fingerprint": "075ac34699dbaa3f", "layer": "network", "severity": "medium", "confidence": 1.0, "tags": ["security", "ports"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/sandbox/src/processes/complaints/harness/complaint-scenarios.yaml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e891e3d2a48990a1", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in apps/api/serve-lite.mjs:66"}, "properties": {"repobilityId": "3bd57300e49067cb", "scanner": "scanner-primary", "fingerprint": "e891e3d2a48990a1", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/serve-lite.mjs"}, "region": {"startLine": 66}}}]}, {"ruleId": "scanner-af71d53e23eac6c8", "level": "warning", "message": {"text": "Insecure pattern 'direct_innerhtml_assignment' in apps/api/src/services/AgentBundler.ts:253"}, "properties": {"repobilityId": "2306e8904751b0ef", "scanner": "scanner-primary", "fingerprint": "af71d53e23eac6c8", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "direct_innerhtml_assignment"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/src/services/AgentBundler.ts"}, "region": {"startLine": 253}}}]}, {"ruleId": "scanner-0096d36ad20926e8", "level": "error", "message": {"text": "Possible secret in packages/mcp-server/scripts/smoke.mjs"}, "properties": {"repobilityId": "7f0e9c522ad237cf", "scanner": "scanner-primary", "fingerprint": "0096d36ad20926e8", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/mcp-server/scripts/smoke.mjs"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-200c4602cb0221c5", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in packages/mcp-server/scripts/smoke.mjs:11"}, "properties": {"repobilityId": "403131febb4e2620", "scanner": "scanner-primary", "fingerprint": "200c4602cb0221c5", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/mcp-server/scripts/smoke.mjs"}, "region": {"startLine": 11}}}]}, {"ruleId": "scanner-65aa740cba4a4a73", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "8860eac61a1ebe26", "scanner": "scanner-primary", "fingerprint": "65aa740cba4a4a73", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/codeql.yml"}, "region": {"startLine": 23}}}]}, {"ruleId": "scanner-65aa740cba4a4a73", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "549a2de1ac0c3fa9", "scanner": "scanner-primary", "fingerprint": "65aa740cba4a4a73", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/codeql.yml"}, "region": {"startLine": 26}}}]}, {"ruleId": "scanner-65aa740cba4a4a73", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "a4f0ab9334543546", "scanner": "scanner-primary", "fingerprint": "65aa740cba4a4a73", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/codeql.yml"}, "region": {"startLine": 32}}}]}, {"ruleId": "scanner-65aa740cba4a4a73", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "a5721e15e3a54aa2", "scanner": "scanner-primary", "fingerprint": "65aa740cba4a4a73", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/codeql.yml"}, "region": {"startLine": 35}}}]}, {"ruleId": "scanner-5d2dba911b3e3517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b0aed2fd6db8abc3", "scanner": "scanner-primary", "fingerprint": "5d2dba911b3e3517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/eval.yml"}, "region": {"startLine": 52}}}]}, {"ruleId": "scanner-5d2dba911b3e3517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "b0aed2fd6db8abc3", "scanner": "scanner-primary", "fingerprint": "5d2dba911b3e3517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/eval.yml"}, "region": {"startLine": 102}}}]}, {"ruleId": "scanner-5d2dba911b3e3517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "c4e7fbb63c94419d", "scanner": "scanner-primary", "fingerprint": "5d2dba911b3e3517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/eval.yml"}, "region": {"startLine": 117}}}]}, {"ruleId": "scanner-5d2dba911b3e3517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "57bfed0996c35130", "scanner": "scanner-primary", "fingerprint": "5d2dba911b3e3517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/eval.yml"}, "region": {"startLine": 123}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ae16880318b99912", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 24}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "54597edb7f5bad38", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 27}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "989a74409a402368", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ae16880318b99912", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 60}}}]}, {"ruleId": "scanner-27924aa79fa4a517", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "f28bea84d363ff64", "scanner": "scanner-primary", "fingerprint": "27924aa79fa4a517", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/ci.yml"}, "region": {"startLine": 63}}}]}, {"ruleId": "scanner-48fb8ac0ffe1b092", "level": "note", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ea2fcabdefcc99a4", "scanner": "scanner-primary", "fingerprint": "48fb8ac0ffe1b092", "layer": "cicd", "severity": "low", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/container.yml"}, "region": {"startLine": 33}}}]}, {"ruleId": "scanner-48fb8ac0ffe1b092", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "50f496eda53cf393", "scanner": "scanner-primary", "fingerprint": "48fb8ac0ffe1b092", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/container.yml"}, "region": {"startLine": 36}}}]}, {"ruleId": "scanner-48fb8ac0ffe1b092", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "11190bc927c98fe5", "scanner": "scanner-primary", "fingerprint": "48fb8ac0ffe1b092", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/container.yml"}, "region": {"startLine": 39}}}]}, {"ruleId": "scanner-48fb8ac0ffe1b092", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "133b32f840c74f56", "scanner": "scanner-primary", "fingerprint": "48fb8ac0ffe1b092", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/container.yml"}, "region": {"startLine": 47}}}]}, {"ruleId": "scanner-48fb8ac0ffe1b092", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "86816eea95eb21ca", "scanner": "scanner-primary", "fingerprint": "48fb8ac0ffe1b092", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/container.yml"}, "region": {"startLine": 55}}}]}, {"ruleId": "scanner-139b11d10599a9c4", "level": "error", "message": {"text": "GitHub Action tracks a moving branch"}, "properties": {"repobilityId": "5690d9ccd93a5f17", "scanner": "scanner-primary", "fingerprint": "139b11d10599a9c4", "layer": "cicd", "severity": "high", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/container.yml"}, "region": {"startLine": 71}}}]}, {"ruleId": "scanner-48fb8ac0ffe1b092", "level": "warning", "message": {"text": "GitHub Action is tag-pinned rather than SHA-pinned"}, "properties": {"repobilityId": "ba2b9c4ab6e1c0f0", "scanner": "scanner-primary", "fingerprint": "48fb8ac0ffe1b092", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "pinned-dependencies"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/container.yml"}, "region": {"startLine": 79}}}]}, {"ruleId": "scanner-e5b8e6d3f2b30391", "level": "warning", "message": {"text": "GitHub Actions workflow grants broad write permissions"}, "properties": {"repobilityId": "7304a07598adf36e", "scanner": "scanner-primary", "fingerprint": "e5b8e6d3f2b30391", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["supply-chain", "github-actions", "least-privilege"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".github/workflows/container.yml"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f112cb87ef05f4cf", "level": "note", "message": {"text": "Very large file: apps/web/src/lib/psurDocuments.ts (1131 lines)"}, "properties": {"repobilityId": "2d1da0571e46e213", "scanner": "scanner-primary", "fingerprint": "f112cb87ef05f4cf", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ba49967cf0b0efe7", "level": "note", "message": {"text": "Very large file: apps/web/src/pages/ProcessDesigner.tsx (2042 lines)"}, "properties": {"repobilityId": "ecd16d221f57529c", "scanner": "scanner-primary", "fingerprint": "ba49967cf0b0efe7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-edfde1549cdf4308", "level": "note", "message": {"text": "Very large file: apps/web/src/pages/Sandbox.tsx (1920 lines)"}, "properties": {"repobilityId": "57436bd7dbea543e", "scanner": "scanner-primary", "fingerprint": "edfde1549cdf4308", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ada82e818b0aefd3", "level": "note", "message": {"text": "Very large file: apps/web/src/pages/PsurDemo.tsx (2263 lines)"}, "properties": {"repobilityId": "4fbda90e7d8439ad", "scanner": "scanner-primary", "fingerprint": "ada82e818b0aefd3", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-ea3b5e389d8c9c0f", "level": "note", "message": {"text": "Low test-to-source ratio"}, "properties": {"repobilityId": "ef7b2552cc00a375", "scanner": "scanner-primary", "fingerprint": "ea3b5e389d8c9c0f", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["tests"]}}, {"ruleId": "scanner-b06b8d86f24c77f9", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/api/package.json"}, "properties": {"repobilityId": "ce77cd34ed0306d4", "scanner": "scanner-primary", "fingerprint": "b06b8d86f24c77f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4a9eb7dc7c6e3880", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "properties": {"repobilityId": "6c1704bf24cf19ac", "scanner": "scanner-primary", "fingerprint": "4a9eb7dc7c6e3880", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8cad527fa7b2fdd7", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/sandbox/package.json"}, "properties": {"repobilityId": "ef462da675e271cd", "scanner": "scanner-primary", "fingerprint": "8cad527fa7b2fdd7", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/sandbox/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-28e92806c0db3cd2", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/core/package.json"}, "properties": {"repobilityId": "8640e46be7e3f9b2", "scanner": "scanner-primary", "fingerprint": "28e92806c0db3cd2", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/core/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-7eb3bf44d969a4e1", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/evals/package.json"}, "properties": {"repobilityId": "97db63c723165f06", "scanner": "scanner-primary", "fingerprint": "7eb3bf44d969a4e1", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/evals/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "9425e13b68075ada", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "40e7275d04b5be17", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "e00628677af1a08a", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "3df03c1c24c10878", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "2a47939b10ccb063", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "5e8a9ca61cdfac39", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-1824f43a23904319", "level": "warning", "message": {"text": "Agent instruction contains unpinned remote install: .claude/commands/goal-publish-mcp.md"}, "properties": {"repobilityId": "5f47f3997ed5fb36", "scanner": "scanner-primary", "fingerprint": "1824f43a23904319", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "supply-chain", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/commands/goal-publish-mcp.md"}, "region": {"startLine": 30}}}]}, {"ruleId": "scanner-80e352046295c6a4", "level": "none", "message": {"text": "Commented-code block (6 lines) in apps/api/src/index.ts:162"}, "properties": {"repobilityId": "77e5b961d9012b68", "scanner": "scanner-primary", "fingerprint": "80e352046295c6a4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-f9969136b2edef74", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/psur.test.ts:248"}, "properties": {"repobilityId": "301d895e7d5e82cf", "scanner": "scanner-primary", "fingerprint": "f9969136b2edef74", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-e77de2c3d67a964c", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/api/src/routes/managed-agents.ts:173"}, "properties": {"repobilityId": "074e8ed817ead53d", "scanner": "scanner-primary", "fingerprint": "e77de2c3d67a964c", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-485a7486c916d937", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/builder.test.ts:352"}, "properties": {"repobilityId": "e1c7ccdb28c6f389", "scanner": "scanner-primary", "fingerprint": "485a7486c916d937", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-79fbdb9ca8f7c5c4", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/api/src/routes/psur.ts:396"}, "properties": {"repobilityId": "f570754cac15a3e7", "scanner": "scanner-primary", "fingerprint": "79fbdb9ca8f7c5c4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-7cf706f7c69b2e2c", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/workspace.test.ts:201"}, "properties": {"repobilityId": "baec55e991fb5ef9", "scanner": "scanner-primary", "fingerprint": "7cf706f7c69b2e2c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-713c2f6d53fe2bd9", "level": "none", "message": {"text": "Commented-code block (6 lines) in apps/api/src/routes/builder.ts:412"}, "properties": {"repobilityId": "22be937f482a2349", "scanner": "scanner-primary", "fingerprint": "713c2f6d53fe2bd9", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-ccc2445df8fe4d57", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/sandbox.test.ts:144"}, "properties": {"repobilityId": "319792bb55827629", "scanner": "scanner-primary", "fingerprint": "ccc2445df8fe4d57", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-3aa546a6adae2556", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/traces.test.ts:86"}, "properties": {"repobilityId": "5d0166ab74c0f0a0", "scanner": "scanner-primary", "fingerprint": "3aa546a6adae2556", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b6da3446d8da0580", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/api/src/routes/clerk-webhook.ts:12"}, "properties": {"repobilityId": "c3cf197e24cd51a8", "scanner": "scanner-primary", "fingerprint": "b6da3446d8da0580", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-666063d532949853", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/services/AgentBundler.ts:203"}, "properties": {"repobilityId": "b92438585faca852", "scanner": "scanner-primary", "fingerprint": "666063d532949853", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-f5b6b328881b5463", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/lib/queryClient.ts:68"}, "properties": {"repobilityId": "063740292aa18211", "scanner": "scanner-primary", "fingerprint": "f5b6b328881b5463", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c9194db6a17a9dcb", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/web/src/pages/PsurDemo.tsx:208"}, "properties": {"repobilityId": "9d1a07bc004d6f56", "scanner": "scanner-primary", "fingerprint": "c9194db6a17a9dcb", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0ae0507d83b98182", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/core/src/agents/BaseGroundedAgent.ts:74"}, "properties": {"repobilityId": "e83ccff41e49d093", "scanner": "scanner-primary", "fingerprint": "0ae0507d83b98182", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-c2cdaf6da03f88ef", "level": "none", "message": {"text": "Commented-code block (5 lines) in packages/core/src/db/schema.ts:453"}, "properties": {"repobilityId": "7375bc5f5c26f843", "scanner": "scanner-primary", "fingerprint": "c2cdaf6da03f88ef", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-4b80f34ce98ef6f0", "level": "none", "message": {"text": "Commented-code block (6 lines) in packages/core/src/graph/GraphSeeder.ts:98"}, "properties": {"repobilityId": "0841bab71bdb1cec", "scanner": "scanner-primary", "fingerprint": "4b80f34ce98ef6f0", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-75818801ee2810ec", "level": "none", "message": {"text": "Commented-code block (7 lines) in packages/core/src/graph/types.ts:109"}, "properties": {"repobilityId": "20d2a88828f91bcb", "scanner": "scanner-primary", "fingerprint": "75818801ee2810ec", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-37b0d5c20fdb19dd", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/core/src/llm/providers/GenericProvider.ts:50"}, "properties": {"repobilityId": "26b15cc1bea9e221", "scanner": "scanner-primary", "fingerprint": "37b0d5c20fdb19dd", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-836d214f86d62353", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 packages/core/src/llm/providers/DeepSeekProvider.ts:55"}, "properties": {"repobilityId": "63dbcfd2d7fa24d1", "scanner": "scanner-primary", "fingerprint": "836d214f86d62353", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-b0b5e7cb1208a7cd", "level": "note", "message": {"text": "13 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "2737b8666c1f7eeb", "scanner": "scanner-primary", "fingerprint": "b0b5e7cb1208a7cd", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-ee8e83033be6be0e", "level": "warning", "message": {"text": "Frontend route `/app/sandbox/:taskId` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "6654c0619626a666", "scanner": "scanner-primary", "fingerprint": "ee8e83033be6be0e", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-b9c7753083de896c", "level": "warning", "message": {"text": "Frontend route `/app/trails/:id` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "fc3f95894c6bca92", "scanner": "scanner-primary", "fingerprint": "b9c7753083de896c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-8f5af48edf1c1df4", "level": "warning", "message": {"text": "Frontend route `/app/trails` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "6f2cd63a0d73f212", "scanner": "scanner-primary", "fingerprint": "8f5af48edf1c1df4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-a30e97e5b3f0c1a8", "level": "warning", "message": {"text": "Frontend route `/app/*` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "e6c294d6cae7b629", "scanner": "scanner-primary", "fingerprint": "a30e97e5b3f0c1a8", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-b1cea81df8fa1d86", "level": "note", "message": {"text": "Unused endpoint: USE /api/clerk-webhook"}, "properties": {"repobilityId": "7b76577fb7b84026", "scanner": "scanner-primary", "fingerprint": "b1cea81df8fa1d86", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-44f28055eb716379", "level": "note", "message": {"text": "Unused endpoint: USE /ready"}, "properties": {"repobilityId": "10cf75ea04a6eba1", "scanner": "scanner-primary", "fingerprint": "44f28055eb716379", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2d88bf633f398006", "level": "note", "message": {"text": "Unused endpoint: GET /api/graph/stats"}, "properties": {"repobilityId": "7d9a9319790b5369", "scanner": "scanner-primary", "fingerprint": "2d88bf633f398006", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dde3adb27bf7eebe", "level": "note", "message": {"text": "Unused endpoint: USE /api"}, "properties": {"repobilityId": "282c1d529b9a1d98", "scanner": "scanner-primary", "fingerprint": "dde3adb27bf7eebe", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-962186af7cd159b9", "level": "note", "message": {"text": "Unused endpoint: USE /api/psur"}, "properties": {"repobilityId": "614c19aa2ce7195c", "scanner": "scanner-primary", "fingerprint": "962186af7cd159b9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6b11d62e5e5c482b", "level": "note", "message": {"text": "Unused endpoint: USE /api/graph"}, "properties": {"repobilityId": "72dbe1e0f55fd84e", "scanner": "scanner-primary", "fingerprint": "6b11d62e5e5c482b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-55125999d15d30ae", "level": "note", "message": {"text": "Unused endpoint: USE /api/traces"}, "properties": {"repobilityId": "0a4bfb5067b130cb", "scanner": "scanner-primary", "fingerprint": "55125999d15d30ae", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d1c6d1d11f461711", "level": "note", "message": {"text": "Unused endpoint: USE /api/api-keys"}, "properties": {"repobilityId": "49ac10ee535f83b7", "scanner": "scanner-primary", "fingerprint": "d1c6d1d11f461711", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-50d9d80b509ac18d", "level": "note", "message": {"text": "Unused endpoint: USE /api/sandbox"}, "properties": {"repobilityId": "4c0221a789830fc4", "scanner": "scanner-primary", "fingerprint": "50d9d80b509ac18d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6cd3f7afb94e8b8f", "level": "note", "message": {"text": "Unused endpoint: USE /api/builder"}, "properties": {"repobilityId": "e2c7fbe4a8278ca7", "scanner": "scanner-primary", "fingerprint": "6cd3f7afb94e8b8f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1afa00d06cb7e7d5", "level": "note", "message": {"text": "Unused endpoint: USE /api/usage"}, "properties": {"repobilityId": "eeaeccd564f45337", "scanner": "scanner-primary", "fingerprint": "1afa00d06cb7e7d5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f29e8d5ce947efbb", "level": "note", "message": {"text": "Unused endpoint: USE /api/workspace"}, "properties": {"repobilityId": "b57078780bc1271a", "scanner": "scanner-primary", "fingerprint": "f29e8d5ce947efbb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f81b49bb89fa3006", "level": "note", "message": {"text": "Unused endpoint: USE /api/validate-draft"}, "properties": {"repobilityId": "489978ae8929e191", "scanner": "scanner-primary", "fingerprint": "f81b49bb89fa3006", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd0e06afbaab19b3", "level": "note", "message": {"text": "Unused endpoint: GET /tasks"}, "properties": {"repobilityId": "b1dfb3484fe7ebfb", "scanner": "scanner-primary", "fingerprint": "fd0e06afbaab19b3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4d2b27fe30e2e2c2", "level": "note", "message": {"text": "Unused endpoint: GET /tasks/:id"}, "properties": {"repobilityId": "ff07a80f27d9ee91", "scanner": "scanner-primary", "fingerprint": "4d2b27fe30e2e2c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f6786e723a23903c", "level": "note", "message": {"text": "Unused endpoint: POST /tasks/:id/run"}, "properties": {"repobilityId": "6b24cda972a17967", "scanner": "scanner-primary", "fingerprint": "f6786e723a23903c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-275993b4e45208e5", "level": "note", "message": {"text": "Unused endpoint: GET /runs/:runId/stream"}, "properties": {"repobilityId": "a0eec7e98d022028", "scanner": "scanner-primary", "fingerprint": "275993b4e45208e5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd5f43776a3755fc", "level": "note", "message": {"text": "Unused endpoint: GET /runs/recent"}, "properties": {"repobilityId": "14c57c0d02a6ea4c", "scanner": "scanner-primary", "fingerprint": "fd5f43776a3755fc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4a9c351022ff0983", "level": "note", "message": {"text": "Unused endpoint: GET /runs/:runId/result"}, "properties": {"repobilityId": "ddb8b4405f307d16", "scanner": "scanner-primary", "fingerprint": "4a9c351022ff0983", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ddbb94d0d606421e", "level": "note", "message": {"text": "Unused endpoint: GET /runs/:runId/trace"}, "properties": {"repobilityId": "9cd3bdd8a89c4266", "scanner": "scanner-primary", "fingerprint": "ddbb94d0d606421e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e4be0e9456fdc2b4", "level": "note", "message": {"text": "Unused endpoint: GET /runs/:runId/trace/verify"}, "properties": {"repobilityId": "f5b39f7db27abf4d", "scanner": "scanner-primary", "fingerprint": "e4be0e9456fdc2b4", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8a2e4c1c7d468070", "level": "note", "message": {"text": "Unused endpoint: GET /runs/:runId/audit-pack"}, "properties": {"repobilityId": "708f4626617d5e0e", "scanner": "scanner-primary", "fingerprint": "8a2e4c1c7d468070", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-abe36e0d2e7b63c9", "level": "note", "message": {"text": "Unused endpoint: POST /runs/:runId/judge"}, "properties": {"repobilityId": "f71bc2d1699d5d26", "scanner": "scanner-primary", "fingerprint": "abe36e0d2e7b63c9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8c16eb1659ee9897", "level": "note", "message": {"text": "Unused endpoint: GET /tasks/:id/download"}, "properties": {"repobilityId": "11af70afee1f7d68", "scanner": "scanner-primary", "fingerprint": "8c16eb1659ee9897", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "5acbb84154c50e5f", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c2584bcef569ae26", "level": "note", "message": {"text": "Unused endpoint: POST /agents/:id/deploy"}, "properties": {"repobilityId": "a33841eb99cf8a31", "scanner": "scanner-primary", "fingerprint": "c2584bcef569ae26", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-28362816735f463c", "level": "note", "message": {"text": "Unused endpoint: POST /agents/:id/runs"}, "properties": {"repobilityId": "11e2786d68795578", "scanner": "scanner-primary", "fingerprint": "28362816735f463c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8dcc3675973e7474", "level": "note", "message": {"text": "Unused endpoint: GET /agents/:id/runs"}, "properties": {"repobilityId": "c94dff3f612e016d", "scanner": "scanner-primary", "fingerprint": "8dcc3675973e7474", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c9b8229e40690bb9", "level": "note", "message": {"text": "Unused endpoint: GET /agents/:id/runs/:runId"}, "properties": {"repobilityId": "d4bbfc6538eb8f0e", "scanner": "scanner-primary", "fingerprint": "c9b8229e40690bb9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ad79d9b65733f752", "level": "note", "message": {"text": "Unused endpoint: POST /agents/:id/runs/:runId/save"}, "properties": {"repobilityId": "bc8c1285de926922", "scanner": "scanner-primary", "fingerprint": "ad79d9b65733f752", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-92e4fb1a8c310c5d", "level": "note", "message": {"text": "Unused endpoint: GET /agents/:id/runs/:runId/stream"}, "properties": {"repobilityId": "26483725f7a13aec", "scanner": "scanner-primary", "fingerprint": "92e4fb1a8c310c5d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "121033f73eaf09e0", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-10c14b30d098b8b6", "level": "note", "message": {"text": "Unused endpoint: GET /:processInstanceId"}, "properties": {"repobilityId": "be191ca71ff46cf8", "scanner": "scanner-primary", "fingerprint": "10c14b30d098b8b6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3d8d3b89d66eecdb", "level": "note", "message": {"text": "Unused endpoint: GET /:processInstanceId/verify"}, "properties": {"repobilityId": "1f107e9e60de9bc9", "scanner": "scanner-primary", "fingerprint": "3d8d3b89d66eecdb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b30638f97b764f09", "level": "note", "message": {"text": "Unused endpoint: GET /:processInstanceId/export.jsonl"}, "properties": {"repobilityId": "2016570a77e84025", "scanner": "scanner-primary", "fingerprint": "b30638f97b764f09", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9c41b5a0ddeb29b1", "level": "note", "message": {"text": "Unused endpoint: GET /:processInstanceId/export.dot"}, "properties": {"repobilityId": "6729bbaf32ef5973", "scanner": "scanner-primary", "fingerprint": "9c41b5a0ddeb29b1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-339f9dd69037b797", "level": "note", "message": {"text": "Unused endpoint: GET /:processInstanceId/audit-report"}, "properties": {"repobilityId": "17557ed09b60fd29", "scanner": "scanner-primary", "fingerprint": "339f9dd69037b797", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4ac3174931f5a7e8", "level": "note", "message": {"text": "Unused endpoint: GET /:processInstanceId/audit-pack"}, "properties": {"repobilityId": "c898c55611ed6f01", "scanner": "scanner-primary", "fingerprint": "4ac3174931f5a7e8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7ab45f4d06595901", "level": "note", "message": {"text": "Unused endpoint: GET /obligations"}, "properties": {"repobilityId": "9f9b9c47e85c2a0b", "scanner": "scanner-primary", "fingerprint": "7ab45f4d06595901", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2b38bd6a95a90406", "level": "note", "message": {"text": "Unused endpoint: GET /obligations/:id"}, "properties": {"repobilityId": "4417692e25a3e6e8", "scanner": "scanner-primary", "fingerprint": "2b38bd6a95a90406", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-502c83fb6274eae0", "level": "note", "message": {"text": "Unused endpoint: GET /obligations/:id/explain"}, "properties": {"repobilityId": "1869112abc9df0dc", "scanner": "scanner-primary", "fingerprint": "502c83fb6274eae0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aa8ee0adbe1e9daf", "level": "note", "message": {"text": "Unused endpoint: POST /obligations"}, "properties": {"repobilityId": "0e86cb10e94b86ee", "scanner": "scanner-primary", "fingerprint": "aa8ee0adbe1e9daf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9ea480e0c5b1a862", "level": "note", "message": {"text": "Unused endpoint: DELETE /obligations/:id"}, "properties": {"repobilityId": "b329ae08d7d9154b", "scanner": "scanner-primary", "fingerprint": "9ea480e0c5b1a862", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1bb3714794b14146", "level": "note", "message": {"text": "Unused endpoint: POST /query"}, "properties": {"repobilityId": "c49c9897721cd907", "scanner": "scanner-primary", "fingerprint": "1bb3714794b14146", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4e1590f41fc76e5b", "level": "note", "message": {"text": "Unused endpoint: POST /compliance-check"}, "properties": {"repobilityId": "ef21273cc187072f", "scanner": "scanner-primary", "fingerprint": "4e1590f41fc76e5b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7bf655151935db1a", "level": "note", "message": {"text": "Unused endpoint: POST /schedule-cadence"}, "properties": {"repobilityId": "7d72b71115550b2e", "scanner": "scanner-primary", "fingerprint": "7bf655151935db1a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6f43d8ef9e363507", "level": "note", "message": {"text": "Unused endpoint: POST /evidence-map"}, "properties": {"repobilityId": "865d658ba5da1f30", "scanner": "scanner-primary", "fingerprint": "6f43d8ef9e363507", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-09b021c60df86e61", "level": "note", "message": {"text": "Unused endpoint: POST /explain-path"}, "properties": {"repobilityId": "af26e3b023d90113", "scanner": "scanner-primary", "fingerprint": "09b021c60df86e61", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6af224edb292ca8f", "level": "note", "message": {"text": "Unused endpoint: GET /process-types"}, "properties": {"repobilityId": "dc1050a7dc9fd27f", "scanner": "scanner-primary", "fingerprint": "6af224edb292ca8f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cd8dc4599ec52a08", "level": "note", "message": {"text": "Unused endpoint: GET /stats"}, "properties": {"repobilityId": "502c847da9b98d33", "scanner": "scanner-primary", "fingerprint": "cd8dc4599ec52a08", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}