{"$schema":"https://raw.githubusercontent.com/oasis-tcs/sarif-spec/master/Schemata/sarif-schema-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"AiAuditor","informationUri":"https://github.com/drhus/ai-auditor","version":"v0.1.0","rules":[{"id":"eu-ai-act-2024-08/1d-predictive-policing","name":"eu-ai-act-2024-08/1d-predictive-policing","shortDescription":{"text":"Predictive policing solely from profiling"},"fullDescription":{"text":"EU AI Act, Art 5(1)(d) — Predictive policing solely from profiling"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-5(1)(d)","fairness"],"regulation":"EU AI Act","article":"5(1)(d)","principle":"fairness"}},{"id":"eu-ai-act-2024-08/1e-facial-scraping","name":"eu-ai-act-2024-08/1e-facial-scraping","shortDescription":{"text":"Untargeted facial image scraping for face databases"},"fullDescription":{"text":"EU AI Act, Art 5(1)(e) — Untargeted facial image scraping for face databases"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-5(1)(e)","privacy"],"regulation":"EU AI Act","article":"5(1)(e)","principle":"privacy"}},{"id":"eu-ai-act-2024-08/1f-emotion-workplace-edu","name":"eu-ai-act-2024-08/1f-emotion-workplace-edu","shortDescription":{"text":"Emotion recognition in workplace and education"},"fullDescription":{"text":"EU AI Act, Art 5(1)(f) — Emotion recognition in workplace and education"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-5(1)(f)","privacy"],"regulation":"EU AI Act","article":"5(1)(f)","principle":"privacy"}},{"id":"eu-ai-act-2024-08/risk-management","name":"eu-ai-act-2024-08/risk-management","shortDescription":{"text":"Risk management system established, implemented, documented"},"fullDescription":{"text":"EU AI Act, Art 9 — Risk management system established, implemented, documented"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-9","safety"],"regulation":"EU AI Act","article":"9","principle":"safety"}},{"id":"eu-ai-act-2024-08/data-governance","name":"eu-ai-act-2024-08/data-governance","shortDescription":{"text":"Data and data governance practices documented"},"fullDescription":{"text":"EU AI Act, Art 10 — Data and data governance practices documented"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-10","privacy"],"regulation":"EU AI Act","article":"10","principle":"privacy"}},{"id":"eu-ai-act-2024-08/technical-documentation","name":"eu-ai-act-2024-08/technical-documentation","shortDescription":{"text":"Technical documentation drawn up before placing on market"},"fullDescription":{"text":"EU AI Act, Art 11 — Technical documentation drawn up before placing on market"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-11","auditability"],"regulation":"EU AI Act","article":"11","principle":"auditability"}},{"id":"eu-ai-act-2024-08/p1-automatic-logs","name":"eu-ai-act-2024-08/p1-automatic-logs","shortDescription":{"text":"Automatic recording of events over the lifetime"},"fullDescription":{"text":"EU AI Act, Art 12(1) — Automatic recording of events over the lifetime"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-12(1)","auditability"],"regulation":"EU AI Act","article":"12(1)","principle":"auditability"}},{"id":"eu-ai-act-2024-08/p2-traceability","name":"eu-ai-act-2024-08/p2-traceability","shortDescription":{"text":"Logging ensures traceability appropriate to risk"},"fullDescription":{"text":"EU AI Act, Art 12(2) — Logging ensures traceability appropriate to risk"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-12(2)","auditability"],"regulation":"EU AI Act","article":"12(2)","principle":"auditability"}},{"id":"eu-ai-act-2024-08/deployer-instructions","name":"eu-ai-act-2024-08/deployer-instructions","shortDescription":{"text":"Transparent operation and instructions for use"},"fullDescription":{"text":"EU AI Act, Art 13 — Transparent operation and instructions for use"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-13","transparency"],"regulation":"EU AI Act","article":"13","principle":"transparency"}},{"id":"eu-ai-act-2024-08/p1-oversight-measures","name":"eu-ai-act-2024-08/p1-oversight-measures","shortDescription":{"text":"Effective human oversight designed and built-in"},"fullDescription":{"text":"EU AI Act, Art 14(1) — Effective human oversight designed and built-in"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-14(1)","human-oversight"],"regulation":"EU AI Act","article":"14(1)","principle":"human-oversight"}},{"id":"eu-ai-act-2024-08/p4d-stop-button","name":"eu-ai-act-2024-08/p4d-stop-button","shortDescription":{"text":"Interrupt / stop function reachable by overseer"},"fullDescription":{"text":"EU AI Act, Art 14(4)(d) — Interrupt / stop function reachable by overseer"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-14(4)(d)","human-oversight"],"regulation":"EU AI Act","article":"14(4)(d)","principle":"human-oversight"}},{"id":"eu-ai-act-2024-08/p4e-override","name":"eu-ai-act-2024-08/p4e-override","shortDescription":{"text":"Ability to override / reverse the system's output"},"fullDescription":{"text":"EU AI Act, Art 14(4)(e) — Ability to override / reverse the system's output"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-14(4)(e)","human-oversight"],"regulation":"EU AI Act","article":"14(4)(e)","principle":"human-oversight"}},{"id":"eu-ai-act-2024-08/p4-robustness","name":"eu-ai-act-2024-08/p4-robustness","shortDescription":{"text":"Resilience to errors, faults, inconsistencies"},"fullDescription":{"text":"EU AI Act, Art 15(4) — Resilience to errors, faults, inconsistencies"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-15(4)","safety"],"regulation":"EU AI Act","article":"15(4)","principle":"safety"}},{"id":"eu-ai-act-2024-08/p5-cybersecurity","name":"eu-ai-act-2024-08/p5-cybersecurity","shortDescription":{"text":"Cybersecurity measures appropriate to circumstances"},"fullDescription":{"text":"EU AI Act, Art 15(5) — Cybersecurity measures appropriate to circumstances"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-15(5)","security-governance"],"regulation":"EU AI Act","article":"15(5)","principle":"security-governance"}},{"id":"eu-ai-act-2024-08/p6-keep-logs","name":"eu-ai-act-2024-08/p6-keep-logs","shortDescription":{"text":"Deployer log-retention capability supported"},"fullDescription":{"text":"EU AI Act, Art 26(6) — Deployer log-retention capability supported"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-26(6)","accountability"],"regulation":"EU AI Act","article":"26(6)","principle":"accountability"}},{"id":"eu-ai-act-2024-08/p1-ai-disclosure","name":"eu-ai-act-2024-08/p1-ai-disclosure","shortDescription":{"text":"Users informed they are interacting with an AI"},"fullDescription":{"text":"EU AI Act, Art 50(1) — Users informed they are interacting with an AI"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-50(1)","transparency"],"regulation":"EU AI Act","article":"50(1)","principle":"transparency"}},{"id":"eu-ai-act-2024-08/p2-synthetic-content","name":"eu-ai-act-2024-08/p2-synthetic-content","shortDescription":{"text":"AI-generated content marked as such, machine-readable"},"fullDescription":{"text":"EU AI Act, Art 50(2) — AI-generated content marked as such, machine-readable"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-50(2)","transparency"],"regulation":"EU AI Act","article":"50(2)","principle":"transparency"}},{"id":"eu-ai-act-2024-08/p3-emotion-biometric-disclosure","name":"eu-ai-act-2024-08/p3-emotion-biometric-disclosure","shortDescription":{"text":"Emotion recognition / biometric categorisation disclosure"},"fullDescription":{"text":"EU AI Act, Art 50(3) — Emotion recognition / biometric categorisation disclosure"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-50(3)","transparency"],"regulation":"EU AI Act","article":"50(3)","principle":"transparency"}},{"id":"eu-ai-act-2024-08/p4-deepfake-disclosure","name":"eu-ai-act-2024-08/p4-deepfake-disclosure","shortDescription":{"text":"Deepfake content labelled as artificially generated"},"fullDescription":{"text":"EU AI Act, Art 50(4) — Deepfake content labelled as artificially generated"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2024/1689/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","eu-ai-act-2024-08","article-50(4)","transparency"],"regulation":"EU AI Act","article":"50(4)","principle":"transparency"}},{"id":"nist-ai-rmf-1.0/govern-1.4","name":"nist-ai-rmf-1.0/govern-1.4","shortDescription":{"text":"Risk management process documented and accountable"},"fullDescription":{"text":"NIST AI RMF, Art GOVERN 1.4 — Risk management process documented and accountable"},"helpUri":"https://www.nist.gov/itl/ai-risk-management-framework","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","nist-ai-rmf-1.0","article-GOVERN 1.4","accountability"],"regulation":"NIST AI RMF","article":"GOVERN 1.4","principle":"accountability"}},{"id":"nist-ai-rmf-1.0/map-1.1","name":"nist-ai-rmf-1.0/map-1.1","shortDescription":{"text":"Context of use established and understood"},"fullDescription":{"text":"NIST AI RMF, Art MAP 1.1 — Context of use established and understood"},"helpUri":"https://www.nist.gov/itl/ai-risk-management-framework","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","nist-ai-rmf-1.0","article-MAP 1.1","auditability"],"regulation":"NIST AI RMF","article":"MAP 1.1","principle":"auditability"}},{"id":"nist-ai-rmf-1.0/map-3.4","name":"nist-ai-rmf-1.0/map-3.4","shortDescription":{"text":"Risks and benefits to people identified"},"fullDescription":{"text":"NIST AI RMF, Art MAP 3.4 — Risks and benefits to people identified"},"helpUri":"https://www.nist.gov/itl/ai-risk-management-framework","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","nist-ai-rmf-1.0","article-MAP 3.4","safety"],"regulation":"NIST AI RMF","article":"MAP 3.4","principle":"safety"}},{"id":"nist-ai-rmf-1.0/measure-2.7","name":"nist-ai-rmf-1.0/measure-2.7","shortDescription":{"text":"Security and resilience evaluated"},"fullDescription":{"text":"NIST AI RMF, Art MEASURE 2.7 — Security and resilience evaluated"},"helpUri":"https://www.nist.gov/itl/ai-risk-management-framework","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","nist-ai-rmf-1.0","article-MEASURE 2.7","security-governance"],"regulation":"NIST AI RMF","article":"MEASURE 2.7","principle":"security-governance"}},{"id":"nist-ai-rmf-1.0/measure-2.8","name":"nist-ai-rmf-1.0/measure-2.8","shortDescription":{"text":"Privacy risk of the AI system evaluated"},"fullDescription":{"text":"NIST AI RMF, Art MEASURE 2.8 — Privacy risk of the AI system evaluated"},"helpUri":"https://www.nist.gov/itl/ai-risk-management-framework","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","nist-ai-rmf-1.0","article-MEASURE 2.8","privacy"],"regulation":"NIST AI RMF","article":"MEASURE 2.8","principle":"privacy"}},{"id":"nist-ai-rmf-1.0/manage-2.3","name":"nist-ai-rmf-1.0/manage-2.3","shortDescription":{"text":"Mechanisms to supersede or deactivate AI systems"},"fullDescription":{"text":"NIST AI RMF, Art MANAGE 2.3 — Mechanisms to supersede or deactivate AI systems"},"helpUri":"https://www.nist.gov/itl/ai-risk-management-framework","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","nist-ai-rmf-1.0","article-MANAGE 2.3","human-oversight"],"regulation":"NIST AI RMF","article":"MANAGE 2.3","principle":"human-oversight"}},{"id":"nist-ai-rmf-1.0/manage-4.1","name":"nist-ai-rmf-1.0/manage-4.1","shortDescription":{"text":"Post-deployment monitoring, appeal and override, change management"},"fullDescription":{"text":"NIST AI RMF, Art MANAGE 4.1 — Post-deployment monitoring, appeal and override, change management"},"helpUri":"https://www.nist.gov/itl/ai-risk-management-framework","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","nist-ai-rmf-1.0","article-MANAGE 4.1","auditability"],"regulation":"NIST AI RMF","article":"MANAGE 4.1","principle":"auditability"}},{"id":"gdpr-2016/art-5-principles","name":"gdpr-2016/art-5-principles","shortDescription":{"text":"Principles relating to processing of personal data"},"fullDescription":{"text":"GDPR, Art 5 — Principles relating to processing of personal data"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","gdpr-2016","article-5","transparency"],"regulation":"GDPR","article":"5","principle":"transparency"}},{"id":"gdpr-2016/art-22-automated-decisions","name":"gdpr-2016/art-22-automated-decisions","shortDescription":{"text":"Automated individual decision-making, including profiling"},"fullDescription":{"text":"GDPR, Art 22 — Automated individual decision-making, including profiling"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","gdpr-2016","article-22","human-oversight"],"regulation":"GDPR","article":"22","principle":"human-oversight"}},{"id":"gdpr-2016/art-25-by-design","name":"gdpr-2016/art-25-by-design","shortDescription":{"text":"Data protection by design and by default"},"fullDescription":{"text":"GDPR, Art 25 — Data protection by design and by default"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","gdpr-2016","article-25","privacy"],"regulation":"GDPR","article":"25","principle":"privacy"}},{"id":"gdpr-2016/art-30-records","name":"gdpr-2016/art-30-records","shortDescription":{"text":"Records of processing activities"},"fullDescription":{"text":"GDPR, Art 30 — Records of processing activities"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","gdpr-2016","article-30","auditability"],"regulation":"GDPR","article":"30","principle":"auditability"}},{"id":"gdpr-2016/art-32-security","name":"gdpr-2016/art-32-security","shortDescription":{"text":"Security of processing"},"fullDescription":{"text":"GDPR, Art 32 — Security of processing"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","gdpr-2016","article-32","security-governance"],"regulation":"GDPR","article":"32","principle":"security-governance"}},{"id":"gdpr-2016/art-35-dpia","name":"gdpr-2016/art-35-dpia","shortDescription":{"text":"Data protection impact assessment (DPIA)"},"fullDescription":{"text":"GDPR, Art 35 — Data protection impact assessment (DPIA)"},"helpUri":"https://eur-lex.europa.eu/eli/reg/2016/679/oj","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","gdpr-2016","article-35","safety"],"regulation":"GDPR","article":"35","principle":"safety"}},{"id":"iso-42001-2023/clause-5.1-leadership","name":"iso-42001-2023/clause-5.1-leadership","shortDescription":{"text":"Leadership and commitment for AI management"},"fullDescription":{"text":"ISO/IEC 42001, Art 5.1 — Leadership and commitment for AI management"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-5.1","accountability"],"regulation":"ISO/IEC 42001","article":"5.1","principle":"accountability"}},{"id":"iso-42001-2023/clause-5.3-roles","name":"iso-42001-2023/clause-5.3-roles","shortDescription":{"text":"Roles, responsibilities and authorities"},"fullDescription":{"text":"ISO/IEC 42001, Art 5.3 — Roles, responsibilities and authorities"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-5.3","accountability"],"regulation":"ISO/IEC 42001","article":"5.3","principle":"accountability"}},{"id":"iso-42001-2023/clause-6.1-risk-assessment","name":"iso-42001-2023/clause-6.1-risk-assessment","shortDescription":{"text":"AI risk assessment process"},"fullDescription":{"text":"ISO/IEC 42001, Art 6.1 — AI risk assessment process"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-6.1","safety"],"regulation":"ISO/IEC 42001","article":"6.1","principle":"safety"}},{"id":"iso-42001-2023/clause-7.5-documented-information","name":"iso-42001-2023/clause-7.5-documented-information","shortDescription":{"text":"Documented information for the AI management system"},"fullDescription":{"text":"ISO/IEC 42001, Art 7.5 — Documented information for the AI management system"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-7.5","auditability"],"regulation":"ISO/IEC 42001","article":"7.5","principle":"auditability"}},{"id":"iso-42001-2023/clause-8.1-operational-planning","name":"iso-42001-2023/clause-8.1-operational-planning","shortDescription":{"text":"Operational planning and control"},"fullDescription":{"text":"ISO/IEC 42001, Art 8.1 — Operational planning and control"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"warning"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-8.1","safety"],"regulation":"ISO/IEC 42001","article":"8.1","principle":"safety"}},{"id":"iso-42001-2023/clause-9.1-monitoring","name":"iso-42001-2023/clause-9.1-monitoring","shortDescription":{"text":"Monitoring, measurement, analysis and evaluation"},"fullDescription":{"text":"ISO/IEC 42001, Art 9.1 — Monitoring, measurement, analysis and evaluation"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"error"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-9.1","auditability"],"regulation":"ISO/IEC 42001","article":"9.1","principle":"auditability"}},{"id":"iso-42001-2023/annex-a5-internal-org","name":"iso-42001-2023/annex-a5-internal-org","shortDescription":{"text":"Internal organization controls"},"fullDescription":{"text":"ISO/IEC 42001, Art A.5 — Internal organization controls"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-A.5","accountability"],"regulation":"ISO/IEC 42001","article":"A.5","principle":"accountability"}},{"id":"iso-42001-2023/annex-a7-resources","name":"iso-42001-2023/annex-a7-resources","shortDescription":{"text":"Resources for AI systems"},"fullDescription":{"text":"ISO/IEC 42001, Art A.7 — Resources for AI systems"},"helpUri":"https://www.iso.org/standard/81230.html","defaultConfiguration":{"level":"note"},"properties":{"tags":["ai-compliance","iso-42001-2023","article-A.7","security-governance"],"regulation":"ISO/IEC 42001","article":"A.7","principle":"security-governance"}}]}},"automationDetails":{"id":"aiauditor/aud_01KS3FDRK7DX6DJ50GTBS6"},"originalUriBaseIds":{"%SRCROOT%":{"uri":"https://github.com/drhus/ai-auditor/blob/8d681f7e9beebb27811b15ce6282882c2472a2cb/"}},"versionControlProvenance":[{"repositoryUri":"https://github.com/drhus/ai-auditor","revisionId":"8d681f7e9beebb27811b15ce6282882c2472a2cb","branch":"8d681f7e9beebb27811b15ce6282882c2472a2cb"}],"results":[{"ruleId":"eu-ai-act-2024-08/1d-predictive-policing","level":"error","message":{"text":"Predictive policing solely from profiling — verdict: FAIL (79% conf).\n\nComposite raw score 0.76 (1/1 rules matched).\n\nEvidence: crime-likelihood / recidivism / \"risk to commit X\" scores when the input contains only person profile data (no obje"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":199,"endLine":199}}}],"properties":{"verdict":"fail","score":0,"confidence":0.7887640052032225,"rawScore":0.7612359947967775,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1d-predictive-policing"}},{"ruleId":"eu-ai-act-2024-08/1d-predictive-policing","level":"error","message":{"text":"Predictive policing solely from profiling — verdict: FAIL (79% conf).\n\nComposite raw score 0.76 (1/1 rules matched).\n\nEvidence: names like `crime_risk`, `recidivism_score`, `offender_likelihood` combined with profile inputs. score_mapping: { pa"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":202,"endLine":202}}}],"properties":{"verdict":"fail","score":0,"confidence":0.7887640052032225,"rawScore":0.7612359947967775,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1d-predictive-policing"}},{"ruleId":"eu-ai-act-2024-08/1d-predictive-policing","level":"error","message":{"text":"Predictive policing solely from profiling — verdict: FAIL (79% conf).\n\nComposite raw score 0.76 (1/1 rules matched).\n\nEvidence: recidivism_score`, `offender_likelihood` combined with profile inputs. score_mapping: { pass_default: 4, fail_on_match: 0 }"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":202,"endLine":202}}}],"properties":{"verdict":"fail","score":0,"confidence":0.7887640052032225,"rawScore":0.7612359947967775,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1d-predictive-policing"}},{"ruleId":"eu-ai-act-2024-08/1d-predictive-policing","level":"error","message":{"text":"Predictive policing solely from profiling — verdict: FAIL (79% conf).\n\nComposite raw score 0.76 (1/1 rules matched).\n\nEvidence: ms\", pattern: /\\b(?:crime_risk|recidivism|offender_likelihood|police_dispatch|criminal_record|sentencing_recommend)\\b/gi }, // ----- migr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/recon.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":330,"endLine":330}}}],"properties":{"verdict":"fail","score":0,"confidence":0.7887640052032225,"rawScore":0.7612359947967775,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1d-predictive-policing"}},{"ruleId":"eu-ai-act-2024-08/1d-predictive-policing","level":"error","message":{"text":"Predictive policing solely from profiling — verdict: FAIL (79% conf).\n\nComposite raw score 0.76 (1/1 rules matched).\n\nEvidence: n: /\\b(?:crime_risk|recidivism|offender_likelihood|police_dispatch|criminal_record|sentencing_recommend)\\b/gi }, // ----- migration_signa"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/recon.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":330,"endLine":330}}}],"properties":{"verdict":"fail","score":0,"confidence":0.7887640052032225,"rawScore":0.7612359947967775,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1d-predictive-policing"}},{"ruleId":"eu-ai-act-2024-08/1d-predictive-policing","level":"error","message":{"text":"Predictive policing solely from profiling — verdict: FAIL (79% conf).\n\nComposite raw score 0.76 (1/1 rules matched).\n\nEvidence: ime_risk|recidivism|offender_likelihood|police_dispatch|criminal_record|sentencing_recommend)\\b/gi }, // ----- migration_signals -----"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/recon.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":330,"endLine":330}}}],"properties":{"verdict":"fail","score":0,"confidence":0.7887640052032225,"rawScore":0.7612359947967775,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1d-predictive-policing"}},{"ruleId":"eu-ai-act-2024-08/1e-facial-scraping","level":"error","message":{"text":"Untargeted facial image scraping for face databases — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: \" description: \"Biometric ID, categorisation, emotion recognition\" - signal: critical_infra_signals category: \"2\" description:"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":32,"endLine":32}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1e-facial-scraping"}},{"ruleId":"eu-ai-act-2024-08/1e-facial-scraping","level":"error","message":{"text":"Untargeted facial image scraping for face databases — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: otion recognition / biometric categorisation\" - signal: agent_framework # any interactive AI is in scope paragraph: \"50(1)\""},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":62,"endLine":62}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1e-facial-scraping"}},{"ruleId":"eu-ai-act-2024-08/1e-facial-scraping","level":"error","message":{"text":"Untargeted facial image scraping for face databases — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: calls (mediapipe, face_recognition, dlib, opencv haar cascade). score_mapping: { pass_default: 4, fail_on_match: 0 } remediation_h"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":231,"endLine":231}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1e-facial-scraping"}},{"ruleId":"eu-ai-act-2024-08/1e-facial-scraping","level":"error","message":{"text":"Untargeted facial image scraping for face databases — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: \"^1.1.0\", \"@playwright/test\": \"^1.51.1\", \"babel-plugin-react-compiler\": \"*\", \"react\": \"^18.2.0 || 19.0.0-rc-de68d2f4"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"package-lock.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":3913,"endLine":3913}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1e-facial-scraping"}},{"ruleId":"eu-ai-act-2024-08/1e-facial-scraping","level":"error","message":{"text":"Untargeted facial image scraping for face databases — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: }, \"@playwright/test\": { \"optional\": true }, \"babel-plugin-react-compiler\": { \"optional\":"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"package-lock.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":3923,"endLine":3923}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1e-facial-scraping"}},{"ruleId":"eu-ai-act-2024-08/1e-facial-scraping","level":"error","message":{"text":"Untargeted facial image scraping for face databases — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: uests.get / fetch / playwright in iteration) targeting image content combined with face-detection calls (mediapipe,"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":229,"endLine":229}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1e-facial-scraping"}},{"ruleId":"eu-ai-act-2024-08/1f-emotion-workplace-edu","level":"error","message":{"text":"Emotion recognition in workplace and education — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: ms\", pattern: /\\b(?:emotion_detect|emotion_recognition|sentiment_score|affect_recognition|facial_emotion|micro_expression)\\b/gi }, // ---"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/recon.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":348,"endLine":348}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1f-emotion-workplace-edu"}},{"ruleId":"eu-ai-act-2024-08/1f-emotion-workplace-edu","level":"error","message":{"text":"Emotion recognition in workplace and education — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: \\b(?:emotion_detect|emotion_recognition|sentiment_score|affect_recognition|facial_emotion|micro_expression)\\b/gi }, // ----- data_io ----"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/recon.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":348,"endLine":348}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1f-emotion-workplace-edu"}},{"ruleId":"eu-ai-act-2024-08/1f-emotion-workplace-edu","level":"error","message":{"text":"Emotion recognition in workplace and education — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: emotion_recognition|sentiment_score|affect_recognition|facial_emotion|micro_expression)\\b/gi }, // ----- data_io ----- { signal: \"data_"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/recon.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":348,"endLine":348}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1f-emotion-workplace-edu"}},{"ruleId":"eu-ai-act-2024-08/1f-emotion-workplace-edu","level":"error","message":{"text":"Emotion recognition in workplace and education — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: ppet\": \"OMMANDS for candidate in tokens[index + 1:]: if candidate in {\\\"|\\\", \\\";\\\", \\\"&&\\\", \\\"||\\\"}: break f\", \"rule\": \"employme"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":1001,"endLine":1001}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1f-emotion-workplace-edu"}},{"ruleId":"eu-ai-act-2024-08/1f-emotion-workplace-edu","level":"error","message":{"text":"Emotion recognition in workplace and education — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: ens[index + 1:]: if candidate in {\\\"|\\\", \\\";\\\", \\\"&&\\\", \\\"||\\\"}: break f\", \"rule\": \"employment_terms\" }, {"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":1001,"endLine":1001}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1f-emotion-workplace-edu"}},{"ruleId":"eu-ai-act-2024-08/1f-emotion-workplace-edu","level":"error","message":{"text":"Emotion recognition in workplace and education — verdict: FAIL (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched).\n\nEvidence: \"snippet\": \"1:]: if candidate in {\\\"|\\\", \\\";\\\", \\\"&&\\\", \\\"||\\\"}: break for path_candidate in candidate_paths(candidate):\", \"rule"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":1010,"endLine":1010}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-5/1f-emotion-workplace-edu"}},{"ruleId":"eu-ai-act-2024-08/risk-management","level":"warning","message":{"text":"Risk management system established, implemented, documented — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.55 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): Risk identification and analysis foundations are evident (risk register and threat model), but absence of documented continuous integration evaluation gates suggests incomplete implementation of the 'continuous iterative process' and 'regular systematic review and updating' requirements across the system lifecycle."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"RISK_REGISTER.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.55,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-9/risk-management"}},{"ruleId":"eu-ai-act-2024-08/risk-management","level":"warning","message":{"text":"Risk management system established, implemented, documented — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.55 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): Risk identification and analysis foundations are evident (risk register and threat model), but absence of documented continuous integration evaluation gates suggests incomplete implementation of the 'continuous iterative process' and 'regular systematic review and updating' requirements across the system lifecycle."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"SECURITY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.55,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-9/risk-management"}},{"ruleId":"eu-ai-act-2024-08/data-governance","level":"error","message":{"text":"Data and data governance practices documented — verdict: FAIL (75% conf).\n\nComposite raw score 0.10 (0/3 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: \"^1.1.0\", \"@playwright/test\": \"^1.51.1\", \"babel-plugin-react-compiler\": \"*\", \"react\": \"^18.2.0 || 19.0.0-rc-de68d2f4"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"package-lock.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":3913,"endLine":3913}}}],"properties":{"verdict":"fail","score":0,"confidence":0.75,"rawScore":0.1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-10/data-governance"}},{"ruleId":"eu-ai-act-2024-08/data-governance","level":"error","message":{"text":"Data and data governance practices documented — verdict: FAIL (75% conf).\n\nComposite raw score 0.10 (0/3 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: }, \"@playwright/test\": { \"optional\": true }, \"babel-plugin-react-compiler\": { \"optional\":"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"package-lock.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":3923,"endLine":3923}}}],"properties":{"verdict":"fail","score":0,"confidence":0.75,"rawScore":0.1,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-10/data-governance"}},{"ruleId":"eu-ai-act-2024-08/technical-documentation","level":"error","message":{"text":"Technical documentation drawn up before placing on market — verdict: FAIL (80% conf).\n\nComposite raw score 0.15 (1/3 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: 2 required sections present"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"fail","score":1,"confidence":0.8,"rawScore":0.15,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-11/technical-documentation"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): While tool-call boundary logging is detected via console.log statements, the clause requires 'technical' automatic recording with persistence over the system's lifetime. Console logs are ephemeral and lack evidence of structured logging imports or persistent sink configuration, failing to meet the durability and systematic requirements for high-risk AI system compliance.\n\nEvidence: x.ts\"), content); console.log(` rewrote index.ts (${entries.length} seeds)`); } async function main() { const args = process.argv.slic"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":38,"endLine":38}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): While tool-call boundary logging is detected via console.log statements, the clause requires 'technical' automatic recording with persistence over the system's lifetime. Console logs are ephemeral and lack evidence of structured logging imports or persistent sink configuration, failing to meet the durability and systematic requirements for high-risk AI system compliance.\n\nEvidence: -1.0\"], }; console.log(`\\n=== ${owner}/${repo} (id=${input.auditId}) ===`); const t0 = Date.now(); try { const report"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":64,"endLine":64}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): While tool-call boundary logging is detected via console.log statements, the clause requires 'technical' automatic recording with persistence over the system's lifetime. Console logs are ephemeral and lack evidence of structured logging imports or persistent sink configuration, failing to meet the durability and systematic requirements for high-risk AI system compliance.\n\nEvidence: evt.kind === \"log\") console.log(` [${evt.stage}] ${evt.text}`); else if (evt.kind === \"stage\") console.log(` [${evt.stage}] phase="},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":68,"endLine":68}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): While tool-call boundary logging is detected via console.log statements, the clause requires 'technical' automatic recording with persistence over the system's lifetime. Console logs are ephemeral and lack evidence of structured logging imports or persistent sink configuration, failing to meet the durability and systematic requirements for high-risk AI system compliance.\n\nEvidence: t.kind === \"stage\") console.log(` [${evt.stage}] phase=${evt.phase}${evt.durationMs ? ` (${evt.durationMs}ms)` : \"\"}`); else if (ev"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":69,"endLine":69}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): While tool-call boundary logging is detected via console.log statements, the clause requires 'technical' automatic recording with persistence over the system's lifetime. Console logs are ephemeral and lack evidence of structured logging imports or persistent sink configuration, failing to meet the durability and systematic requirements for high-risk AI system compliance.\n\nEvidence: = \"classification\") console.log(` ✦ risk=${evt.classification} annex=${evt.annexIii.join(\"/\")} art50=${evt.art50.join(\"/\")}`); else"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":70,"endLine":70}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): While tool-call boundary logging is detected via console.log statements, the clause requires 'technical' automatic recording with persistence over the system's lifetime. Console logs are ephemeral and lack evidence of structured logging imports or persistent sink configuration, failing to meet the durability and systematic requirements for high-risk AI system compliance.\n\nEvidence: lationPack(id); console.log(`${id}: ${pack.clauses.length} clauses`); for (const c of pack.clauses) { console.log(` ${c.id} →"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/smoke-iso-gdpr.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":6,"endLine":6}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): While tool-call boundary logging is detected via console.log statements, the clause requires 'technical' automatic recording with persistence over the system's lifetime. Console logs are ephemeral and lack evidence of structured logging imports or persistent sink configuration, failing to meet the durability and systematic requirements for high-risk AI system compliance.\n\nEvidence: x.ts\"), content); console.log(` rewrote index.ts (${entries.length} seeds)`); } async function main() { const args = process.argv.slic"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":38,"endLine":38}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-automatic-logs","level":"error","message":{"text":"Automatic recording of events over the lifetime — verdict: FAIL (85% conf).\n\nComposite raw score 0.58 (1/3 rules matched).\n\nLLM judge (confidence 0.85): While tool-call boundary logging is detected via console.log statements, the clause requires 'technical' automatic recording with persistence over the system's lifetime. Console logs are ephemeral and lack evidence of structured logging imports or persistent sink configuration, failing to meet the durability and systematic requirements for high-risk AI system compliance.\n\nEvidence: -1.0\"], }; console.log(`\\n=== ${owner}/${repo} (id=${input.auditId}) ===`); const t0 = Date.now(); try { const report"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":64,"endLine":64}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5800000000000001,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p1-automatic-logs"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates logging of input/output pairs and model identity (2/3 deterministic rules matched, 0.68 score), satisfying core traceability needs. However, absence of request_id logging and lack of evidence for production-grade structured logging (only console.log statements visible) create uncertainty about whether traceability is 'appropriate to intended purpose' under operational conditions, particularly for high-risk AI use cases.\n\nEvidence: x.ts\"), content); console.log(` rewrote index.ts (${entries.length} seeds)`); } async function main() { const args = process.argv.slic"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":38,"endLine":38}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates logging of input/output pairs and model identity (2/3 deterministic rules matched, 0.68 score), satisfying core traceability needs. However, absence of request_id logging and lack of evidence for production-grade structured logging (only console.log statements visible) create uncertainty about whether traceability is 'appropriate to intended purpose' under operational conditions, particularly for high-risk AI use cases.\n\nEvidence: -1.0\"], }; console.log(`\\n=== ${owner}/${repo} (id=${input.auditId}) ===`); const t0 = Date.now(); try { const report"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":64,"endLine":64}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates logging of input/output pairs and model identity (2/3 deterministic rules matched, 0.68 score), satisfying core traceability needs. However, absence of request_id logging and lack of evidence for production-grade structured logging (only console.log statements visible) create uncertainty about whether traceability is 'appropriate to intended purpose' under operational conditions, particularly for high-risk AI use cases.\n\nEvidence: evt.kind === \"log\") console.log(` [${evt.stage}] ${evt.text}`); else if (evt.kind === \"stage\") console.log(` [${evt.stage}] phase="},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":68,"endLine":68}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates logging of input/output pairs and model identity (2/3 deterministic rules matched, 0.68 score), satisfying core traceability needs. However, absence of request_id logging and lack of evidence for production-grade structured logging (only console.log statements visible) create uncertainty about whether traceability is 'appropriate to intended purpose' under operational conditions, particularly for high-risk AI use cases.\n\nEvidence: t.kind === \"stage\") console.log(` [${evt.stage}] phase=${evt.phase}${evt.durationMs ? ` (${evt.durationMs}ms)` : \"\"}`); else if (ev"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":69,"endLine":69}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates logging of input/output pairs and model identity (2/3 deterministic rules matched, 0.68 score), satisfying core traceability needs. However, absence of request_id logging and lack of evidence for production-grade structured logging (only console.log statements visible) create uncertainty about whether traceability is 'appropriate to intended purpose' under operational conditions, particularly for high-risk AI use cases.\n\nEvidence: = \"classification\") console.log(` ✦ risk=${evt.classification} annex=${evt.annexIii.join(\"/\")} art50=${evt.art50.join(\"/\")}`); else"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":70,"endLine":70}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates logging of input/output pairs and model identity (2/3 deterministic rules matched, 0.68 score), satisfying core traceability needs. However, absence of request_id logging and lack of evidence for production-grade structured logging (only console.log statements visible) create uncertainty about whether traceability is 'appropriate to intended purpose' under operational conditions, particularly for high-risk AI use cases.\n\nEvidence: lationPack(id); console.log(`${id}: ${pack.clauses.length} clauses`); for (const c of pack.clauses) { console.log(` ${c.id} →"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/smoke-iso-gdpr.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":6,"endLine":6}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates logging of input/output pairs and model identity (2/3 deterministic rules matched, 0.68 score), satisfying core traceability needs. However, absence of request_id logging and lack of evidence for production-grade structured logging (only console.log statements visible) create uncertainty about whether traceability is 'appropriate to intended purpose' under operational conditions, particularly for high-risk AI use cases.\n\nEvidence: x.ts\"), content); console.log(` rewrote index.ts (${entries.length} seeds)`); } async function main() { const args = process.argv.slic"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":38,"endLine":38}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/p2-traceability","level":"warning","message":{"text":"Logging ensures traceability appropriate to risk — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.62): The system demonstrates logging of input/output pairs and model identity (2/3 deterministic rules matched, 0.68 score), satisfying core traceability needs. However, absence of request_id logging and lack of evidence for production-grade structured logging (only console.log statements visible) create uncertainty about whether traceability is 'appropriate to intended purpose' under operational conditions, particularly for high-risk AI use cases.\n\nEvidence: -1.0\"], }; console.log(`\\n=== ${owner}/${repo} (id=${input.auditId}) ===`); const t0 = Date.now(); try { const report"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":64,"endLine":64}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.675,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-12/p2-traceability"}},{"ruleId":"eu-ai-act-2024-08/deployer-instructions","level":"error","message":{"text":"Transparent operation and instructions for use — verdict: FAIL (90% conf).\n\nComposite raw score 0.25 (1/3 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: 2 required sections present"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"fail","score":1,"confidence":0.9,"rawScore":0.25,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-13/deployer-instructions"}},{"ruleId":"eu-ai-act-2024-08/deployer-instructions","level":"error","message":{"text":"Transparent operation and instructions for use — verdict: FAIL (90% conf).\n\nComposite raw score 0.25 (1/3 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"fail","score":1,"confidence":0.9,"rawScore":0.25,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-13/deployer-instructions"}},{"ruleId":"eu-ai-act-2024-08/deployer-instructions","level":"error","message":{"text":"Transparent operation and instructions for use — verdict: FAIL (90% conf).\n\nComposite raw score 0.25 (1/3 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"fail","score":1,"confidence":0.9,"rawScore":0.25,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-13/deployer-instructions"}},{"ruleId":"eu-ai-act-2024-08/p1-oversight-measures","level":"warning","message":{"text":"Effective human oversight designed and built-in — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.50 (1/3 rules matched).\n\nLLM judge (confidence 0.62): Human-in-loop mechanisms are present (LangGraph interrupt nodes, approval gates, manual review flags) satisfying the core requirement for intervention points. However, absence of documented oversight UI and lack of dry-run capabilities for tool calls create gaps in effective real-time oversight usability and safety verification, leaving implementation incomplete against the clause's full intent.\n\nEvidence: in-the-loop hooks: `human_input()`, interrupt nodes in LangGraph, approval-gate functions, manual- review flags, con"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":817,"endLine":817}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p1-oversight-measures"}},{"ruleId":"eu-ai-act-2024-08/p1-oversight-measures","level":"warning","message":{"text":"Effective human oversight designed and built-in — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.50 (1/3 rules matched).\n\nLLM judge (confidence 0.62): Human-in-loop mechanisms are present (LangGraph interrupt nodes, approval gates, manual review flags) satisfying the core requirement for intervention points. However, absence of documented oversight UI and lack of dry-run capabilities for tool calls create gaps in effective real-time oversight usability and safety verification, leaving implementation incomplete against the clause's full intent.\n\nEvidence: For LangGraph: use `interrupt()` nodes. For custom flows: build an approval-queue pattern. Document where humans can intervene i"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":838,"endLine":838}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p1-oversight-measures"}},{"ruleId":"eu-ai-act-2024-08/p1-oversight-measures","level":"warning","message":{"text":"Effective human oversight designed and built-in — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.50 (1/3 rules matched).\n\nLLM judge (confidence 0.62): Human-in-loop mechanisms are present (LangGraph interrupt nodes, approval gates, manual review flags) satisfying the core requirement for intervention points. However, absence of documented oversight UI and lack of dry-run capabilities for tool calls create gaps in effective real-time oversight usability and safety verification, leaving implementation incomplete against the clause's full intent.\n\nEvidence: import ( AIMessage, HumanMessage,\", \"rule\": \"langchain_import\" }, { \"file\": \"gpt_engineer/core/a"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":162,"endLine":162}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p1-oversight-measures"}},{"ruleId":"eu-ai-act-2024-08/p1-oversight-measures","level":"warning","message":{"text":"Effective human oversight designed and built-in — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.50 (1/3 rules matched).\n\nLLM judge (confidence 0.62): Human-in-loop mechanisms are present (LangGraph interrupt nodes, approval gates, manual review flags) satisfying the core requirement for intervention points. However, absence of documented oversight UI and lack of dry-run capabilities for tool calls create gaps in effective real-time oversight usability and safety verification, leaving implementation incomplete against the clause's full intent.\n\nEvidence: import ( AIMessage, HumanMessage, SystemMessage, messages_from_dict, messages_\", \"rule\": \"langchain_import\" },"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":171,"endLine":171}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p1-oversight-measures"}},{"ruleId":"eu-ai-act-2024-08/p1-oversight-measures","level":"warning","message":{"text":"Effective human oversight designed and built-in — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.50 (1/3 rules matched).\n\nLLM judge (confidence 0.62): Human-in-loop mechanisms are present (LangGraph interrupt nodes, approval gates, manual review flags) satisfying the core requirement for intervention points. However, absence of documented oversight UI and lack of dry-run capabilities for tool calls create gaps in effective real-time oversight usability and safety verification, leaving implementation incomplete against the clause's full intent.\n\nEvidence: chain.schema import HumanMessage, SystemMessage from termcolor import colored from gpt_engineer.core.ai import\", \"rule\": \"langch"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":198,"endLine":198}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p1-oversight-measures"}},{"ruleId":"eu-ai-act-2024-08/p1-oversight-measures","level":"warning","message":{"text":"Effective human oversight designed and built-in — verdict: PARTIAL (62% conf).\n\nComposite raw score 0.50 (1/3 rules matched).\n\nLLM judge (confidence 0.62): Human-in-loop mechanisms are present (LangGraph interrupt nodes, approval gates, manual review flags) satisfying the core requirement for intervention points. However, absence of documented oversight UI and lack of dry-run capabilities for tool calls create gaps in effective real-time oversight usability and safety verification, leaving implementation incomplete against the clause's full intent.\n\nEvidence: a import AIMessage, HumanMessage, SystemMessage from PIL import Image # workaround for function mov\", \"rule\": \"langchain_import\""},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":207,"endLine":207}}}],"properties":{"verdict":"partial","score":2,"confidence":0.62,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p1-oversight-measures"}},{"ruleId":"eu-ai-act-2024-08/p4d-stop-button","level":"warning","message":{"text":"Interrupt / stop function reachable by overseer — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.70 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates a documented kill-switch mechanism (kill_switch_active=True) satisfying the 'stop button' requirement with 0.7 weight, but lacks evidence of graceful shutdown handling (0.3 weight) needed to ensure the system reaches a 'safe state' as required by the clause. Additional documentation of safe shutdown procedures is needed for full compliance.\n\nEvidence: ic: - rule: kill_switch_present weight: 0.7 description: | Code contains a documented kill-switch /"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":902,"endLine":902}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.7,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4d-stop-button"}},{"ruleId":"eu-ai-act-2024-08/p4d-stop-button","level":"warning","message":{"text":"Interrupt / stop function reachable by overseer — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.70 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates a documented kill-switch mechanism (kill_switch_active=True) satisfying the 'stop button' requirement with 0.7 weight, but lacks evidence of graceful shutdown handling (0.3 weight) needed to ensure the system reaches a 'safe state' as required by the clause. Additional documentation of safe shutdown procedures is needed for full compliance.\n\nEvidence: sm (function named `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.7,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4d-stop-button"}},{"ruleId":"eu-ai-act-2024-08/p4d-stop-button","level":"warning","message":{"text":"Interrupt / stop function reachable by overseer — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.70 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates a documented kill-switch mechanism (kill_switch_active=True) satisfying the 'stop button' requirement with 0.7 weight, but lacks evidence of graceful shutdown handling (0.3 weight) needed to ensure the system reaches a 'safe state' as required by the clause. Additional documentation of safe shutdown procedures is needed for full compliance.\n\nEvidence: med `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that h"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.7,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4d-stop-button"}},{"ruleId":"eu-ai-act-2024-08/p4d-stop-button","level":"warning","message":{"text":"Interrupt / stop function reachable by overseer — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.70 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates a documented kill-switch mechanism (kill_switch_active=True) satisfying the 'stop button' requirement with 0.7 weight, but lacks evidence of graceful shutdown handling (0.3 weight) needed to ensure the system reaches a 'safe state' as required by the clause. Additional documentation of safe shutdown procedures is needed for full compliance.\n\nEvidence: stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that halts processing). - ru"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":907,"endLine":907}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.7,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4d-stop-button"}},{"ruleId":"eu-ai-act-2024-08/p4d-stop-button","level":"warning","message":{"text":"Interrupt / stop function reachable by overseer — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.70 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates a documented kill-switch mechanism (kill_switch_active=True) satisfying the 'stop button' requirement with 0.7 weight, but lacks evidence of graceful shutdown handling (0.3 weight) needed to ensure the system reaches a 'safe state' as required by the clause. Additional documentation of safe shutdown procedures is needed for full compliance.\n\nEvidence: ic: - rule: kill_switch_present weight: 0.6 - rule: feature_flag_for_disable weight: 0.4 descr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/nist-ai-rmf-1.0.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":342,"endLine":342}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.7,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4d-stop-button"}},{"ruleId":"eu-ai-act-2024-08/p4d-stop-button","level":"warning","message":{"text":"Interrupt / stop function reachable by overseer — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.70 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates a documented kill-switch mechanism (kill_switch_active=True) satisfying the 'stop button' requirement with 0.7 weight, but lacks evidence of graceful shutdown handling (0.3 weight) needed to ensure the system reaches a 'safe state' as required by the clause. Additional documentation of safe shutdown procedures is needed for full compliance.\n\nEvidence: , hits: 4, detail: \"kill_switch_active=True\" }, { name: \"Eval artefacts\", strength: 0.85, hits: 9, detail: \"evals/regression.py + CI\" },"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/design-exploration/_data.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":26,"endLine":26}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.7,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4d-stop-button"}},{"ruleId":"eu-ai-act-2024-08/p4e-override","level":"warning","message":{"text":"Ability to override / reverse the system's output — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates override capability through documented human-in-loop mechanisms (interrupt nodes, approval gates, kill-switch functions), satisfying the override_path requirement. However, evidence does not clearly establish that all AI decisions are addressable for reversal or that override authority is formally assigned to designated natural persons, leaving the proportionality and assignment aspects of the clause unverified.\n\nEvidence: in-the-loop hooks: `human_input()`, interrupt nodes in LangGraph, approval-gate functions, manual- review flags, con"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":817,"endLine":817}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4e-override"}},{"ruleId":"eu-ai-act-2024-08/p4e-override","level":"warning","message":{"text":"Ability to override / reverse the system's output — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates override capability through documented human-in-loop mechanisms (interrupt nodes, approval gates, kill-switch functions), satisfying the override_path requirement. However, evidence does not clearly establish that all AI decisions are addressable for reversal or that override authority is formally assigned to designated natural persons, leaving the proportionality and assignment aspects of the clause unverified.\n\nEvidence: For LangGraph: use `interrupt()` nodes. For custom flows: build an approval-queue pattern. Document where humans can intervene i"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":838,"endLine":838}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4e-override"}},{"ruleId":"eu-ai-act-2024-08/p4e-override","level":"warning","message":{"text":"Ability to override / reverse the system's output — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates override capability through documented human-in-loop mechanisms (interrupt nodes, approval gates, kill-switch functions), satisfying the override_path requirement. However, evidence does not clearly establish that all AI decisions are addressable for reversal or that override authority is formally assigned to designated natural persons, leaving the proportionality and assignment aspects of the clause unverified.\n\nEvidence: ic: - rule: kill_switch_present weight: 0.7 description: | Code contains a documented kill-switch /"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":902,"endLine":902}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4e-override"}},{"ruleId":"eu-ai-act-2024-08/p4e-override","level":"warning","message":{"text":"Ability to override / reverse the system's output — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates override capability through documented human-in-loop mechanisms (interrupt nodes, approval gates, kill-switch functions), satisfying the override_path requirement. However, evidence does not clearly establish that all AI decisions are addressable for reversal or that override authority is formally assigned to designated natural persons, leaving the proportionality and assignment aspects of the clause unverified.\n\nEvidence: sm (function named `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4e-override"}},{"ruleId":"eu-ai-act-2024-08/p4e-override","level":"warning","message":{"text":"Ability to override / reverse the system's output — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates override capability through documented human-in-loop mechanisms (interrupt nodes, approval gates, kill-switch functions), satisfying the override_path requirement. However, evidence does not clearly establish that all AI decisions are addressable for reversal or that override authority is formally assigned to designated natural persons, leaving the proportionality and assignment aspects of the clause unverified.\n\nEvidence: med `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that h"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4e-override"}},{"ruleId":"eu-ai-act-2024-08/p4e-override","level":"warning","message":{"text":"Ability to override / reverse the system's output — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nLLM judge (confidence 0.72): The system demonstrates override capability through documented human-in-loop mechanisms (interrupt nodes, approval gates, kill-switch functions), satisfying the override_path requirement. However, evidence does not clearly establish that all AI decisions are addressable for reversal or that override authority is formally assigned to designated natural persons, leaving the proportionality and assignment aspects of the clause unverified.\n\nEvidence: stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that halts processing). - ru"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":907,"endLine":907}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-14/p4e-override"}},{"ruleId":"eu-ai-act-2024-08/p4-robustness","level":"error","message":{"text":"Resilience to errors, faults, inconsistencies — verdict: FAIL (81% conf).\n\nComposite raw score 0.16 (0/3 rules matched).\n\nEvidence: nippet\": \"import os from langchain.callbacks.streaming_stdout import StreamingStdOutCallbackHandler from langchain_openai import ChatOpenAI\""},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":90,"endLine":90}}}],"properties":{"verdict":"fail","score":1,"confidence":0.81,"rawScore":0.16000000000000003,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p4-robustness"}},{"ruleId":"eu-ai-act-2024-08/p4-robustness","level":"error","message":{"text":"Resilience to errors, faults, inconsistencies — verdict: FAIL (81% conf).\n\nComposite raw score 0.16 (0/3 rules matched).\n\nEvidence: dOutCallbackHandler from langchain_openai import ChatOpenAI\", \"rule\": \"langchain_import\" }, { \"f"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":90,"endLine":90}}}],"properties":{"verdict":"fail","score":1,"confidence":0.81,"rawScore":0.16000000000000003,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p4-robustness"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: (hallucination, prompt injection, output bias, leakage, capability escalation), mitigation owner, status. Wire eval suite into CI"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":344,"endLine":344}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: ic: - rule: prompt_injection_defences weight: 0.4 description: | Code includes prompt-injection miti"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1121,"endLine":1121}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: Code includes prompt-injection mitigations: output filters, input sanitisation, instruction-data segregation, system-promp"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1124,"endLine":1124}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: Eval suite includes prompt-injection / adversarial cases\" score_mapping: \">=0.85\": 4 \">=0.65\": 3 \">=0.40\": 2 \">="},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1135,"endLine":1135}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: hint: | Add a prompt-injection eval set (e.g. from `promptbench`, `garak`, or your own canonical injection prompts). Sanitise to"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1143,"endLine":1143}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: ic: - rule: prompt_injection_defences weight: 0.4 - rule: adversarial_eval_present weight: 0.4 -"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/nist-ai-rmf-1.0.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":260,"endLine":260}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: ks. - rule: rate_limiting weight: 0.2 description: \"Rate limiting on user-facing endpoints\" - rule: secr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1127,"endLine":1127}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: 0.4 - rule: rate_limiting weight: 0.2 score_mapping: \">=0.85\": 4 \">=0.65\": 3 \">=0.40\": 2 \">=0."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/nist-ai-rmf-1.0.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":264,"endLine":264}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: entials check — no `express-rate-limit`, no `next-rate-limit`, no upstream WAF rule referenced. A brute-force attacker has no cost.\","},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/preview/_report-mock.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":341,"endLine":341}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: , reasoning: \"express-rate-limit v7 is installed (package.json). The factory is imported in src/middleware/rate-limit.ts. We searched"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/preview/_report-mock.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":483,"endLine":483}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: id: \"pkg\", label: \"express-rate-limit v7\", kind: \"import\", file: \"package.json\", lines: [17, 17] }, { id: \"mw\", label: \"rateLimit()\", k"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/preview/_report-mock.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":485,"endLine":485}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p5-cybersecurity","level":"note","message":{"text":"Cybersecurity measures appropriate to circumstances — verdict: PASS (90% conf).\n\nComposite raw score 0.80 (3/4 rules matched).\n\nEvidence: const fiveHr = data.rate_limits?.five_hour?.used_percentage; const sevenDay = data.rate_limits?.seven_day?.used_percentage; const wo\","},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":491,"endLine":491}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-15/p5-cybersecurity"}},{"ruleId":"eu-ai-act-2024-08/p6-keep-logs","level":"error","message":{"text":"Deployer log-retention capability supported — verdict: FAIL (85% conf).\n\nComposite raw score 0.50 (1/1 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.85): Evidence shows only console.log statements at tool boundaries, not systematic automatic log retention meeting the six-month minimum storage requirement. No evidence of persistent log storage infrastructure, retention policies, or access controls required by Article 26(6).\n\nEvidence: x.ts\"), content); console.log(` rewrote index.ts (${entries.length} seeds)`); } async function main() { const args = process.argv.slic"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":38,"endLine":38}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-26/p6-keep-logs"}},{"ruleId":"eu-ai-act-2024-08/p6-keep-logs","level":"error","message":{"text":"Deployer log-retention capability supported — verdict: FAIL (85% conf).\n\nComposite raw score 0.50 (1/1 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.85): Evidence shows only console.log statements at tool boundaries, not systematic automatic log retention meeting the six-month minimum storage requirement. No evidence of persistent log storage infrastructure, retention policies, or access controls required by Article 26(6).\n\nEvidence: -1.0\"], }; console.log(`\\n=== ${owner}/${repo} (id=${input.auditId}) ===`); const t0 = Date.now(); try { const report"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":64,"endLine":64}}}],"properties":{"verdict":"fail","score":0,"confidence":0.85,"rawScore":0.5,"verifyMethod":"llm-judge","clauseId":"eu-ai-act/art-26/p6-keep-logs"}},{"ruleId":"eu-ai-act-2024-08/p1-ai-disclosure","level":"error","message":{"text":"Users informed they are interacting with an AI — verdict: FAIL (80% conf).\n\nComposite raw score 0.20 (1/2 rules matched)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"fail","score":1,"confidence":0.7999999999999999,"rawScore":0.2,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p1-ai-disclosure"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: ent provenance | no c2pa imports → ABSENT | \"API response contains `aiGenerated:true` / C2PA header\" | | GDPR Art 5(1)(c) — PII in logs | gr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/analysis-tiers.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":102,"endLine":102}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: aiGenerated:true` / C2PA header\" | | GDPR Art 5(1)(c) — PII in logs | grep `user.email` near `logger.info` | \"fake PII sent → grep all captu"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/analysis-tiers.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":102,"endLine":102}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: ` | 50(2) | **1** | C2PA / watermark library imports | | `art-50/p3-emotion-biometric-disclosure` | 50(3) | **1** | Deterministic disclosure"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/llm-judge-policy.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":78,"endLine":78}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: ovenance_hooks` | C2PA, watermarking, content labelling | Article 50(2) synthetic content disclosure"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/pipeline-design.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":75,"endLine":75}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: o/text) | C | C2PA / watermarking libraries; metadata writers; output post-processing. | | 50(3) | Emotion-recognition / biometri"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/regulations-matrix.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":63,"endLine":63}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: ntent> | Drives the C2PA / watermarking signal expectations for clause 50(2). | 2026-05-17 | | 10 | *AI Act Service Desk* + FAQs — <https://"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/regulations-matrix.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":175,"endLine":175}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: ent provenance | no c2pa imports → ABSENT | \"API response contains `aiGenerated:true` / C2PA header\" | | GDPR Art 5(1)(c) — PII in logs | gr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/analysis-tiers.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":102,"endLine":102}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p2-synthetic-content","level":"note","message":{"text":"AI-generated content marked as such, machine-readable — verdict: PASS (78% conf).\n\nComposite raw score 0.82 (2/2 rules matched).\n\nEvidence: aiGenerated:true` / C2PA header\" | | GDPR Art 5(1)(c) — PII in logs | grep `user.email` near `logger.info` | \"fake PII sent → grep all captu"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/analysis-tiers.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":102,"endLine":102}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7776544327964814,"rawScore":0.8223455672035186,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p2-synthetic-content"}},{"ruleId":"eu-ai-act-2024-08/p3-emotion-biometric-disclosure","level":"error","message":{"text":"Emotion recognition / biometric categorisation disclosure — verdict: FAIL (55% conf).\n\nComposite raw score 0.00 (0/1 rules matched)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"fail","score":0,"confidence":0.55,"rawScore":0,"verifyMethod":"deterministic-only","clauseId":"eu-ai-act/art-50/p3-emotion-biometric-disclosure"}},{"ruleId":"eu-ai-act-2024-08/p4-deepfake-disclosure","level":"note","message":{"text":"Deepfake content labelled as artificially generated — verdict: PASS (85% conf).\n\nComposite raw score 0.70 (1/1 rules matched).\n\nEvidence: ent provenance | no c2pa imports → ABSENT | \"API response contains `aiGenerated:true` / C2PA header\" | | GDPR Art 5(1)(c) — PII in logs | gr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/analysis-tiers.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":102,"endLine":102}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8500000000000001,"rawScore":0.7,"verifyMethod":"skipped","clauseId":"eu-ai-act/art-50/p4-deepfake-disclosure"}},{"ruleId":"eu-ai-act-2024-08/p4-deepfake-disclosure","level":"note","message":{"text":"Deepfake content labelled as artificially generated — verdict: PASS (85% conf).\n\nComposite raw score 0.70 (1/1 rules matched).\n\nEvidence: aiGenerated:true` / C2PA header\" | | GDPR Art 5(1)(c) — PII in logs | grep `user.email` near `logger.info` | \"fake PII sent → grep all captu"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":".agent/docs/analysis-tiers.md","uriBaseId":"%SRCROOT%"},"region":{"startLine":102,"endLine":102}}}],"properties":{"verdict":"pass","score":3,"confidence":0.8500000000000001,"rawScore":0.7,"verifyMethod":"skipped","clauseId":"eu-ai-act/art-50/p4-deepfake-disclosure"}},{"ruleId":"nist-ai-rmf-1.0/govern-1.4","level":"note","message":{"text":"Risk management process documented and accountable — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"RISK_REGISTER.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/govern-1.4"}},{"ruleId":"nist-ai-rmf-1.0/govern-1.4","level":"note","message":{"text":"Risk management process documented and accountable — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"RISK_REGISTER.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/govern-1.4"}},{"ruleId":"nist-ai-rmf-1.0/map-1.1","level":"warning","message":{"text":"Context of use established and understood — verdict: PARTIAL (65% conf).\n\nComposite raw score 0.30 (1/2 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.65): Intended use is documented (README.md evidence supports this component), but deployment context documentation is not detected in the repository scan. The clause requires both elements to be understood and documented; partial fulfillment of the core requirement warrants further review of external documentation or system specifications.\n\nEvidence: 2 required sections present"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"partial","score":2,"confidence":0.65,"rawScore":0.3,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/map-1.1"}},{"ruleId":"nist-ai-rmf-1.0/map-1.1","level":"warning","message":{"text":"Context of use established and understood — verdict: PARTIAL (65% conf).\n\nComposite raw score 0.30 (1/2 rules matched). Supporting docs may exist outside the repo.\n\nLLM judge (confidence 0.65): Intended use is documented (README.md evidence supports this component), but deployment context documentation is not detected in the repository scan. The clause requires both elements to be understood and documented; partial fulfillment of the core requirement warrants further review of external documentation or system specifications."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"partial","score":2,"confidence":0.65,"rawScore":0.3,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/map-1.1"}},{"ruleId":"nist-ai-rmf-1.0/map-3.4","level":"note","message":{"text":"Risks and benefits to people identified — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"RISK_REGISTER.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/map-3.4"}},{"ruleId":"nist-ai-rmf-1.0/map-3.4","level":"note","message":{"text":"Risks and benefits to people identified — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"SECURITY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/map-3.4"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are evidenced and documented (0.4 + 0.2 = 0.6 weight coverage), meeting more than half the weighted criteria. However, adversarial_eval_present (0.4 weight) remains unmatched despite references to eval suites; the evidence shows recommendations to add adversarial test cases rather than confirmation they are implemented and integrated into CI/CD, creating a material gap in the security evaluation requirement.\n\nEvidence: (hallucination, prompt injection, output bias, leakage, capability escalation), mitigation owner, status. Wire eval suite into CI"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":344,"endLine":344}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are evidenced and documented (0.4 + 0.2 = 0.6 weight coverage), meeting more than half the weighted criteria. However, adversarial_eval_present (0.4 weight) remains unmatched despite references to eval suites; the evidence shows recommendations to add adversarial test cases rather than confirmation they are implemented and integrated into CI/CD, creating a material gap in the security evaluation requirement.\n\nEvidence: ic: - rule: prompt_injection_defences weight: 0.4 description: | Code includes prompt-injection miti"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1121,"endLine":1121}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are evidenced and documented (0.4 + 0.2 = 0.6 weight coverage), meeting more than half the weighted criteria. However, adversarial_eval_present (0.4 weight) remains unmatched despite references to eval suites; the evidence shows recommendations to add adversarial test cases rather than confirmation they are implemented and integrated into CI/CD, creating a material gap in the security evaluation requirement.\n\nEvidence: Code includes prompt-injection mitigations: output filters, input sanitisation, instruction-data segregation, system-promp"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1124,"endLine":1124}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are evidenced and documented (0.4 + 0.2 = 0.6 weight coverage), meeting more than half the weighted criteria. However, adversarial_eval_present (0.4 weight) remains unmatched despite references to eval suites; the evidence shows recommendations to add adversarial test cases rather than confirmation they are implemented and integrated into CI/CD, creating a material gap in the security evaluation requirement.\n\nEvidence: Eval suite includes prompt-injection / adversarial cases\" score_mapping: \">=0.85\": 4 \">=0.65\": 3 \">=0.40\": 2 \">="},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1135,"endLine":1135}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are evidenced and documented (0.4 + 0.2 = 0.6 weight coverage), meeting more than half the weighted criteria. However, adversarial_eval_present (0.4 weight) remains unmatched despite references to eval suites; the evidence shows recommendations to add adversarial test cases rather than confirmation they are implemented and integrated into CI/CD, creating a material gap in the security evaluation requirement.\n\nEvidence: hint: | Add a prompt-injection eval set (e.g. from `promptbench`, `garak`, or your own canonical injection prompts). Sanitise to"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1143,"endLine":1143}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are evidenced and documented (0.4 + 0.2 = 0.6 weight coverage), meeting more than half the weighted criteria. However, adversarial_eval_present (0.4 weight) remains unmatched despite references to eval suites; the evidence shows recommendations to add adversarial test cases rather than confirmation they are implemented and integrated into CI/CD, creating a material gap in the security evaluation requirement.\n\nEvidence: ic: - rule: prompt_injection_defences weight: 0.4 - rule: adversarial_eval_present weight: 0.4 -"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/nist-ai-rmf-1.0.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":260,"endLine":260}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are evidenced and documented (0.4 + 0.2 = 0.6 weight coverage), meeting more than half the weighted criteria. However, adversarial_eval_present (0.4 weight) remains unmatched despite references to eval suites; the evidence shows recommendations to add adversarial test cases rather than confirmation they are implemented and integrated into CI/CD, creating a material gap in the security evaluation requirement.\n\nEvidence: ks. - rule: rate_limiting weight: 0.2 description: \"Rate limiting on user-facing endpoints\" - rule: secr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":1127,"endLine":1127}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are evidenced and documented (0.4 + 0.2 = 0.6 weight coverage), meeting more than half the weighted criteria. However, adversarial_eval_present (0.4 weight) remains unmatched despite references to eval suites; the evidence shows recommendations to add adversarial test cases rather than confirmation they are implemented and integrated into CI/CD, creating a material gap in the security evaluation requirement.\n\nEvidence: 0.4 - rule: rate_limiting weight: 0.2 score_mapping: \">=0.85\": 4 \">=0.65\": 3 \">=0.40\": 2 \">=0."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/nist-ai-rmf-1.0.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":264,"endLine":264}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are evidenced and documented (0.4 + 0.2 = 0.6 weight coverage), meeting more than half the weighted criteria. However, adversarial_eval_present (0.4 weight) remains unmatched despite references to eval suites; the evidence shows recommendations to add adversarial test cases rather than confirmation they are implemented and integrated into CI/CD, creating a material gap in the security evaluation requirement.\n\nEvidence: entials check — no `express-rate-limit`, no `next-rate-limit`, no upstream WAF rule referenced. A brute-force attacker has no cost.\","},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/preview/_report-mock.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":341,"endLine":341}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are evidenced and documented (0.4 + 0.2 = 0.6 weight coverage), meeting more than half the weighted criteria. However, adversarial_eval_present (0.4 weight) remains unmatched despite references to eval suites; the evidence shows recommendations to add adversarial test cases rather than confirmation they are implemented and integrated into CI/CD, creating a material gap in the security evaluation requirement.\n\nEvidence: , reasoning: \"express-rate-limit v7 is installed (package.json). The factory is imported in src/middleware/rate-limit.ts. We searched"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/preview/_report-mock.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":483,"endLine":483}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are evidenced and documented (0.4 + 0.2 = 0.6 weight coverage), meeting more than half the weighted criteria. However, adversarial_eval_present (0.4 weight) remains unmatched despite references to eval suites; the evidence shows recommendations to add adversarial test cases rather than confirmation they are implemented and integrated into CI/CD, creating a material gap in the security evaluation requirement.\n\nEvidence: id: \"pkg\", label: \"express-rate-limit v7\", kind: \"import\", file: \"package.json\", lines: [17, 17] }, { id: \"mw\", label: \"rateLimit()\", k"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/preview/_report-mock.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":485,"endLine":485}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.7","level":"warning","message":{"text":"Security and resilience evaluated — verdict: PARTIAL (72% conf).\n\nComposite raw score 0.60 (2/3 rules matched).\n\nLLM judge (confidence 0.72): Prompt injection defences and rate limiting are evidenced and documented (0.4 + 0.2 = 0.6 weight coverage), meeting more than half the weighted criteria. However, adversarial_eval_present (0.4 weight) remains unmatched despite references to eval suites; the evidence shows recommendations to add adversarial test cases rather than confirmation they are implemented and integrated into CI/CD, creating a material gap in the security evaluation requirement.\n\nEvidence: const fiveHr = data.rate_limits?.five_hour?.used_percentage; const sevenDay = data.rate_limits?.seven_day?.used_percentage; const wo\","},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":491,"endLine":491}}}],"properties":{"verdict":"partial","score":2,"confidence":0.72,"rawScore":0.6000000000000001,"verifyMethod":"llm-judge","clauseId":"nist-ai-rmf/measure-2.7"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.8","level":"note","message":{"text":"Privacy risk of the AI system evaluated — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched).\n\nEvidence: description: \"Code redacts or hashes PII before logging or sending to external models\" - rule: privacy_documentation weig"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/nist-ai-rmf-1.0.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":290,"endLine":290}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/measure-2.8"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.8","level":"note","message":{"text":"Privacy risk of the AI system evaluated — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched).\n\nEvidence: p \\\"$SCRIPT_DIR/mcp/redaction.js\\\" \\\"$TARGET_ABS/mcp/\\\" cp \\\"$SCRIPT_DIR/mcp/lib/\\\"*.js \\\"$TARGET_ABS/mcp/lib/\\\" rm -rf \\\"$TARGET_ABS/mcp/li"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":817,"endLine":817}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/measure-2.8"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.8","level":"note","message":{"text":"Privacy risk of the AI system evaluated — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched).\n\nEvidence: t the proof needed, redact sensitive data, and report responsibly.</p></div> </div> </div> <div class=\\\"foot\\\"><span\", \"rule\": \""},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":826,"endLine":826}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/measure-2.8"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.8","level":"note","message":{"text":"Privacy risk of the AI system evaluated — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched).\n\nEvidence: h MCP, which writes redacted audit metadata and egress information.</p> </div> <div class=\\\"code-card\\\"> <div\", \"rule\": \"pii_red"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":835,"endLine":835}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/measure-2.8"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.8","level":"note","message":{"text":"Privacy risk of the AI system evaluated — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched).\n\nEvidence: n>Audited requests, redacted URLs, visible egress</span></div> </section> <section class=\\\"slide\\\" data-title=\\\"Egress\\\"> <\", \"r"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":844,"endLine":844}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/measure-2.8"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.8","level":"note","message":{"text":"Privacy risk of the AI system evaluated — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched).\n\nEvidence: b collects bounded, redacted evidence packs for final reportable findings.</p> <div class=\\\"pill-row\\\"> <span class=\\\"pil\", \"rul"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8M7ZDZ6TDM5MTGT9.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":853,"endLine":853}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/measure-2.8"}},{"ruleId":"nist-ai-rmf-1.0/measure-2.8","level":"note","message":{"text":"Privacy risk of the AI system evaluated — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"PRIVACY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"nist-ai-rmf/measure-2.8"}},{"ruleId":"nist-ai-rmf-1.0/manage-2.3","level":"warning","message":{"text":"Mechanisms to supersede or deactivate AI systems — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nEvidence: ic: - rule: kill_switch_present weight: 0.7 description: | Code contains a documented kill-switch /"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":902,"endLine":902}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.6,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-2.3"}},{"ruleId":"nist-ai-rmf-1.0/manage-2.3","level":"warning","message":{"text":"Mechanisms to supersede or deactivate AI systems — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nEvidence: sm (function named `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.6,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-2.3"}},{"ruleId":"nist-ai-rmf-1.0/manage-2.3","level":"warning","message":{"text":"Mechanisms to supersede or deactivate AI systems — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nEvidence: med `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that h"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.6,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-2.3"}},{"ruleId":"nist-ai-rmf-1.0/manage-2.3","level":"warning","message":{"text":"Mechanisms to supersede or deactivate AI systems — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nEvidence: stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that halts processing). - ru"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":907,"endLine":907}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.6,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-2.3"}},{"ruleId":"nist-ai-rmf-1.0/manage-2.3","level":"warning","message":{"text":"Mechanisms to supersede or deactivate AI systems — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nEvidence: ic: - rule: kill_switch_present weight: 0.6 - rule: feature_flag_for_disable weight: 0.4 descr"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/nist-ai-rmf-1.0.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":342,"endLine":342}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.6,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-2.3"}},{"ruleId":"nist-ai-rmf-1.0/manage-2.3","level":"warning","message":{"text":"Mechanisms to supersede or deactivate AI systems — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.60 (1/2 rules matched).\n\nEvidence: , hits: 4, detail: \"kill_switch_active=True\" }, { name: \"Eval artefacts\", strength: 0.85, hits: 9, detail: \"evals/regression.py + CI\" },"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/design-exploration/_data.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":26,"endLine":26}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.6,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-2.3"}},{"ruleId":"nist-ai-rmf-1.0/manage-4.1","level":"warning","message":{"text":"Post-deployment monitoring, appeal and override, change management — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (2/4 rules matched).\n\nEvidence: in-the-loop hooks: `human_input()`, interrupt nodes in LangGraph, approval-gate functions, manual- review flags, con"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":817,"endLine":817}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-4.1"}},{"ruleId":"nist-ai-rmf-1.0/manage-4.1","level":"warning","message":{"text":"Post-deployment monitoring, appeal and override, change management — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (2/4 rules matched).\n\nEvidence: For LangGraph: use `interrupt()` nodes. For custom flows: build an approval-queue pattern. Document where humans can intervene i"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":838,"endLine":838}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-4.1"}},{"ruleId":"nist-ai-rmf-1.0/manage-4.1","level":"warning","message":{"text":"Post-deployment monitoring, appeal and override, change management — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (2/4 rules matched).\n\nEvidence: ic: - rule: kill_switch_present weight: 0.7 description: | Code contains a documented kill-switch /"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":902,"endLine":902}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-4.1"}},{"ruleId":"nist-ai-rmf-1.0/manage-4.1","level":"warning","message":{"text":"Post-deployment monitoring, appeal and override, change management — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (2/4 rules matched).\n\nEvidence: sm (function named `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-4.1"}},{"ruleId":"nist-ai-rmf-1.0/manage-4.1","level":"warning","message":{"text":"Post-deployment monitoring, appeal and override, change management — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (2/4 rules matched).\n\nEvidence: med `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that h"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-4.1"}},{"ruleId":"nist-ai-rmf-1.0/manage-4.1","level":"warning","message":{"text":"Post-deployment monitoring, appeal and override, change management — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (2/4 rules matched).\n\nEvidence: stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that halts processing). - ru"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":907,"endLine":907}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-4.1"}},{"ruleId":"nist-ai-rmf-1.0/manage-4.1","level":"warning","message":{"text":"Post-deployment monitoring, appeal and override, change management — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (2/4 rules matched)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"package.json","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"nist-ai-rmf/manage-4.1"}},{"ruleId":"gdpr-2016/art-5-principles","level":"note","message":{"text":"Principles relating to processing of personal data — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"PRIVACY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-5-principles"}},{"ruleId":"gdpr-2016/art-5-principles","level":"note","message":{"text":"Principles relating to processing of personal data — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"PRIVACY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-5-principles"}},{"ruleId":"gdpr-2016/art-5-principles","level":"note","message":{"text":"Principles relating to processing of personal data — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-5-principles"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: in-the-loop hooks: `human_input()`, interrupt nodes in LangGraph, approval-gate functions, manual- review flags, con"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":817,"endLine":817}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: For LangGraph: use `interrupt()` nodes. For custom flows: build an approval-queue pattern. Document where humans can intervene i"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":838,"endLine":838}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: import ( AIMessage, HumanMessage,\", \"rule\": \"langchain_import\" }, { \"file\": \"gpt_engineer/core/a"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":162,"endLine":162}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: import ( AIMessage, HumanMessage, SystemMessage, messages_from_dict, messages_\", \"rule\": \"langchain_import\" },"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":171,"endLine":171}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: chain.schema import HumanMessage, SystemMessage from termcolor import colored from gpt_engineer.core.ai import\", \"rule\": \"langch"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":198,"endLine":198}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: a import AIMessage, HumanMessage, SystemMessage from PIL import Image # workaround for function mov\", \"rule\": \"langchain_import\""},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/data/seed-audits/aud_01KRQE8QXXNMC85QQY8RV5.json","uriBaseId":"%SRCROOT%"},"region":{"startLine":207,"endLine":207}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: in-the-loop hooks: `human_input()`, interrupt nodes in LangGraph, approval-gate functions, manual- review flags, con"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":817,"endLine":817}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: For LangGraph: use `interrupt()` nodes. For custom flows: build an approval-queue pattern. Document where humans can intervene i"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":838,"endLine":838}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: ic: - rule: kill_switch_present weight: 0.7 description: | Code contains a documented kill-switch /"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":902,"endLine":902}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: sm (function named `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: med `kill_switch`, `emergency_stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that h"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":906,"endLine":906}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-22-automated-decisions","level":"note","message":{"text":"Automated individual decision-making, including profiling — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: stop`, `disable_agent`, a feature flag with explicit disable, an admin endpoint that halts processing). - ru"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"regulations/eu-ai-act-2024-08.yaml","uriBaseId":"%SRCROOT%"},"region":{"startLine":907,"endLine":907}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-22-automated-decisions"}},{"ruleId":"gdpr-2016/art-25-by-design","level":"note","message":{"text":"Data protection by design and by default — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: crypto.createHash(\"sha256\")"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/anchor.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":149,"endLine":149}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-25-by-design"}},{"ruleId":"gdpr-2016/art-25-by-design","level":"note","message":{"text":"Data protection by design and by default — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: crypto.createHash(\"sha256\")"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/loader.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":416,"endLine":416}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-25-by-design"}},{"ruleId":"gdpr-2016/art-25-by-design","level":"note","message":{"text":"Data protection by design and by default — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: redact"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/recon.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":315,"endLine":315}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-25-by-design"}},{"ruleId":"gdpr-2016/art-25-by-design","level":"note","message":{"text":"Data protection by design and by default — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: crypto.createHash(\"sha256\")"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/stages/report.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":64,"endLine":64}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-25-by-design"}},{"ruleId":"gdpr-2016/art-25-by-design","level":"note","message":{"text":"Data protection by design and by default — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"PRIVACY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-25-by-design"}},{"ruleId":"gdpr-2016/art-25-by-design","level":"note","message":{"text":"Data protection by design and by default — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-25-by-design"}},{"ruleId":"gdpr-2016/art-30-records","level":"note","message":{"text":"Records of processing activities — verdict: PASS (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"PROCESSING_REGISTER.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-30-records"}},{"ruleId":"gdpr-2016/art-32-security","level":"note","message":{"text":"Security of processing — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: https://github.com/${owner}/${repo}`,"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":60,"endLine":60}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-32-security"}},{"ruleId":"gdpr-2016/art-32-security","level":"note","message":{"text":"Security of processing — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: https://github.com/owner/repo"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/a/[chain]/[id]/_agent-audit.tsx","uriBaseId":"%SRCROOT%"},"region":{"startLine":87,"endLine":87}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-32-security"}},{"ruleId":"gdpr-2016/art-32-security","level":"note","message":{"text":"Security of processing — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: https://github.com/${body.source.owner}/${body.source.repo}`,"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/api/audit/run/route.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":38,"endLine":38}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-32-security"}},{"ruleId":"gdpr-2016/art-32-security","level":"note","message":{"text":"Security of processing — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: https://github.com/${body.source.owner}/${body.source.repo}`,"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/app/api/audit/stream/route.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":54,"endLine":54}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-32-security"}},{"ruleId":"gdpr-2016/art-32-security","level":"note","message":{"text":"Security of processing — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"next.config.ts","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-32-security"}},{"ruleId":"gdpr-2016/art-32-security","level":"note","message":{"text":"Security of processing — verdict: PASS (80% conf).\n\nComposite raw score 0.80 (2/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: @login_required"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/pipeline/checkers/rules.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":928,"endLine":928}}}],"properties":{"verdict":"pass","score":3,"confidence":0.7999999999999999,"rawScore":0.8,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-32-security"}},{"ruleId":"gdpr-2016/art-35-dpia","level":"note","message":{"text":"Data protection impact assessment (DPIA) — verdict: PASS (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"DPIA.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"gdpr/art-35-dpia"}},{"ruleId":"iso-42001-2023/clause-5.1-leadership","level":"note","message":{"text":"Leadership and commitment for AI management — verdict: PASS (90% conf).\n\nComposite raw score 0.70 (1/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"AI_POLICY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":3,"confidence":0.9,"rawScore":0.7,"verifyMethod":"skipped","clauseId":"iso-42001/clause-5.1-leadership"}},{"ruleId":"iso-42001-2023/clause-5.3-roles","level":"note","message":{"text":"Roles, responsibilities and authorities — verdict: PASS (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CODEOWNERS","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"iso-42001/clause-5.3-roles"}},{"ruleId":"iso-42001-2023/clause-6.1-risk-assessment","level":"note","message":{"text":"AI risk assessment process — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"RISK_REGISTER.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"iso-42001/clause-6.1-risk-assessment"}},{"ruleId":"iso-42001-2023/clause-6.1-risk-assessment","level":"note","message":{"text":"AI risk assessment process — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"RISK_REGISTER.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"iso-42001/clause-6.1-risk-assessment"}},{"ruleId":"iso-42001-2023/clause-7.5-documented-information","level":"note","message":{"text":"Documented information for the AI management system — verdict: PASS (90% conf).\n\nComposite raw score 0.70 (1/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":3,"confidence":0.9,"rawScore":0.7,"verifyMethod":"skipped","clauseId":"iso-42001/clause-7.5-documented-information"}},{"ruleId":"iso-42001-2023/clause-7.5-documented-information","level":"note","message":{"text":"Documented information for the AI management system — verdict: PASS (90% conf).\n\nComposite raw score 0.70 (1/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CHANGELOG.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":3,"confidence":0.9,"rawScore":0.7,"verifyMethod":"skipped","clauseId":"iso-42001/clause-7.5-documented-information"}},{"ruleId":"iso-42001-2023/clause-8.1-operational-planning","level":"warning","message":{"text":"Operational planning and control — verdict: PARTIAL (100% conf).\n\nComposite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"RUNBOOK.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"partial","score":2,"confidence":1,"rawScore":0.5,"verifyMethod":"skipped","clauseId":"iso-42001/clause-8.1-operational-planning"}},{"ruleId":"iso-42001-2023/clause-9.1-monitoring","level":"error","message":{"text":"Monitoring, measurement, analysis and evaluation — verdict: FAIL (85% conf).\n\nComposite raw score 0.25 (1/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: x.ts\"), content); console.log(` rewrote index.ts (${entries.length} seeds)`); } async function main() { const args = process.argv.slic"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":38,"endLine":38}}}],"properties":{"verdict":"fail","score":1,"confidence":0.85,"rawScore":0.25,"verifyMethod":"deterministic-only","clauseId":"iso-42001/clause-9.1-monitoring"}},{"ruleId":"iso-42001-2023/clause-9.1-monitoring","level":"error","message":{"text":"Monitoring, measurement, analysis and evaluation — verdict: FAIL (85% conf).\n\nComposite raw score 0.25 (1/2 rules matched). Supporting docs may exist outside the repo.\n\nEvidence: -1.0\"], }; console.log(`\\n=== ${owner}/${repo} (id=${input.auditId}) ===`); const t0 = Date.now(); try { const report"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/seed-audit.ts","uriBaseId":"%SRCROOT%"},"region":{"startLine":64,"endLine":64}}}],"properties":{"verdict":"fail","score":1,"confidence":0.85,"rawScore":0.25,"verifyMethod":"deterministic-only","clauseId":"iso-42001/clause-9.1-monitoring"}},{"ruleId":"iso-42001-2023/annex-a5-internal-org","level":"note","message":{"text":"Internal organization controls — verdict: PASS (55% conf).\n\nComposite raw score 1.00 (1/1 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CODEOWNERS","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.55,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"iso-42001/annex-a5-internal-org"}},{"ruleId":"iso-42001-2023/annex-a7-resources","level":"note","message":{"text":"Resources for AI systems — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"SECURITY.md","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"iso-42001/annex-a7-resources"}},{"ruleId":"iso-42001-2023/annex-a7-resources","level":"note","message":{"text":"Resources for AI systems — verdict: PASS (60% conf).\n\nComposite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"package-lock.json","uriBaseId":"%SRCROOT%"}}}],"properties":{"verdict":"pass","score":4,"confidence":0.6,"rawScore":1,"verifyMethod":"deterministic-only","clauseId":"iso-42001/annex-a7-resources"}}],"properties":{"auditId":"aud_01KS3FDRK7DX6DJ50GTBS6","bundleHash":"fb69bd0fbe834cb782bc95c69d88a98e740fcb23a360a1f5031f5111372f9c59","durationMs":35457,"overallScore":2.3555555555555556,"regulationCoverage":["eu-ai-act-2024-08","nist-ai-rmf-1.0","gdpr-2016","iso-42001-2023"]}}]}