{"$schema":"https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"AiAuditor","informationUri":"https://github.com/drhus/ai-auditor","version":"v0.1.0","rules":[{"id":"eu-ai-act-2024-08/1d-predictive-policing","name":"eu-ai-act-2024-08/1d-predictive-policing","shortDescription":{"text":"Predictive policing solely from profiling"},"fullDescription":{"text":"EU AI Act, Art 5(1)(d) — Predictive policing solely from profiling"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-5(1)(d)","fairness"],"regulation":"EU AI Act","article":"5(1)(d)","principle":"fairness"}},{"id":"eu-ai-act-2024-08/1e-facial-scraping","name":"eu-ai-act-2024-08/1e-facial-scraping","shortDescription":{"text":"Untargeted facial image scraping for face databases"},"fullDescription":{"text":"EU AI Act, Art 5(1)(e) — Untargeted facial image scraping for face databases"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-5(1)(e)","privacy"],"regulation":"EU AI Act","article":"5(1)(e)","principle":"privacy"}},{"id":"eu-ai-act-2024-08/1f-emotion-workplace-edu","name":"eu-ai-act-2024-08/1f-emotion-workplace-edu","shortDescription":{"text":"Emotion recognition in workplace and education"},"fullDescription":{"text":"EU AI Act, Art 5(1)(f) — Emotion recognition in workplace and education"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-5(1)(f)","privacy"],"regulation":"EU AI Act","article":"5(1)(f)","principle":"privacy"}},{"id":"eu-ai-act-2024-08/risk-management","name":"eu-ai-act-2024-08/risk-management","shortDescription":{"text":"Risk management system established, implemented, documented"},"fullDescription":{"text":"EU AI Act, Art 9 — Risk management system established, implemented, documented"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-9","safety"],"regulation":"EU AI Act","article":"9","principle":"safety"}},{"id":"eu-ai-act-2024-08/data-governance","name":"eu-ai-act-2024-08/data-governance","shortDescription":{"text":"Data and data governance practices documented"},"fullDescription":{"text":"EU AI Act, Art 10 — Data and data governance practices documented"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-10","privacy"],"regulation":"EU AI Act","article":"10","principle":"privacy"}},{"id":"eu-ai-act-2024-08/technical-documentation","name":"eu-ai-act-2024-08/technical-documentation","shortDescription":{"text":"Technical documentation drawn up before placing on market"},"fullDescription":{"text":"EU AI Act, Art 11 — Technical documentation drawn up before placing on market"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-11","auditability"],"regulation":"EU AI Act","article":"11","principle":"auditability"}},{"id":"eu-ai-act-2024-08/p1-automatic-logs","name":"eu-ai-act-2024-08/p1-automatic-logs","shortDescription":{"text":"Automatic recording of events over the lifetime"},"fullDescription":{"text":"EU AI Act, Art 12(1) — Automatic recording of events over the lifetime"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-12(1)","auditability"],"regulation":"EU AI Act","article":"12(1)","principle":"auditability"}},{"id":"eu-ai-act-2024-08/p2-traceability","name":"eu-ai-act-2024-08/p2-traceability","shortDescription":{"text":"Logging ensures traceability appropriate to risk"},"fullDescription":{"text":"EU AI Act, Art 12(2) — Logging ensures traceability appropriate to risk"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-12(2)","auditability"],"regulation":"EU AI Act","article":"12(2)","principle":"auditability"}},{"id":"eu-ai-act-2024-08/deployer-instructions","name":"eu-ai-act-2024-08/deployer-instructions","shortDescription":{"text":"Transparent operation and instructions for use"},"fullDescription":{"text":"EU AI Act, Art 13 — Transparent operation and instructions for use"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-13","transparency"],"regulation":"EU AI Act","article":"13","principle":"transparency"}},{"id":"eu-ai-act-2024-08/p1-oversight-measures","name":"eu-ai-act-2024-08/p1-oversight-measures","shortDescription":{"text":"Effective human oversight designed and built-in"},"fullDescription":{"text":"EU AI Act, Art 14(1) — Effective human oversight designed and built-in"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-14(1)","human-oversight"],"regulation":"EU AI Act","article":"14(1)","principle":"human-oversight"}},{"id":"eu-ai-act-2024-08/p4d-stop-button","name":"eu-ai-act-2024-08/p4d-stop-button","shortDescription":{"text":"Interrupt / stop function reachable by overseer"},"fullDescription":{"text":"EU AI Act, Art 14(4)(d) — Interrupt / stop function reachable by overseer"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-14(4)(d)","human-oversight"],"regulation":"EU AI Act","article":"14(4)(d)","principle":"human-oversight"}},{"id":"eu-ai-act-2024-08/p4e-override","name":"eu-ai-act-2024-08/p4e-override","shortDescription":{"text":"Ability to override / reverse the system's output"},"fullDescription":{"text":"EU AI Act, Art 14(4)(e) — Ability to override / reverse the system's output"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-14(4)(e)","human-oversight"],"regulation":"EU AI Act","article":"14(4)(e)","principle":"human-oversight"}},{"id":"eu-ai-act-2024-08/p4-robustness","name":"eu-ai-act-2024-08/p4-robustness","shortDescription":{"text":"Resilience to errors, faults, inconsistencies"},"fullDescription":{"text":"EU AI Act, Art 15(4) — Resilience to errors, faults, inconsistencies"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-15(4)","safety"],"regulation":"EU AI Act","article":"15(4)","principle":"safety"}},{"id":"eu-ai-act-2024-08/p5-cybersecurity","name":"eu-ai-act-2024-08/p5-cybersecurity","shortDescription":{"text":"Cybersecurity measures appropriate to circumstances"},"fullDescription":{"text":"EU AI Act, Art 15(5) — Cybersecurity measures appropriate to circumstances"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-15(5)","security-governance"],"regulation":"EU AI Act","article":"15(5)","principle":"security-governance"}},{"id":"eu-ai-act-2024-08/p6-keep-logs","name":"eu-ai-act-2024-08/p6-keep-logs","shortDescription":{"text":"Deployer log-retention capability supported"},"fullDescription":{"text":"EU AI Act, Art 26(6) — Deployer log-retention capability supported"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-26(6)","accountability"],"regulation":"EU AI Act","article":"26(6)","principle":"accountability"}},{"id":"eu-ai-act-2024-08/p1-ai-disclosure","name":"eu-ai-act-2024-08/p1-ai-disclosure","shortDescription":{"text":"Users informed they are interacting with an AI"},"fullDescription":{"text":"EU AI Act, Art 50(1) — Users informed they are interacting with an AI"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-50(1)","transparency"],"regulation":"EU AI Act","article":"50(1)","principle":"transparency"}},{"id":"eu-ai-act-2024-08/p2-synthetic-content","name":"eu-ai-act-2024-08/p2-synthetic-content","shortDescription":{"text":"AI-generated content marked as such, machine-readable"},"fullDescription":{"text":"EU AI Act, Art 50(2) — AI-generated content marked as such, machine-readable"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-50(2)","transparency"],"regulation":"EU AI Act","article":"50(2)","principle":"transparency"}},{"id":"eu-ai-act-2024-08/p3-emotion-biometric-disclosure","name":"eu-ai-act-2024-08/p3-emotion-biometric-disclosure","shortDescription":{"text":"Emotion recognition / biometric categorisation disclosure"},"fullDescription":{"text":"EU AI Act, Art 50(3) — Emotion recognition / biometric categorisation disclosure"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-50(3)","transparency"],"regulation":"EU AI Act","article":"50(3)","principle":"transparency"}},{"id":"eu-ai-act-2024-08/p4-deepfake-disclosure","name":"eu-ai-act-2024-08/p4-deepfake-disclosure","shortDescription":{"text":"Deepfake content labelled as artificially generated"},"fullDescription":{"text":"EU AI Act, Art 50(4) — Deepfake content labelled as artificially generated"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-50(4)","transparency"],"regulation":"EU AI Act","article":"50(4)","principle":"transparency"}},{"id":"nist-ai-rmf-1.0/govern-1.4","name":"nist-ai-rmf-1.0/govern-1.4","shortDescription":{"text":"Risk management process documented and accountable"},"fullDescription":{"text":"NIST AI RMF, Art GOVERN 1.4 — Risk management process documented and accountable"},"helpUri":"https://www.nist.gov/itl/ai-risk-management-framework","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","nist-ai-rmf-1.0","article-GOVERN 1.4","accountability"],"regulation":"NIST AI RMF","article":"GOVERN 1.4","principle":"accountability"}},{"id":"nist-ai-rmf-1.0/map-1.1","name":"nist-ai-rmf-1.0/map-1.1","shortDescription":{"text":"Context of use established and understood"},"fullDescription":{"text":"NIST AI RMF, Art MAP 1.1 — Context of use established and understood"},"helpUri":"https://www.nist.gov/itl/ai-risk-management-framework","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","nist-ai-rmf-1.0","article-MAP 1.1","auditability"],"regulation":"NIST AI RMF","article":"MAP 1.1","principle":"auditability"}},{"id":"nist-ai-rmf-1.0/map-3.4","name":"nist-ai-rmf-1.0/map-3.4","shortDescription":{"text":"Risks and benefits to people identified"},"fullDescription":{"text":"NIST AI RMF, Art MAP 3.4 — Risks and benefits to people identified"},"helpUri":"https://www.nist.gov/itl/ai-risk-management-framework","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","nist-ai-rmf-1.0","article-MAP 3.4","safety"],"regulation":"NIST AI RMF","article":"MAP 3.4","principle":"safety"}},{"id":"nist-ai-rmf-1.0/measure-2.7","name":"nist-ai-rmf-1.0/measure-2.7","shortDescription":{"text":"Security and resilience evaluated"},"fullDescription":{"text":"NIST AI RMF, Art MEASURE 2.7 — Security and resilience evaluated"},"helpUri":"https://www.nist.gov/itl/ai-risk-management-framework","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","nist-ai-rmf-1.0","article-MEASURE 2.7","security-governance"],"regulation":"NIST AI RMF","article":"MEASURE 2.7","principle":"security-governance"}},{"id":"nist-ai-rmf-1.0/measure-2.8","name":"nist-ai-rmf-1.0/measure-2.8","shortDescription":{"text":"Privacy risk of the AI system evaluated"},"fullDescription":{"text":"NIST AI RMF, Art MEASURE 2.8 — Privacy risk of the AI system evaluated"},"helpUri":"https://www.nist.gov/itl/ai-risk-management-framework","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","nist-ai-rmf-1.0","article-MEASURE 2.8","privacy"],"regulation":"NIST AI RMF","article":"MEASURE 2.8","principle":"privacy"}},{"id":"nist-ai-rmf-1.0/manage-2.3","name":"nist-ai-rmf-1.0/manage-2.3","shortDescription":{"text":"Mechanisms to supersede or deactivate AI systems"},"fullDescription":{"text":"NIST AI RMF, Art MANAGE 2.3 — Mechanisms to supersede or deactivate AI systems"},"helpUri":"https://www.nist.gov/itl/ai-risk-management-framework","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","nist-ai-rmf-1.0","article-MANAGE 2.3","human-oversight"],"regulation":"NIST AI RMF","article":"MANAGE 2.3","principle":"human-oversight"}},{"id":"nist-ai-rmf-1.0/manage-4.1","name":"nist-ai-rmf-1.0/manage-4.1","shortDescription":{"text":"Post-deployment monitoring, appeal and override, change management"},"fullDescription":{"text":"NIST AI RMF, Art MANAGE 4.1 — Post-deployment monitoring, appeal and override, change management"},"helpUri":"https://www.nist.gov/itl/ai-risk-management-framework","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","nist-ai-rmf-1.0","article-MANAGE 4.1","auditability"],"regulation":"NIST AI RMF","article":"MANAGE 4.1","principle":"auditability"}},{"id":"iso-42001-2023/clause-5.1-leadership","name":"iso-42001-2023/clause-5.1-leadership","shortDescription":{"text":"Leadership and commitment for AI management"},"fullDescription":{"text":"ISO/IEC 42001, Art 5.1 — Leadership and commitment for AI management"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-5.1","accountability"],"regulation":"ISO/IEC 42001","article":"5.1","principle":"accountability"}},{"id":"iso-42001-2023/clause-5.3-roles","name":"iso-42001-2023/clause-5.3-roles","shortDescription":{"text":"Roles, responsibilities and authorities"},"fullDescription":{"text":"ISO/IEC 42001, Art 5.3 — Roles, responsibilities and authorities"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-5.3","accountability"],"regulation":"ISO/IEC 42001","article":"5.3","principle":"accountability"}},{"id":"iso-42001-2023/clause-6.1-risk-assessment","name":"iso-42001-2023/clause-6.1-risk-assessment","shortDescription":{"text":"AI risk assessment process"},"fullDescription":{"text":"ISO/IEC 42001, Art 6.1 — AI risk assessment process"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-6.1","safety"],"regulation":"ISO/IEC 42001","article":"6.1","principle":"safety"}},{"id":"iso-42001-2023/clause-7.5-documented-information","name":"iso-42001-2023/clause-7.5-documented-information","shortDescription":{"text":"Documented information for the AI management system"},"fullDescription":{"text":"ISO/IEC 42001, Art 7.5 — Documented information for the AI management system"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-7.5","auditability"],"regulation":"ISO/IEC 42001","article":"7.5","principle":"auditability"}},{"id":"iso-42001-2023/clause-8.1-operational-planning","name":"iso-42001-2023/clause-8.1-operational-planning","shortDescription":{"text":"Operational planning and control"},"fullDescription":{"text":"ISO/IEC 42001, Art 8.1 — Operational planning and control"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-8.1","safety"],"regulation":"ISO/IEC 42001","article":"8.1","principle":"safety"}},{"id":"iso-42001-2023/clause-9.1-monitoring","name":"iso-42001-2023/clause-9.1-monitoring","shortDescription":{"text":"Monitoring, measurement, analysis and evaluation"},"fullDescription":{"text":"ISO/IEC 42001, Art 9.1 — Monitoring, measurement, analysis and evaluation"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-9.1","auditability"],"regulation":"ISO/IEC 42001","article":"9.1","principle":"auditability"}},{"id":"iso-42001-2023/annex-a5-internal-org","name":"iso-42001-2023/annex-a5-internal-org","shortDescription":{"text":"Internal organization controls"},"fullDescription":{"text":"ISO/IEC 42001, Art A.5 — Internal organization controls"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-A.5","accountability"],"regulation":"ISO/IEC 42001","article":"A.5","principle":"accountability"}},{"id":"iso-42001-2023/annex-a7-resources","name":"iso-42001-2023/annex-a7-resources","shortDescription":{"text":"Resources for AI systems"},"fullDescription":{"text":"ISO/IEC 42001, Art A.7 — Resources for AI systems"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-A.7","security-governance"],"regulation":"ISO/IEC 42001","article":"A.7","principle":"security-governance"}},{"id":"gdpr-2016/art-5-principles","name":"gdpr-2016/art-5-principles","shortDescription":{"text":"Principles relating to processing of personal data"},"fullDescription":{"text":"GDPR, Art 5 — Principles relating to processing of personal data"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","gdpr-2016","article-5","transparency"],"regulation":"GDPR","article":"5","principle":"transparency"}},{"id":"gdpr-2016/art-22-automated-decisions","name":"gdpr-2016/art-22-automated-decisions","shortDescription":{"text":"Automated individual decision-making, including profiling"},"fullDescription":{"text":"GDPR, Art 22 — Automated individual decision-making, including profiling"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","gdpr-2016","article-22","human-oversight"],"regulation":"GDPR","article":"22","principle":"human-oversight"}},{"id":"gdpr-2016/art-25-by-design","name":"gdpr-2016/art-25-by-design","shortDescription":{"text":"Data protection by design and by default"},"fullDescription":{"text":"GDPR, Art 25 — Data protection by design and by default"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","gdpr-2016","article-25","privacy"],"regulation":"GDPR","article":"25","principle":"privacy"}},{"id":"gdpr-2016/art-30-records","name":"gdpr-2016/art-30-records","shortDescription":{"text":"Records of processing activities"},"fullDescription":{"text":"GDPR, Art 30 — Records of processing activities"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","gdpr-2016","article-30","auditability"],"regulation":"GDPR","article":"30","principle":"auditability"}},{"id":"gdpr-2016/art-32-security","name":"gdpr-2016/art-32-security","shortDescription":{"text":"Security of processing"},"fullDescription":{"text":"GDPR, Art 32 — Security of processing"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","gdpr-2016","article-32","security-governance"],"regulation":"GDPR","article":"32","principle":"security-governance"}},{"id":"gdpr-2016/art-35-dpia","name":"gdpr-2016/art-35-dpia","shortDescription":{"text":"Data protection impact assessment (DPIA)"},"fullDescription":{"text":"GDPR, Art 35 — Data protection impact assessment (DPIA)"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","gdpr-2016","article-35","safety"],"regulation":"GDPR","article":"35","principle":"safety"}}]}},"automationDetails":{"id":"aiauditor/aud_01KS3F6HGWVX3WT37PDM3D"},"originalUriBaseIds":{"%SRCROOT%":{"uri":"https://github.com/drhus/ai-auditor/blob/8d681f7e9beebb27811b15ce6282882c2472a2cb/"}},"versionControlProvenance":[{"repositoryUri":"https://github.com/drhus/ai-auditor","revisionId":"8d681f7e9beebb27811b15ce6282882c2472a2cb","branch":"8d681f7e9beebb27811b15ce6282882c2472a2cb"}],"results":[{"ruleId":"eu-ai-act-2024-08/1d-predictive-policing","level":"error","message":{"text":"Predictive policing solely from profiling — verdict: FAIL (79% conf).\n\nComposite raw score 0.76 (1/1 rules matched).\n\nEvidence: crime-likelihood / recidivism / \"risk to commit X\" scores when the input contains only person profile data (no obje"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":199,"endLine":199}}}],"properties":{"verdict":"fail","score":0,"confidence":0.7887640052032225,"rawScore":0.7612359947967775,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1d-predictive-policing"}},{"ruleId":"eu-ai-act-2024-08/1d-predictive-policing","level":"error","message":{"text":"Predictive policing solely from profiling — verdict: FAIL (79% conf).\n\nComposite raw score 0.76 (1/1 rules matched).\n\nEvidence: names like `crime_risk`, `recidivism_score`, `offender_likelihood` combined with profile inputs. score_mapping: { pa"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":202,"endLine":202}}}],"properties":{"verdict":"fail","score":0,"confidence":0.7887640052032225,"rawScore":0.7612359947967775,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1d-predictive-policing"}},{"ruleId":"eu-ai-act-2024-08/1d-predictive-policing","level":"error","message":{"text":"Predictive policing solely from profiling — verdict: FAIL (79% conf).\n\nComposite raw score 0.76 (1/1 rules matched).\n\nEvidence: recidivism_score`, `offender_likelihood` combined with profile inputs. score_mapping: { pass_default: 4, fail_on_match: 0 }"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":202,"endLine":202}}}],"properties":{"verdict":"fail","score":0,"confidence":0.7887640052032225,"rawScore":0.7612359947967775,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1d-predictive-policing"}},{"ruleId":"eu-ai-act-2024-08/1d-predictive-policing","level":"error","message":{"text":"Predictive policing solely from profiling — verdict: FAIL (79% conf).\n\nComposite raw score 0.76 (1/1 rules matched).\n\nEvidence: ms\", pattern: /\\b(?:crime_risk|recidivism|offender_likelihood|police_dispatch|criminal_record|sentencing_recommend)\\b/gi }, // ----- migr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/recon.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":330,"endLine":330}}}],"properties":{"verdict":"fail","score":0,"confidence":0.7887640052032225,"rawScore":0.7612359947967775,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1d-predictive-policing"}},{"ruleId":"eu-ai-act-2024-08/1d-predictive-policing","level":"error","message":{"text":"Predictive policing solely from profiling — verdict: FAIL (79% conf).\n\nComposite raw score 0.76 (1/1 rules matched).\n\nEvidence: n: /\\b(?:crime_risk|recidivism|offender_likelihood|police_dispatch|criminal_record|sentencing_recommend)\\b/gi }, // ----- migration_signa"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/recon.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":330,"endLine":330}}}],"properties":{"verdict":"fail","score":0,"confidence":0.7887640052032225,"rawScore":0.7612359947967775,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1d-predictive-policing"}},{"ruleId":"eu-ai-act-2024-08/1d-predictive-policing","level":"error","message":{"text":"Predictive policing solely from profiling — verdict: FAIL (79% conf).\n\nComposite raw score 0.76 (1/1 rules matched).\n\nEvidence: ime_risk|recidivism|offender_likelihood|police_dispatch|criminal_record|sentencing_recommend)\\b/gi }, // ----- migration_signals -----"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/recon.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":330,"endLine":330}}}],"properties":{"verdict":"fail","score":0,"confidence":0.7887640052032225,"rawScore":0.7612359947967775,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1d-predictive-policing"}},{"ruleId":"eu-ai-act-2024-08/1e-facial-scraping","level":"error","message":{"text":"Untargeted facial image scraping for face databases — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: \" description: \"Biometric ID, categorisation, emotion recognition\" - signal: critical_infra_signals category: \"2\" description:"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":32,"endLine":32}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1e-facial-scraping"}},{"ruleId":"eu-ai-act-2024-08/1e-facial-scraping","level":"error","message":{"text":"Untargeted facial image scraping for face databases — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: otion recognition / biometric categorisation\" - signal: agent_framework # any interactive AI is in scope paragraph: \"50(1)\""},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":62,"endLine":62}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1e-facial-scraping"}},{"ruleId":"eu-ai-act-2024-08/1e-facial-scraping","level":"error","message":{"text":"Untargeted facial image scraping for face databases — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: calls (mediapipe, face_recognition, dlib, opencv haar cascade). score_mapping: { pass_default: 4, fail_on_match: 0 } remediation_h"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":231,"endLine":231}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1e-facial-scraping"}},{"ruleId":"eu-ai-act-2024-08/1e-facial-scraping","level":"error","message":{"text":"Untargeted facial image scraping for face databases — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: \"^1.1.0\", \"@playwright/test\": \"^1.51.1\", \"babel-plugin-react-compiler\": \"*\", \"react\": \"^18.2.0 || 19.0.0-rc-de68d2f4"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"package-lock.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":3913,"endLine":3913}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1e-facial-scraping"}},{"ruleId":"eu-ai-act-2024-08/1e-facial-scraping","level":"error","message":{"text":"Untargeted facial image scraping for face databases — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: }, \"@playwright/test\": { \"optional\": true }, \"babel-plugin-react-compiler\": { \"optional\":"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"package-lock.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":3923,"endLine":3923}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1e-facial-scraping"}},{"ruleId":"eu-ai-act-2024-08/1e-facial-scraping","level":"error","message":{"text":"Untargeted facial image scraping for face databases — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: uests.get / fetch / playwright in iteration) targeting image content combined with face-detection calls (mediapipe,"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":229,"endLine":229}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1e-facial-scraping"}},{"ruleId":"eu-ai-act-2024-08/1f-emotion-workplace-edu","level":"error","message":{"text":"Emotion recognition in workplace and education — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: ms\", pattern: /\\b(?:emotion_detect|emotion_recognition|sentiment_score|affect_recognition|facial_emotion|micro_expression)\\b/gi }, // ---"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/recon.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":348,"endLine":348}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1f-emotion-workplace-edu"}},{"ruleId":"eu-ai-act-2024-08/1f-emotion-workplace-edu","level":"error","message":{"text":"Emotion recognition in workplace and education — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: \\b(?:emotion_detect|emotion_recognition|sentiment_score|affect_recognition|facial_emotion|micro_expression)\\b/gi }, // ----- data_io ----"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/recon.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":348,"endLine":348}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1f-emotion-workplace-edu"}},{"ruleId":"eu-ai-act-2024-08/1f-emotion-workplace-edu","level":"error","message":{"text":"Emotion recognition in workplace and education — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: emotion_recognition|sentiment_score|affect_recognition|facial_emotion|micro_expression)\\b/gi }, // ----- data_io ----- { signal: \"data_"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/recon.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":348,"endLine":348}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1f-emotion-workplace-edu"}},{"ruleId":"eu-ai-act-2024-08/1f-emotion-workplace-edu","level":"error","message":{"text":"Emotion recognition in workplace and education — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: ppet\": \"OMMANDS for candidate in tokens[index + 1:]: if candidate in {\\\"|\\\", \\\";\\\", \\\"&&\\\", \\\"||\\\"}: break f\", \"rule\": \"employme"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":1001,"endLine":1001}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1f-emotion-workplace-edu"}},{"ruleId":"eu-ai-act-2024-08/1f-emotion-workplace-edu","level":"error","message":{"text":"Emotion recognition in workplace and education — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: ens[index + 1:]: if candidate in {\\\"|\\\", \\\";\\\", \\\"&&\\\", \\\"||\\\"}: break f\", \"rule\": \"employment_terms\" }, {"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":1001,"endLine":1001}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1f-emotion-workplace-edu"}},{"ruleId":"eu-ai-act-2024-08/1f-emotion-workplace-edu","level":"error","message":{"text":"Emotion recognition in workplace and education — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: \"snippet\": \"1:]: if candidate in {\\\"|\\\", \\\";\\\", \\\"&&\\\", \\\"||\\\"}: break for path_candidate in candidate_paths(candidate):\", \"rule"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":1010,"endLine":1010}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1f-emotion-workplace-edu"}},{"ruleId":"eu-ai-act-2024-08/risk-management","level":"warning","message":{"text":"Risk management system established, implemented, documented — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.55 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): Risk identification and analysis are evidenced (risk register and threat model), but the absence of documented CI/CD evaluation gates creates ambiguity about whether the 'continuous iterative process' and 'regular systematic review and updating' requirements are satisfied throughout the entire lifecycle. Human judgment needed to assess whether evaluation gates exist outside the repository or if alternative continuous monitoring mechanisms are documented elsewhere."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"RISK_REGISTER.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.55,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-9/risk-management"}},{"ruleId":"eu-ai-act-2024-08/risk-management","level":"warning","message":{"text":"Risk management system established, implemented, documented — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.55 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): Risk identification and analysis are evidenced (risk register and threat model), but the absence of documented CI/CD evaluation gates creates ambiguity about whether the 'continuous iterative process' and 'regular systematic review and updating' requirements are satisfied throughout the entire lifecycle. Human judgment needed to assess whether evaluation gates exist outside the repository or if alternative continuous monitoring mechanisms are documented elsewhere."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"SECURITY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.55,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-9/risk-management"}},{"ruleId":"eu-ai-act-2024-08/data-governance","level":"error","message":{"text":"Data and data governance practices documented — verdict: FAIL (75% conf).\n\nComposite raw score 0.10 (0/3 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: \"^1.1.0\", \"@playwright/test\": \"^1.51.1\", \"babel-plugin-react-compiler\": \"*\", \"react\": \"^18.2.0 || 19.0.0-rc-de68d2f4"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"package-lock.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":3913,"endLine":3913}}}],"properties":{"verdict":"fail","score":0,"confidence":0.75,"rawScore":0.1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-10/data-governance"}},{"ruleId":"eu-ai-act-2024-08/data-governance","level":"error","message":{"text":"Data and data governance practices documented — verdict: FAIL (75% conf).\n\nComposite raw score 0.10 (0/3 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: }, \"@playwright/test\": { \"optional\": true }, \"babel-plugin-react-compiler\": { \"optional\":"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"package-lock.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":3923,"endLine":3923}}}],"properties":{"verdict":"fail","score":0,"confidence":0.75,"rawScore":0.1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-10/data-governance"}},{"ruleId":"eu-ai-act-2024-08/technical-documentation","level":"error","message":{"text":"Technical documentation drawn up before placing on market — verdict: FAIL (80% conf).\n\nComposite raw score 0.15 (1/3 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: 2 required sections present"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"fail","score":1,"confidence":0.8,"rawScore":0.15,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-11/technical-documentation"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): The evidence shows only ad-hoc console.log() statements at tool boundaries, which are runtime output rather than persistent, structured automatic logging. The clause requires technically enabled automatic recording over the system's lifetime, necessitating structured logging import and a persistent sink—neither of which matched the deterministic rules.\n\nEvidence: x.ts\"), content); console.log(` rewrote index.ts (${entries.length} seeds)`); } async function main() { const args = process.argv.slic"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":38,"endLine":38}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): The evidence shows only ad-hoc console.log() statements at tool boundaries, which are runtime output rather than persistent, structured automatic logging. The clause requires technically enabled automatic recording over the system's lifetime, necessitating structured logging import and a persistent sink—neither of which matched the deterministic rules.\n\nEvidence: -1.0\"], }; console.log(`\\n=== ${owner}/${repo} (id=${input.auditId}) ===`); const t0 = Date.now(); try { const report"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":64,"endLine":64}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): The evidence shows only ad-hoc console.log() statements at tool boundaries, which are runtime output rather than persistent, structured automatic logging. The clause requires technically enabled automatic recording over the system's lifetime, necessitating structured logging import and a persistent sink—neither of which matched the deterministic rules.\n\nEvidence: evt.kind === \"log\") console.log(` [${evt.stage}] ${evt.text}`); else if (evt.kind === \"stage\") console.log(` [${evt.stage}] phase="},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":68,"endLine":68}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): The evidence shows only ad-hoc console.log() statements at tool boundaries, which are runtime output rather than persistent, structured automatic logging. The clause requires technically enabled automatic recording over the system's lifetime, necessitating structured logging import and a persistent sink—neither of which matched the deterministic rules.\n\nEvidence: t.kind === \"stage\") console.log(` [${evt.stage}] phase=${evt.phase}${evt.durationMs ? ` (${evt.durationMs}ms)` : \"\"}`); else if (ev"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":69,"endLine":69}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): The evidence shows only ad-hoc console.log() statements at tool boundaries, which are runtime output rather than persistent, structured automatic logging. The clause requires technically enabled automatic recording over the system's lifetime, necessitating structured logging import and a persistent sink—neither of which matched the deterministic rules.\n\nEvidence: = \"classification\") console.log(` ✦ risk=${evt.classification} annex=${evt.annexIii.join(\"/\")} art50=${evt.art50.join(\"/\")}`); else"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":70,"endLine":70}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): The evidence shows only ad-hoc console.log() statements at tool boundaries, which are runtime output rather than persistent, structured automatic logging. The clause requires technically enabled automatic recording over the system's lifetime, necessitating structured logging import and a persistent sink—neither of which matched the deterministic rules.\n\nEvidence: lationPack(id); console.log(`${id}: ${pack.clauses.length} clauses`); for (const c of pack.clauses) { console.log(` ${c.id} →"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/smoke-iso-gdpr.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":6,"endLine":6}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): The evidence shows only ad-hoc console.log() statements at tool boundaries, which are runtime output rather than persistent, structured automatic logging. The clause requires technically enabled automatic recording over the system's lifetime, necessitating structured logging import and a persistent sink—neither of which matched the deterministic rules.\n\nEvidence: x.ts\"), content); console.log(` rewrote index.ts (${entries.length} seeds)`); } async function main() { const args = process.argv.slic"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":38,"endLine":38}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): The evidence shows only ad-hoc console.log() statements at tool boundaries, which are runtime output rather than persistent, structured automatic logging. The clause requires technically enabled automatic recording over the system's lifetime, necessitating structured logging import and a persistent sink—neither of which matched the deterministic rules.\n\nEvidence: -1.0\"], }; console.log(`\\n=== ${owner}/${repo} (id=${input.auditId}) ===`); const t0 = Date.now(); try { const report"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":64,"endLine":64}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates input/output pair logging and model identity tracking (0.75 weighted compliance), but lacks explicit request_id correlation in reviewed logs, preventing full traceability chain. Evidence shows audit-level logging rather than request-level granularity needed for deterministic request tracking.\n\nEvidence: x.ts\"), content); console.log(` rewrote index.ts (${entries.length} seeds)`); } async function main() { const args = process.argv.slic"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":38,"endLine":38}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates input/output pair logging and model identity tracking (0.75 weighted compliance), but lacks explicit request_id correlation in reviewed logs, preventing full traceability chain. Evidence shows audit-level logging rather than request-level granularity needed for deterministic request tracking.\n\nEvidence: -1.0\"], }; console.log(`\\n=== ${owner}/${repo} (id=${input.auditId}) ===`); const t0 = Date.now(); try { const report"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":64,"endLine":64}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates input/output pair logging and model identity tracking (0.75 weighted compliance), but lacks explicit request_id correlation in reviewed logs, preventing full traceability chain. Evidence shows audit-level logging rather than request-level granularity needed for deterministic request tracking.\n\nEvidence: evt.kind === \"log\") console.log(` [${evt.stage}] ${evt.text}`); else if (evt.kind === \"stage\") console.log(` [${evt.stage}] phase="},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":68,"endLine":68}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates input/output pair logging and model identity tracking (0.75 weighted compliance), but lacks explicit request_id correlation in reviewed logs, preventing full traceability chain. Evidence shows audit-level logging rather than request-level granularity needed for deterministic request tracking.\n\nEvidence: t.kind === \"stage\") console.log(` [${evt.stage}] phase=${evt.phase}${evt.durationMs ? ` (${evt.durationMs}ms)` : \"\"}`); else if (ev"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":69,"endLine":69}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates input/output pair logging and model identity tracking (0.75 weighted compliance), but lacks explicit request_id correlation in reviewed logs, preventing full traceability chain. Evidence shows audit-level logging rather than request-level granularity needed for deterministic request tracking.\n\nEvidence: = \"classification\") console.log(` ✦ risk=${evt.classification} annex=${evt.annexIii.join(\"/\")} art50=${evt.art50.join(\"/\")}`); else"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":70,"endLine":70}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates input/output pair logging and model identity tracking (0.75 weighted compliance), but lacks explicit request_id correlation in reviewed logs, preventing full traceability chain. Evidence shows audit-level logging rather than request-level granularity needed for deterministic request tracking.\n\nEvidence: lationPack(id); console.log(`${id}: ${pack.clauses.length} clauses`); for (const c of pack.clauses) { console.log(` ${c.id} →"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/smoke-iso-gdpr.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":6,"endLine":6}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates input/output pair logging and model identity tracking (0.75 weighted compliance), but lacks explicit request_id correlation in reviewed logs, preventing full traceability chain. Evidence shows audit-level logging rather than request-level granularity needed for deterministic request tracking.\n\nEvidence: x.ts\"), content); console.log(` rewrote index.ts (${entries.length} seeds)`); } async function main() { const args = process.argv.slic"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":38,"endLine":38}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates input/output pair logging and model identity tracking (0.75 weighted compliance), but lacks explicit request_id correlation in reviewed logs, preventing full traceability chain. Evidence shows audit-level logging rather than request-level granularity needed for deterministic request tracking.\n\nEvidence: -1.0\"], }; console.log(`\\n=== ${owner}/${repo} (id=${input.auditId}) ===`); const t0 = Date.now(); try { const report"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":64,"endLine":64}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/deployer-instructions","level":"error","message":{"text":"Transparent operation and instructions for use — verdict: FAIL (90% conf).\n\nComposite raw score 0.25 (1/3 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: 2 required sections present"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"fail","score":1,"confidence":0.9,"rawScore":0.25,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-13/deployer-instructions"}},{"ruleId":"eu-ai-act-2024-08/deployer-instructions","level":"error","message":{"text":"Transparent operation and instructions for use — verdict: FAIL (90% conf).\n\nComposite raw score 0.25 (1/3 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"fail","score":1,"confidence":0.9,"rawScore":0.25,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-13/deployer-instructions"}},{"ruleId":"eu-ai-act-2024-08/deployer-instructions","level":"error","message":{"text":"Transparent operation and instructions for use — verdict: FAIL (90% conf).\n\nComposite raw score 0.25 (1/3 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"fail","score":1,"confidence":0.9,"rawScore":0.25,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-13/deployer-instructions"}},{"ruleId":"eu-ai-act-2024-08/p1-oversight-measures","level":"warning","message":{"text":"Effective human oversight designed and built-in — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.50 (1/3 rules matched).\n\nLLM judge (confidence 0.62): Human-in-loop hooks are demonstrably present (LangGraph interrupt nodes, approval-gate functions, manual-review flags), satisfying the core intervention mechanism. However, the absence of a dedicated oversight UI and lack of dry-run/simulation capabilities for tool calls leaves the 'effectively overseen' requirement incomplete—operators cannot safely preview or test system actions before execution, limiting practical oversight capability.\n\nEvidence: in-the-loop hooks: `human_input()`, interrupt nodes in LangGraph, approval-gate functions, manual- review flags, con"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":817,"endLine":817}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p1-oversight-measures"}},{"ruleId":"eu-ai-act-2024-08/p1-oversight-measures","level":"warning","message":{"text":"Effective human oversight designed and built-in — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.50 (1/3 rules matched).\n\nLLM judge (confidence 0.62): Human-in-loop hooks are demonstrably present (LangGraph interrupt nodes, approval-gate functions, manual-review flags), satisfying the core intervention mechanism. However, the absence of a dedicated oversight UI and lack of dry-run/simulation capabilities for tool calls leaves the 'effectively overseen' requirement incomplete—operators cannot safely preview or test system actions before execution, limiting practical oversight capability.\n\nEvidence: For LangGraph: use `interrupt()` nodes. For custom flows: build an approval-queue pattern. Document where humans can intervene i"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":838,"endLine":838}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p1-oversight-measures"}},{"ruleId":"eu-ai-act-2024-08/p1-oversight-measures","level":"warning","message":{"text":"Effective human oversight designed and built-in — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.50 (1/3 rules matched).\n\nLLM judge (confidence 0.62): Human-in-loop hooks are demonstrably present (LangGraph interrupt nodes, approval-gate functions, manual-review flags), satisfying the core intervention mechanism. However, the absence of a dedicated oversight UI and lack of dry-run/simulation capabilities for tool calls leaves the 'effectively overseen' requirement incomplete—operators cannot safely preview or test system actions before execution, limiting practical oversight capability.\n\nEvidence: import ( AIMessage, HumanMessage,\", \"rule\": \"langchain_import\" }, { \"file\": \"gpt_engineer/core/a"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":162,"endLine":162}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p1-oversight-measures"}},{"ruleId":"eu-ai-act-2024-08/p1-oversight-measures","level":"warning","message":{"text":"Effective human oversight designed and built-in — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.50 (1/3 rules matched).\n\nLLM judge (confidence 0.62): Human-in-loop hooks are demonstrably present (LangGraph interrupt nodes, approval-gate functions, manual-review flags), satisfying the core intervention mechanism. However, the absence of a dedicated oversight UI and lack of dry-run/simulation capabilities for tool calls leaves the 'effectively overseen' requirement incomplete—operators cannot safely preview or test system actions before execution, limiting practical oversight capability.\n\nEvidence: import ( AIMessage, HumanMessage, SystemMessage, messages_from_dict, messages_\", \"rule\": \"langchain_import\" },"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":171,"endLine":171}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p1-oversight-measures"}},{"ruleId":"eu-ai-act-2024-08/p1-oversight-measures","level":"warning","message":{"text":"Effective human oversight designed and built-in — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.50 (1/3 rules matched).\n\nLLM judge (confidence 0.62): Human-in-loop hooks are demonstrably present (LangGraph interrupt nodes, approval-gate functions, manual-review flags), satisfying the core intervention mechanism. However, the absence of a dedicated oversight UI and lack of dry-run/simulation capabilities for tool calls leaves the 'effectively overseen' requirement incomplete—operators cannot safely preview or test system actions before execution, limiting practical oversight capability.\n\nEvidence: chain.schema import HumanMessage, SystemMessage from termcolor import colored from gpt_engineer.core.ai import\", \"rule\": \"langch"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":198,"endLine":198}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p1-oversight-measures"}},{"ruleId":"eu-ai-act-2024-08/p1-oversight-measures","level":"warning","message":{"text":"Effective human oversight designed and built-in — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.50 (1/3 rules matched).\n\nLLM judge (confidence 0.62): Human-in-loop hooks are demonstrably present (LangGraph interrupt nodes, approval-gate functions, manual-review flags), satisfying the core intervention mechanism. However, the absence of a dedicated oversight UI and lack of dry-run/simulation capabilities for tool calls leaves the 'effectively overseen' requirement incomplete—operators cannot safely preview or test system actions before execution, limiting practical oversight capability.\n\nEvidence: a import AIMessage, HumanMessage, SystemMessage from PIL import Image # workaround for function mov\", \"rule\": \"langchain_import\""},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":207,"endLine":207}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p1-oversight-measures"}},{"ruleId":"eu-ai-act-2024-08/p4d-stop-button","level":"warning","message":{"text":"Interrupt / stop function reachable by overseer — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.70 (1/2 rules matched).\n\nLLM judge (confidence 0.72): A kill-switch mechanism is present and documented (rule matched at 0.7 weight), satisfying the core requirement for intervention capability. However, the absence of evidence for graceful_shutdown_handler (0.3 weight) creates ambiguity about whether the system reliably achieves a 'safe state' as required by the clause—implementation details on safe shutdown semantics must be verified.\n\nEvidence: ic: - rule: kill_switch_present weight: 0.7 description: | Code contains a documented kill-switch /"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":902,"endLine":902}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.7,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4d-stop-button"}},{"ruleId":"eu-ai-act-2024-08/p4d-stop-button","level":"warning","message":{"text":"Interrupt / stop function reachable by overseer — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.70 (1/2 rules matched).\n\nLLM judge (confidence 0.72): A kill-switch mechanism is present and documented (rule matched at 0.7 weight), satisfying the core requirement for intervention capability. However, the absence of evidence for graceful_shutdown_handler (0.3 weight) creates ambiguity about whether the system reliably achieves a 'safe state' as required by the clause—implementation details on safe shutdown semantics must be verified.\n\nEvidence: sm (function named `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.7,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4d-stop-button"}},{"ruleId":"eu-ai-act-2024-08/p4d-stop-button","level":"warning","message":{"text":"Interrupt / stop function reachable by overseer — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.70 (1/2 rules matched).\n\nLLM judge (confidence 0.72): A kill-switch mechanism is present and documented (rule matched at 0.7 weight), satisfying the core requirement for intervention capability. However, the absence of evidence for graceful_shutdown_handler (0.3 weight) creates ambiguity about whether the system reliably achieves a 'safe state' as required by the clause—implementation details on safe shutdown semantics must be verified.\n\nEvidence: med `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that h"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.7,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4d-stop-button"}},{"ruleId":"eu-ai-act-2024-08/p4d-stop-button","level":"warning","message":{"text":"Interrupt / stop function reachable by overseer — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.70 (1/2 rules matched).\n\nLLM judge (confidence 0.72): A kill-switch mechanism is present and documented (rule matched at 0.7 weight), satisfying the core requirement for intervention capability. However, the absence of evidence for graceful_shutdown_handler (0.3 weight) creates ambiguity about whether the system reliably achieves a 'safe state' as required by the clause—implementation details on safe shutdown semantics must be verified.\n\nEvidence: stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that halts processing). - ru"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":907,"endLine":907}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.7,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4d-stop-button"}},{"ruleId":"eu-ai-act-2024-08/p4d-stop-button","level":"warning","message":{"text":"Interrupt / stop function reachable by overseer — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.70 (1/2 rules matched).\n\nLLM judge (confidence 0.72): A kill-switch mechanism is present and documented (rule matched at 0.7 weight), satisfying the core requirement for intervention capability. However, the absence of evidence for graceful_shutdown_handler (0.3 weight) creates ambiguity about whether the system reliably achieves a 'safe state' as required by the clause—implementation details on safe shutdown semantics must be verified.\n\nEvidence: ic: - rule: kill_switch_present weight: 0.6 - rule: feature_flag_for_disable weight: 0.4 descr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/nist-ai-rmf-1.0.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":342,"endLine":342}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.7,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4d-stop-button"}},{"ruleId":"eu-ai-act-2024-08/p4d-stop-button","level":"warning","message":{"text":"Interrupt / stop function reachable by overseer — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.70 (1/2 rules matched).\n\nLLM judge (confidence 0.72): A kill-switch mechanism is present and documented (rule matched at 0.7 weight), satisfying the core requirement for intervention capability. However, the absence of evidence for graceful_shutdown_handler (0.3 weight) creates ambiguity about whether the system reliably achieves a 'safe state' as required by the clause—implementation details on safe shutdown semantics must be verified.\n\nEvidence: , hits: 4, detail: \"kill_switch_active=True\" }, { name: \"Eval artefacts\", strength: 0.85, hits: 9, detail: \"evals/regression.py + CI\" },"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/design-exploration/_data.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":26,"endLine":26}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.7,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4d-stop-button"}},{"ruleId":"eu-ai-act-2024-08/p4e-override","level":"warning","message":{"text":"Ability to override / reverse the system's output — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates override capability through documented human-in-loop mechanisms (interrupt nodes, approval gates, kill-switch functions), satisfying the override path requirement. However, evidence does not clearly establish that all AI decisions are addressable or reversible by humans, leaving the proportionality and completeness of override scope ambiguous.\n\nEvidence: in-the-loop hooks: `human_input()`, interrupt nodes in LangGraph, approval-gate functions, manual- review flags, con"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":817,"endLine":817}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4e-override"}},{"ruleId":"eu-ai-act-2024-08/p4e-override","level":"warning","message":{"text":"Ability to override / reverse the system's output — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates override capability through documented human-in-loop mechanisms (interrupt nodes, approval gates, kill-switch functions), satisfying the override path requirement. However, evidence does not clearly establish that all AI decisions are addressable or reversible by humans, leaving the proportionality and completeness of override scope ambiguous.\n\nEvidence: For LangGraph: use `interrupt()` nodes. For custom flows: build an approval-queue pattern. Document where humans can intervene i"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":838,"endLine":838}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4e-override"}},{"ruleId":"eu-ai-act-2024-08/p4e-override","level":"warning","message":{"text":"Ability to override / reverse the system's output — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates override capability through documented human-in-loop mechanisms (interrupt nodes, approval gates, kill-switch functions), satisfying the override path requirement. However, evidence does not clearly establish that all AI decisions are addressable or reversible by humans, leaving the proportionality and completeness of override scope ambiguous.\n\nEvidence: ic: - rule: kill_switch_present weight: 0.7 description: | Code contains a documented kill-switch /"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":902,"endLine":902}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4e-override"}},{"ruleId":"eu-ai-act-2024-08/p4e-override","level":"warning","message":{"text":"Ability to override / reverse the system's output — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates override capability through documented human-in-loop mechanisms (interrupt nodes, approval gates, kill-switch functions), satisfying the override path requirement. However, evidence does not clearly establish that all AI decisions are addressable or reversible by humans, leaving the proportionality and completeness of override scope ambiguous.\n\nEvidence: sm (function named `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4e-override"}},{"ruleId":"eu-ai-act-2024-08/p4e-override","level":"warning","message":{"text":"Ability to override / reverse the system's output — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates override capability through documented human-in-loop mechanisms (interrupt nodes, approval gates, kill-switch functions), satisfying the override path requirement. However, evidence does not clearly establish that all AI decisions are addressable or reversible by humans, leaving the proportionality and completeness of override scope ambiguous.\n\nEvidence: med `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that h"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4e-override"}},{"ruleId":"eu-ai-act-2024-08/p4e-override","level":"warning","message":{"text":"Ability to override / reverse the system's output — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates override capability through documented human-in-loop mechanisms (interrupt nodes, approval gates, kill-switch functions), satisfying the override path requirement. However, evidence does not clearly establish that all AI decisions are addressable or reversible by humans, leaving the proportionality and completeness of override scope ambiguous.\n\nEvidence: stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that halts processing). - ru"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":907,"endLine":907}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4e-override"}},{"ruleId":"eu-ai-act-2024-08/p4-robustness","level":"error","message":{"text":"Resilience to errors, faults, inconsistencies — verdict: FAIL (81% conf).\n\nComposite raw score 0.16 (0/3 rules matched).\n\nEvidence: nippet\": \"import os from langchain.callbacks.streaming_stdout import StreamingStdOutCallbackHandler from langchain_openai import ChatOpenAI\""},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":90,"endLine":90}}}],"properties":{"verdict":"fail","score":1,"confidence":0.81,"rawScore":0.16000000000000003,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p4-robustness"}},{"ruleId":"eu-ai-act-2024-08/p4-robustness","level":"error","message":{"text":"Resilience to errors, faults, inconsistencies — verdict: FAIL (81% conf).\n\nComposite raw score 0.16 (0/3 rules matched).\n\nEvidence: dOutCallbackHandler from langchain_openai import ChatOpenAI\", \"rule\": \"langchain_import\" }, { \"f"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":90,"endLine":90}}}],"properties":{"verdict":"fail","score":1,"confidence":0.81,"rawScore":0.16000000000000003,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p4-robustness"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: (hallucination, prompt injection, output bias, leakage, capability escalation), mitigation owner, status. Wire eval suite into CI"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":344,"endLine":344}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: ic: - rule: prompt_injection_defences weight: 0.4 description: | Code includes prompt-injection miti"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1121,"endLine":1121}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: Code includes prompt-injection mitigations: output filters, input sanitisation, instruction-data segregation, system-promp"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1124,"endLine":1124}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: Eval suite includes prompt-injection / adversarial cases\" score_mapping: \">=0.85\": 4 \">=0.65\": 3 \">=0.40\": 2 \">="},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1135,"endLine":1135}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: hint: | Add a prompt-injection eval set (e.g. from `promptbench`, `garak`, or your own canonical injection prompts). Sanitise to"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1143,"endLine":1143}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: ic: - rule: prompt_injection_defences weight: 0.4 - rule: adversarial_eval_present weight: 0.4 -"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/nist-ai-rmf-1.0.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":260,"endLine":260}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: ks. - rule: rate_limiting weight: 0.2 description: \"Rate limiting on user-facing endpoints\" - rule: secr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1127,"endLine":1127}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: 0.4 - rule: rate_limiting weight: 0.2 score_mapping: \">=0.85\": 4 \">=0.65\": 3 \">=0.40\": 2 \">=0."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/nist-ai-rmf-1.0.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":264,"endLine":264}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: entials check — no `express-rate-limit`, no `next-rate-limit`, no upstream WAF rule referenced. A brute-force attacker has no cost.\","},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/preview/_report-mock.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":341,"endLine":341}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: , reasoning: \"express-rate-limit v7 is installed (package.json). The factory is imported in src/middleware/rate-limit.ts. We searched"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/preview/_report-mock.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":483,"endLine":483}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: id: \"pkg\", label: \"express-rate-limit v7\", kind: \"import\", file: \"package.json\", lines: [17, 17] }, { id: \"mw\", label: \"rateLimit()\", k"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/preview/_report-mock.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":485,"endLine":485}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: const fiveHr = data.rate_limits?.five_hour?.used_percentage; const sevenDay = data.rate_limits?.seven_day?.used_percentage; const wo\","},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":491,"endLine":491}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p6-keep-logs","level":"error","message":{"text":"Deployer log-retention capability supported — verdict: FAIL (85% conf).\n\nComposite raw score 0.50 (1/1 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.85): Evidence shows only console.log statements at tool boundaries, which are runtime debugging outputs, not persistent audit logs meeting the 6-month retention requirement. No evidence of automatic log generation, storage mechanism, or retention policy controls required by Art. 26(6).\n\nEvidence: x.ts\"), content); console.log(` rewrote index.ts (${entries.length} seeds)`); } async function main() { const args = process.argv.slic"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":38,"endLine":38}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-26/p6-keep-logs"}},{"ruleId":"eu-ai-act-2024-08/p6-keep-logs","level":"error","message":{"text":"Deployer log-retention capability supported — verdict: FAIL (85% conf).\n\nComposite raw score 0.50 (1/1 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.85): Evidence shows only console.log statements at tool boundaries, which are runtime debugging outputs, not persistent audit logs meeting the 6-month retention requirement. No evidence of automatic log generation, storage mechanism, or retention policy controls required by Art. 26(6).\n\nEvidence: -1.0\"], }; console.log(`\\n=== ${owner}/${repo} (id=${input.auditId}) ===`); const t0 = Date.now(); try { const report"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":64,"endLine":64}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-26/p6-keep-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-ai-disclosure","level":"error","message":{"text":"Users informed they are interacting with an AI — verdict: FAIL (80% conf).\n\nComposite raw score 0.20 (1/2 rules matched)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"fail","score":1,"confidence":0.7999999999999999,"rawScore":0.2,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p1-ai-disclosure"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: ent provenance | no c2pa imports → ABSENT | \"API response contains `aiGenerated:true` / C2PA header\" | | GDPR Art 5(1)(c) — PII in logs | gr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/analysis-tiers.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":102,"endLine":102}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: aiGenerated:true` / C2PA header\" | | GDPR Art 5(1)(c) — PII in logs | grep `user.email` near `logger.info` | \"fake PII sent → grep all captu"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/analysis-tiers.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":102,"endLine":102}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: ` | 50(2) | **1** | C2PA / watermark library imports | | `art-50/p3-emotion-biometric-disclosure` | 50(3) | **1** | Deterministic disclosure"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/llm-judge-policy.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":78,"endLine":78}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: ovenance_hooks` | C2PA, watermarking, content labelling | Article 50(2) synthetic content disclosure"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/pipeline-design.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":75,"endLine":75}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: o/text) | C | C2PA / watermarking libraries; metadata writers; output post-processing. | | 50(3) | Emotion-recognition / biometri"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/regulations-matrix.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":63,"endLine":63}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: ntent> | Drives the C2PA / watermarking signal expectations for clause 50(2). | 2026-05-17 | | 10 | *AI Act Service Desk* + FAQs — <https://"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/regulations-matrix.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":175,"endLine":175}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: ent provenance | no c2pa imports → ABSENT | \"API response contains `aiGenerated:true` / C2PA header\" | | GDPR Art 5(1)(c) — PII in logs | gr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/analysis-tiers.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":102,"endLine":102}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: aiGenerated:true` / C2PA header\" | | GDPR Art 5(1)(c) — PII in logs | grep `user.email` near `logger.info` | \"fake PII sent → grep all captu"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/analysis-tiers.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":102,"endLine":102}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p3-emotion-biometric-disclosure","level":"error","message":{"text":"Emotion recognition / biometric categorisation disclosure — verdict: FAIL (55% conf).\n\nComposite raw score 0.00 (0/1 rules matched)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":0,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p3-emotion-biometric-disclosure"}},{"ruleId":"eu-ai-act-2024-08/p4-deepfake-disclosure","level":"note","message":{"text":"Deepfake content labelled as artificially generated — verdict: PASS (85% conf).\n\nComposite raw score 0.70 (1/1 rules matched).\n\nEvidence: ent provenance | no c2pa imports → ABSENT | \"API response contains `aiGenerated:true` / C2PA header\" | | GDPR Art 5(1)(c) — PII in logs | gr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/analysis-tiers.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":102,"endLine":102}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8500000000000001,"rawScore":0.7,"verifyMethod":"skipped","clauseId":"eu-ai-act/art-50/p4-deepfake-disclosure"}},{"ruleId":"eu-ai-act-2024-08/p4-deepfake-disclosure","level":"note","message":{"text":"Deepfake content labelled as artificially generated — verdict: PASS (85% conf).\n\nComposite raw score 0.70 (1/1 rules matched).\n\nEvidence: aiGenerated:true` / C2PA header\" | | GDPR Art 5(1)(c) — PII in logs | grep `user.email` near `logger.info` | \"fake PII sent → grep all captu"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/analysis-tiers.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":102,"endLine":102}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8500000000000001,"rawScore":0.7,"verifyMethod":"skipped","clauseId":"eu-ai-act/art-50/p4-deepfake-disclosure"}},{"ruleId":"nist-ai-rmf-1.0/govern-1.4","level":"note","message":{"text":"Risk management process documented and accountable — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"RISK_REGISTER.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/govern-1.4"}},{"ruleId":"nist-ai-rmf-1.0/govern-1.4","level":"note","message":{"text":"Risk management process documented and accountable — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"RISK_REGISTER.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/govern-1.4"}},{"ruleId":"nist-ai-rmf-1.0/map-1.1","level":"warning","message":{"text":"Context of use established and understood — verdict: PARTIAL (65% conf).\n\nComposite raw score 0.30 (1/2 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.65): Intended purposes are documented (README.md evidence), satisfying 60% of weighted requirements, but deployment context documentation is not confirmed in the repository scan. The clause requires both understanding of purposes AND prospective deployment settings; partial fulfillment warrants 'partial' pending external documentation review.\n\nEvidence: 2 required sections present"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"partial","score":2,"confidence":0.65,"rawScore":0.3,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/map-1.1"}},{"ruleId":"nist-ai-rmf-1.0/map-1.1","level":"warning","message":{"text":"Context of use established and understood — verdict: PARTIAL (65% conf).\n\nComposite raw score 0.30 (1/2 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.65): Intended purposes are documented (README.md evidence), satisfying 60% of weighted requirements, but deployment context documentation is not confirmed in the repository scan. The clause requires both understanding of purposes AND prospective deployment settings; partial fulfillment warrants 'partial' pending external documentation review."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"partial","score":2,"confidence":0.65,"rawScore":0.3,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/map-1.1"}},{"ruleId":"nist-ai-rmf-1.0/map-3.4","level":"note","message":{"text":"Risks and benefits to people identified — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"RISK_REGISTER.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/map-3.4"}},{"ruleId":"nist-ai-rmf-1.0/map-3.4","level":"note","message":{"text":"Risks and benefits to people identified — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"SECURITY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/map-3.4"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are documented and implemented (2 of 3 rules matched, 60% composite score), but adversarial evaluation is absent—a critical gap for demonstrating comprehensive security and resilience evaluation as required by MEASURE 2.7. The system has defensive controls but lacks the evaluation rigor needed for full compliance.\n\nEvidence: (hallucination, prompt injection, output bias, leakage, capability escalation), mitigation owner, status. Wire eval suite into CI"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":344,"endLine":344}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are documented and implemented (2 of 3 rules matched, 60% composite score), but adversarial evaluation is absent—a critical gap for demonstrating comprehensive security and resilience evaluation as required by MEASURE 2.7. The system has defensive controls but lacks the evaluation rigor needed for full compliance.\n\nEvidence: ic: - rule: prompt_injection_defences weight: 0.4 description: | Code includes prompt-injection miti"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1121,"endLine":1121}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are documented and implemented (2 of 3 rules matched, 60% composite score), but adversarial evaluation is absent—a critical gap for demonstrating comprehensive security and resilience evaluation as required by MEASURE 2.7. The system has defensive controls but lacks the evaluation rigor needed for full compliance.\n\nEvidence: Code includes prompt-injection mitigations: output filters, input sanitisation, instruction-data segregation, system-promp"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1124,"endLine":1124}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are documented and implemented (2 of 3 rules matched, 60% composite score), but adversarial evaluation is absent—a critical gap for demonstrating comprehensive security and resilience evaluation as required by MEASURE 2.7. The system has defensive controls but lacks the evaluation rigor needed for full compliance.\n\nEvidence: Eval suite includes prompt-injection / adversarial cases\" score_mapping: \">=0.85\": 4 \">=0.65\": 3 \">=0.40\": 2 \">="},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1135,"endLine":1135}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are documented and implemented (2 of 3 rules matched, 60% composite score), but adversarial evaluation is absent—a critical gap for demonstrating comprehensive security and resilience evaluation as required by MEASURE 2.7. The system has defensive controls but lacks the evaluation rigor needed for full compliance.\n\nEvidence: hint: | Add a prompt-injection eval set (e.g. from `promptbench`, `garak`, or your own canonical injection prompts). Sanitise to"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1143,"endLine":1143}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are documented and implemented (2 of 3 rules matched, 60% composite score), but adversarial evaluation is absent—a critical gap for demonstrating comprehensive security and resilience evaluation as required by MEASURE 2.7. The system has defensive controls but lacks the evaluation rigor needed for full compliance.\n\nEvidence: ic: - rule: prompt_injection_defences weight: 0.4 - rule: adversarial_eval_present weight: 0.4 -"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/nist-ai-rmf-1.0.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":260,"endLine":260}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are documented and implemented (2 of 3 rules matched, 60% composite score), but adversarial evaluation is absent—a critical gap for demonstrating comprehensive security and resilience evaluation as required by MEASURE 2.7. The system has defensive controls but lacks the evaluation rigor needed for full compliance.\n\nEvidence: ks. - rule: rate_limiting weight: 0.2 description: \"Rate limiting on user-facing endpoints\" - rule: secr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1127,"endLine":1127}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are documented and implemented (2 of 3 rules matched, 60% composite score), but adversarial evaluation is absent—a critical gap for demonstrating comprehensive security and resilience evaluation as required by MEASURE 2.7. The system has defensive controls but lacks the evaluation rigor needed for full compliance.\n\nEvidence: 0.4 - rule: rate_limiting weight: 0.2 score_mapping: \">=0.85\": 4 \">=0.65\": 3 \">=0.40\": 2 \">=0."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/nist-ai-rmf-1.0.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":264,"endLine":264}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are documented and implemented (2 of 3 rules matched, 60% composite score), but adversarial evaluation is absent—a critical gap for demonstrating comprehensive security and resilience evaluation as required by MEASURE 2.7. The system has defensive controls but lacks the evaluation rigor needed for full compliance.\n\nEvidence: entials check — no `express-rate-limit`, no `next-rate-limit`, no upstream WAF rule referenced. A brute-force attacker has no cost.\","},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/preview/_report-mock.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":341,"endLine":341}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are documented and implemented (2 of 3 rules matched, 60% composite score), but adversarial evaluation is absent—a critical gap for demonstrating comprehensive security and resilience evaluation as required by MEASURE 2.7. The system has defensive controls but lacks the evaluation rigor needed for full compliance.\n\nEvidence: , reasoning: \"express-rate-limit v7 is installed (package.json). The factory is imported in src/middleware/rate-limit.ts. We searched"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/preview/_report-mock.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":483,"endLine":483}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are documented and implemented (2 of 3 rules matched, 60% composite score), but adversarial evaluation is absent—a critical gap for demonstrating comprehensive security and resilience evaluation as required by MEASURE 2.7. The system has defensive controls but lacks the evaluation rigor needed for full compliance.\n\nEvidence: id: \"pkg\", label: \"express-rate-limit v7\", kind: \"import\", file: \"package.json\", lines: [17, 17] }, { id: \"mw\", label: \"rateLimit()\", k"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/preview/_report-mock.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":485,"endLine":485}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are documented and implemented (2 of 3 rules matched, 60% composite score), but adversarial evaluation is absent—a critical gap for demonstrating comprehensive security and resilience evaluation as required by MEASURE 2.7. The system has defensive controls but lacks the evaluation rigor needed for full compliance.\n\nEvidence: const fiveHr = data.rate_limits?.five_hour?.used_percentage; const sevenDay = data.rate_limits?.seven_day?.used_percentage; const wo\","},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":491,"endLine":491}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.8","level":"note","message":{"text":"Privacy risk of the AI system evaluated — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched).\n\nEvidence: description: \"Code redacts or hashes PII before logging or sending to external models\" - rule: privacy_documentation weig"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/nist-ai-rmf-1.0.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":290,"endLine":290}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/measure-2.8"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.8","level":"note","message":{"text":"Privacy risk of the AI system evaluated — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched).\n\nEvidence: p \\\"$SCRIPT_DIR/mcp/redaction.js\\\" \\\"$TARGET_ABS/mcp/\\\" cp \\\"$SCRIPT_DIR/mcp/lib/\\\"*.js \\\"$TARGET_ABS/mcp/lib/\\\" rm -rf \\\"$TARGET_ABS/mcp/li"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":817,"endLine":817}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/measure-2.8"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.8","level":"note","message":{"text":"Privacy risk of the AI system evaluated — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched).\n\nEvidence: t the proof needed, redact sensitive data, and report responsibly.</p></div> </div> </div> <div class=\\\"foot\\\"><span\", \"rule\": \""},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":826,"endLine":826}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/measure-2.8"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.8","level":"note","message":{"text":"Privacy risk of the AI system evaluated — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched).\n\nEvidence: h MCP, which writes redacted audit metadata and egress information.</p> </div> <div class=\\\"code-card\\\"> <div\", \"rule\": \"pii_red"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":835,"endLine":835}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/measure-2.8"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.8","level":"note","message":{"text":"Privacy risk of the AI system evaluated — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched).\n\nEvidence: n>Audited requests, redacted URLs, visible egress</span></div> </section> <section class=\\\"slide\\\" data-title=\\\"Egress\\\"> <\", \"r"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":844,"endLine":844}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/measure-2.8"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.8","level":"note","message":{"text":"Privacy risk of the AI system evaluated — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched).\n\nEvidence: b collects bounded, redacted evidence packs for final reportable findings.</p> <div class=\\\"pill-row\\\"> <span class=\\\"pil\", \"rul"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":853,"endLine":853}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/measure-2.8"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.8","level":"note","message":{"text":"Privacy risk of the AI system evaluated — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"PRIVACY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/measure-2.8"}},{"ruleId":"nist-ai-rmf-1.0/manage-2.3","level":"warning","message":{"text":"Mechanisms to supersede or deactivate AI systems — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nEvidence: ic: - rule: kill_switch_present weight: 0.7 description: | Code contains a documented kill-switch /"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":902,"endLine":902}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.6,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-2.3"}},{"ruleId":"nist-ai-rmf-1.0/manage-2.3","level":"warning","message":{"text":"Mechanisms to supersede or deactivate AI systems — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nEvidence: sm (function named `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.6,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-2.3"}},{"ruleId":"nist-ai-rmf-1.0/manage-2.3","level":"warning","message":{"text":"Mechanisms to supersede or deactivate AI systems — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nEvidence: med `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that h"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.6,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-2.3"}},{"ruleId":"nist-ai-rmf-1.0/manage-2.3","level":"warning","message":{"text":"Mechanisms to supersede or deactivate AI systems — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nEvidence: stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that halts processing). - ru"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":907,"endLine":907}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.6,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-2.3"}},{"ruleId":"nist-ai-rmf-1.0/manage-2.3","level":"warning","message":{"text":"Mechanisms to supersede or deactivate AI systems — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nEvidence: ic: - rule: kill_switch_present weight: 0.6 - rule: feature_flag_for_disable weight: 0.4 descr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/nist-ai-rmf-1.0.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":342,"endLine":342}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.6,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-2.3"}},{"ruleId":"nist-ai-rmf-1.0/manage-2.3","level":"warning","message":{"text":"Mechanisms to supersede or deactivate AI systems — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nEvidence: , hits: 4, detail: \"kill_switch_active=True\" }, { name: \"Eval artefacts\", strength: 0.85, hits: 9, detail: \"evals/regression.py + CI\" },"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/design-exploration/_data.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":26,"endLine":26}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.6,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-2.3"}},{"ruleId":"nist-ai-rmf-1.0/manage-4.1","level":"warning","message":{"text":"Post-deployment monitoring, appeal and override, change management — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (2/4 rules matched).\n\nEvidence: in-the-loop hooks: `human_input()`, interrupt nodes in LangGraph, approval-gate functions, manual- review flags, con"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":817,"endLine":817}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-4.1"}},{"ruleId":"nist-ai-rmf-1.0/manage-4.1","level":"warning","message":{"text":"Post-deployment monitoring, appeal and override, change management — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (2/4 rules matched).\n\nEvidence: For LangGraph: use `interrupt()` nodes. For custom flows: build an approval-queue pattern. Document where humans can intervene i"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":838,"endLine":838}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-4.1"}},{"ruleId":"nist-ai-rmf-1.0/manage-4.1","level":"warning","message":{"text":"Post-deployment monitoring, appeal and override, change management — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (2/4 rules matched).\n\nEvidence: ic: - rule: kill_switch_present weight: 0.7 description: | Code contains a documented kill-switch /"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":902,"endLine":902}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-4.1"}},{"ruleId":"nist-ai-rmf-1.0/manage-4.1","level":"warning","message":{"text":"Post-deployment monitoring, appeal and override, change management — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (2/4 rules matched).\n\nEvidence: sm (function named `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-4.1"}},{"ruleId":"nist-ai-rmf-1.0/manage-4.1","level":"warning","message":{"text":"Post-deployment monitoring, appeal and override, change management — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (2/4 rules matched).\n\nEvidence: med `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that h"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-4.1"}},{"ruleId":"nist-ai-rmf-1.0/manage-4.1","level":"warning","message":{"text":"Post-deployment monitoring, appeal and override, change management — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (2/4 rules matched).\n\nEvidence: stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that halts processing). - ru"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":907,"endLine":907}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-4.1"}},{"ruleId":"nist-ai-rmf-1.0/manage-4.1","level":"warning","message":{"text":"Post-deployment monitoring, appeal and override, change management — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (2/4 rules matched)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"package.json","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-4.1"}},{"ruleId":"iso-42001-2023/clause-5.1-leadership","level":"note","message":{"text":"Leadership and commitment for AI management — verdict: PASS (90% conf).\n\nComposite raw score 0.70 (1/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"AI_POLICY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":3,"confidence":0.9,"rawScore":0.7,"verifyMethod":"skipped","clauseId":"iso-42001/clause-5.1-leadership"}},{"ruleId":"iso-42001-2023/clause-5.3-roles","level":"note","message":{"text":"Roles, responsibilities and authorities — verdict: PASS (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CODEOWNERS","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"iso-42001/clause-5.3-roles"}},{"ruleId":"iso-42001-2023/clause-6.1-risk-assessment","level":"note","message":{"text":"AI risk assessment process — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"RISK_REGISTER.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"iso-42001/clause-6.1-risk-assessment"}},{"ruleId":"iso-42001-2023/clause-6.1-risk-assessment","level":"note","message":{"text":"AI risk assessment process — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"RISK_REGISTER.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"iso-42001/clause-6.1-risk-assessment"}},{"ruleId":"iso-42001-2023/clause-7.5-documented-information","level":"note","message":{"text":"Documented information for the AI management system — verdict: PASS (90% conf).\n\nComposite raw score 0.70 (1/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":3,"confidence":0.9,"rawScore":0.7,"verifyMethod":"skipped","clauseId":"iso-42001/clause-7.5-documented-information"}},{"ruleId":"iso-42001-2023/clause-7.5-documented-information","level":"note","message":{"text":"Documented information for the AI management system — verdict: PASS (90% conf).\n\nComposite raw score 0.70 (1/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CHANGELOG.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":3,"confidence":0.9,"rawScore":0.7,"verifyMethod":"skipped","clauseId":"iso-42001/clause-7.5-documented-information"}},{"ruleId":"iso-42001-2023/clause-8.1-operational-planning","level":"warning","message":{"text":"Operational planning and control — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"RUNBOOK.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"iso-42001/clause-8.1-operational-planning"}},{"ruleId":"iso-42001-2023/clause-9.1-monitoring","level":"error","message":{"text":"Monitoring, measurement, analysis and evaluation — verdict: FAIL (85% conf).\n\nComposite raw score 0.25 (1/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: x.ts\"), content); console.log(` rewrote index.ts (${entries.length} seeds)`); } async function main() { const args = process.argv.slic"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":38,"endLine":38}}}],"properties":{"verdict":"fail","score":1,"confidence":0.85,"rawScore":0.25,"verifyMethod":"deterministic-only","clauseId":"iso-42001/clause-9.1-monitoring"}},{"ruleId":"iso-42001-2023/clause-9.1-monitoring","level":"error","message":{"text":"Monitoring, measurement, analysis and evaluation — verdict: FAIL (85% conf).\n\nComposite raw score 0.25 (1/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: -1.0\"], }; console.log(`\\n=== ${owner}/${repo} (id=${input.auditId}) ===`); const t0 = Date.now(); try { const report"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":64,"endLine":64}}}],"properties":{"verdict":"fail","score":1,"confidence":0.85,"rawScore":0.25,"verifyMethod":"deterministic-only","clauseId":"iso-42001/clause-9.1-monitoring"}},{"ruleId":"iso-42001-2023/annex-a5-internal-org","level":"note","message":{"text":"Internal organization controls — verdict: PASS (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CODEOWNERS","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"iso-42001/annex-a5-internal-org"}},{"ruleId":"iso-42001-2023/annex-a7-resources","level":"note","message":{"text":"Resources for AI systems — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"SECURITY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"iso-42001/annex-a7-resources"}},{"ruleId":"iso-42001-2023/annex-a7-resources","level":"note","message":{"text":"Resources for AI systems — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"package-lock.json","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"iso-42001/annex-a7-resources"}},{"ruleId":"gdpr-2016/art-5-principles","level":"note","message":{"text":"Principles relating to processing of personal data — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"PRIVACY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-5-principles"}},{"ruleId":"gdpr-2016/art-5-principles","level":"note","message":{"text":"Principles relating to processing of personal data — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"PRIVACY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-5-principles"}},{"ruleId":"gdpr-2016/art-5-principles","level":"note","message":{"text":"Principles relating to processing of personal data — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-5-principles"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: in-the-loop hooks: `human_input()`, interrupt nodes in LangGraph, approval-gate functions, manual- review flags, con"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":817,"endLine":817}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: For LangGraph: use `interrupt()` nodes. For custom flows: build an approval-queue pattern. Document where humans can intervene i"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":838,"endLine":838}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: import ( AIMessage, HumanMessage,\", \"rule\": \"langchain_import\" }, { \"file\": \"gpt_engineer/core/a"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":162,"endLine":162}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: import ( AIMessage, HumanMessage, SystemMessage, messages_from_dict, messages_\", \"rule\": \"langchain_import\" },"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":171,"endLine":171}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: chain.schema import HumanMessage, SystemMessage from termcolor import colored from gpt_engineer.core.ai import\", \"rule\": \"langch"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":198,"endLine":198}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: a import AIMessage, HumanMessage, SystemMessage from PIL import Image # workaround for function mov\", \"rule\": \"langchain_import\""},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":207,"endLine":207}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: in-the-loop hooks: `human_input()`, interrupt nodes in LangGraph, approval-gate functions, manual- review flags, con"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":817,"endLine":817}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: For LangGraph: use `interrupt()` nodes. For custom flows: build an approval-queue pattern. Document where humans can intervene i"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":838,"endLine":838}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: ic: - rule: kill_switch_present weight: 0.7 description: | Code contains a documented kill-switch /"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":902,"endLine":902}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: sm (function named `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: med `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that h"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that halts processing). - ru"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":907,"endLine":907}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-25-by-design","level":"note","message":{"text":"Data protection by design and by default — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: crypto.createHash(\"sha256\")"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/anchor.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":149,"endLine":149}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-25-by-design"}},{"ruleId":"gdpr-2016/art-25-by-design","level":"note","message":{"text":"Data protection by design and by default — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: crypto.createHash(\"sha256\")"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/loader.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":416,"endLine":416}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-25-by-design"}},{"ruleId":"gdpr-2016/art-25-by-design","level":"note","message":{"text":"Data protection by design and by default — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: redact"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/recon.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":315,"endLine":315}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-25-by-design"}},{"ruleId":"gdpr-2016/art-25-by-design","level":"note","message":{"text":"Data protection by design and by default — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: crypto.createHash(\"sha256\")"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/report.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":64,"endLine":64}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-25-by-design"}},{"ruleId":"gdpr-2016/art-25-by-design","level":"note","message":{"text":"Data protection by design and by default — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"PRIVACY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-25-by-design"}},{"ruleId":"gdpr-2016/art-25-by-design","level":"note","message":{"text":"Data protection by design and by default — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-25-by-design"}},{"ruleId":"gdpr-2016/art-30-records","level":"note","message":{"text":"Records of processing activities — verdict: PASS (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"PROCESSING_REGISTER.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-30-records"}},{"ruleId":"gdpr-2016/art-32-security","level":"note","message":{"text":"Security of processing — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: https://github.com/${owner}/${repo}`,"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":60,"endLine":60}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-32-security"}},{"ruleId":"gdpr-2016/art-32-security","level":"note","message":{"text":"Security of processing — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: https://github.com/owner/repo"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/a/[chain]/[id]/_agent-audit.tsx","uriBaseId":"%SRCROOT%"},"region":{"startLine":87,"endLine":87}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-32-security"}},{"ruleId":"gdpr-2016/art-32-security","level":"note","message":{"text":"Security of processing — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: https://github.com/${body.source.owner}/${body.source.repo}`,"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/api/audit/run/route.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":38,"endLine":38}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-32-security"}},{"ruleId":"gdpr-2016/art-32-security","level":"note","message":{"text":"Security of processing — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: https://github.com/${body.source.owner}/${body.source.repo}`,"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/api/audit/stream/route.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":54,"endLine":54}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-32-security"}},{"ruleId":"gdpr-2016/art-32-security","level":"note","message":{"text":"Security of processing — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"next.config.ts","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-32-security"}},{"ruleId":"gdpr-2016/art-32-security","level":"note","message":{"text":"Security of processing — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: @login_required"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/checkers/rules.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":928,"endLine":928}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-32-security"}},{"ruleId":"gdpr-2016/art-35-dpia","level":"note","message":{"text":"Data protection impact assessment (DPIA) — verdict: PASS (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"DPIA.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-35-dpia"}}],"properties":{"auditId":"aud_01KS3F6HGWVX3WT37PDM3D","bundleHash":"fb69bd0fbe834cb782bc95c69d88a98e740fcb23a360a1f5031f5111372f9c59","durationMs":34847,"overallScore":2.3555555555555556,"regulationCoverage":["eu-ai-act-2024-08","nist-ai-rmf-1.0","iso-42001-2023","gdpr-2016"]}}]}