{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-c75edc7426f4b28a", "name": "Possibly dead Python function: current_user_id", "shortDescription": {"text": "Possibly dead Python function: current_user_id"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0cc18d8c0159371e", "name": "Possibly dead Python function: upgrade", "shortDescription": {"text": "Possibly dead Python function: upgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b378557f51a405de", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8df0ddb30c8b606e", "name": "Possibly dead Python function: upgrade", "shortDescription": {"text": "Possibly dead Python function: upgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e92b46846efd8e71", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-085bc2356019e36b", "name": "Possibly dead Python function: upgrade", "shortDescription": {"text": "Possibly dead Python function: upgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9f5e051fe2907333", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f4c87863afc9fc1b", "name": "Possibly dead Python function: upgrade", "shortDescription": {"text": "Possibly dead Python function: upgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30305992a9a2aecf", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4f23584e11198394", "name": "Possibly dead Python function: upgrade", "shortDescription": {"text": "Possibly dead Python function: upgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ed311aca81e2f24b", "name": "Possibly dead Python function: downgrade", "shortDescription": {"text": "Possibly dead Python function: downgrade"}, "fullDescription": {"text": "No callers detected by AST scan in this repo. Could be exported for external callers or a framework handler."}, "properties": {"scanner": "scanner-primary", "layer": "software", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f272d45d35f3d9fe", "name": "Stray `console.log` in TS/JS \u2014 extension/index.ts:1", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 extension/index.ts:1"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-00083c430ff92179", "name": "Stray `console.log` in TS/JS \u2014 console/server.ts:21", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 console/server.ts:21"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-922ed57d9070916b", "name": "Very large file: design/design-canvas.jsx (974 lines)", "shortDescription": {"text": "Very large file: design/design-canvas.jsx (974 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, ci. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-14b94de34d897ad4", "name": "Agent authority lacks a verifier contract: .claude/skills/openspec-apply-change/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/openspec-apply-change/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8a585f74bb40a5f1", "name": "Agent authority lacks a verifier contract: .claude/skills/openspec-archive-change/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/openspec-archive-change/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1861f29946301e43", "name": "Agent authority lacks a verifier contract: .claude/skills/openspec-sync-specs/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: .claude/skills/openspec-sync-specs/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-32a1cb96ff854706", "name": "Agent authority lacks a verifier contract: console/CLAUDE.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: console/CLAUDE.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-5f67e54e1cc8c59a", "name": "Commented-code block (7 lines) in design/design-canvas.jsx:4", "shortDescription": {"text": "Commented-code block (7 lines) in design/design-canvas.jsx:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-93f6b9e365a2fc33", "name": "`fetch()` without try/.catch or AbortSignal \u2014 design/design-canvas.jsx:136", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 design/design-canvas.jsx:136"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a47626af955081f4", "name": "`fetch()` without try/.catch or AbortSignal \u2014 extension/src/lib/cloud-api.ts:90", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 extension/src/lib/cloud-api.ts:90"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-467d4b4309364108", "name": "Legacy-named symbol `open_v2` in extension/src/db/worker.ts:32", "shortDescription": {"text": "Legacy-named symbol `open_v2` in extension/src/db/worker.ts:32"}, "fullDescription": {"text": "Names with suffixes like `_old`, `_v1`, `_deprecated` usually indicate replaced-but-not-removed code (typical AI-coder leftover). Confirm and delete, or rename if it's the active version."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3d7e7cc2b7ca61da", "name": "Commented-code block (5 lines) in extension/src/db/worker.ts:1", "shortDescription": {"text": "Commented-code block (5 lines) in extension/src/db/worker.ts:1"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1b5a76780c3df9aa", "name": "1 env vars used in code but missing from .env.example", "shortDescription": {"text": "1 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `MCE_API_URL`. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-968054d8651de9d3", "name": "Frontend route `/capture/:id` has no Link/navigate to it \u2014 console/src/App.tsx", "shortDescription": {"text": "Frontend route `/capture/:id` has no Link/navigate to it \u2014 console/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-e6770cdd7771ac41", "name": "FastAPI POST `refresh` without auth dependency \u2014 api-server/app/routes/auth.py:45", "shortDescription": {"text": "FastAPI POST `refresh` without auth dependency \u2014 api-server/app/routes/auth.py:45"}, "fullDescription": {"text": "`@router.post` decorator with no `Depends(get_current_user)` or auth-shaped dependency in its signature. Mutating endpoints should require authentication unless explicitly public."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-26b0cf1ff295bd1a", "name": "Dangling fetch: POST /v1/auth/register (extension/src/lib/cloud-api.ts:106)", "shortDescription": {"text": "Dangling fetch: POST /v1/auth/register (extension/src/lib/cloud-api.ts:106)"}, "fullDescription": {"text": "`extension/src/lib/cloud-api.ts:106` calls `POST /v1/auth/register` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/register`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-200e6296fbba6add", "name": "Dangling fetch: POST /v1/auth/login (extension/src/lib/cloud-api.ts:112)", "shortDescription": {"text": "Dangling fetch: POST /v1/auth/login (extension/src/lib/cloud-api.ts:112)"}, "fullDescription": {"text": "`extension/src/lib/cloud-api.ts:112` calls `POST /v1/auth/login` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/login`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-c496116a215f0030", "name": "Dangling fetch: POST /v1/auth/refresh (extension/src/lib/cloud-api.ts:118)", "shortDescription": {"text": "Dangling fetch: POST /v1/auth/refresh (extension/src/lib/cloud-api.ts:118)"}, "fullDescription": {"text": "`extension/src/lib/cloud-api.ts:118` calls `POST /v1/auth/refresh` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/refresh`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-128d768909333310", "name": "Dangling fetch: POST /v1/auth/logout (extension/src/lib/cloud-api.ts:124)", "shortDescription": {"text": "Dangling fetch: POST /v1/auth/logout (extension/src/lib/cloud-api.ts:124)"}, "fullDescription": {"text": "`extension/src/lib/cloud-api.ts:124` calls `POST /v1/auth/logout` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/logout`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f9d11f0415ac3da7", "name": "Dangling fetch: POST /v1/captures (extension/src/lib/cloud-api.ts:130)", "shortDescription": {"text": "Dangling fetch: POST /v1/captures (extension/src/lib/cloud-api.ts:130)"}, "fullDescription": {"text": "`extension/src/lib/cloud-api.ts:130` calls `POST /v1/captures` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/captures`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-1a6573b13b817367", "name": "Dangling fetch: GET /v1/captures/${encodeURIComponent(id)} (extension/src/lib/cloud-api.ts:140)", "shortDescription": {"text": "Dangling fetch: GET /v1/captures/${encodeURIComponent(id)} (extension/src/lib/cloud-api.ts:140)"}, "fullDescription": {"text": "`extension/src/lib/cloud-api.ts:140` calls `GET /v1/captures/${encodeURIComponent(id)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/captures/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e81bd891a0724ce1", "name": "Dangling fetch: DELETE /v1/captures/${encodeURIComponent(id)} (extension/src/lib/cloud-api.ts:143)", "shortDescription": {"text": "Dangling fetch: DELETE /v1/captures/${encodeURIComponent(id)} (extension/src/lib/cloud-api.ts:143)"}, "fullDescription": {"text": "`extension/src/lib/cloud-api.ts:143` calls `DELETE /v1/captures/${encodeURIComponent(id)}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/captures/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-e49a039ff5aa8642", "name": "Dangling fetch: POST /v1/auth/login (console/src/lib/api.ts:68)", "shortDescription": {"text": "Dangling fetch: POST /v1/auth/login (console/src/lib/api.ts:68)"}, "fullDescription": {"text": "`console/src/lib/api.ts:68` calls `POST /v1/auth/login` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/auth/login`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-96678d51e9e9b7fd", "name": "Dangling fetch: GET /v1/captures?${qs} (console/src/lib/api.ts:81)", "shortDescription": {"text": "Dangling fetch: GET /v1/captures?${qs} (console/src/lib/api.ts:81)"}, "fullDescription": {"text": "`console/src/lib/api.ts:81` calls `GET /v1/captures?${qs}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/captures`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-01614bc0ae5a2a75", "name": "Dangling fetch: GET /v1/captures/${id} (console/src/lib/api.ts:85)", "shortDescription": {"text": "Dangling fetch: GET /v1/captures/${id} (console/src/lib/api.ts:85)"}, "fullDescription": {"text": "`console/src/lib/api.ts:85` calls `GET /v1/captures/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/captures/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-5ed44631619f7597", "name": "Dangling fetch: DELETE /v1/captures/${id} (console/src/lib/api.ts:89)", "shortDescription": {"text": "Dangling fetch: DELETE /v1/captures/${id} (console/src/lib/api.ts:89)"}, "fullDescription": {"text": "`console/src/lib/api.ts:89` calls `DELETE /v1/captures/${id}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: helper:request\nNormalized path used for matching: `/captures/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-ce27624faa1e5362", "name": "Dangling fetch: GET /api/dev-creds (console/src/pages/Login.tsx:13)", "shortDescription": {"text": "Dangling fetch: GET /api/dev-creds (console/src/pages/Login.tsx:13)"}, "fullDescription": {"text": "`console/src/pages/Login.tsx:13` calls `GET /api/dev-creds` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/dev-creds`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-304b6f2b403d93f7", "name": "Unused endpoint: POST /register", "shortDescription": {"text": "Unused endpoint: POST /register"}, "fullDescription": {"text": "`api-server/app/routes/auth.py` declares `POST /register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-618721b912bad1c2", "name": "Unused endpoint: POST /login", "shortDescription": {"text": "Unused endpoint: POST /login"}, "fullDescription": {"text": "`api-server/app/routes/auth.py` declares `POST /login` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7ce17d6b092a81ca", "name": "Unused endpoint: POST /refresh", "shortDescription": {"text": "Unused endpoint: POST /refresh"}, "fullDescription": {"text": "`api-server/app/routes/auth.py` declares `POST /refresh` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99fc36db98c134ce", "name": "Unused endpoint: POST /logout", "shortDescription": {"text": "Unused endpoint: POST /logout"}, "fullDescription": {"text": "`api-server/app/routes/auth.py` declares `POST /logout` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca4c3a6fd7d717d0", "name": "Unused endpoint: GET /brief", "shortDescription": {"text": "Unused endpoint: GET /brief"}, "fullDescription": {"text": "`api-server/app/routes/profile.py` declares `GET /brief` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-daa962bae78e470b", "name": "Unused endpoint: GET /claims", "shortDescription": {"text": "Unused endpoint: GET /claims"}, "fullDescription": {"text": "`api-server/app/routes/profile.py` declares `GET /claims` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f338a44a207ea435", "name": "Unused endpoint: GET /claims/{claim_id}/evidence", "shortDescription": {"text": "Unused endpoint: GET /claims/{claim_id}/evidence"}, "fullDescription": {"text": "`api-server/app/routes/profile.py` declares `GET /claims/{claim_id}/evidence` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f24d30801c8c888f", "name": "Unused endpoint: POST /calibrations", "shortDescription": {"text": "Unused endpoint: POST /calibrations"}, "fullDescription": {"text": "`api-server/app/routes/profile.py` declares `POST /calibrations` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d24be71767c6f2ae", "name": "Unused endpoint: GET /dreams/latest", "shortDescription": {"text": "Unused endpoint: GET /dreams/latest"}, "fullDescription": {"text": "`api-server/app/routes/profile.py` declares `GET /dreams/latest` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a7703e292f068ddb", "name": "Unused endpoint: POST /backfill", "shortDescription": {"text": "Unused endpoint: POST /backfill"}, "fullDescription": {"text": "`api-server/app/routes/profile.py` declares `POST /backfill` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`api-server/app/routes/captures.py` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`api-server/app/routes/captures.py` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-04a88033c0087f27", "name": "Unused endpoint: GET /{capture_id}", "shortDescription": {"text": "Unused endpoint: GET /{capture_id}"}, "fullDescription": {"text": "`api-server/app/routes/captures.py` declares `GET /{capture_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f7609e84186c4840", "name": "Unused endpoint: DELETE /{capture_id}", "shortDescription": {"text": "Unused endpoint: DELETE /{capture_id}"}, "fullDescription": {"text": "`api-server/app/routes/captures.py` declares `DELETE /{capture_id}` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/17584"}, "properties": {"repository": "qianh/ai-mce", "repoUrl": "https://github.com/qianh/ai-mce", "branch": "main"}, "results": [{"ruleId": "scanner-c75edc7426f4b28a", "level": "note", "message": {"text": "Possibly dead Python function: current_user_id"}, "properties": {"repobilityId": "5272dc1a1913ac51", "scanner": "scanner-primary", "fingerprint": "c75edc7426f4b28a", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "api-server/app/routes/captures.py:14"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-0cc18d8c0159371e", "level": "note", "message": {"text": "Possibly dead Python function: upgrade"}, "properties": {"repobilityId": "cf0b8e5e6e2f8bc4", "scanner": "scanner-primary", "fingerprint": "0cc18d8c0159371e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "api-server/app/alembic/versions/0004_add_session_id.py:22"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-b378557f51a405de", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "b378557f51a405de", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "api-server/app/alembic/versions/0004_add_session_id.py:37"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8df0ddb30c8b606e", "level": "note", "message": {"text": "Possibly dead Python function: upgrade"}, "properties": {"repobilityId": "cf0b8e5e6e2f8bc4", "scanner": "scanner-primary", "fingerprint": "8df0ddb30c8b606e", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "api-server/app/alembic/versions/0001_initial.py:19"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-e92b46846efd8e71", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "e92b46846efd8e71", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "api-server/app/alembic/versions/0001_initial.py:73"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-085bc2356019e36b", "level": "note", "message": {"text": "Possibly dead Python function: upgrade"}, "properties": {"repobilityId": "cf0b8e5e6e2f8bc4", "scanner": "scanner-primary", "fingerprint": "085bc2356019e36b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "api-server/app/alembic/versions/0002_fix_capture_dedup_key.py:19"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-9f5e051fe2907333", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "9f5e051fe2907333", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "api-server/app/alembic/versions/0002_fix_capture_dedup_key.py:30"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f4c87863afc9fc1b", "level": "note", "message": {"text": "Possibly dead Python function: upgrade"}, "properties": {"repobilityId": "cf0b8e5e6e2f8bc4", "scanner": "scanner-primary", "fingerprint": "f4c87863afc9fc1b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "api-server/app/alembic/versions/0003_add_message_count.py:19"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-30305992a9a2aecf", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "30305992a9a2aecf", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "api-server/app/alembic/versions/0003_add_message_count.py:28"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4f23584e11198394", "level": "note", "message": {"text": "Possibly dead Python function: upgrade"}, "properties": {"repobilityId": "cf0b8e5e6e2f8bc4", "scanner": "scanner-primary", "fingerprint": "4f23584e11198394", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "api-server/app/alembic/versions/0005_profile_tables.py:33"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-ed311aca81e2f24b", "level": "note", "message": {"text": "Possibly dead Python function: downgrade"}, "properties": {"repobilityId": "c03debbf11efa0c5", "scanner": "scanner-primary", "fingerprint": "ed311aca81e2f24b", "layer": "software", "severity": "low", "confidence": 1.0, "tags": ["dead-code"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "api-server/app/alembic/versions/0005_profile_tables.py:41"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-f272d45d35f3d9fe", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 extension/index.ts:1"}, "properties": {"repobilityId": "bd49ca69c59b0b9f", "scanner": "scanner-primary", "fingerprint": "f272d45d35f3d9fe", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-00083c430ff92179", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 console/server.ts:21"}, "properties": {"repobilityId": "e4cb4d1f5109eec3", "scanner": "scanner-primary", "fingerprint": "00083c430ff92179", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-922ed57d9070916b", "level": "note", "message": {"text": "Very large file: design/design-canvas.jsx (974 lines)"}, "properties": {"repobilityId": "28c90a665b689b1c", "scanner": "scanner-primary", "fingerprint": "922ed57d9070916b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "2f75923628f8ea09", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "a6adc42beacec682", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "note", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "5194369645bcde63", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "2f9daaae92b32f78", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "93dc567db54d75e5", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "1e6e8673acbe03c9", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-14b94de34d897ad4", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/openspec-apply-change/SKILL.md"}, "properties": {"repobilityId": "ff525910a58aad1b", "scanner": "scanner-primary", "fingerprint": "14b94de34d897ad4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/openspec-apply-change/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-8a585f74bb40a5f1", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/openspec-archive-change/SKILL.md"}, "properties": {"repobilityId": "1499167b45dee6be", "scanner": "scanner-primary", "fingerprint": "8a585f74bb40a5f1", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/openspec-archive-change/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-1861f29946301e43", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: .claude/skills/openspec-sync-specs/SKILL.md"}, "properties": {"repobilityId": "67a28bca6aa28ab2", "scanner": "scanner-primary", "fingerprint": "1861f29946301e43", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/openspec-sync-specs/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-32a1cb96ff854706", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: console/CLAUDE.md"}, "properties": {"repobilityId": "ec7b69d2863e1df2", "scanner": "scanner-primary", "fingerprint": "32a1cb96ff854706", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "console/CLAUDE.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-5f67e54e1cc8c59a", "level": "none", "message": {"text": "Commented-code block (7 lines) in design/design-canvas.jsx:4"}, "properties": {"repobilityId": "eabc5b950e1033ae", "scanner": "scanner-primary", "fingerprint": "5f67e54e1cc8c59a", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-93f6b9e365a2fc33", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 design/design-canvas.jsx:136"}, "properties": {"repobilityId": "377ff28a6af6c625", "scanner": "scanner-primary", "fingerprint": "93f6b9e365a2fc33", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a47626af955081f4", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 extension/src/lib/cloud-api.ts:90"}, "properties": {"repobilityId": "91d83f0ec44bd12c", "scanner": "scanner-primary", "fingerprint": "a47626af955081f4", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-467d4b4309364108", "level": "note", "message": {"text": "Legacy-named symbol `open_v2` in extension/src/db/worker.ts:32"}, "properties": {"repobilityId": "6b7f6cdc035e0d02", "scanner": "scanner-primary", "fingerprint": "467d4b4309364108", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "legacy-marker", "dead-code"]}}, {"ruleId": "scanner-3d7e7cc2b7ca61da", "level": "none", "message": {"text": "Commented-code block (5 lines) in extension/src/db/worker.ts:1"}, "properties": {"repobilityId": "620c232375d27178", "scanner": "scanner-primary", "fingerprint": "3d7e7cc2b7ca61da", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-1b5a76780c3df9aa", "level": "none", "message": {"text": "1 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "d04379b337b44a15", "scanner": "scanner-primary", "fingerprint": "1b5a76780c3df9aa", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-968054d8651de9d3", "level": "warning", "message": {"text": "Frontend route `/capture/:id` has no Link/navigate to it \u2014 console/src/App.tsx"}, "properties": {"repobilityId": "d441d9cf2ba1111b", "scanner": "scanner-primary", "fingerprint": "968054d8651de9d3", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-e6770cdd7771ac41", "level": "error", "message": {"text": "FastAPI POST `refresh` without auth dependency \u2014 api-server/app/routes/auth.py:45"}, "properties": {"repobilityId": "29bf23ff90cac422", "scanner": "scanner-primary", "fingerprint": "e6770cdd7771ac41", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["auth", "owasp", "auth.fastapi.unauth_mutation"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "api-server/app/routes/auth.py"}, "region": {"startLine": 45}}}]}, {"ruleId": "scanner-26b0cf1ff295bd1a", "level": "error", "message": {"text": "Dangling fetch: POST /v1/auth/register (extension/src/lib/cloud-api.ts:106)"}, "properties": {"repobilityId": "e13e6385f6429439", "scanner": "scanner-primary", "fingerprint": "26b0cf1ff295bd1a", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-200e6296fbba6add", "level": "error", "message": {"text": "Dangling fetch: POST /v1/auth/login (extension/src/lib/cloud-api.ts:112)"}, "properties": {"repobilityId": "a8e9caf27f400ab0", "scanner": "scanner-primary", "fingerprint": "200e6296fbba6add", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-c496116a215f0030", "level": "error", "message": {"text": "Dangling fetch: POST /v1/auth/refresh (extension/src/lib/cloud-api.ts:118)"}, "properties": {"repobilityId": "5e811949a9d341cf", "scanner": "scanner-primary", "fingerprint": "c496116a215f0030", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-128d768909333310", "level": "error", "message": {"text": "Dangling fetch: POST /v1/auth/logout (extension/src/lib/cloud-api.ts:124)"}, "properties": {"repobilityId": "bfe736c8487a7219", "scanner": "scanner-primary", "fingerprint": "128d768909333310", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-f9d11f0415ac3da7", "level": "error", "message": {"text": "Dangling fetch: POST /v1/captures (extension/src/lib/cloud-api.ts:130)"}, "properties": {"repobilityId": "b9030837cfd8a437", "scanner": "scanner-primary", "fingerprint": "f9d11f0415ac3da7", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-1a6573b13b817367", "level": "error", "message": {"text": "Dangling fetch: GET /v1/captures/${encodeURIComponent(id)} (extension/src/lib/cloud-api.ts:140)"}, "properties": {"repobilityId": "bee0ee3334e9f4b4", "scanner": "scanner-primary", "fingerprint": "1a6573b13b817367", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-e81bd891a0724ce1", "level": "error", "message": {"text": "Dangling fetch: DELETE /v1/captures/${encodeURIComponent(id)} (extension/src/lib/cloud-api.ts:143)"}, "properties": {"repobilityId": "726f5fd02e3efc15", "scanner": "scanner-primary", "fingerprint": "e81bd891a0724ce1", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-e49a039ff5aa8642", "level": "error", "message": {"text": "Dangling fetch: POST /v1/auth/login (console/src/lib/api.ts:68)"}, "properties": {"repobilityId": "c6262d235382eb04", "scanner": "scanner-primary", "fingerprint": "e49a039ff5aa8642", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-96678d51e9e9b7fd", "level": "error", "message": {"text": "Dangling fetch: GET /v1/captures?${qs} (console/src/lib/api.ts:81)"}, "properties": {"repobilityId": "5b674f86814d5a07", "scanner": "scanner-primary", "fingerprint": "96678d51e9e9b7fd", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-01614bc0ae5a2a75", "level": "error", "message": {"text": "Dangling fetch: GET /v1/captures/${id} (console/src/lib/api.ts:85)"}, "properties": {"repobilityId": "8c0d59c9f9d3f719", "scanner": "scanner-primary", "fingerprint": "01614bc0ae5a2a75", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-5ed44631619f7597", "level": "error", "message": {"text": "Dangling fetch: DELETE /v1/captures/${id} (console/src/lib/api.ts:89)"}, "properties": {"repobilityId": "96035d7f3793c12a", "scanner": "scanner-primary", "fingerprint": "5ed44631619f7597", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "helper:request"]}}, {"ruleId": "scanner-ce27624faa1e5362", "level": "error", "message": {"text": "Dangling fetch: GET /api/dev-creds (console/src/pages/Login.tsx:13)"}, "properties": {"repobilityId": "6c3996fc42ee6455", "scanner": "scanner-primary", "fingerprint": "ce27624faa1e5362", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-304b6f2b403d93f7", "level": "note", "message": {"text": "Unused endpoint: POST /register"}, "properties": {"repobilityId": "f49c3f2e1ddb27bb", "scanner": "scanner-primary", "fingerprint": "304b6f2b403d93f7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-618721b912bad1c2", "level": "note", "message": {"text": "Unused endpoint: POST /login"}, "properties": {"repobilityId": "727bf64d190d8f6c", "scanner": "scanner-primary", "fingerprint": "618721b912bad1c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7ce17d6b092a81ca", "level": "note", "message": {"text": "Unused endpoint: POST /refresh"}, "properties": {"repobilityId": "933f6645da697cc6", "scanner": "scanner-primary", "fingerprint": "7ce17d6b092a81ca", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99fc36db98c134ce", "level": "note", "message": {"text": "Unused endpoint: POST /logout"}, "properties": {"repobilityId": "b6491a96bcc879ba", "scanner": "scanner-primary", "fingerprint": "99fc36db98c134ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca4c3a6fd7d717d0", "level": "note", "message": {"text": "Unused endpoint: GET /brief"}, "properties": {"repobilityId": "197cafcc282df202", "scanner": "scanner-primary", "fingerprint": "ca4c3a6fd7d717d0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-daa962bae78e470b", "level": "note", "message": {"text": "Unused endpoint: GET /claims"}, "properties": {"repobilityId": "0ad3309a138c63a0", "scanner": "scanner-primary", "fingerprint": "daa962bae78e470b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f338a44a207ea435", "level": "note", "message": {"text": "Unused endpoint: GET /claims/{claim_id}/evidence"}, "properties": {"repobilityId": "2b44bb34075de890", "scanner": "scanner-primary", "fingerprint": "f338a44a207ea435", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f24d30801c8c888f", "level": "note", "message": {"text": "Unused endpoint: POST /calibrations"}, "properties": {"repobilityId": "097a3dbbcc3dbaa2", "scanner": "scanner-primary", "fingerprint": "f24d30801c8c888f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d24be71767c6f2ae", "level": "note", "message": {"text": "Unused endpoint: GET /dreams/latest"}, "properties": {"repobilityId": "33f1264f3d5b5dd9", "scanner": "scanner-primary", "fingerprint": "d24be71767c6f2ae", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a7703e292f068ddb", "level": "note", "message": {"text": "Unused endpoint: POST /backfill"}, "properties": {"repobilityId": "8a7ee1ff7f7dfc5d", "scanner": "scanner-primary", "fingerprint": "a7703e292f068ddb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "56908ba585172878", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "263d16fc6ca8e243", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-04a88033c0087f27", "level": "note", "message": {"text": "Unused endpoint: GET /{capture_id}"}, "properties": {"repobilityId": "3558e996766bdf3e", "scanner": "scanner-primary", "fingerprint": "04a88033c0087f27", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f7609e84186c4840", "level": "note", "message": {"text": "Unused endpoint: DELETE /{capture_id}"}, "properties": {"repobilityId": "d4a2d4861aebe9b1", "scanner": "scanner-primary", "fingerprint": "f7609e84186c4840", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}