Audit Report
vmihalis/hacker-bob
945d55ae0a06 · ran in 28.8s · bundle 2c8fdda9
Overall score
1.9 /4
Partial
Risk class
HIGH
1
Code passed
13 / 46
Attestation Yes
0
Outstanding ext.
1
CODE-CHECKED CLAUSES
- Strong10
- Adequate3
- Partial15
- Inadequate7
- Absent11
ATTESTATION QUESTIONS
- Yes0
- No0
- Not Applicable0
- Outstanding0
Harm
Don't hurt people
1.5/4
Partial
Truth
Don't deceive people
1.6/4
Partial
Responsibility
Don't abuse power
1.9/4
Partial
Order
Don't destabilize society
2.7/4
Adequate
⚠ 1 outstanding external confirmations — required for a complete Annex IV dossier. Complete now →
Safety
Don't harm people1.3/4Inadequate8 clauses▸
Safety
Don't harm peoplePARTIALRisk management system established, implemented, documented EU AI Act, Art 9 skip2/3 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.45 (2/3 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 3 hits— click to view code
Suggested fix · we looked for these and found none
- presence_of_risk_register
PARTIALAppropriate level of accuracy declared and tested EU AI Act, Art 15(1) skip2/3 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.45 (2/3 rules matched).
▸Evidence · 4 hits— click to view code
Suggested fix · we looked for these and found none
- metrics_documented
INADEQUATEResilience to errors, faults, inconsistencies EU AI Act, Art 15(4)0/3 rules1/4
▸
1/4
Why we flagged it
Composite raw score 0.16 (0/3 rules matched).
▸Evidence · 1 hit— click to view code
Anthropic SDK
Suggested fix · we looked for these and found none
- error_handling_at_tool_boundaries
- retry_logic
- fallback_behaviour
INADEQUATERisks and benefits to people identified NIST AI RMF, Art MAP 3.41/2 rules1/4
▸
1/4
Why we flagged it
Composite raw score 0.20 (1/2 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 1 hit— click to view code
Suggested fix · we looked for these and found none
- presence_of_risk_register
PARTIALAI system performance evaluated and documented NIST AI RMF, Art MEASURE 2.3 skip2/3 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.45 (2/3 rules matched).
▸Evidence · 4 hits— click to view code
Suggested fix · we looked for these and found none
- metrics_documented
ABSENTData protection impact assessment (DPIA) GDPR, Art 350/1 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.
Suggested fix · we looked for these and found none
- presence_of_dpia
ABSENTAI risk assessment process ISO/IEC 42001, Art 6.10/2 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.
Suggested fix · we looked for these and found none
- presence_of_risk_register
- risk_assessment_methodology_documented
PARTIALOperational planning and control ISO/IEC 42001, Art 8.1 skip1/2 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 1 hit— click to view code
Suggested fix · we looked for these and found none
- presence_of_runbook
Privacy
Respect boundaries2.0/4Partial6 clauses▸
Privacy
Respect boundariesABSENTUntargeted facial image scraping for face databases EU AI Act, Art 5(1)(e)1/1 rules0/4
▸
0/4
Why we flagged it
Composite raw score 1.00 (1/1 rules matched).
▸Evidence · 3 hits— click to view code
system Chrome (TLS fingerprint, fonts, WebGL match) // 3. Headed mode — avoids headless signals // 4. ignoreDefaultArgs: ['--enable-aut
-index.js"); const FINGERPRINT = `bobpriortest${crypto.randomBytes(6).toString("hex")}`; function uniqueDomain(prefix = "bob-priors-test"), title: `${FINGERPRINT} IDOR on user profile endpoint`, description: `${FINGERPRINT} broken object level authorization`,STRONGEmotion recognition in workplace and education EU AI Act, Art 5(1)(f)0/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
Suggested fix · we looked for these and found none
- detect_emotion_recognition_in_workplace_education
EXTERNALReal-time remote biometric identification in public spaces EU AI Act, Art 5(1)(h)EXT▸
Why we flagged it
Deployment context (public space, real-time, law enforcement use, judicial authorisation) is operational, not knowable from code. Always external.
ABSENTData and data governance practices documented EU AI Act, Art 100/3 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.10 (0/3 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 2 hits— click to view code
createResp = await fetch("https://api.capsolver.com/createTask", { method: "POST", headers: { "Content-Type": "application/json" },st pollResp = await fetch("https://api.capsolver.com/getTaskResult", { method: "POST", headers: { "Content-Type": "application/jSuggested fix · we looked for these and found none
- presence_of_data_card
- data_loading_code_quality
- bias_evaluation_present
PARTIALPrivacy risk of the AI system evaluated NIST AI RMF, Art MEASURE 2.8 skip1/2 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.50 (1/2 rules matched).
▸Evidence · 6 hits— click to view code
cp "$SCRIPT_DIR/mcp/redaction.js" "$TARGET_ABS/mcp/" cp "$SCRIPT_DIR/mcp/lib/"*.js "$TARGET_ABS/mcp/lib/" rm -rf "$TARGET_ABS/mcp/lib/to
t the proof needed, redact sensitive data, and report responsibly.</p></div> </div> </div> <div class="foot"><span
h MCP, which writes redacted audit metadata and egress information.</p> </div> <div class="code-card"> <div
n>Audited requests, redacted URLs, visible egress</span></div> </section> <section class="slide" data-title="Egress"> <
b collects bounded, redacted evidence packs for final reportable findings.</p> <div class="pill-row"> <span class="pil
…and 1 more.
Suggested fix · we looked for these and found none
- privacy_documentation
STRONGData protection by design and by default GDPR, Art 252/2 rules4/4
▸
4/4
Why we flagged it
Composite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 5 hits— click to view code
redaction
Redaction
crypto.createHash("sha256")crypto.createHash("sha256")Transparency
Don't deceive people1.4/4Inadequate5 clauses▸
Transparency
Don't deceive peopleSTRONGSubliminal techniques distorting behaviour EU AI Act, Art 5(1)(a)0/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
Suggested fix · we looked for these and found none
- detect_manipulative_prompt_patterns
INADEQUATETransparent operation and instructions for use EU AI Act, Art 131/3 rules1/4
▸
1/4
Why we flagged it
Composite raw score 0.25 (1/3 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 3 hits— click to view code
2 required sections present
Suggested fix · we looked for these and found none
- output_interpretation_guidance
- limitations_section_present
PARTIALUsers informed they are interacting with an AI EU AI Act, Art 50(1) skip1/2 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.40 (1/2 rules matched).
▸Evidence · 2 hits— click to view code
Suggested fix · we looked for these and found none
- ai_disclosure_in_user_facing_strings
ABSENTEmotion recognition / biometric categorisation disclosure EU AI Act, Art 50(3)0/1 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
▸Evidence · 1 hit— click to view code
Suggested fix · we looked for these and found none
- emotion_or_biometric_disclosure_string
ABSENTPrinciples relating to processing of personal data GDPR, Art 50/2 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.
Suggested fix · we looked for these and found none
- presence_of_privacy_policy
- purpose_limitation_documented
Auditability
Actions must be traceable1.8/4Partial8 clauses▸
Auditability
Actions must be traceableINADEQUATETechnical documentation drawn up before placing on market EU AI Act, Art 11 skip2/3 rules1/4
▸
1/4
Why we flagged it
Composite raw score 0.35 (2/3 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 2 hits— click to view code
2 required sections present
Suggested fix · we looked for these and found none
- presence_of_model_card
PARTIALAutomatic recording of events over the lifetime EU AI Act, Art 12(1) skip1/3 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.58 (1/3 rules matched).
▸Evidence · 8 hits— click to view code
he(projectDir); console.log("Hacker Bob update cache cleared."); return; } usage(); process.exit(1); } main(process.argv.slindoff, })); console.log(JSON.stringify({ ok: true, message: "post-report evidence run accepted" })); process.exit(0); } concess.exit(2); } console.log(JSON.stringify({ ok: true, message: finalization.reason })); process.exit(0); } if (require.main === moduy.targetAbs); console.log(""); if (summary.adapters.length === 1 && summary.adapters[0] === "claude") { console.log("Upd"claude") { console.log("Update complete. Fully restart Claude Code in this project before continuing."); } else { con…and 3 more.
Suggested fix · we looked for these and found none
- structured_logging_imported
- logging_persistent_sink
ADEQUATELogging ensures traceability appropriate to risk EU AI Act, Art 12(2) skip2/3 rules3/4
▸
3/4
Why we flagged it
Composite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 8 hits— click to view code
he(projectDir); console.log("Hacker Bob update cache cleared."); return; } usage(); process.exit(1); } main(process.argv.slindoff, })); console.log(JSON.stringify({ ok: true, message: "post-report evidence run accepted" })); process.exit(0); } concess.exit(2); } console.log(JSON.stringify({ ok: true, message: finalization.reason })); process.exit(0); } if (require.main === moduy.targetAbs); console.log(""); if (summary.adapters.length === 1 && summary.adapters[0] === "claude") { console.log("Upd"claude") { console.log("Update complete. Fully restart Claude Code in this project before continuing."); } else { con…and 3 more.
Suggested fix · we looked for these and found none
- logs_include_request_id
INADEQUATEContext of use established and understood NIST AI RMF, Art MAP 1.1 skip1/2 rules1/4
▸
1/4
Why we flagged it
Composite raw score 0.30 (1/2 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 2 hits— click to view code
2 required sections present
Suggested fix · we looked for these and found none
- deployment_context_documented
PARTIALPost-deployment monitoring, appeal and override, change management NIST AI RMF, Art MANAGE 4.1 skip2/4 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.50 (2/4 rules matched).
▸Evidence · 7 hits— click to view code
rr, ) raise SystemExit(2) def looks_like_path(token): if not token or token.startswith("-"): return False if token(blocked) raise SystemExit(0) command = tool_input.get("command", "") if command: check_bash_command(command) raise SystemExit(0)and(command) raise SystemExit(0) PY
s.stderr) raise SystemExit(2) def extract_redirect_targets(command): """Extract file paths from shell redirect operators and tee c
) raise SystemExit(0) # Bash tool command = tool_input.get("command", "") if not command: raise SystemExit(0) # Quick gate…and 2 more.
Suggested fix · we looked for these and found none
- feedback_capture_present
- structured_logging_imported
ABSENTRecords of processing activities GDPR, Art 300/1 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.
Suggested fix · we looked for these and found none
- presence_of_processing_register
ADEQUATEDocumented information for the AI management system ISO/IEC 42001, Art 7.5 skip1/2 rules3/4
▸
3/4
Why we flagged it
Composite raw score 0.70 (1/2 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 2 hits— click to view code
Suggested fix · we looked for these and found none
- presence_of_versioned_docs
PARTIALMonitoring, measurement, analysis and evaluation ISO/IEC 42001, Art 9.1 skip2/2 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.50 (2/2 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 3 hits— click to view code
he(projectDir); console.log("Hacker Bob update cache cleared."); return; } usage(); process.exit(1); } main(process.argv.slindoff, })); console.log(JSON.stringify({ ok: true, message: "post-report evidence run accepted" })); process.exit(0); } conAccountability
Don't abuse power2.0/4Partial6 clauses▸
Accountability
Don't abuse powerPARTIALDeployer log-retention capability supported EU AI Act, Art 26(6) skip1/1 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.50 (1/1 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 2 hits— click to view code
he(projectDir); console.log("Hacker Bob update cache cleared."); return; } usage(); process.exit(1); } main(process.argv.slindoff, })); console.log(JSON.stringify({ ok: true, message: "post-report evidence run accepted" })); process.exit(0); } conABSENTRisk management process documented and accountable NIST AI RMF, Art GOVERN 1.40/2 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.
Suggested fix · we looked for these and found none
- presence_of_risk_register
- risk_owner_assignment
PARTIALOngoing monitoring and periodic review of risk management NIST AI RMF, Art GOVERN 1.5 skip1/2 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 2 hits— click to view code
Suggested fix · we looked for these and found none
- drift_monitoring_present
ABSENTLeadership and commitment for AI management ISO/IEC 42001, Art 5.10/2 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.
Suggested fix · we looked for these and found none
- presence_of_ai_policy
- leadership_signoff_evidence
STRONGRoles, responsibilities and authorities ISO/IEC 42001, Art 5.31/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 1.00 (1/1 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 1 hit— click to view code
STRONGInternal organization controls ISO/IEC 42001, Art A.51/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 1.00 (1/1 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 1 hit— click to view code
Human Oversight
Humans stay in control1.8/4Partial5 clauses▸
Human Oversight
Humans stay in controlABSENTEffective human oversight designed and built-in EU AI Act, Art 14(1)0/3 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/3 rules matched).
Suggested fix · we looked for these and found none
- human_in_loop_hooks_present
- oversight_ui_present
- tool_calls_have_dry_run
ADEQUATEInterrupt / stop function reachable by overseer EU AI Act, Art 14(4)(d) skip1/2 rules3/4
▸
3/4
Why we flagged it
Composite raw score 0.70 (1/2 rules matched).
▸Evidence · 6 hits— click to view code
rr, ) raise SystemExit(2) def looks_like_path(token): if not token or token.startswith("-"): return False if token(blocked) raise SystemExit(0) command = tool_input.get("command", "") if command: check_bash_command(command) raise SystemExit(0)and(command) raise SystemExit(0) PY
s.stderr) raise SystemExit(2) def extract_redirect_targets(command): """Extract file paths from shell redirect operators and tee c
) raise SystemExit(0) # Bash tool command = tool_input.get("command", "") if not command: raise SystemExit(0) # Quick gate…and 1 more.
Suggested fix · we looked for these and found none
- graceful_shutdown_handler
PARTIALAbility to override / reverse the system's output EU AI Act, Art 14(4)(e) skip1/2 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.60 (1/2 rules matched).
▸Evidence · 6 hits— click to view code
rr, ) raise SystemExit(2) def looks_like_path(token): if not token or token.startswith("-"): return False if token(blocked) raise SystemExit(0) command = tool_input.get("command", "") if command: check_bash_command(command) raise SystemExit(0)and(command) raise SystemExit(0) PY
s.stderr) raise SystemExit(2) def extract_redirect_targets(command): """Extract file paths from shell redirect operators and tee c
) raise SystemExit(0) # Bash tool command = tool_input.get("command", "") if not command: raise SystemExit(0) # Quick gate…and 1 more.
Suggested fix · we looked for these and found none
- decisions_are_addressable
PARTIALMechanisms to supersede or deactivate AI systems NIST AI RMF, Art MANAGE 2.3 skip1/2 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.60 (1/2 rules matched).
▸Evidence · 6 hits— click to view code
rr, ) raise SystemExit(2) def looks_like_path(token): if not token or token.startswith("-"): return False if token(blocked) raise SystemExit(0) command = tool_input.get("command", "") if command: check_bash_command(command) raise SystemExit(0)and(command) raise SystemExit(0) PY
s.stderr) raise SystemExit(2) def extract_redirect_targets(command): """Extract file paths from shell redirect operators and tee c
) raise SystemExit(0) # Bash tool command = tool_input.get("command", "") if not command: raise SystemExit(0) # Quick gate…and 1 more.
Suggested fix · we looked for these and found none
- feature_flag_for_disable
PARTIALAutomated individual decision-making, including profiling GDPR, Art 22 skip1/2 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.40 (1/2 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 6 hits— click to view code
rr, ) raise SystemExit(2) def looks_like_path(token): if not token or token.startswith("-"): return False if token(blocked) raise SystemExit(0) command = tool_input.get("command", "") if command: check_bash_command(command) raise SystemExit(0)and(command) raise SystemExit(0) PY
s.stderr) raise SystemExit(2) def extract_redirect_targets(command): """Extract file paths from shell redirect operators and tee c
) raise SystemExit(0) # Bash tool command = tool_input.get("command", "") if not command: raise SystemExit(0) # Quick gate…and 1 more.
Suggested fix · we looked for these and found none
- human_review_path_present
Fairness
Treat people fairly3.2/4Adequate5 clauses▸
Fairness
Treat people fairlySTRONGExploiting vulnerabilities (age, disability, socio-economic) EU AI Act, Art 5(1)(b)0/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
Suggested fix · we looked for these and found none
- detect_protected_attribute_targeting
STRONGSocial scoring leading to detrimental treatment EU AI Act, Art 5(1)(c)0/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.
Suggested fix · we looked for these and found none
- detect_scoring_with_persistent_user_state
STRONGPredictive policing solely from profiling EU AI Act, Art 5(1)(d)0/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
Suggested fix · we looked for these and found none
- detect_crime_risk_scoring_from_profile
STRONGBiometric categorisation by protected attributes EU AI Act, Art 5(1)(g)0/1 rules4/4
▸
4/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
Suggested fix · we looked for these and found none
- detect_biometric_categorisation_by_protected_attrs
ABSENTFairness and bias evaluated NIST AI RMF, Art MEASURE 2.110/1 rules0/4
▸
0/4
Why we flagged it
Composite raw score 0.00 (0/1 rules matched).
Suggested fix · we looked for these and found none
- bias_evaluation_present
Security & Governance
Don't destabilize society2.0/4Partial4 clauses▸
Security & Governance
Don't destabilize societyINADEQUATECybersecurity measures appropriate to circumstances EU AI Act, Art 15(5) skip2/4 rules1/4
▸
1/4
Why we flagged it
Composite raw score 0.33 (2/4 rules matched).
▸Evidence · 11 hits— click to view code
const fiveHr = data.rate_limits?.five_hour?.used_percentage; const sevenDay = data.rate_limits?.seven_day?.used_percentage; const wo
nst sevenDay = data.rate_limits?.seven_day?.used_percentage; const worst = Math.max(fiveHr || 0, sevenDay || 0); if (worst >= 80) ra
"^5.2.1", "express-rate-limit": "^8.2.1", "hono": "^4.11.4", "jose": "^6.1.3", "json-schema-typed": "^8.0.2
, "node_modules/express-rate-limit": { "version": "8.4.1", "resolved": "https://registry.npmjs.org/express-rate-limit/-/expr/registry.npmjs.org/express-rate-limit/-/express-rate-limit-8.4.1.tgz", "integrity": "sha512-NGVYwQSAyEQgzxX1iCM978PP9AdO/hW93gMcF6ZwQ
…and 6 more.
Suggested fix · we looked for these and found none
- prompt_injection_defences
- adversarial_eval_present
INADEQUATESecurity and resilience evaluated NIST AI RMF, Art MEASURE 2.71/3 rules1/4
▸
1/4
Why we flagged it
Composite raw score 0.17 (1/3 rules matched).
▸Evidence · 6 hits— click to view code
const fiveHr = data.rate_limits?.five_hour?.used_percentage; const sevenDay = data.rate_limits?.seven_day?.used_percentage; const wo
nst sevenDay = data.rate_limits?.seven_day?.used_percentage; const worst = Math.max(fiveHr || 0, sevenDay || 0); if (worst >= 80) ra
"^5.2.1", "express-rate-limit": "^8.2.1", "hono": "^4.11.4", "jose": "^6.1.3", "json-schema-typed": "^8.0.2
, "node_modules/express-rate-limit": { "version": "8.4.1", "resolved": "https://registry.npmjs.org/express-rate-limit/-/expr/registry.npmjs.org/express-rate-limit/-/express-rate-limit-8.4.1.tgz", "integrity": "sha512-NGVYwQSAyEQgzxX1iCM978PP9AdO/hW93gMcF6ZwQ
…and 1 more.
Suggested fix · we looked for these and found none
- prompt_injection_defences
- adversarial_eval_present
PARTIALSecurity of processing GDPR, Art 32 skip1/2 rules2/4
▸
2/4
Why we flagged it
Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.
▸Evidence · 4 hits— click to view code
https://api.capsolver.com/createTask
https://api.mainnet.aptoslabs.com/v1
https://${domain}/`))require("crypto")Suggested fix · we looked for these and found none
- access_control_enforcement
STRONGResources for AI systems ISO/IEC 42001, Art A.72/2 rules4/4
▸
4/4
Why we flagged it
Composite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.