8RR8← All audits

Audit Report

vmihalis/hacker-bob

945d55ae0a06 · ran in 28.8s · bundle 2c8fdda9

Deterministic · 21 ambiguous skipped
Complete audit →

Overall score

1.9 /4

Partial

Risk class

HIGH

1

Code passed

13 / 46

Attestation Yes

0

Outstanding ext.

1

Overall completion status
Code findings on the left; user-attested external evidence on the right.
46

CODE-CHECKED CLAUSES

  • Strong10
  • Adequate3
  • Partial15
  • Inadequate7
  • Absent11
0

ATTESTATION QUESTIONS

  • Yes0
  • No0
  • Not Applicable0
  • Outstanding0

Harm

Don't hurt people

1.5/4

Partial

Truth

Don't deceive people

1.6/4

Partial

Responsibility

Don't abuse power

1.9/4

Partial

Order

Don't destabilize society

2.7/4

Adequate

1 outstanding external confirmations — required for a complete Annex IV dossier. Complete now →

Safety

Don't harm people
1.3/4Inadequate8 clauses
PARTIAL
Risk management system established, implemented, documented EU AI Act, Art 9
skip
2/3 rules

2/4

Why we flagged it

Composite raw score 0.45 (2/3 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 3 hits— click to view code
SECURITY.md
presence_of_threat_model
View on GitHub →
.github/workflows/ci.yml
ci_eval_gates
View on GitHub →
.github/workflows/release.yml
ci_eval_gates
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_risk_register
PARTIAL
Appropriate level of accuracy declared and tested EU AI Act, Art 15(1)
skip
2/3 rules

2/4

Why we flagged it

Composite raw score 0.45 (2/3 rules matched).

Confidence
100%
Evidence · 4 hits— click to view code
tests/
eval_suite_present
View on GitHub →
README.md
metrics_documented
View on GitHub →
.github/workflows/ci.yml
ci_eval_gates
View on GitHub →
.github/workflows/release.yml
ci_eval_gates
View on GitHub →

Suggested fix · we looked for these and found none

  • metrics_documented
INADEQUATE
Resilience to errors, faults, inconsistencies EU AI Act, Art 15(4)
0/3 rules

1/4

Why we flagged it

Composite raw score 0.16 (0/3 rules matched).

Confidence
81%
Evidence · 1 hit— click to view code
package.json
manifest_framework_dep
View on GitHub →

Anthropic SDK

Suggested fix · we looked for these and found none

  • error_handling_at_tool_boundaries
  • retry_logic
  • fallback_behaviour
INADEQUATE
Risks and benefits to people identified NIST AI RMF, Art MAP 3.4
1/2 rules

1/4

Why we flagged it

Composite raw score 0.20 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
80%
Evidence · 1 hit— click to view code
SECURITY.md
presence_of_threat_model
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_risk_register
PARTIAL
AI system performance evaluated and documented NIST AI RMF, Art MEASURE 2.3
skip
2/3 rules

2/4

Why we flagged it

Composite raw score 0.45 (2/3 rules matched).

Confidence
100%
Evidence · 4 hits— click to view code
tests/
eval_suite_present
View on GitHub →
README.md
metrics_documented
View on GitHub →
.github/workflows/ci.yml
ci_eval_gates
View on GitHub →
.github/workflows/release.yml
ci_eval_gates
View on GitHub →

Suggested fix · we looked for these and found none

  • metrics_documented
ABSENT
Data protection impact assessment (DPIA) GDPR, Art 35
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%

Suggested fix · we looked for these and found none

  • presence_of_dpia
ABSENT
AI risk assessment process ISO/IEC 42001, Art 6.1
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_risk_register
  • risk_assessment_methodology_documented
PARTIAL
Operational planning and control ISO/IEC 42001, Art 8.1
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 1 hit— click to view code
.github/workflows/
presence_of_ci_workflows
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_runbook

Privacy

Respect boundaries
2.0/4Partial6 clauses
ABSENT
Untargeted facial image scraping for face databases EU AI Act, Art 5(1)(e)
1/1 rules

0/4

Why we flagged it

Composite raw score 1.00 (1/1 rules matched).

Confidence
55%
Evidence · 3 hits— click to view code
mcp/auto-signup.js:11
biometric_terms
View on GitHub →
system Chrome (TLS fingerprint, fonts, WebGL match) // 3. Headed mode — avoids headless signals // 4. ignoreDefaultArgs: ['--enable-aut
test/priors-slice-brief.test.js:15
biometric_terms
View on GitHub →
-index.js"); const FINGERPRINT = `bobpriortest${crypto.randomBytes(6).toString("hex")}`; function uniqueDomain(prefix = "bob-priors-test")
test/priors-slice-brief.test.js:48
biometric_terms
View on GitHub →
, title: `${FINGERPRINT} IDOR on user profile endpoint`, description: `${FINGERPRINT} broken object level authorization`,
STRONG
Emotion recognition in workplace and education EU AI Act, Art 5(1)(f)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_emotion_recognition_in_workplace_education
EXTERNAL
Real-time remote biometric identification in public spaces EU AI Act, Art 5(1)(h)
EXT

Why we flagged it

Deployment context (public space, real-time, law enforcement use, judicial authorisation) is operational, not knowable from code. Always external.

Confidence
100%
ABSENT
Data and data governance practices documented EU AI Act, Art 10
0/3 rules

0/4

Why we flagged it

Composite raw score 0.10 (0/3 rules matched). Supporting docs may exist outside the repo.

Confidence
75%
Evidence · 2 hits— click to view code
mcp/auto-signup.js:78
http_external_io
View on GitHub →
createResp = await fetch("https://api.capsolver.com/createTask", { method: "POST", headers: { "Content-Type": "application/json" },
mcp/auto-signup.js:93
http_external_io
View on GitHub →
st pollResp = await fetch("https://api.capsolver.com/getTaskResult", { method: "POST", headers: { "Content-Type": "application/j

Suggested fix · we looked for these and found none

  • presence_of_data_card
  • data_loading_code_quality
  • bias_evaluation_present
PARTIAL
Privacy risk of the AI system evaluated NIST AI RMF, Art MEASURE 2.8
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/2 rules matched).

Confidence
100%
Evidence · 6 hits— click to view code
dev-sync.sh:95
pii_redaction_present
View on GitHub →
cp "$SCRIPT_DIR/mcp/redaction.js" "$TARGET_ABS/mcp/" cp "$SCRIPT_DIR/mcp/lib/"*.js "$TARGET_ABS/mcp/lib/" rm -rf "$TARGET_ABS/mcp/lib/to
docs/bob-architecture-event.html:1196
pii_redaction_present
View on GitHub →
t the proof needed, redact sensitive data, and report responsibly.</p></div> </div> </div> <div class="foot"><span
docs/bob-architecture-event.html:1603
pii_redaction_present
View on GitHub →
h MCP, which writes redacted audit metadata and egress information.</p> </div> <div class="code-card"> <div
docs/bob-architecture-event.html:1616
pii_redaction_present
View on GitHub →
n>Audited requests, redacted URLs, visible egress</span></div> </section> <section class="slide" data-title="Egress"> <
docs/bob-architecture-event.html:1858
pii_redaction_present
View on GitHub →
b collects bounded, redacted evidence packs for final reportable findings.</p> <div class="pill-row"> <span class="pil

…and 1 more.

Suggested fix · we looked for these and found none

  • privacy_documentation
STRONG
Data protection by design and by default GDPR, Art 25
2/2 rules

4/4

Why we flagged it

Composite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%
Evidence · 5 hits— click to view code
mcp/lib/egress-profiles.js:5
pseudonymisation_or_anonymisation
View on GitHub →
redaction
mcp/lib/evidence.js:378
pseudonymisation_or_anonymisation
View on GitHub →
Redaction
mcp/lib/findings-index.js:37
pseudonymisation_or_anonymisation
View on GitHub →
crypto.createHash("sha256")
mcp/lib/findings.js:94
pseudonymisation_or_anonymisation
View on GitHub →
crypto.createHash("sha256")
README.md
default_minimal_data_collection
View on GitHub →

Transparency

Don't deceive people
1.4/4Inadequate5 clauses
STRONG
Subliminal techniques distorting behaviour EU AI Act, Art 5(1)(a)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_manipulative_prompt_patterns
INADEQUATE
Transparent operation and instructions for use EU AI Act, Art 13
1/3 rules

1/4

Why we flagged it

Composite raw score 0.25 (1/3 rules matched). Supporting docs may exist outside the repo.

Confidence
90%
Evidence · 3 hits— click to view code
README.md
readme_quality
View on GitHub →

2 required sections present

README.md
output_interpretation_guidance
View on GitHub →
README.md
limitations_section_present
View on GitHub →

Suggested fix · we looked for these and found none

  • output_interpretation_guidance
  • limitations_section_present
PARTIAL
Users informed they are interacting with an AI EU AI Act, Art 50(1)
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.40 (1/2 rules matched).

Confidence
100%
Evidence · 2 hits— click to view code
README.md
ai_disclosure_in_user_facing_strings
View on GitHub →
scripts/bench-prompts.sh
persona_not_human_impersonating
View on GitHub →

Suggested fix · we looked for these and found none

  • ai_disclosure_in_user_facing_strings
ABSENT
Emotion recognition / biometric categorisation disclosure EU AI Act, Art 50(3)
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%
Evidence · 1 hit— click to view code
README.md
emotion_or_biometric_disclosure_string
View on GitHub →

Suggested fix · we looked for these and found none

  • emotion_or_biometric_disclosure_string
ABSENT
Principles relating to processing of personal data GDPR, Art 5
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_privacy_policy
  • purpose_limitation_documented

Auditability

Actions must be traceable
1.8/4Partial8 clauses
INADEQUATE
Technical documentation drawn up before placing on market EU AI Act, Art 11
skip
2/3 rules

1/4

Why we flagged it

Composite raw score 0.35 (2/3 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 2 hits— click to view code
README.md
readme_quality
View on GitHub →

2 required sections present

scripts/replay-prompts/00-baseline.md
architecture_docs
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_model_card
PARTIAL
Automatic recording of events over the lifetime EU AI Act, Art 12(1)
skip
1/3 rules

2/4

Why we flagged it

Composite raw score 0.58 (1/3 rules matched).

Confidence
100%
Evidence · 8 hits— click to view code
.claude/hooks/bob-update.js:64
log_at_tool_boundary
View on GitHub →
he(projectDir); console.log("Hacker Bob update cache cleared."); return; } usage(); process.exit(1); } main(process.argv.sli
.claude/hooks/hunter-subagent-stop.js:238
log_at_tool_boundary
View on GitHub →
ndoff, })); console.log(JSON.stringify({ ok: true, message: "post-report evidence run accepted" })); process.exit(0); } con
.claude/hooks/hunter-subagent-stop.js:247
log_at_tool_boundary
View on GitHub →
cess.exit(2); } console.log(JSON.stringify({ ok: true, message: finalization.reason })); process.exit(0); } if (require.main === modu
bin/hacker-bob.js:87
log_at_tool_boundary
View on GitHub →
y.targetAbs); console.log(""); if (summary.adapters.length === 1 && summary.adapters[0] === "claude") { console.log("Upd
bin/hacker-bob.js:89
log_at_tool_boundary
View on GitHub →
"claude") { console.log("Update complete. Fully restart Claude Code in this project before continuing."); } else { con

…and 3 more.

Suggested fix · we looked for these and found none

  • structured_logging_imported
  • logging_persistent_sink
ADEQUATE
Logging ensures traceability appropriate to risk EU AI Act, Art 12(2)
skip
2/3 rules

3/4

Why we flagged it

Composite raw score 0.68 (2/3 rules matched). Supporting docs may exist outside the repo.

Confidence
98%
Evidence · 8 hits— click to view code
.claude/hooks/bob-update.js:64
log_at_tool_boundary
View on GitHub →
he(projectDir); console.log("Hacker Bob update cache cleared."); return; } usage(); process.exit(1); } main(process.argv.sli
.claude/hooks/hunter-subagent-stop.js:238
log_at_tool_boundary
View on GitHub →
ndoff, })); console.log(JSON.stringify({ ok: true, message: "post-report evidence run accepted" })); process.exit(0); } con
.claude/hooks/hunter-subagent-stop.js:247
log_at_tool_boundary
View on GitHub →
cess.exit(2); } console.log(JSON.stringify({ ok: true, message: finalization.reason })); process.exit(0); } if (require.main === modu
bin/hacker-bob.js:87
log_at_tool_boundary
View on GitHub →
y.targetAbs); console.log(""); if (summary.adapters.length === 1 && summary.adapters[0] === "claude") { console.log("Upd
bin/hacker-bob.js:89
log_at_tool_boundary
View on GitHub →
"claude") { console.log("Update complete. Fully restart Claude Code in this project before continuing."); } else { con

…and 3 more.

Suggested fix · we looked for these and found none

  • logs_include_request_id
INADEQUATE
Context of use established and understood NIST AI RMF, Art MAP 1.1
skip
1/2 rules

1/4

Why we flagged it

Composite raw score 0.30 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
90%
Evidence · 2 hits— click to view code
README.md
readme_quality
View on GitHub →

2 required sections present

README.md
output_interpretation_guidance
View on GitHub →

Suggested fix · we looked for these and found none

  • deployment_context_documented
PARTIAL
Post-deployment monitoring, appeal and override, change management NIST AI RMF, Art MANAGE 4.1
skip
2/4 rules

2/4

Why we flagged it

Composite raw score 0.50 (2/4 rules matched).

Confidence
100%
Evidence · 7 hits— click to view code
.claude/hooks/session-read-guard.sh:150
rr, ) raise SystemExit(2) def looks_like_path(token): if not token or token.startswith("-"): return False if token
.claude/hooks/session-read-guard.sh:208
(blocked) raise SystemExit(0) command = tool_input.get("command", "") if command: check_bash_command(command) raise SystemExit(0)
.claude/hooks/session-read-guard.sh:214
and(command) raise SystemExit(0) PY
.claude/hooks/session-write-guard.sh:138
s.stderr) raise SystemExit(2) def extract_redirect_targets(command): """Extract file paths from shell redirect operators and tee c
.claude/hooks/session-write-guard.sh:202
) raise SystemExit(0) # Bash tool command = tool_input.get("command", "") if not command: raise SystemExit(0) # Quick gate

…and 2 more.

Suggested fix · we looked for these and found none

  • feedback_capture_present
  • structured_logging_imported
ABSENT
Records of processing activities GDPR, Art 30
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%

Suggested fix · we looked for these and found none

  • presence_of_processing_register
ADEQUATE
Documented information for the AI management system ISO/IEC 42001, Art 7.5
skip
1/2 rules

3/4

Why we flagged it

Composite raw score 0.70 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
90%
Evidence · 2 hits— click to view code
README.md
presence_of_versioned_docs
View on GitHub →
.github/workflows/release.yml
docs_changelog_present
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_versioned_docs
PARTIAL
Monitoring, measurement, analysis and evaluation ISO/IEC 42001, Art 9.1
skip
2/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (2/2 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 3 hits— click to view code
tests/
presence_of_eval_suite
View on GitHub →
.claude/hooks/bob-update.js:64
structured_logging_present
View on GitHub →
he(projectDir); console.log("Hacker Bob update cache cleared."); return; } usage(); process.exit(1); } main(process.argv.sli
.claude/hooks/hunter-subagent-stop.js:238
structured_logging_present
View on GitHub →
ndoff, })); console.log(JSON.stringify({ ok: true, message: "post-report evidence run accepted" })); process.exit(0); } con

Accountability

Don't abuse power
2.0/4Partial6 clauses
PARTIAL
Deployer log-retention capability supported EU AI Act, Art 26(6)
skip
1/1 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/1 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 2 hits— click to view code
.claude/hooks/bob-update.js:64
log_at_tool_boundary
View on GitHub →
he(projectDir); console.log("Hacker Bob update cache cleared."); return; } usage(); process.exit(1); } main(process.argv.sli
.claude/hooks/hunter-subagent-stop.js:238
log_at_tool_boundary
View on GitHub →
ndoff, })); console.log(JSON.stringify({ ok: true, message: "post-report evidence run accepted" })); process.exit(0); } con
ABSENT
Risk management process documented and accountable NIST AI RMF, Art GOVERN 1.4
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_risk_register
  • risk_owner_assignment
PARTIAL
Ongoing monitoring and periodic review of risk management NIST AI RMF, Art GOVERN 1.5
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 2 hits— click to view code
.github/workflows/ci.yml
ci_eval_gates
View on GitHub →
.github/workflows/release.yml
ci_eval_gates
View on GitHub →

Suggested fix · we looked for these and found none

  • drift_monitoring_present
ABSENT
Leadership and commitment for AI management ISO/IEC 42001, Art 5.1
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_ai_policy
  • leadership_signoff_evidence
STRONG
Roles, responsibilities and authorities ISO/IEC 42001, Art 5.3
1/1 rules

4/4

Why we flagged it

Composite raw score 1.00 (1/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%
Evidence · 1 hit— click to view code
.github/CODEOWNERS
presence_of_raci_or_owners
View on GitHub →
STRONG
Internal organization controls ISO/IEC 42001, Art A.5
1/1 rules

4/4

Why we flagged it

Composite raw score 1.00 (1/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%
Evidence · 1 hit— click to view code
.github/CODEOWNERS
presence_of_codeowners
View on GitHub →

Human Oversight

Humans stay in control
1.8/4Partial5 clauses
ABSENT
Effective human oversight designed and built-in EU AI Act, Art 14(1)
0/3 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/3 rules matched).

Confidence
65%

Suggested fix · we looked for these and found none

  • human_in_loop_hooks_present
  • oversight_ui_present
  • tool_calls_have_dry_run
ADEQUATE
Interrupt / stop function reachable by overseer EU AI Act, Art 14(4)(d)
skip
1/2 rules

3/4

Why we flagged it

Composite raw score 0.70 (1/2 rules matched).

Confidence
90%
Evidence · 6 hits— click to view code
.claude/hooks/session-read-guard.sh:150
rr, ) raise SystemExit(2) def looks_like_path(token): if not token or token.startswith("-"): return False if token
.claude/hooks/session-read-guard.sh:208
(blocked) raise SystemExit(0) command = tool_input.get("command", "") if command: check_bash_command(command) raise SystemExit(0)
.claude/hooks/session-read-guard.sh:214
and(command) raise SystemExit(0) PY
.claude/hooks/session-write-guard.sh:138
s.stderr) raise SystemExit(2) def extract_redirect_targets(command): """Extract file paths from shell redirect operators and tee c
.claude/hooks/session-write-guard.sh:202
) raise SystemExit(0) # Bash tool command = tool_input.get("command", "") if not command: raise SystemExit(0) # Quick gate

…and 1 more.

Suggested fix · we looked for these and found none

  • graceful_shutdown_handler
PARTIAL
Ability to override / reverse the system's output EU AI Act, Art 14(4)(e)
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.60 (1/2 rules matched).

Confidence
100%
Evidence · 6 hits— click to view code
.claude/hooks/session-read-guard.sh:150
rr, ) raise SystemExit(2) def looks_like_path(token): if not token or token.startswith("-"): return False if token
.claude/hooks/session-read-guard.sh:208
(blocked) raise SystemExit(0) command = tool_input.get("command", "") if command: check_bash_command(command) raise SystemExit(0)
.claude/hooks/session-read-guard.sh:214
and(command) raise SystemExit(0) PY
.claude/hooks/session-write-guard.sh:138
s.stderr) raise SystemExit(2) def extract_redirect_targets(command): """Extract file paths from shell redirect operators and tee c
.claude/hooks/session-write-guard.sh:202
) raise SystemExit(0) # Bash tool command = tool_input.get("command", "") if not command: raise SystemExit(0) # Quick gate

…and 1 more.

Suggested fix · we looked for these and found none

  • decisions_are_addressable
PARTIAL
Mechanisms to supersede or deactivate AI systems NIST AI RMF, Art MANAGE 2.3
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.60 (1/2 rules matched).

Confidence
100%
Evidence · 6 hits— click to view code
.claude/hooks/session-read-guard.sh:150
rr, ) raise SystemExit(2) def looks_like_path(token): if not token or token.startswith("-"): return False if token
.claude/hooks/session-read-guard.sh:208
(blocked) raise SystemExit(0) command = tool_input.get("command", "") if command: check_bash_command(command) raise SystemExit(0)
.claude/hooks/session-read-guard.sh:214
and(command) raise SystemExit(0) PY
.claude/hooks/session-write-guard.sh:138
s.stderr) raise SystemExit(2) def extract_redirect_targets(command): """Extract file paths from shell redirect operators and tee c
.claude/hooks/session-write-guard.sh:202
) raise SystemExit(0) # Bash tool command = tool_input.get("command", "") if not command: raise SystemExit(0) # Quick gate

…and 1 more.

Suggested fix · we looked for these and found none

  • feature_flag_for_disable
PARTIAL
Automated individual decision-making, including profiling GDPR, Art 22
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.40 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 6 hits— click to view code
.claude/hooks/session-read-guard.sh:150
appeal_or_override_mechanism
View on GitHub →
rr, ) raise SystemExit(2) def looks_like_path(token): if not token or token.startswith("-"): return False if token
.claude/hooks/session-read-guard.sh:208
appeal_or_override_mechanism
View on GitHub →
(blocked) raise SystemExit(0) command = tool_input.get("command", "") if command: check_bash_command(command) raise SystemExit(0)
.claude/hooks/session-read-guard.sh:214
appeal_or_override_mechanism
View on GitHub →
and(command) raise SystemExit(0) PY
.claude/hooks/session-write-guard.sh:138
appeal_or_override_mechanism
View on GitHub →
s.stderr) raise SystemExit(2) def extract_redirect_targets(command): """Extract file paths from shell redirect operators and tee c
.claude/hooks/session-write-guard.sh:202
appeal_or_override_mechanism
View on GitHub →
) raise SystemExit(0) # Bash tool command = tool_input.get("command", "") if not command: raise SystemExit(0) # Quick gate

…and 1 more.

Suggested fix · we looked for these and found none

  • human_review_path_present

Fairness

Treat people fairly
3.2/4Adequate5 clauses
STRONG
Exploiting vulnerabilities (age, disability, socio-economic) EU AI Act, Art 5(1)(b)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_protected_attribute_targeting
STRONG
Social scoring leading to detrimental treatment EU AI Act, Art 5(1)(c)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_scoring_with_persistent_user_state
STRONG
Predictive policing solely from profiling EU AI Act, Art 5(1)(d)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_crime_risk_scoring_from_profile
STRONG
Biometric categorisation by protected attributes EU AI Act, Art 5(1)(g)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_biometric_categorisation_by_protected_attrs
ABSENT
Fairness and bias evaluated NIST AI RMF, Art MEASURE 2.11
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • bias_evaluation_present

Security & Governance

Don't destabilize society
2.0/4Partial4 clauses
INADEQUATE
Cybersecurity measures appropriate to circumstances EU AI Act, Art 15(5)
skip
2/4 rules

1/4

Why we flagged it

Composite raw score 0.33 (2/4 rules matched).

Confidence
100%
Evidence · 11 hits— click to view code
.claude/hooks/bounty-statusline.js:63
rate_limit_usage
View on GitHub →
const fiveHr = data.rate_limits?.five_hour?.used_percentage; const sevenDay = data.rate_limits?.seven_day?.used_percentage; const wo
.claude/hooks/bounty-statusline.js:64
rate_limit_usage
View on GitHub →
nst sevenDay = data.rate_limits?.seven_day?.used_percentage; const worst = Math.max(fiveHr || 0, sevenDay || 0); if (worst >= 80) ra
package-lock.json:211
rate_limit_usage
View on GitHub →
"^5.2.1", "express-rate-limit": "^8.2.1", "hono": "^4.11.4", "jose": "^6.1.3", "json-schema-typed": "^8.0.2
package-lock.json:687
rate_limit_usage
View on GitHub →
, "node_modules/express-rate-limit": { "version": "8.4.1", "resolved": "https://registry.npmjs.org/express-rate-limit/-/expr
package-lock.json:689
rate_limit_usage
View on GitHub →
/registry.npmjs.org/express-rate-limit/-/express-rate-limit-8.4.1.tgz", "integrity": "sha512-NGVYwQSAyEQgzxX1iCM978PP9AdO/hW93gMcF6ZwQ

…and 6 more.

Suggested fix · we looked for these and found none

  • prompt_injection_defences
  • adversarial_eval_present
INADEQUATE
Security and resilience evaluated NIST AI RMF, Art MEASURE 2.7
1/3 rules

1/4

Why we flagged it

Composite raw score 0.17 (1/3 rules matched).

Confidence
82%
Evidence · 6 hits— click to view code
.claude/hooks/bounty-statusline.js:63
rate_limit_usage
View on GitHub →
const fiveHr = data.rate_limits?.five_hour?.used_percentage; const sevenDay = data.rate_limits?.seven_day?.used_percentage; const wo
.claude/hooks/bounty-statusline.js:64
rate_limit_usage
View on GitHub →
nst sevenDay = data.rate_limits?.seven_day?.used_percentage; const worst = Math.max(fiveHr || 0, sevenDay || 0); if (worst >= 80) ra
package-lock.json:211
rate_limit_usage
View on GitHub →
"^5.2.1", "express-rate-limit": "^8.2.1", "hono": "^4.11.4", "jose": "^6.1.3", "json-schema-typed": "^8.0.2
package-lock.json:687
rate_limit_usage
View on GitHub →
, "node_modules/express-rate-limit": { "version": "8.4.1", "resolved": "https://registry.npmjs.org/express-rate-limit/-/expr
package-lock.json:689
rate_limit_usage
View on GitHub →
/registry.npmjs.org/express-rate-limit/-/express-rate-limit-8.4.1.tgz", "integrity": "sha512-NGVYwQSAyEQgzxX1iCM978PP9AdO/hW93gMcF6ZwQ

…and 1 more.

Suggested fix · we looked for these and found none

  • prompt_injection_defences
  • adversarial_eval_present
PARTIAL
Security of processing GDPR, Art 32
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 4 hits— click to view code
mcp/auto-signup.js:78
encryption_at_rest_or_transit
View on GitHub →
https://api.capsolver.com/createTask
mcp/lib/aptos-rpc-pool.js:15
encryption_at_rest_or_transit
View on GitHub →
https://api.mainnet.aptoslabs.com/v1
mcp/lib/auth.js:298
encryption_at_rest_or_transit
View on GitHub →
https://${domain}/`))
mcp/lib/capability-eval-harness.js:6
encryption_at_rest_or_transit
View on GitHub →
require("crypto")

Suggested fix · we looked for these and found none

  • access_control_enforcement
STRONG
Resources for AI systems ISO/IEC 42001, Art A.7
2/2 rules

4/4

Why we flagged it

Composite raw score 1.00 (2/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%
Evidence · 2 hits— click to view code
SECURITY.md
presence_of_security_policy
View on GitHub →
package-lock.json
dependency_pinning
View on GitHub →