{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-0c0bee9b122f5336", "name": "Stray `console.log` in TS/JS \u2014 scripts/compile.ts:41", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/compile.ts:41"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-972fc0f03819bd89", "name": "Stray `console.log` in TS/JS \u2014 scripts/deploy-market.ts:20", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/deploy-market.ts:20"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-25d6336853441fc9", "name": "Stray `console.log` in TS/JS \u2014 scripts/venice-check.ts:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/venice-check.ts:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a013421acb9f7145", "name": "Stray `console.log` in TS/JS \u2014 scripts/deploy-nfa.ts:12", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/deploy-nfa.ts:12"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b0dc53e27f3b3cdf", "name": "Stray `console.log` in TS/JS \u2014 spike/04-replay-grant.ts:32", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 spike/04-replay-grant.ts:32"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-084a2a89aed91c76", "name": "Stray `console.log` in TS/JS \u2014 spike/02-send-webhook.ts:73", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 spike/02-send-webhook.ts:73"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-54d77c5f6c26329e", "name": "Stray `console.log` in TS/JS \u2014 spike/lib.ts:101", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 spike/lib.ts:101"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e7693526b5876c59", "name": "Stray `console.log` in TS/JS \u2014 spike/01-probe-chain.ts:97", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 spike/01-probe-chain.ts:97"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ac16b9ae364480e8", "name": "Stray `console.log` in TS/JS \u2014 spike/03-redeem-call.ts:107", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 spike/03-redeem-call.ts:107"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f708e2d7decec2e5", "name": "Stray `console.log` in TS/JS \u2014 spike/00-setup.ts:22", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 spike/00-setup.ts:22"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99f181d9e21d2e23", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/AIBrainConfig.tsx:220", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/AIBrainConfig.tsx:220"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-01760913ea37259c", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/ActiveConsole.tsx:120", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/ActiveConsole.tsx:120"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-6afcbd3559bb23f7", "name": "\"active\" state uses light bg in a dark theme \u2014 src/components/ActiveConsole.tsx:115", "shortDescription": {"text": "\"active\" state uses light bg in a dark theme \u2014 src/components/ActiveConsole.tsx:115"}, "fullDescription": {"text": "A ternary like `active ? 'bg-white' : '...'` (or bg-gray-100/200) on a dark theme produces jarring white pills. Use a dark-emphasized active state instead \u2014 border + ring or slightly brighter dark bg. Example: `active ? 'bg-gray-800 border-gray-500 ring-1 ring-blue-500/30' : '\u2026'`.\n\nWhy: P-E in CHECKLIST.md \u2014 light bg in a dark theme is a class of regression.\nRule id: fq.active-light-bg"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-383cd49cac61c444", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/ExploreSignals.tsx:119", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/ExploreSignals.tsx:119"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-275e4e85af6b1493", "name": "`truncate` class without `title=` for hover reveal \u2014 src/components/GuardrailConfig.tsx:84", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/GuardrailConfig.tsx:84"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-cb48a52c9da25555", "name": "Stray `console.log` in TS/JS \u2014 server/relayer.ts:106", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server/relayer.ts:106"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5d99142595ab1771", "name": "Stray `console.log` in TS/JS \u2014 server/state.ts:107", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 server/state.ts:107"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c79c5bc0e2fea9f0", "name": "Insecure pattern 'node_child_process' in spike/02-send-webhook.ts:17", "shortDescription": {"text": "Insecure pattern 'node_child_process' in spike/02-send-webhook.ts:17"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-1e97ea89b39dc629", "name": "Insecure pattern 'node_child_process' in server/index.ts:14", "shortDescription": {"text": "Insecure pattern 'node_child_process' in server/index.ts:14"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6372cebde0220094", "name": "No auth library detected", "shortDescription": {"text": "No auth library detected"}, "fullDescription": {"text": "The scanner did not find any standard auth library (JWT, OAuth, NextAuth, Auth0, etc.). The repo has auth/admin/session surface indicators, so auth may live in custom code, in a separate service, or be missing."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 31 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 57 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci, tests. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, ci, tests. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bae7eb749ec1df3c", "name": "Agent instruction/config may expose a secret: .claude/skills/public-relayer/references/schemas.md", "shortDescription": {"text": "Agent instruction/config may expose a secret: .claude/skills/public-relayer/references/schemas.md"}, "fullDescription": {"text": "Agent-facing files are routinely pasted into LLM/tool contexts. Move literal tokens, keys, and passwords into a secret manager or document them as placeholders only."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-2f38a489339079f1", "name": "`fetch()` without try/.catch or AbortSignal \u2014 spike/lib.ts:28", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 spike/lib.ts:28"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-9ed4f3551eb0afb0", "name": "`fetch()` without try/.catch or AbortSignal \u2014 src/lib/api.ts:86", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/lib/api.ts:86"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cc0f9d8e41b33b0e", "name": "11 env vars used in code but missing from .env.example", "shortDescription": {"text": "11 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `DISABLE_HMR`, `POLYMARKET_MAX_MATCHES`, `POLYMARKET_POLL_MS`, `POLYMARKET_SIGNAL_DELTA`, `PORT`, `RELAYER_URL`, `SEPOLIA_RPC`, `VENICE_MODEL` + 3 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-797929ef13aea4c3", "name": "Unused endpoint: POST /relayer-webhook", "shortDescription": {"text": "Unused endpoint: POST /relayer-webhook"}, "fullDescription": {"text": "`spike/02-send-webhook.ts` declares `POST /relayer-webhook` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ca8d20dc76e69f2a", "name": "Unused endpoint: GET /api/telemetry", "shortDescription": {"text": "Unused endpoint: GET /api/telemetry"}, "fullDescription": {"text": "`server/index.ts` declares `GET /api/telemetry` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fee809d16b1698f1", "name": "Unused endpoint: POST /api/markets/inject", "shortDescription": {"text": "Unused endpoint: POST /api/markets/inject"}, "fullDescription": {"text": "`server/index.ts` declares `POST /api/markets/inject` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5f1d97c57d4aca2f", "name": "Unused endpoint: POST /api/agents/mint", "shortDescription": {"text": "Unused endpoint: POST /api/agents/mint"}, "fullDescription": {"text": "`server/index.ts` declares `POST /api/agents/mint` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ab31d7e480a710b2", "name": "Unused endpoint: POST /api/agents", "shortDescription": {"text": "Unused endpoint: POST /api/agents"}, "fullDescription": {"text": "`server/index.ts` declares `POST /api/agents` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7657695c28aedf75", "name": "Unused endpoint: POST /api/agents/activate", "shortDescription": {"text": "Unused endpoint: POST /api/agents/activate"}, "fullDescription": {"text": "`server/index.ts` declares `POST /api/agents/activate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ec86c47ae19eb601", "name": "Unused endpoint: GET /api/mandates", "shortDescription": {"text": "Unused endpoint: GET /api/mandates"}, "fullDescription": {"text": "`server/index.ts` declares `GET /api/mandates` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8a27a16737e51921", "name": "Unused endpoint: POST /api/mandates/:id/stop", "shortDescription": {"text": "Unused endpoint: POST /api/mandates/:id/stop"}, "fullDescription": {"text": "`server/index.ts` declares `POST /api/mandates/:id/stop` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-28123052e28e578d", "name": "Unused endpoint: POST /api/agents/deactivate", "shortDescription": {"text": "Unused endpoint: POST /api/agents/deactivate"}, "fullDescription": {"text": "`server/index.ts` declares `POST /api/agents/deactivate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2832e75c4559a5ce", "name": "Unused endpoint: POST /api/relayer-webhook", "shortDescription": {"text": "Unused endpoint: POST /api/relayer-webhook"}, "fullDescription": {"text": "`server/index.ts` declares `POST /api/relayer-webhook` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4756b4c4da7d2088", "name": "Unused endpoint: GET /api/health", "shortDescription": {"text": "Unused endpoint: GET /api/health"}, "fullDescription": {"text": "`server/index.ts` declares `GET /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/25417"}, "properties": {"repository": "dinghdong/PolyForge", "repoUrl": "https://github.com/dinghdong/PolyForge", "branch": "main"}, "results": [{"ruleId": "scanner-0c0bee9b122f5336", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/compile.ts:41"}, "properties": {"repobilityId": "60a51bb5ebd55123", "scanner": "scanner-primary", "fingerprint": "0c0bee9b122f5336", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-972fc0f03819bd89", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/deploy-market.ts:20"}, "properties": {"repobilityId": "170b11b80abbdec7", "scanner": "scanner-primary", "fingerprint": "972fc0f03819bd89", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-25d6336853441fc9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/venice-check.ts:23"}, "properties": {"repobilityId": "22fca6bf14818782", "scanner": "scanner-primary", "fingerprint": "25d6336853441fc9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a013421acb9f7145", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/deploy-nfa.ts:12"}, "properties": {"repobilityId": "b1b349d1d6f09bda", "scanner": "scanner-primary", "fingerprint": "a013421acb9f7145", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b0dc53e27f3b3cdf", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 spike/04-replay-grant.ts:32"}, "properties": {"repobilityId": "247a142db3748452", "scanner": "scanner-primary", "fingerprint": "b0dc53e27f3b3cdf", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-084a2a89aed91c76", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 spike/02-send-webhook.ts:73"}, "properties": {"repobilityId": "9fff3725e71116e5", "scanner": "scanner-primary", "fingerprint": "084a2a89aed91c76", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-54d77c5f6c26329e", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 spike/lib.ts:101"}, "properties": {"repobilityId": "48506f3c203eb842", "scanner": "scanner-primary", "fingerprint": "54d77c5f6c26329e", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e7693526b5876c59", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 spike/01-probe-chain.ts:97"}, "properties": {"repobilityId": "fc5e59e3ab1b3d59", "scanner": "scanner-primary", "fingerprint": "e7693526b5876c59", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ac16b9ae364480e8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 spike/03-redeem-call.ts:107"}, "properties": {"repobilityId": "6971dfd8b131a860", "scanner": "scanner-primary", "fingerprint": "ac16b9ae364480e8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f708e2d7decec2e5", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 spike/00-setup.ts:22"}, "properties": {"repobilityId": "9359d59aa1dadfe0", "scanner": "scanner-primary", "fingerprint": "f708e2d7decec2e5", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-99f181d9e21d2e23", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/AIBrainConfig.tsx:220"}, "properties": {"repobilityId": "83981e67921f2657", "scanner": "scanner-primary", "fingerprint": "99f181d9e21d2e23", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-01760913ea37259c", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/ActiveConsole.tsx:120"}, "properties": {"repobilityId": "78a97f5d160f0693", "scanner": "scanner-primary", "fingerprint": "01760913ea37259c", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-6afcbd3559bb23f7", "level": "note", "message": {"text": "\"active\" state uses light bg in a dark theme \u2014 src/components/ActiveConsole.tsx:115"}, "properties": {"repobilityId": "f9e092d7b8cace91", "scanner": "scanner-primary", "fingerprint": "6afcbd3559bb23f7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.active-light-bg"]}}, {"ruleId": "scanner-383cd49cac61c444", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/ExploreSignals.tsx:119"}, "properties": {"repobilityId": "b8804eab830a9e66", "scanner": "scanner-primary", "fingerprint": "383cd49cac61c444", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-275e4e85af6b1493", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 src/components/GuardrailConfig.tsx:84"}, "properties": {"repobilityId": "367f3950686e3d96", "scanner": "scanner-primary", "fingerprint": "275e4e85af6b1493", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-cb48a52c9da25555", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server/relayer.ts:106"}, "properties": {"repobilityId": "d6876c197432140d", "scanner": "scanner-primary", "fingerprint": "cb48a52c9da25555", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5d99142595ab1771", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 server/state.ts:107"}, "properties": {"repobilityId": "03fefc47e9fcd494", "scanner": "scanner-primary", "fingerprint": "5d99142595ab1771", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-c79c5bc0e2fea9f0", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in spike/02-send-webhook.ts:17"}, "properties": {"repobilityId": "4f0f9856a63aa1c5", "scanner": "scanner-primary", "fingerprint": "c79c5bc0e2fea9f0", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "spike/02-send-webhook.ts"}, "region": {"startLine": 17}}}]}, {"ruleId": "scanner-1e97ea89b39dc629", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in server/index.ts:14"}, "properties": {"repobilityId": "6e16f30da262171d", "scanner": "scanner-primary", "fingerprint": "1e97ea89b39dc629", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "server/index.ts"}, "region": {"startLine": 14}}}]}, {"ruleId": "scanner-6372cebde0220094", "level": "warning", "message": {"text": "No auth library detected"}, "properties": {"repobilityId": "a5b6035a5bbf8054", "scanner": "scanner-primary", "fingerprint": "6372cebde0220094", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["coverage", "auth"]}}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "d31c922d6e2ac6c5", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "44dbefff6e672aa2", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "124afb7d70bf04c2", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "432ef6d032abe639", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "0b385fd11dacf6c7", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-bae7eb749ec1df3c", "level": "error", "message": {"text": "Agent instruction/config may expose a secret: .claude/skills/public-relayer/references/schemas.md"}, "properties": {"repobilityId": "c50a9dc140efc528", "scanner": "scanner-primary", "fingerprint": "bae7eb749ec1df3c", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["agent-instructions", "secrets", "claude_instruction"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": ".claude/skills/public-relayer/references/schemas.md"}, "region": {"startLine": 108}}}]}, {"ruleId": "scanner-2f38a489339079f1", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 spike/lib.ts:28"}, "properties": {"repobilityId": "fa5a26131110e417", "scanner": "scanner-primary", "fingerprint": "2f38a489339079f1", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-9ed4f3551eb0afb0", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 src/lib/api.ts:86"}, "properties": {"repobilityId": "d025a86c5b501076", "scanner": "scanner-primary", "fingerprint": "9ed4f3551eb0afb0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-cc0f9d8e41b33b0e", "level": "note", "message": {"text": "11 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "c82cd8cd626c3599", "scanner": "scanner-primary", "fingerprint": "cc0f9d8e41b33b0e", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-797929ef13aea4c3", "level": "note", "message": {"text": "Unused endpoint: POST /relayer-webhook"}, "properties": {"repobilityId": "01927bd338088a9c", "scanner": "scanner-primary", "fingerprint": "797929ef13aea4c3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ca8d20dc76e69f2a", "level": "note", "message": {"text": "Unused endpoint: GET /api/telemetry"}, "properties": {"repobilityId": "61f26388c9fbcb21", "scanner": "scanner-primary", "fingerprint": "ca8d20dc76e69f2a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fee809d16b1698f1", "level": "note", "message": {"text": "Unused endpoint: POST /api/markets/inject"}, "properties": {"repobilityId": "259e31a915b2fb6f", "scanner": "scanner-primary", "fingerprint": "fee809d16b1698f1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5f1d97c57d4aca2f", "level": "note", "message": {"text": "Unused endpoint: POST /api/agents/mint"}, "properties": {"repobilityId": "524ebbacb83ba83c", "scanner": "scanner-primary", "fingerprint": "5f1d97c57d4aca2f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ab31d7e480a710b2", "level": "note", "message": {"text": "Unused endpoint: POST /api/agents"}, "properties": {"repobilityId": "ccfa1782c0762e43", "scanner": "scanner-primary", "fingerprint": "ab31d7e480a710b2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7657695c28aedf75", "level": "note", "message": {"text": "Unused endpoint: POST /api/agents/activate"}, "properties": {"repobilityId": "7ed54b7f734411bf", "scanner": "scanner-primary", "fingerprint": "7657695c28aedf75", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ec86c47ae19eb601", "level": "note", "message": {"text": "Unused endpoint: GET /api/mandates"}, "properties": {"repobilityId": "7eb7b4fe8696a2aa", "scanner": "scanner-primary", "fingerprint": "ec86c47ae19eb601", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8a27a16737e51921", "level": "note", "message": {"text": "Unused endpoint: POST /api/mandates/:id/stop"}, "properties": {"repobilityId": "75c9e76b42e68ba7", "scanner": "scanner-primary", "fingerprint": "8a27a16737e51921", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-28123052e28e578d", "level": "note", "message": {"text": "Unused endpoint: POST /api/agents/deactivate"}, "properties": {"repobilityId": "622ff1bacd56c4ea", "scanner": "scanner-primary", "fingerprint": "28123052e28e578d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2832e75c4559a5ce", "level": "note", "message": {"text": "Unused endpoint: POST /api/relayer-webhook"}, "properties": {"repobilityId": "9bc1a0c7feaec3dc", "scanner": "scanner-primary", "fingerprint": "2832e75c4559a5ce", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4756b4c4da7d2088", "level": "note", "message": {"text": "Unused endpoint: GET /api/health"}, "properties": {"repobilityId": "779ee59986e3e7ae", "scanner": "scanner-primary", "fingerprint": "4756b4c4da7d2088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}