{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-4fab93c792865c55", "name": "Icon-only button without accessible name \u2014 frontend/src/pages/Scrapers.jsx:149", "shortDescription": {"text": "Icon-only button without accessible name \u2014 frontend/src/pages/Scrapers.jsx:149"}, "fullDescription": {"text": "A `<button>` whose only child is a single glyph or symbol needs `title=` or `aria-label=` so screen readers (and tooltips on hover) work.\n\nWhy: P3 in CHECKLIST.md \u2014 icon-only buttons skipped a title.\nRule id: fq.button.no-label"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0e6d353f9be174d3", "name": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Leads.jsx:337", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Leads.jsx:337"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-1d160c5781a6151f", "name": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Transcripts.jsx:107", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Transcripts.jsx:107"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-b3c1a900d9b34f7b", "name": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/LeadCleaner.jsx:1040", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/LeadCleaner.jsx:1040"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-894d9514f293d0ac", "name": "Stray `console.log` in TS/JS \u2014 frontend/src/pages/LeadCleaner.jsx:869", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/pages/LeadCleaner.jsx:869"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fa7c151d376de531", "name": "Icon-only button without accessible name \u2014 frontend/src/pages/Replies.jsx:56", "shortDescription": {"text": "Icon-only button without accessible name \u2014 frontend/src/pages/Replies.jsx:56"}, "fullDescription": {"text": "A `<button>` whose only child is a single glyph or symbol needs `title=` or `aria-label=` so screen readers (and tooltips on hover) work.\n\nWhy: P3 in CHECKLIST.md \u2014 icon-only buttons skipped a title.\nRule id: fq.button.no-label"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-30cf85ae3069bfab", "name": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Dashboard.jsx:288", "shortDescription": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Dashboard.jsx:288"}, "fullDescription": {"text": "A truncated value should reveal the full text on hover. Pass the full string via `title={...}` so the user can read it.\n\nWhy: P2 in CHECKLIST.md \u2014 truncate without hover-reveal.\nRule id: fq.truncate.no-title"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "info", "confidence": 1.0}}, {"id": "scanner-d723dc1f2777f26b", "name": "Stray `console.log` in TS/JS \u2014 backend/reset_leads.js:46", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/reset_leads.js:46"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-92c8c91a52e1e47d", "name": "Stray `console.log` in TS/JS \u2014 backend/server.js:16", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/server.js:16"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b478452a007ae19b", "name": "Stray `console.log` in TS/JS \u2014 backend/scrapers/fl-campaign-finance.js:44", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/scrapers/fl-campaign-finance.js:44"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-41e2a4600380bbd8", "name": "Stray `console.log` in TS/JS \u2014 backend/scripts/backfill_heyreach_text.js:45", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/scripts/backfill_heyreach_text.js:45"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f4fb77964c2b02a", "name": "Stray `console.log` in TS/JS \u2014 backend/routes/enrich.js:76", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/enrich.js:76"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ef5ba23b34578735", "name": "Stray `console.log` in TS/JS \u2014 backend/routes/scrapers.js:151", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/scrapers.js:151"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a144a34715d2aa91", "name": "Stray `console.log` in TS/JS \u2014 backend/routes/scraper.js:25", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/scraper.js:25"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1010f5e6bbac7cf8", "name": "Stray `console.log` in TS/JS \u2014 backend/routes/fireflies.js:97", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/fireflies.js:97"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d22891021f0b4bc6", "name": "Stray `console.log` in TS/JS \u2014 backend/routes/replies.js:112", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/replies.js:112"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2504eb5b73e99e56", "name": "Stray `console.log` in TS/JS \u2014 backend/routes/cleaner.js:248", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/cleaner.js:248"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-32d38e26a5974678", "name": "Stray `console.log` in TS/JS \u2014 backend/routes/heyreach.js:311", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/heyreach.js:311"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2fe8794aa1419840", "name": "Stray `console.log` in TS/JS \u2014 backend/routes/ingest.js:86", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/ingest.js:86"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4fabdb4f7c42d13c", "name": "Stray `console.log` in TS/JS \u2014 backend/cron/reclassify.js:52", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/reclassify.js:52"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3d76c3fd9b18a478", "name": "Stray `console.log` in TS/JS \u2014 backend/cron/cleanup.js:11", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/cleanup.js:11"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7dbbc60ef0651e86", "name": "Stray `console.log` in TS/JS \u2014 backend/cron/dashboard.js:11", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/dashboard.js:11"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-25800858dd53df6f", "name": "Stray `console.log` in TS/JS \u2014 backend/cron/brief.js:191", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/brief.js:191"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e198af216ce67827", "name": "Stray `console.log` in TS/JS \u2014 backend/cron/insights.js:136", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/insights.js:136"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4bfb76c3157c5610", "name": "Stray `console.log` in TS/JS \u2014 backend/cron/healthcheck.js:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/healthcheck.js:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b8389cbbda1fdcbb", "name": "Stray `console.log` in TS/JS \u2014 backend/cron/ulinc-poll.js:97", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/ulinc-poll.js:97"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-731be3763da25752", "name": "Stray `console.log` in TS/JS \u2014 backend/cron/daily-metrics.js:12", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/daily-metrics.js:12"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e17f82f784e4e39c", "name": "Stray `console.log` in TS/JS \u2014 backend/cron/queueSync.js:149", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/queueSync.js:149"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2f9fa77edb077c33", "name": "Stray `console.log` in TS/JS \u2014 backend/services/apify.js:111", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/apify.js:111"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-84611cd28a3f1a73", "name": "Stray `console.log` in TS/JS \u2014 backend/services/instantly.js:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/instantly.js:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-615e8ca16f0dc9a4", "name": "Stray `console.log` in TS/JS \u2014 backend/services/hubspot.js:7", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/hubspot.js:7"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a2b2de632b9c54a7", "name": "Stray `console.log` in TS/JS \u2014 backend/services/fireflies.js:83", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/fireflies.js:83"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0ece0adf2db827b4", "name": "Stray `console.log` in TS/JS \u2014 backend/services/calendar.js:76", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/calendar.js:76"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-726a3913feb4cda2", "name": "Stray `console.log` in TS/JS \u2014 backend/services/coteriehq.js:7", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/coteriehq.js:7"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-abe41add1851f988", "name": "Possible secret in frontend/src/pages/LeadCleaner.jsx", "shortDescription": {"text": "Possible secret in frontend/src/pages/LeadCleaner.jsx"}, "fullDescription": {"text": "Detected pattern matching generic_api_key. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-1374ff885f0dc7d4", "name": "Insecure pattern 'exec_used' in backend/server.js:761", "shortDescription": {"text": "Insecure pattern 'exec_used' in backend/server.js:761"}, "fullDescription": {"text": "Found a known-risky pattern (exec_used). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "high", "confidence": 1.0}}, {"id": "scanner-53a28eb53a96a7b3", "name": "Insecure pattern 'node_child_process' in backend/server.js:760", "shortDescription": {"text": "Insecure pattern 'node_child_process' in backend/server.js:760"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d5ba2bf29054209e", "name": "Insecure pattern 'cors_wildcard' in backend/server.js:10", "shortDescription": {"text": "Insecure pattern 'cors_wildcard' in backend/server.js:10"}, "fullDescription": {"text": "Found a known-risky pattern (cors_wildcard). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-eb6bfcc5cbc73eb7", "name": "Insecure pattern 'node_child_process' in backend/services/claude.js:1", "shortDescription": {"text": "Insecure pattern 'node_child_process' in backend/services/claude.js:1"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c1c9f006790cca86", "name": "Very large file: frontend/src/pages/LeadCleaner.jsx (1278 lines)", "shortDescription": {"text": "Very large file: frontend/src/pages/LeadCleaner.jsx (1278 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "0 test file(s) for 54 source file(s) (ratio 0.00). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-faccb9061e9b52a0", "name": "No README detected", "shortDescription": {"text": "No README detected"}, "fullDescription": {"text": "No README file was found. Generated repos without README context are hard to operate, validate, or safely hand off."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 122 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci, tests, operator-readme. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-749d4bc1bd66df5f", "name": "Agent instructions exist but release-hardening basics are missing", "shortDescription": {"text": "Agent instructions exist but release-hardening basics are missing"}, "fullDescription": {"text": "AI-coder instruction files were found, but the repo is missing license, ci, tests, operator-readme. Treat this as a contract gap: the agent is guided, but the generated output is not yet guarded by the controls that make it repeatable."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-25222cb35526f91a", "name": "Agent authority lacks a verifier contract: docs/icp-filter/SKILL.md", "shortDescription": {"text": "Agent authority lacks a verifier contract: docs/icp-filter/SKILL.md"}, "fullDescription": {"text": "This agent instruction grants code or shell authority but does not state the verification gate that decides promotion. The recurring safe pattern is: LLM proposes; deterministic tests/build/security checks verify; only verified code promotes."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-d8f3c4f32771876a", "name": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/Scrapers.jsx:92", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/Scrapers.jsx:92"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-c4a15a0ab7cc2388", "name": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/LeadCleaner.jsx:556", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/LeadCleaner.jsx:556"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ba281459c5b72619", "name": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/Replies.jsx:158", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/Replies.jsx:158"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-15710c3f93d93324", "name": "Commented-code block (5 lines) in docs/icp-filter/filter.py:309", "shortDescription": {"text": "Commented-code block (5 lines) in docs/icp-filter/filter.py:309"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-012d3c85edee0c02", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/routes/scraper.js:43", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/routes/scraper.js:43"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-3e49b97a6a3867d4", "name": "Commented-code block (8 lines) in backend/cron/queueSync.js:4", "shortDescription": {"text": "Commented-code block (8 lines) in backend/cron/queueSync.js:4"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-701fcf265dbb3b17", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/apify.js:7", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/apify.js:7"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-0bb9f21ae3e733fd", "name": "Commented-code block (5 lines) in backend/services/replyClassifier.js:3", "shortDescription": {"text": "Commented-code block (5 lines) in backend/services/replyClassifier.js:3"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-45260b27deb154aa", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/instantly.js:21", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/instantly.js:21"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-8f0c8a841716823d", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/hubspot.js:18", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/hubspot.js:18"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-640be5552843f312", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/fireflies.js:5", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/fireflies.js:5"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2ab11bb822d508ad", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/ulinc.js:51", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/ulinc.js:51"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ecee4ed46a7afc98", "name": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/coteriehq.js:18", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/coteriehq.js:18"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a807912cc82a5d39", "name": "Frontend route `/leads` has no Link/navigate to it \u2014 frontend/src/App.jsx", "shortDescription": {"text": "Frontend route `/leads` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-a75735f912c943e2", "name": "Frontend route `/replies` has no Link/navigate to it \u2014 frontend/src/App.jsx", "shortDescription": {"text": "Frontend route `/replies` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-42f860c5940d6177", "name": "Frontend route `/linkedin` has no Link/navigate to it \u2014 frontend/src/App.jsx", "shortDescription": {"text": "Frontend route `/linkedin` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-420370b9cafcbcbe", "name": "Frontend route `/scrapers` has no Link/navigate to it \u2014 frontend/src/App.jsx", "shortDescription": {"text": "Frontend route `/scrapers` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ffafdd8bb92a64d9", "name": "Frontend route `/transcripts` has no Link/navigate to it \u2014 frontend/src/App.jsx", "shortDescription": {"text": "Frontend route `/transcripts` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-408c598be52f63d2", "name": "Frontend route `/cleaner` has no Link/navigate to it \u2014 frontend/src/App.jsx", "shortDescription": {"text": "Frontend route `/cleaner` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-11814fef526a1ac0", "name": "Frontend route `/command` has no Link/navigate to it \u2014 frontend/src/App.jsx", "shortDescription": {"text": "Frontend route `/command` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ec0af1b5985b9238", "name": "Dangling fetch: POST https://api.instantly.ai/api/v2/leads/list (backend/routes/calendar.js:70)", "shortDescription": {"text": "Dangling fetch: POST https://api.instantly.ai/api/v2/leads/list (backend/routes/calendar.js:70)"}, "fullDescription": {"text": "`backend/routes/calendar.js:70` calls `POST https://api.instantly.ai/api/v2/leads/list` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/api.instantly.ai/api/v2/leads/list`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-f7dd07750c6d1204", "name": "Dangling fetch: GET https://api.instantly.ai/api/v2/campaigns/${campaignId} (backend/routes/calendar.js:140)", "shortDescription": {"text": "Dangling fetch: GET https://api.instantly.ai/api/v2/campaigns/${campaignId} (backend/routes/calendar.js:140)"}, "fullDescription": {"text": "`backend/routes/calendar.js:140` calls `GET https://api.instantly.ai/api/v2/campaigns/${campaignId}` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: axios\nNormalized path used for matching: `/https:/api.instantly.ai/api/v2/campaigns/<p>`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-27bbb88239cb3bc2", "name": "Unused endpoint: USE /api/ingest", "shortDescription": {"text": "Unused endpoint: USE /api/ingest"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/ingest` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2c5cc593f0f60854", "name": "Unused endpoint: USE /api/enrich", "shortDescription": {"text": "Unused endpoint: USE /api/enrich"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/enrich` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1f7f62dde5e39627", "name": "Unused endpoint: USE /api/reply", "shortDescription": {"text": "Unused endpoint: USE /api/reply"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/reply` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d43f7d425113b21a", "name": "Unused endpoint: USE /api/scraper", "shortDescription": {"text": "Unused endpoint: USE /api/scraper"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/scraper` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5918feffd8b49beb", "name": "Unused endpoint: USE /api/scrapers", "shortDescription": {"text": "Unused endpoint: USE /api/scrapers"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/scrapers` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8196904e8d03f681", "name": "Unused endpoint: USE /api/cleaner", "shortDescription": {"text": "Unused endpoint: USE /api/cleaner"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/cleaner` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-17573a86e04bfde5", "name": "Unused endpoint: USE /api/fireflies", "shortDescription": {"text": "Unused endpoint: USE /api/fireflies"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/fireflies` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a497b27960efb959", "name": "Unused endpoint: USE /api/heyreach", "shortDescription": {"text": "Unused endpoint: USE /api/heyreach"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/heyreach` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0ac145975c9694ab", "name": "Unused endpoint: USE /api/instantly", "shortDescription": {"text": "Unused endpoint: USE /api/instantly"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/instantly` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aebdad2655c302c7", "name": "Unused endpoint: USE /api/calendar", "shortDescription": {"text": "Unused endpoint: USE /api/calendar"}, "fullDescription": {"text": "`backend/server.js` declares `USE /api/calendar` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4756b4c4da7d2088", "name": "Unused endpoint: GET /api/health", "shortDescription": {"text": "Unused endpoint: GET /api/health"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/health` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6ae92428b89c54b8", "name": "Unused endpoint: GET /api/dashboard", "shortDescription": {"text": "Unused endpoint: GET /api/dashboard"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/dashboard` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-679d5c7141cd7f27", "name": "Unused endpoint: GET /api/dashboard/funnel", "shortDescription": {"text": "Unused endpoint: GET /api/dashboard/funnel"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/dashboard/funnel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b4f01423e4c38ed6", "name": "Unused endpoint: GET /api/leads", "shortDescription": {"text": "Unused endpoint: GET /api/leads"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/leads` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d2f3cea69f4cddb5", "name": "Unused endpoint: GET /api/replies", "shortDescription": {"text": "Unused endpoint: GET /api/replies"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/replies` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-adffbd304c0a3f0b", "name": "Unused endpoint: GET /api/ulinc/conversation/:contactId", "shortDescription": {"text": "Unused endpoint: GET /api/ulinc/conversation/:contactId"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/ulinc/conversation/:contactId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-59a9339ce5f794fd", "name": "Unused endpoint: POST /api/ulinc/webhook", "shortDescription": {"text": "Unused endpoint: POST /api/ulinc/webhook"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/ulinc/webhook` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-77d62e8726ce8418", "name": "Unused endpoint: POST /api/instantly/send", "shortDescription": {"text": "Unused endpoint: POST /api/instantly/send"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/instantly/send` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-37546e1afd0cde7f", "name": "Unused endpoint: POST /api/ulinc/send", "shortDescription": {"text": "Unused endpoint: POST /api/ulinc/send"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/ulinc/send` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f07b9da10082fae0", "name": "Unused endpoint: PATCH /api/replies/:id/handled", "shortDescription": {"text": "Unused endpoint: PATCH /api/replies/:id/handled"}, "fullDescription": {"text": "`backend/server.js` declares `PATCH /api/replies/:id/handled` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7b279d062b0a7dff", "name": "Unused endpoint: PATCH /api/replies/:id/ulinc-status", "shortDescription": {"text": "Unused endpoint: PATCH /api/replies/:id/ulinc-status"}, "fullDescription": {"text": "`backend/server.js` declares `PATCH /api/replies/:id/ulinc-status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7f31ee5a011576bb", "name": "Unused endpoint: PATCH /api/replies/:id", "shortDescription": {"text": "Unused endpoint: PATCH /api/replies/:id"}, "fullDescription": {"text": "`backend/server.js` declares `PATCH /api/replies/:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-29efa05a3ba27177", "name": "Unused endpoint: GET /api/replies/thread/:email", "shortDescription": {"text": "Unused endpoint: GET /api/replies/thread/:email"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/replies/thread/:email` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-58d221b86f417a3a", "name": "Unused endpoint: GET /api/instantly/leads", "shortDescription": {"text": "Unused endpoint: GET /api/instantly/leads"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/instantly/leads` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d822c522a807c253", "name": "Unused endpoint: GET /api/instantly/subsequences", "shortDescription": {"text": "Unused endpoint: GET /api/instantly/subsequences"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/instantly/subsequences` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ae6432be6fae4129", "name": "Unused endpoint: POST /api/instantly/subsequence/add", "shortDescription": {"text": "Unused endpoint: POST /api/instantly/subsequence/add"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/instantly/subsequence/add` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d814d4208ebcda5d", "name": "Unused endpoint: POST /api/trigger/cleanup", "shortDescription": {"text": "Unused endpoint: POST /api/trigger/cleanup"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/trigger/cleanup` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-04bfad63e4b7ad06", "name": "Unused endpoint: POST /api/trigger/dashboard", "shortDescription": {"text": "Unused endpoint: POST /api/trigger/dashboard"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/trigger/dashboard` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-86f66dbbc70ffa7b", "name": "Unused endpoint: POST /api/trigger/daily-metrics", "shortDescription": {"text": "Unused endpoint: POST /api/trigger/daily-metrics"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/trigger/daily-metrics` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-25a9077f1bd17037", "name": "Unused endpoint: POST /api/trigger/brief", "shortDescription": {"text": "Unused endpoint: POST /api/trigger/brief"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/trigger/brief` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9834803fcb808f6c", "name": "Unused endpoint: GET /api/trigger/brief/preview", "shortDescription": {"text": "Unused endpoint: GET /api/trigger/brief/preview"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/trigger/brief/preview` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e0431640f07eeb7b", "name": "Unused endpoint: GET /api/command", "shortDescription": {"text": "Unused endpoint: GET /api/command"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/command` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f4f94400f7c1023c", "name": "Unused endpoint: POST /api/trigger/insights", "shortDescription": {"text": "Unused endpoint: POST /api/trigger/insights"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/trigger/insights` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4e43ccb397ece9e6", "name": "Unused endpoint: GET /api/insights", "shortDescription": {"text": "Unused endpoint: GET /api/insights"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/insights` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f45a2c9811fa90f9", "name": "Unused endpoint: GET /api/brains", "shortDescription": {"text": "Unused endpoint: GET /api/brains"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/brains` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6a8cf1cbf122a368", "name": "Unused endpoint: POST /api/trigger/healthcheck", "shortDescription": {"text": "Unused endpoint: POST /api/trigger/healthcheck"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/trigger/healthcheck` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-78fe24162b5b98a1", "name": "Unused endpoint: POST /api/trigger/queue-sync", "shortDescription": {"text": "Unused endpoint: POST /api/trigger/queue-sync"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/trigger/queue-sync` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-99ea709a012c3eb6", "name": "Unused endpoint: POST /api/trigger/reclassify", "shortDescription": {"text": "Unused endpoint: POST /api/trigger/reclassify"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/trigger/reclassify` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cebdc1c9bc69ebd5", "name": "Unused endpoint: GET /api/dashboard/daily-metrics", "shortDescription": {"text": "Unused endpoint: GET /api/dashboard/daily-metrics"}, "fullDescription": {"text": "`backend/server.js` declares `GET /api/dashboard/daily-metrics` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a87e60b297cd2de", "name": "Unused endpoint: POST /api/deploy", "shortDescription": {"text": "Unused endpoint: POST /api/deploy"}, "fullDescription": {"text": "`backend/server.js` declares `POST /api/deploy` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a009b1a56794f45", "name": "Unused endpoint: POST /", "shortDescription": {"text": "Unused endpoint: POST /"}, "fullDescription": {"text": "`backend/routes/enrich.js` declares `POST /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`backend/routes/scrapers.js` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-359f35937bed4935", "name": "Unused endpoint: GET /registry", "shortDescription": {"text": "Unused endpoint: GET /registry"}, "fullDescription": {"text": "`backend/routes/scrapers.js` declares `GET /registry` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8d5b2b188d08ca82", "name": "Unused endpoint: PUT /:id", "shortDescription": {"text": "Unused endpoint: PUT /:id"}, "fullDescription": {"text": "`backend/routes/scrapers.js` declares `PUT /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a61c112b611f4bb", "name": "Unused endpoint: DELETE /:id", "shortDescription": {"text": "Unused endpoint: DELETE /:id"}, "fullDescription": {"text": "`backend/routes/scrapers.js` declares `DELETE /:id` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-53c4efb11ed0ac76", "name": "Unused endpoint: POST /:id/run", "shortDescription": {"text": "Unused endpoint: POST /:id/run"}, "fullDescription": {"text": "`backend/routes/scrapers.js` declares `POST /:id/run` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a4c3d46b552a5899", "name": "Unused endpoint: POST /run-type/:type", "shortDescription": {"text": "Unused endpoint: POST /run-type/:type"}, "fullDescription": {"text": "`backend/routes/scrapers.js` declares `POST /run-type/:type` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-03e921a06be65aa1", "name": "Unused endpoint: GET /:id/runs", "shortDescription": {"text": "Unused endpoint: GET /:id/runs"}, "fullDescription": {"text": "`backend/routes/scrapers.js` declares `GET /:id/runs` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2e64a326a4f5aa73", "name": "Unused endpoint: GET /daily-stats", "shortDescription": {"text": "Unused endpoint: GET /daily-stats"}, "fullDescription": {"text": "`backend/routes/instantly.js` declares `GET /daily-stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f267cc6244ff132b", "name": "Unused endpoint: GET /campaigns", "shortDescription": {"text": "Unused endpoint: GET /campaigns"}, "fullDescription": {"text": "`backend/routes/instantly.js` declares `GET /campaigns` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/22280"}, "properties": {"repository": "vinniecatalano9/story-group-gtm", "repoUrl": "https://github.com/vinniecatalano9/story-group-gtm", "branch": "main"}, "results": [{"ruleId": "scanner-4fab93c792865c55", "level": "note", "message": {"text": "Icon-only button without accessible name \u2014 frontend/src/pages/Scrapers.jsx:149"}, "properties": {"repobilityId": "b7c492d3b082fb10", "scanner": "scanner-primary", "fingerprint": "4fab93c792865c55", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.button.no-label"]}}, {"ruleId": "scanner-0e6d353f9be174d3", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Leads.jsx:337"}, "properties": {"repobilityId": "26096191656107fc", "scanner": "scanner-primary", "fingerprint": "0e6d353f9be174d3", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-1d160c5781a6151f", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Transcripts.jsx:107"}, "properties": {"repobilityId": "7a29009bfa661462", "scanner": "scanner-primary", "fingerprint": "1d160c5781a6151f", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-b3c1a900d9b34f7b", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/LeadCleaner.jsx:1040"}, "properties": {"repobilityId": "29e685a50ee371e0", "scanner": "scanner-primary", "fingerprint": "b3c1a900d9b34f7b", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-894d9514f293d0ac", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 frontend/src/pages/LeadCleaner.jsx:869"}, "properties": {"repobilityId": "5539b144a70fbc4b", "scanner": "scanner-primary", "fingerprint": "894d9514f293d0ac", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-fa7c151d376de531", "level": "note", "message": {"text": "Icon-only button without accessible name \u2014 frontend/src/pages/Replies.jsx:56"}, "properties": {"repobilityId": "8f3c78ffb5e63d60", "scanner": "scanner-primary", "fingerprint": "fa7c151d376de531", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.button.no-label"]}}, {"ruleId": "scanner-30cf85ae3069bfab", "level": "none", "message": {"text": "`truncate` class without `title=` for hover reveal \u2014 frontend/src/pages/Dashboard.jsx:288"}, "properties": {"repobilityId": "7918db97b30cf096", "scanner": "scanner-primary", "fingerprint": "30cf85ae3069bfab", "layer": "frontend", "severity": "info", "confidence": 1.0, "tags": ["frontend-quality", "fq.truncate.no-title"]}}, {"ruleId": "scanner-d723dc1f2777f26b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/reset_leads.js:46"}, "properties": {"repobilityId": "bc5b9c54e6ccd3ad", "scanner": "scanner-primary", "fingerprint": "d723dc1f2777f26b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-92c8c91a52e1e47d", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/server.js:16"}, "properties": {"repobilityId": "ec6c625862fd9ddc", "scanner": "scanner-primary", "fingerprint": "92c8c91a52e1e47d", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b478452a007ae19b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/scrapers/fl-campaign-finance.js:44"}, "properties": {"repobilityId": "11ee8f579b087af5", "scanner": "scanner-primary", "fingerprint": "b478452a007ae19b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-41e2a4600380bbd8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/scripts/backfill_heyreach_text.js:45"}, "properties": {"repobilityId": "0e14cdce2e21486a", "scanner": "scanner-primary", "fingerprint": "41e2a4600380bbd8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1f4fb77964c2b02a", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/enrich.js:76"}, "properties": {"repobilityId": "ffe42c38b6ddaae8", "scanner": "scanner-primary", "fingerprint": "1f4fb77964c2b02a", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ef5ba23b34578735", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/scrapers.js:151"}, "properties": {"repobilityId": "fdd37f19441da00f", "scanner": "scanner-primary", "fingerprint": "ef5ba23b34578735", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a144a34715d2aa91", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/scraper.js:25"}, "properties": {"repobilityId": "f2ea42a30b8e4872", "scanner": "scanner-primary", "fingerprint": "a144a34715d2aa91", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-1010f5e6bbac7cf8", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/fireflies.js:97"}, "properties": {"repobilityId": "fae274352c466ef4", "scanner": "scanner-primary", "fingerprint": "1010f5e6bbac7cf8", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-d22891021f0b4bc6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/replies.js:112"}, "properties": {"repobilityId": "67760fdb8fe14d7a", "scanner": "scanner-primary", "fingerprint": "d22891021f0b4bc6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2504eb5b73e99e56", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/cleaner.js:248"}, "properties": {"repobilityId": "d1e8b17c59e8e8b5", "scanner": "scanner-primary", "fingerprint": "2504eb5b73e99e56", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-32d38e26a5974678", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/heyreach.js:311"}, "properties": {"repobilityId": "e39d43dbcd3ea182", "scanner": "scanner-primary", "fingerprint": "32d38e26a5974678", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2fe8794aa1419840", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/routes/ingest.js:86"}, "properties": {"repobilityId": "b02755a14a302b60", "scanner": "scanner-primary", "fingerprint": "2fe8794aa1419840", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4fabdb4f7c42d13c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/reclassify.js:52"}, "properties": {"repobilityId": "a6c7ce3935fd50b4", "scanner": "scanner-primary", "fingerprint": "4fabdb4f7c42d13c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-3d76c3fd9b18a478", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/cleanup.js:11"}, "properties": {"repobilityId": "4657a5cae3604480", "scanner": "scanner-primary", "fingerprint": "3d76c3fd9b18a478", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-7dbbc60ef0651e86", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/dashboard.js:11"}, "properties": {"repobilityId": "4638d98a27961e96", "scanner": "scanner-primary", "fingerprint": "7dbbc60ef0651e86", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-25800858dd53df6f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/brief.js:191"}, "properties": {"repobilityId": "850cb8816c481c81", "scanner": "scanner-primary", "fingerprint": "25800858dd53df6f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e198af216ce67827", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/insights.js:136"}, "properties": {"repobilityId": "8be54115400407a5", "scanner": "scanner-primary", "fingerprint": "e198af216ce67827", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4bfb76c3157c5610", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/healthcheck.js:23"}, "properties": {"repobilityId": "3d9f2492b439da90", "scanner": "scanner-primary", "fingerprint": "4bfb76c3157c5610", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b8389cbbda1fdcbb", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/ulinc-poll.js:97"}, "properties": {"repobilityId": "2f3eebf8564634ab", "scanner": "scanner-primary", "fingerprint": "b8389cbbda1fdcbb", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-731be3763da25752", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/daily-metrics.js:12"}, "properties": {"repobilityId": "4108f29fa6ce386d", "scanner": "scanner-primary", "fingerprint": "731be3763da25752", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e17f82f784e4e39c", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/cron/queueSync.js:149"}, "properties": {"repobilityId": "f991617085293bd2", "scanner": "scanner-primary", "fingerprint": "e17f82f784e4e39c", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-2f9fa77edb077c33", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/apify.js:111"}, "properties": {"repobilityId": "29a0e1e9e15ef178", "scanner": "scanner-primary", "fingerprint": "2f9fa77edb077c33", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-84611cd28a3f1a73", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/instantly.js:23"}, "properties": {"repobilityId": "4bac6c40d67bdbfb", "scanner": "scanner-primary", "fingerprint": "84611cd28a3f1a73", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-615e8ca16f0dc9a4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/hubspot.js:7"}, "properties": {"repobilityId": "ad93df9676cb6441", "scanner": "scanner-primary", "fingerprint": "615e8ca16f0dc9a4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-a2b2de632b9c54a7", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/fireflies.js:83"}, "properties": {"repobilityId": "8213e3666a1e04bb", "scanner": "scanner-primary", "fingerprint": "a2b2de632b9c54a7", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-0ece0adf2db827b4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/calendar.js:76"}, "properties": {"repobilityId": "5a9dfaca5891f664", "scanner": "scanner-primary", "fingerprint": "0ece0adf2db827b4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-726a3913feb4cda2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 backend/services/coteriehq.js:7"}, "properties": {"repobilityId": "5fb9ac95aac0f9dd", "scanner": "scanner-primary", "fingerprint": "726a3913feb4cda2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-abe41add1851f988", "level": "error", "message": {"text": "Possible secret in frontend/src/pages/LeadCleaner.jsx"}, "properties": {"repobilityId": "2a7124b204679ad5", "scanner": "scanner-primary", "fingerprint": "abe41add1851f988", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "frontend/src/pages/LeadCleaner.jsx"}, "region": {"startLine": 427}}}]}, {"ruleId": "scanner-1374ff885f0dc7d4", "level": "error", "message": {"text": "Insecure pattern 'exec_used' in backend/server.js:761"}, "properties": {"repobilityId": "9bacdbe82fe3cdc2", "scanner": "scanner-primary", "fingerprint": "1374ff885f0dc7d4", "layer": "security", "severity": "high", "confidence": 1.0, "tags": ["owasp", "exec_used"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/server.js"}, "region": {"startLine": 761}}}]}, {"ruleId": "scanner-53a28eb53a96a7b3", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in backend/server.js:760"}, "properties": {"repobilityId": "f7a18b8bdf2df44a", "scanner": "scanner-primary", "fingerprint": "53a28eb53a96a7b3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/server.js"}, "region": {"startLine": 760}}}]}, {"ruleId": "scanner-d5ba2bf29054209e", "level": "warning", "message": {"text": "Insecure pattern 'cors_wildcard' in backend/server.js:10"}, "properties": {"repobilityId": "c509a14561e07714", "scanner": "scanner-primary", "fingerprint": "d5ba2bf29054209e", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "cors_wildcard"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/server.js"}, "region": {"startLine": 10}}}]}, {"ruleId": "scanner-eb6bfcc5cbc73eb7", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in backend/services/claude.js:1"}, "properties": {"repobilityId": "451731a159e87bb0", "scanner": "scanner-primary", "fingerprint": "eb6bfcc5cbc73eb7", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "backend/services/claude.js"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-c1c9f006790cca86", "level": "note", "message": {"text": "Very large file: frontend/src/pages/LeadCleaner.jsx (1278 lines)"}, "properties": {"repobilityId": "27331c81c6ef2b33", "scanner": "scanner-primary", "fingerprint": "c1c9f006790cca86", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "97d77366fda6b87b", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-faccb9061e9b52a0", "level": "note", "message": {"text": "No README detected"}, "properties": {"repobilityId": "ca658b26aa749a1b", "scanner": "scanner-primary", "fingerprint": "faccb9061e9b52a0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["docs", "readme", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "3ec1fdd58130e50c", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "98e6435fdf7f8a4d", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "252403edd52ce22e", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-749d4bc1bd66df5f", "level": "warning", "message": {"text": "Agent instructions exist but release-hardening basics are missing"}, "properties": {"repobilityId": "955c3119ce60605d", "scanner": "scanner-primary", "fingerprint": "749d4bc1bd66df5f", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "1b85b170c93c1a9d", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "eeb2f0c792107135", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-25222cb35526f91a", "level": "warning", "message": {"text": "Agent authority lacks a verifier contract: docs/icp-filter/SKILL.md"}, "properties": {"repobilityId": "1e431c3820432f2f", "scanner": "scanner-primary", "fingerprint": "25222cb35526f91a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["agent-instructions", "verification", "skill_file"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "docs/icp-filter/SKILL.md"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d8f3c4f32771876a", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/Scrapers.jsx:92"}, "properties": {"repobilityId": "de372713d5ba0a5b", "scanner": "scanner-primary", "fingerprint": "d8f3c4f32771876a", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-c4a15a0ab7cc2388", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/LeadCleaner.jsx:556"}, "properties": {"repobilityId": "233d411a92f0289f", "scanner": "scanner-primary", "fingerprint": "c4a15a0ab7cc2388", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ba281459c5b72619", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 frontend/src/pages/Replies.jsx:158"}, "properties": {"repobilityId": "4a0f313a43a25d63", "scanner": "scanner-primary", "fingerprint": "ba281459c5b72619", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-15710c3f93d93324", "level": "none", "message": {"text": "Commented-code block (5 lines) in docs/icp-filter/filter.py:309"}, "properties": {"repobilityId": "e01498b7d54053de", "scanner": "scanner-primary", "fingerprint": "15710c3f93d93324", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-012d3c85edee0c02", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/routes/scraper.js:43"}, "properties": {"repobilityId": "b1c51055a8080446", "scanner": "scanner-primary", "fingerprint": "012d3c85edee0c02", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-3e49b97a6a3867d4", "level": "none", "message": {"text": "Commented-code block (8 lines) in backend/cron/queueSync.js:4"}, "properties": {"repobilityId": "fbec685c82130757", "scanner": "scanner-primary", "fingerprint": "3e49b97a6a3867d4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-701fcf265dbb3b17", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/apify.js:7"}, "properties": {"repobilityId": "60a287189ef8f9c3", "scanner": "scanner-primary", "fingerprint": "701fcf265dbb3b17", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-0bb9f21ae3e733fd", "level": "none", "message": {"text": "Commented-code block (5 lines) in backend/services/replyClassifier.js:3"}, "properties": {"repobilityId": "7f34709e53e1d3ca", "scanner": "scanner-primary", "fingerprint": "0bb9f21ae3e733fd", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-45260b27deb154aa", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/instantly.js:21"}, "properties": {"repobilityId": "66d62cfc26370591", "scanner": "scanner-primary", "fingerprint": "45260b27deb154aa", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-8f0c8a841716823d", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/hubspot.js:18"}, "properties": {"repobilityId": "c565680184560ce6", "scanner": "scanner-primary", "fingerprint": "8f0c8a841716823d", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-640be5552843f312", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/fireflies.js:5"}, "properties": {"repobilityId": "23a71199c5c4dac6", "scanner": "scanner-primary", "fingerprint": "640be5552843f312", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-2ab11bb822d508ad", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/ulinc.js:51"}, "properties": {"repobilityId": "691e08cfd28d3d87", "scanner": "scanner-primary", "fingerprint": "2ab11bb822d508ad", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-ecee4ed46a7afc98", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 backend/services/coteriehq.js:18"}, "properties": {"repobilityId": "1aff3774f3e68161", "scanner": "scanner-primary", "fingerprint": "ecee4ed46a7afc98", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-a807912cc82a5d39", "level": "warning", "message": {"text": "Frontend route `/leads` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "properties": {"repobilityId": "3918a0e9525e5dcc", "scanner": "scanner-primary", "fingerprint": "a807912cc82a5d39", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-a75735f912c943e2", "level": "warning", "message": {"text": "Frontend route `/replies` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "properties": {"repobilityId": "d295a3bd27645b36", "scanner": "scanner-primary", "fingerprint": "a75735f912c943e2", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-42f860c5940d6177", "level": "warning", "message": {"text": "Frontend route `/linkedin` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "properties": {"repobilityId": "d88229f9c3dbf38a", "scanner": "scanner-primary", "fingerprint": "42f860c5940d6177", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-420370b9cafcbcbe", "level": "warning", "message": {"text": "Frontend route `/scrapers` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "properties": {"repobilityId": "c3b99e650445d2b5", "scanner": "scanner-primary", "fingerprint": "420370b9cafcbcbe", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-ffafdd8bb92a64d9", "level": "warning", "message": {"text": "Frontend route `/transcripts` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "properties": {"repobilityId": "fd8718340b1ed348", "scanner": "scanner-primary", "fingerprint": "ffafdd8bb92a64d9", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-408c598be52f63d2", "level": "warning", "message": {"text": "Frontend route `/cleaner` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "properties": {"repobilityId": "30f8282a3630a960", "scanner": "scanner-primary", "fingerprint": "408c598be52f63d2", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-11814fef526a1ac0", "level": "warning", "message": {"text": "Frontend route `/command` has no Link/navigate to it \u2014 frontend/src/App.jsx"}, "properties": {"repobilityId": "44154e47528c1ebb", "scanner": "scanner-primary", "fingerprint": "11814fef526a1ac0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-ec0af1b5985b9238", "level": "error", "message": {"text": "Dangling fetch: POST https://api.instantly.ai/api/v2/leads/list (backend/routes/calendar.js:70)"}, "properties": {"repobilityId": "d24bad9d5034aebf", "scanner": "scanner-primary", "fingerprint": "ec0af1b5985b9238", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-f7dd07750c6d1204", "level": "error", "message": {"text": "Dangling fetch: GET https://api.instantly.ai/api/v2/campaigns/${campaignId} (backend/routes/calendar.js:140)"}, "properties": {"repobilityId": "855ac3aa6401dc73", "scanner": "scanner-primary", "fingerprint": "f7dd07750c6d1204", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "axios"]}}, {"ruleId": "scanner-27bbb88239cb3bc2", "level": "note", "message": {"text": "Unused endpoint: USE /api/ingest"}, "properties": {"repobilityId": "c83a9710458f0140", "scanner": "scanner-primary", "fingerprint": "27bbb88239cb3bc2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2c5cc593f0f60854", "level": "note", "message": {"text": "Unused endpoint: USE /api/enrich"}, "properties": {"repobilityId": "3b643a0d1fd6f3a3", "scanner": "scanner-primary", "fingerprint": "2c5cc593f0f60854", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1f7f62dde5e39627", "level": "note", "message": {"text": "Unused endpoint: USE /api/reply"}, "properties": {"repobilityId": "a922414cdebe20f7", "scanner": "scanner-primary", "fingerprint": "1f7f62dde5e39627", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d43f7d425113b21a", "level": "note", "message": {"text": "Unused endpoint: USE /api/scraper"}, "properties": {"repobilityId": "fc891f1bfaeecaed", "scanner": "scanner-primary", "fingerprint": "d43f7d425113b21a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5918feffd8b49beb", "level": "note", "message": {"text": "Unused endpoint: USE /api/scrapers"}, "properties": {"repobilityId": "4b951fd7f0cba4c3", "scanner": "scanner-primary", "fingerprint": "5918feffd8b49beb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8196904e8d03f681", "level": "note", "message": {"text": "Unused endpoint: USE /api/cleaner"}, "properties": {"repobilityId": "057b31a2486f0652", "scanner": "scanner-primary", "fingerprint": "8196904e8d03f681", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-17573a86e04bfde5", "level": "note", "message": {"text": "Unused endpoint: USE /api/fireflies"}, "properties": {"repobilityId": "d56dab2dd77f940f", "scanner": "scanner-primary", "fingerprint": "17573a86e04bfde5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a497b27960efb959", "level": "note", "message": {"text": "Unused endpoint: USE /api/heyreach"}, "properties": {"repobilityId": "f6eed0707503ba7e", "scanner": "scanner-primary", "fingerprint": "a497b27960efb959", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0ac145975c9694ab", "level": "note", "message": {"text": "Unused endpoint: USE /api/instantly"}, "properties": {"repobilityId": "33b620c880ebf401", "scanner": "scanner-primary", "fingerprint": "0ac145975c9694ab", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aebdad2655c302c7", "level": "note", "message": {"text": "Unused endpoint: USE /api/calendar"}, "properties": {"repobilityId": "20bab90ed990992a", "scanner": "scanner-primary", "fingerprint": "aebdad2655c302c7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4756b4c4da7d2088", "level": "note", "message": {"text": "Unused endpoint: GET /api/health"}, "properties": {"repobilityId": "1e5295e69c6e06d8", "scanner": "scanner-primary", "fingerprint": "4756b4c4da7d2088", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6ae92428b89c54b8", "level": "note", "message": {"text": "Unused endpoint: GET /api/dashboard"}, "properties": {"repobilityId": "03b52bdf4999a9a5", "scanner": "scanner-primary", "fingerprint": "6ae92428b89c54b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-679d5c7141cd7f27", "level": "note", "message": {"text": "Unused endpoint: GET /api/dashboard/funnel"}, "properties": {"repobilityId": "32c335923f3accc7", "scanner": "scanner-primary", "fingerprint": "679d5c7141cd7f27", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b4f01423e4c38ed6", "level": "note", "message": {"text": "Unused endpoint: GET /api/leads"}, "properties": {"repobilityId": "26c8798a7a5d9a36", "scanner": "scanner-primary", "fingerprint": "b4f01423e4c38ed6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d2f3cea69f4cddb5", "level": "note", "message": {"text": "Unused endpoint: GET /api/replies"}, "properties": {"repobilityId": "9bd7fdca29b9608f", "scanner": "scanner-primary", "fingerprint": "d2f3cea69f4cddb5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-adffbd304c0a3f0b", "level": "note", "message": {"text": "Unused endpoint: GET /api/ulinc/conversation/:contactId"}, "properties": {"repobilityId": "a72ddc536922515d", "scanner": "scanner-primary", "fingerprint": "adffbd304c0a3f0b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-59a9339ce5f794fd", "level": "note", "message": {"text": "Unused endpoint: POST /api/ulinc/webhook"}, "properties": {"repobilityId": "f7b8c1d2f2905b4b", "scanner": "scanner-primary", "fingerprint": "59a9339ce5f794fd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-77d62e8726ce8418", "level": "note", "message": {"text": "Unused endpoint: POST /api/instantly/send"}, "properties": {"repobilityId": "b76e473d0454c2c2", "scanner": "scanner-primary", "fingerprint": "77d62e8726ce8418", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-37546e1afd0cde7f", "level": "note", "message": {"text": "Unused endpoint: POST /api/ulinc/send"}, "properties": {"repobilityId": "607944fc4598cc81", "scanner": "scanner-primary", "fingerprint": "37546e1afd0cde7f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f07b9da10082fae0", "level": "note", "message": {"text": "Unused endpoint: PATCH /api/replies/:id/handled"}, "properties": {"repobilityId": "2482c171b0b638ce", "scanner": "scanner-primary", "fingerprint": "f07b9da10082fae0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7b279d062b0a7dff", "level": "note", "message": {"text": "Unused endpoint: PATCH /api/replies/:id/ulinc-status"}, "properties": {"repobilityId": "9d9db1fce894ee29", "scanner": "scanner-primary", "fingerprint": "7b279d062b0a7dff", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7f31ee5a011576bb", "level": "note", "message": {"text": "Unused endpoint: PATCH /api/replies/:id"}, "properties": {"repobilityId": "824d028c753f5f17", "scanner": "scanner-primary", "fingerprint": "7f31ee5a011576bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-29efa05a3ba27177", "level": "note", "message": {"text": "Unused endpoint: GET /api/replies/thread/:email"}, "properties": {"repobilityId": "fdc4a4a15c0aeccf", "scanner": "scanner-primary", "fingerprint": "29efa05a3ba27177", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-58d221b86f417a3a", "level": "note", "message": {"text": "Unused endpoint: GET /api/instantly/leads"}, "properties": {"repobilityId": "405db1fc5ba629e1", "scanner": "scanner-primary", "fingerprint": "58d221b86f417a3a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d822c522a807c253", "level": "note", "message": {"text": "Unused endpoint: GET /api/instantly/subsequences"}, "properties": {"repobilityId": "6e8a4d28f21c94fc", "scanner": "scanner-primary", "fingerprint": "d822c522a807c253", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ae6432be6fae4129", "level": "note", "message": {"text": "Unused endpoint: POST /api/instantly/subsequence/add"}, "properties": {"repobilityId": "5348b45e11a1805d", "scanner": "scanner-primary", "fingerprint": "ae6432be6fae4129", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d814d4208ebcda5d", "level": "note", "message": {"text": "Unused endpoint: POST /api/trigger/cleanup"}, "properties": {"repobilityId": "24f63dd8ff9b1fc2", "scanner": "scanner-primary", "fingerprint": "d814d4208ebcda5d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-04bfad63e4b7ad06", "level": "note", "message": {"text": "Unused endpoint: POST /api/trigger/dashboard"}, "properties": {"repobilityId": "dc8ac302f7fc918f", "scanner": "scanner-primary", "fingerprint": "04bfad63e4b7ad06", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-86f66dbbc70ffa7b", "level": "note", "message": {"text": "Unused endpoint: POST /api/trigger/daily-metrics"}, "properties": {"repobilityId": "72117a3b3b4f8b1e", "scanner": "scanner-primary", "fingerprint": "86f66dbbc70ffa7b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-25a9077f1bd17037", "level": "note", "message": {"text": "Unused endpoint: POST /api/trigger/brief"}, "properties": {"repobilityId": "12dbe63637013117", "scanner": "scanner-primary", "fingerprint": "25a9077f1bd17037", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9834803fcb808f6c", "level": "note", "message": {"text": "Unused endpoint: GET /api/trigger/brief/preview"}, "properties": {"repobilityId": "18d46eac405ba422", "scanner": "scanner-primary", "fingerprint": "9834803fcb808f6c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e0431640f07eeb7b", "level": "note", "message": {"text": "Unused endpoint: GET /api/command"}, "properties": {"repobilityId": "c703b1ac95cc7bcb", "scanner": "scanner-primary", "fingerprint": "e0431640f07eeb7b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f4f94400f7c1023c", "level": "note", "message": {"text": "Unused endpoint: POST /api/trigger/insights"}, "properties": {"repobilityId": "4cf8ff8ff574ec91", "scanner": "scanner-primary", "fingerprint": "f4f94400f7c1023c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-4e43ccb397ece9e6", "level": "note", "message": {"text": "Unused endpoint: GET /api/insights"}, "properties": {"repobilityId": "10d4e94b1b033147", "scanner": "scanner-primary", "fingerprint": "4e43ccb397ece9e6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f45a2c9811fa90f9", "level": "note", "message": {"text": "Unused endpoint: GET /api/brains"}, "properties": {"repobilityId": "075d3dfcf023c864", "scanner": "scanner-primary", "fingerprint": "f45a2c9811fa90f9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6a8cf1cbf122a368", "level": "note", "message": {"text": "Unused endpoint: POST /api/trigger/healthcheck"}, "properties": {"repobilityId": "67c99ad312125f7d", "scanner": "scanner-primary", "fingerprint": "6a8cf1cbf122a368", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-78fe24162b5b98a1", "level": "note", "message": {"text": "Unused endpoint: POST /api/trigger/queue-sync"}, "properties": {"repobilityId": "527e1f065729d76d", "scanner": "scanner-primary", "fingerprint": "78fe24162b5b98a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-99ea709a012c3eb6", "level": "note", "message": {"text": "Unused endpoint: POST /api/trigger/reclassify"}, "properties": {"repobilityId": "04ec0935f78a2ddf", "scanner": "scanner-primary", "fingerprint": "99ea709a012c3eb6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cebdc1c9bc69ebd5", "level": "note", "message": {"text": "Unused endpoint: GET /api/dashboard/daily-metrics"}, "properties": {"repobilityId": "da67b77239bb7f48", "scanner": "scanner-primary", "fingerprint": "cebdc1c9bc69ebd5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a87e60b297cd2de", "level": "note", "message": {"text": "Unused endpoint: POST /api/deploy"}, "properties": {"repobilityId": "60e88fd692a028a9", "scanner": "scanner-primary", "fingerprint": "7a87e60b297cd2de", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a009b1a56794f45", "level": "note", "message": {"text": "Unused endpoint: POST /"}, "properties": {"repobilityId": "5791696cb9caae76", "scanner": "scanner-primary", "fingerprint": "7a009b1a56794f45", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "25f455ef8fac38d1", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-359f35937bed4935", "level": "note", "message": {"text": "Unused endpoint: GET /registry"}, "properties": {"repobilityId": "f96ab758d43b5e56", "scanner": "scanner-primary", "fingerprint": "359f35937bed4935", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-8d5b2b188d08ca82", "level": "note", "message": {"text": "Unused endpoint: PUT /:id"}, "properties": {"repobilityId": "37b7552b209e3d78", "scanner": "scanner-primary", "fingerprint": "8d5b2b188d08ca82", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7a61c112b611f4bb", "level": "note", "message": {"text": "Unused endpoint: DELETE /:id"}, "properties": {"repobilityId": "e5e16ef65bf913b8", "scanner": "scanner-primary", "fingerprint": "7a61c112b611f4bb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-53c4efb11ed0ac76", "level": "note", "message": {"text": "Unused endpoint: POST /:id/run"}, "properties": {"repobilityId": "3e3fef567edb65f9", "scanner": "scanner-primary", "fingerprint": "53c4efb11ed0ac76", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a4c3d46b552a5899", "level": "note", "message": {"text": "Unused endpoint: POST /run-type/:type"}, "properties": {"repobilityId": "f9293fe41a4562d6", "scanner": "scanner-primary", "fingerprint": "a4c3d46b552a5899", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-03e921a06be65aa1", "level": "note", "message": {"text": "Unused endpoint: GET /:id/runs"}, "properties": {"repobilityId": "5d520b955bbb8d09", "scanner": "scanner-primary", "fingerprint": "03e921a06be65aa1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2e64a326a4f5aa73", "level": "note", "message": {"text": "Unused endpoint: GET /daily-stats"}, "properties": {"repobilityId": "e6edeafa1263ce3f", "scanner": "scanner-primary", "fingerprint": "2e64a326a4f5aa73", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f267cc6244ff132b", "level": "note", "message": {"text": "Unused endpoint: GET /campaigns"}, "properties": {"repobilityId": "56972a994f4fdba7", "scanner": "scanner-primary", "fingerprint": "f267cc6244ff132b", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}