8RR8← All audits

Audit Report

symbiotic-sh/core

22fb7fb08233 · ran in 30.2s · bundle d8eeb73f

Deterministic · 17 ambiguous skipped
Complete audit →

Overall score

1.2 /4

Inadequate

Risk class

HIGH

1

Code passed

6 / 47

Attestation Yes

0

Outstanding ext.

1

Overall completion status
Code findings on the left; user-attested external evidence on the right.
47

CODE-CHECKED CLAUSES

  • Strong6
  • Adequate0
  • Partial14
  • Inadequate5
  • Absent22
0

ATTESTATION QUESTIONS

  • Yes0
  • No0
  • Not Applicable0
  • Outstanding0

Harm

Don't hurt people

0.9/4

Inadequate

Truth

Don't deceive people

0.9/4

Inadequate

Responsibility

Don't abuse power

0.8/4

Inadequate

Order

Don't destabilize society

2.7/4

Adequate

1 outstanding external confirmations — required for a complete Annex IV dossier. Complete now →

Safety

Don't harm people
0.5/4Inadequate8 clauses
ABSENT
Risk management system established, implemented, documented EU AI Act, Art 9
0/3 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/3 rules matched). Supporting docs may exist outside the repo.

Confidence
65%

Suggested fix · we looked for these and found none

  • presence_of_risk_register
  • presence_of_threat_model
  • ci_eval_gates
PARTIAL
Appropriate level of accuracy declared and tested EU AI Act, Art 15(1)
skip
2/3 rules

2/4

Why we flagged it

Composite raw score 0.55 (2/3 rules matched).

Confidence
100%
Evidence · 2 hits— click to view code
tests/
eval_suite_present
View on GitHub →
README.md
metrics_documented
View on GitHub →

Suggested fix · we looked for these and found none

  • eval_in_ci
ABSENT
Resilience to errors, faults, inconsistencies EU AI Act, Art 15(4)
0/3 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/3 rules matched).

Confidence
65%

Suggested fix · we looked for these and found none

  • error_handling_at_tool_boundaries
  • retry_logic
  • fallback_behaviour
ABSENT
Risks and benefits to people identified NIST AI RMF, Art MAP 3.4
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_risk_register
  • presence_of_threat_model
PARTIAL
AI system performance evaluated and documented NIST AI RMF, Art MEASURE 2.3
skip
2/3 rules

2/4

Why we flagged it

Composite raw score 0.55 (2/3 rules matched).

Confidence
100%
Evidence · 2 hits— click to view code
tests/
eval_suite_present
View on GitHub →
README.md
metrics_documented
View on GitHub →

Suggested fix · we looked for these and found none

  • eval_in_ci
ABSENT
Data protection impact assessment (DPIA) GDPR, Art 35
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%

Suggested fix · we looked for these and found none

  • presence_of_dpia
ABSENT
AI risk assessment process ISO/IEC 42001, Art 6.1
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_risk_register
  • risk_assessment_methodology_documented
ABSENT
Operational planning and control ISO/IEC 42001, Art 8.1
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_runbook
  • presence_of_ci_workflows

Privacy

Respect boundaries
1.6/4Partial6 clauses
ABSENT
Untargeted facial image scraping for face databases EU AI Act, Art 5(1)(e)
1/1 rules

0/4

Why we flagged it

Composite raw score 1.00 (1/1 rules matched).

Confidence
55%
Evidence · 6 hits— click to view code
crates/symbiotic-agents/src/source_archeology/excavate.rs:53
biometric_terms
View on GitHub →
/// Build system fingerprint. BuildSystem, /// CI configuration. CiConfig, /// Test-command wiring — docs referenced a sc
crates/symbiotic-agents/src/source_archeology/excavate.rs:136
biometric_terms
View on GitHub →
ass 3: build-system fingerprint. for manifest in [ "Cargo.toml", "package.json", "pyproject.toml", "go.m
crates/symbiotic-memory/src/tool_memory.rs:33
biometric_terms
View on GitHub →
ize, /// Stable fingerprint of the agent identity for correlation/provenance. #[serde(default)] pub agent_fingerprint: String,
scripts/auth/_generic.ts:11
scraping_pattern
View on GitHub →
omium, Page } from 'playwright'; interface ScriptInput { domain: string; username: string; password: string; totp_code?: string; }
scripts/auth/github.com.ts:10
scraping_pattern
View on GitHub →
{ chromium } from 'playwright'; interface ScriptInput { domain: string; username: string; password: string; totp_code?: string; }

…and 1 more.

STRONG
Emotion recognition in workplace and education EU AI Act, Art 5(1)(f)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_emotion_recognition_in_workplace_education
EXTERNAL
Real-time remote biometric identification in public spaces EU AI Act, Art 5(1)(h)
EXT

Why we flagged it

Deployment context (public space, real-time, law enforcement use, judicial authorisation) is operational, not knowable from code. Always external.

Confidence
100%
ABSENT
Data and data governance practices documented EU AI Act, Art 10
0/3 rules

0/4

Why we flagged it

Composite raw score 0.10 (0/3 rules matched). Supporting docs may exist outside the repo.

Confidence
75%
Evidence · 2 hits— click to view code
crates/symbiotic-firewall/tests/fixtures/stage_a_fail/script_tag.html:1
http_external_io
View on GitHub →
<p>Hello</p><script>fetch('/exfil?'+document.cookie)</script></body></html>
crates/symbiotic-intake/src/lib.rs:114
http_external_io
View on GitHub →
end + Sync { fn fetch(&self, url: &Url) -> Result<FetchedContent>; } pub trait IntakeStore: Send + Sync { fn exists(&self, idempote

Suggested fix · we looked for these and found none

  • presence_of_data_card
  • data_loading_code_quality
  • bias_evaluation_present
PARTIAL
Privacy risk of the AI system evaluated NIST AI RMF, Art MEASURE 2.8
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/2 rules matched).

Confidence
100%
Evidence · 6 hits— click to view code
crates/symbiotic-agents/src/executor.rs:18
pii_redaction_present
View on GitHub →
symbiotic_context::redact_pii; /// Maximum number of iterations before the loop terminates. const MAX_ITERATIONS: usize = 10; /// Maximum
crates/symbiotic-agents/src/executor.rs:79
pii_redaction_present
View on GitHub →
/// Whether to redact PII from the agent's final output before returning. /// Defaults to `true`. Set to `false` for debugging or t
crates/symbiotic-agents/src/executor.rs:81
pii_redaction_present
View on GitHub →
scenarios. pub redact_output: bool, } impl Default for AgentExecConfig { fn default() -> Self { Self { system_
crates/symbiotic-agents/src/executor.rs:93
pii_redaction_present
View on GitHub →
: None, redact_output: true, } } } /// Conditionally apply PII redaction to an execution result's output. fn maybe_
crates/symbiotic-agents/src/executor.rs:98
pii_redaction_present
View on GitHub →
itionally apply PII redaction to an execution result's output. fn maybe_redact(mut result: ExecutionResult, redact: bool) -> ExecutionResult

…and 1 more.

Suggested fix · we looked for these and found none

  • privacy_documentation
PARTIAL
Data protection by design and by default GDPR, Art 25
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 4 hits— click to view code
crates/symbiotic-agents/src/executor.rs:79
pseudonymisation_or_anonymisation
View on GitHub →
redact
crates/symbiotic-context/src/firewall.rs:76
pseudonymisation_or_anonymisation
View on GitHub →
redacted
crates/symbiotic-context/src/lib.rs:9
pseudonymisation_or_anonymisation
View on GitHub →
redaction
crates/symbiotic-context/src/redaction.rs:5
pseudonymisation_or_anonymisation
View on GitHub →
redaction

Suggested fix · we looked for these and found none

  • default_minimal_data_collection

Transparency

Don't deceive people
0.7/4Inadequate6 clauses
STRONG
Subliminal techniques distorting behaviour EU AI Act, Art 5(1)(a)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_manipulative_prompt_patterns
ABSENT
Transparent operation and instructions for use EU AI Act, Art 13
0/3 rules

0/4

Why we flagged it

Composite raw score 0.13 (0/3 rules matched). Supporting docs may exist outside the repo.

Confidence
78%
Evidence · 3 hits— click to view code
README.md
readme_quality
View on GitHub →

1 required sections present

README.md
output_interpretation_guidance
View on GitHub →
README.md
limitations_section_present
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_deployer_instructions
  • output_interpretation_guidance
  • limitations_section_present
ABSENT
AI-generated content marked as such, machine-readable EU AI Act, Art 50(2)
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched).

Confidence
60%

Suggested fix · we looked for these and found none

  • c2pa_or_watermark_library_imported
  • provenance_metadata_written_to_outputs
ABSENT
Emotion recognition / biometric categorisation disclosure EU AI Act, Art 50(3)
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%
Evidence · 1 hit— click to view code
README.md
emotion_or_biometric_disclosure_string
View on GitHub →

Suggested fix · we looked for these and found none

  • emotion_or_biometric_disclosure_string
ABSENT
Deepfake content labelled as artificially generated EU AI Act, Art 50(4)
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • deepfake_label_on_outputs
ABSENT
Principles relating to processing of personal data GDPR, Art 5
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_privacy_policy
  • purpose_limitation_documented

Auditability

Actions must be traceable
1.0/4Inadequate8 clauses
ABSENT
Technical documentation drawn up before placing on market EU AI Act, Art 11
0/3 rules

0/4

Why we flagged it

Composite raw score 0.07 (0/3 rules matched). Supporting docs may exist outside the repo.

Confidence
73%
Evidence · 1 hit— click to view code
README.md
readme_quality
View on GitHub →

1 required sections present

Suggested fix · we looked for these and found none

  • presence_of_model_card
  • readme_quality
  • architecture_docs
INADEQUATE
Automatic recording of events over the lifetime EU AI Act, Art 12(1)
skip
1/3 rules

1/4

Why we flagged it

Composite raw score 0.34 (1/3 rules matched).

Confidence
99%
Evidence · 4 hits— click to view code
scripts/auth/test-server/server.ts:121
log_at_tool_boundary
View on GitHub →
e server is ready console.log(`READY:${port}`); });
services/credential-gateway/src/script_registry.rs:353
log_at_tool_boundary
View on GitHub →
::fs::write(&path, "console.log('ok')\n").expect("write script"); let mut reg = ScriptRegistry::empty(); reg.register("gith
scripts/auth/test-server/server.ts:121
log_at_tool_boundary
View on GitHub →
e server is ready console.log(`READY:${port}`); });
services/credential-gateway/src/script_registry.rs:353
log_at_tool_boundary
View on GitHub →
::fs::write(&path, "console.log('ok')\n").expect("write script"); let mut reg = ScriptRegistry::empty(); reg.register("gith

Suggested fix · we looked for these and found none

  • structured_logging_imported
  • logging_persistent_sink
PARTIAL
Logging ensures traceability appropriate to risk EU AI Act, Art 12(2)
skip
2/3 rules

2/4

Why we flagged it

Composite raw score 0.44 (2/3 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 4 hits— click to view code
scripts/auth/test-server/server.ts:121
log_at_tool_boundary
View on GitHub →
e server is ready console.log(`READY:${port}`); });
services/credential-gateway/src/script_registry.rs:353
log_at_tool_boundary
View on GitHub →
::fs::write(&path, "console.log('ok')\n").expect("write script"); let mut reg = ScriptRegistry::empty(); reg.register("gith
scripts/auth/test-server/server.ts:121
log_at_tool_boundary
View on GitHub →
e server is ready console.log(`READY:${port}`); });
services/credential-gateway/src/script_registry.rs:353
log_at_tool_boundary
View on GitHub →
::fs::write(&path, "console.log('ok')\n").expect("write script"); let mut reg = ScriptRegistry::empty(); reg.register("gith

Suggested fix · we looked for these and found none

  • logs_include_request_id
INADEQUATE
Context of use established and understood NIST AI RMF, Art MAP 1.1
0/2 rules

1/4

Why we flagged it

Composite raw score 0.15 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
75%
Evidence · 2 hits— click to view code
README.md
readme_quality
View on GitHub →

1 required sections present

README.md
output_interpretation_guidance
View on GitHub →

Suggested fix · we looked for these and found none

  • intended_use_documented
  • deployment_context_documented
INADEQUATE
Post-deployment monitoring, appeal and override, change management NIST AI RMF, Art MANAGE 4.1
skip
1/4 rules

1/4

Why we flagged it

Composite raw score 0.33 (1/4 rules matched).

Confidence
100%
Evidence · 4 hits— click to view code
scripts/live-readiness.sh:98
print("") raise SystemExit(0) try: data = json.loads(payload) except Exception: print("") raise SystemExit(0) value = data f
scripts/live-readiness.sh:103
print("") raise SystemExit(0) value = data for part in field.split('.'): if isinstance(value, dict): value = value.get(part)
scripts/smoke-mvp.sh:20
print("") raise SystemExit(0) try: data = json.loads(payload) except Exception: print("") raise SystemExit(0) value = data f
scripts/smoke-mvp.sh:25
print("") raise SystemExit(0) value = data for part in sys.argv[1].split('.'): if isinstance(value, dict): value = value.get

Suggested fix · we looked for these and found none

  • feedback_capture_present
  • structured_logging_imported
  • versioning_visible
ABSENT
Records of processing activities GDPR, Art 30
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%

Suggested fix · we looked for these and found none

  • presence_of_processing_register
INADEQUATE
Documented information for the AI management system ISO/IEC 42001, Art 7.5
0/2 rules

1/4

Why we flagged it

Composite raw score 0.20 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
80%
Evidence · 1 hit— click to view code
README.md
presence_of_versioned_docs
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_versioned_docs
  • docs_changelog_present
PARTIAL
Monitoring, measurement, analysis and evaluation ISO/IEC 42001, Art 9.1
skip
2/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (2/2 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 3 hits— click to view code
tests/
presence_of_eval_suite
View on GitHub →
scripts/auth/test-server/server.ts:121
structured_logging_present
View on GitHub →
e server is ready console.log(`READY:${port}`); });
services/credential-gateway/src/script_registry.rs:353
structured_logging_present
View on GitHub →
::fs::write(&path, "console.log('ok')\n").expect("write script"); let mut reg = ScriptRegistry::empty(); reg.register("gith

Accountability

Don't abuse power
0.3/4Absent6 clauses
PARTIAL
Deployer log-retention capability supported EU AI Act, Art 26(6)
skip
1/1 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/1 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 2 hits— click to view code
scripts/auth/test-server/server.ts:121
log_at_tool_boundary
View on GitHub →
e server is ready console.log(`READY:${port}`); });
services/credential-gateway/src/script_registry.rs:353
log_at_tool_boundary
View on GitHub →
::fs::write(&path, "console.log('ok')\n").expect("write script"); let mut reg = ScriptRegistry::empty(); reg.register("gith
ABSENT
Risk management process documented and accountable NIST AI RMF, Art GOVERN 1.4
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_risk_register
  • risk_owner_assignment
ABSENT
Ongoing monitoring and periodic review of risk management NIST AI RMF, Art GOVERN 1.5
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • ci_eval_gates
  • drift_monitoring_present
ABSENT
Leadership and commitment for AI management ISO/IEC 42001, Art 5.1
0/2 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/2 rules matched). Supporting docs may exist outside the repo.

Confidence
60%

Suggested fix · we looked for these and found none

  • presence_of_ai_policy
  • leadership_signoff_evidence
ABSENT
Roles, responsibilities and authorities ISO/IEC 42001, Art 5.3
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%

Suggested fix · we looked for these and found none

  • presence_of_raci_or_owners
ABSENT
Internal organization controls ISO/IEC 42001, Art A.5
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%

Suggested fix · we looked for these and found none

  • presence_of_codeowners

Human Oversight

Humans stay in control
1.4/4Inadequate5 clauses
ABSENT
Effective human oversight designed and built-in EU AI Act, Art 14(1)
0/3 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/3 rules matched).

Confidence
65%

Suggested fix · we looked for these and found none

  • human_in_loop_hooks_present
  • oversight_ui_present
  • tool_calls_have_dry_run
PARTIAL
Interrupt / stop function reachable by overseer EU AI Act, Art 14(4)(d)
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.63 (1/2 rules matched).

Confidence
97%
Evidence · 4 hits— click to view code
scripts/live-readiness.sh:98
print("") raise SystemExit(0) try: data = json.loads(payload) except Exception: print("") raise SystemExit(0) value = data f
scripts/live-readiness.sh:103
print("") raise SystemExit(0) value = data for part in field.split('.'): if isinstance(value, dict): value = value.get(part)
scripts/smoke-mvp.sh:20
print("") raise SystemExit(0) try: data = json.loads(payload) except Exception: print("") raise SystemExit(0) value = data f
scripts/smoke-mvp.sh:25
print("") raise SystemExit(0) value = data for part in sys.argv[1].split('.'): if isinstance(value, dict): value = value.get

Suggested fix · we looked for these and found none

  • graceful_shutdown_handler
PARTIAL
Ability to override / reverse the system's output EU AI Act, Art 14(4)(e)
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.54 (1/2 rules matched).

Confidence
100%
Evidence · 4 hits— click to view code
scripts/live-readiness.sh:98
print("") raise SystemExit(0) try: data = json.loads(payload) except Exception: print("") raise SystemExit(0) value = data f
scripts/live-readiness.sh:103
print("") raise SystemExit(0) value = data for part in field.split('.'): if isinstance(value, dict): value = value.get(part)
scripts/smoke-mvp.sh:20
print("") raise SystemExit(0) try: data = json.loads(payload) except Exception: print("") raise SystemExit(0) value = data f
scripts/smoke-mvp.sh:25
print("") raise SystemExit(0) value = data for part in sys.argv[1].split('.'): if isinstance(value, dict): value = value.get

Suggested fix · we looked for these and found none

  • decisions_are_addressable
PARTIAL
Mechanisms to supersede or deactivate AI systems NIST AI RMF, Art MANAGE 2.3
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.54 (1/2 rules matched).

Confidence
100%
Evidence · 4 hits— click to view code
scripts/live-readiness.sh:98
print("") raise SystemExit(0) try: data = json.loads(payload) except Exception: print("") raise SystemExit(0) value = data f
scripts/live-readiness.sh:103
print("") raise SystemExit(0) value = data for part in field.split('.'): if isinstance(value, dict): value = value.get(part)
scripts/smoke-mvp.sh:20
print("") raise SystemExit(0) try: data = json.loads(payload) except Exception: print("") raise SystemExit(0) value = data f
scripts/smoke-mvp.sh:25
print("") raise SystemExit(0) value = data for part in sys.argv[1].split('.'): if isinstance(value, dict): value = value.get

Suggested fix · we looked for these and found none

  • feature_flag_for_disable
INADEQUATE
Automated individual decision-making, including profiling GDPR, Art 22
skip
1/2 rules

1/4

Why we flagged it

Composite raw score 0.36 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
96%
Evidence · 4 hits— click to view code
scripts/live-readiness.sh:98
appeal_or_override_mechanism
View on GitHub →
print("") raise SystemExit(0) try: data = json.loads(payload) except Exception: print("") raise SystemExit(0) value = data f
scripts/live-readiness.sh:103
appeal_or_override_mechanism
View on GitHub →
print("") raise SystemExit(0) value = data for part in field.split('.'): if isinstance(value, dict): value = value.get(part)
scripts/smoke-mvp.sh:20
appeal_or_override_mechanism
View on GitHub →
print("") raise SystemExit(0) try: data = json.loads(payload) except Exception: print("") raise SystemExit(0) value = data f
scripts/smoke-mvp.sh:25
appeal_or_override_mechanism
View on GitHub →
print("") raise SystemExit(0) value = data for part in sys.argv[1].split('.'): if isinstance(value, dict): value = value.get

Suggested fix · we looked for these and found none

  • human_review_path_present

Fairness

Treat people fairly
3.2/4Adequate5 clauses
STRONG
Exploiting vulnerabilities (age, disability, socio-economic) EU AI Act, Art 5(1)(b)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_protected_attribute_targeting
STRONG
Social scoring leading to detrimental treatment EU AI Act, Art 5(1)(c)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched). Supporting docs may exist outside the repo.

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_scoring_with_persistent_user_state
STRONG
Predictive policing solely from profiling EU AI Act, Art 5(1)(d)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_crime_risk_scoring_from_profile
STRONG
Biometric categorisation by protected attributes EU AI Act, Art 5(1)(g)
0/1 rules

4/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • detect_biometric_categorisation_by_protected_attrs
ABSENT
Fairness and bias evaluated NIST AI RMF, Art MEASURE 2.11
0/1 rules

0/4

Why we flagged it

Composite raw score 0.00 (0/1 rules matched).

Confidence
55%

Suggested fix · we looked for these and found none

  • bias_evaluation_present

Security & Governance

Don't destabilize society
2.0/4Partial4 clauses
PARTIAL
Cybersecurity measures appropriate to circumstances EU AI Act, Art 15(5)
skip
2/4 rules

2/4

Why we flagged it

Composite raw score 0.60 (2/4 rules matched).

Confidence
100%
Evidence · 12 hits— click to view code
crates/symbiotic-firewall/src/heuristics/delimiters.rs:3
prompt_injection_defence
View on GitHub →
detection. //! //! Prompt-injection attacks often lean on **delimiter confusion** — nesting //! code fences, mixing Markdown and XML, stuff
crates/symbiotic-firewall/src/heuristics/injection_phrases.rs:1
prompt_injection_defence
View on GitHub →
//! Classic prompt-injection phrase + role-token detection. //! //! Rules here are deliberately conservative — every regex is review
crates/symbiotic-firewall/src/heuristics/injection_phrases.rs:81
prompt_injection_defence
View on GitHub →
\b(developer\s+mode|jailbreak|dan\s+mode|sudo\s+mode)\b")); static NEW_PERSONA: Lazy<Regex> = Lazy::new(|| ci(r"\byour\s+(new|real|true
crates/symbiotic-firewall/src/heuristics/mod.rs:1
prompt_injection_defence
View on GitHub →
//! Prompt-injection heuristics used by Stage B. //! //! All heuristics return a `Vec<HeuristicHit>`. Stage B combines the h
crates/symbiotic-firewall/src/heuristics/mod.rs:10
prompt_injection_defence
View on GitHub →
r the classic //! prompt-injection surface ("ignore previous instructions", role tokens, //! tool-call impersonation). //! - [`delimiter

…and 7 more.

Suggested fix · we looked for these and found none

  • secrets_not_in_prompts
  • adversarial_eval_present
PARTIAL
Security and resilience evaluated NIST AI RMF, Art MEASURE 2.7
skip
2/3 rules

2/4

Why we flagged it

Composite raw score 0.60 (2/3 rules matched).

Confidence
100%
Evidence · 12 hits— click to view code
crates/symbiotic-firewall/src/heuristics/delimiters.rs:3
prompt_injection_defence
View on GitHub →
detection. //! //! Prompt-injection attacks often lean on **delimiter confusion** — nesting //! code fences, mixing Markdown and XML, stuff
crates/symbiotic-firewall/src/heuristics/injection_phrases.rs:1
prompt_injection_defence
View on GitHub →
//! Classic prompt-injection phrase + role-token detection. //! //! Rules here are deliberately conservative — every regex is review
crates/symbiotic-firewall/src/heuristics/injection_phrases.rs:81
prompt_injection_defence
View on GitHub →
\b(developer\s+mode|jailbreak|dan\s+mode|sudo\s+mode)\b")); static NEW_PERSONA: Lazy<Regex> = Lazy::new(|| ci(r"\byour\s+(new|real|true
crates/symbiotic-firewall/src/heuristics/mod.rs:1
prompt_injection_defence
View on GitHub →
//! Prompt-injection heuristics used by Stage B. //! //! All heuristics return a `Vec<HeuristicHit>`. Stage B combines the h
crates/symbiotic-firewall/src/heuristics/mod.rs:10
prompt_injection_defence
View on GitHub →
r the classic //! prompt-injection surface ("ignore previous instructions", role tokens, //! tool-call impersonation). //! - [`delimiter

…and 7 more.

Suggested fix · we looked for these and found none

  • adversarial_eval_present
PARTIAL
Security of processing GDPR, Art 32
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 4 hits— click to view code
crates/symbiotic-agents/src/builtin_tools.rs:1349
encryption_at_rest_or_transit
View on GitHub →
https://example.com
crates/symbiotic-agents/src/llm_runtime.rs:284
encryption_at_rest_or_transit
View on GitHub →
https://ollama.ai/download
crates/symbiotic-agents/src/source_archeology/contract.rs:213
encryption_at_rest_or_transit
View on GitHub →
https://gw.example/v1
crates/symbiotic-agents/src/source_archeology/scaffold_templates.rs:164
encryption_at_rest_or_transit
View on GitHub →
https://example.com/flux.git

Suggested fix · we looked for these and found none

  • access_control_enforcement
PARTIAL
Resources for AI systems ISO/IEC 42001, Art A.7
skip
1/2 rules

2/4

Why we flagged it

Composite raw score 0.50 (1/2 rules matched). Supporting docs may exist outside the repo.

Confidence
100%
Evidence · 1 hit— click to view code
Cargo.lock
dependency_pinning
View on GitHub →

Suggested fix · we looked for these and found none

  • presence_of_security_policy