diff --git a/auditor/audits/calesthio-OpenMontage.findings.jsonl b/auditor/audits/calesthio-OpenMontage.findings.jsonl new file mode 100644 index 000000000..bc805e017 --- /dev/null +++ b/auditor/audits/calesthio-OpenMontage.findings.jsonl @@ -0,0 +1,56 @@ +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/motion-graphics/agents/director.md","line":3,"severity":"medium","confidence":"high","evidence":"references/shot-plan-ir.md resolves to agents/references/shot-plan-ir.md relative to the file's own dir, which does not exist; real file is motion-graphics/references/shot-plan-ir.md","penalty":null,"pattern":"broken-relative-path","description":"Broken relative ref to references/shot-plan-ir.md, needs ../ prefix","false_positive":false,"suggested_fix":"Change reference to ../references/shot-plan-ir.md"} +{"category":"bug","rule_id":"BUG-missing-frontmatter","file":".agents/skills/motion-graphics/agents/director.md","line":1,"severity":"high","confidence":"high","evidence":"File has no YAML frontmatter block, no name/description, no model field, zero example blocks","penalty":-45,"pattern":"missing-frontmatter","description":"No frontmatter (name/description), no declared model, zero example blocks","false_positive":false,"suggested_fix":"Add YAML frontmatter with name, description, model, and at least one example block"} +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/motion-graphics/agents/builder.md","line":12,"severity":"medium","confidence":"high","evidence":"catalog-map.md resolves to agents/catalog-map.md relative to file's own dir; real file is motion-graphics/catalog-map.md","penalty":null,"pattern":"broken-relative-path","description":"Broken relative ref to catalog-map.md, needs ../ prefix","false_positive":false,"suggested_fix":"Change reference to ../catalog-map.md"} +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/motion-graphics/agents/builder.md","line":24,"severity":"medium","confidence":"high","evidence":"references/builder-contract.md resolves to agents/references/builder-contract.md relative to file's own dir; real file is motion-graphics/references/builder-contract.md","penalty":null,"pattern":"broken-relative-path","description":"Broken relative ref to references/builder-contract.md, needs ../ prefix","false_positive":false,"suggested_fix":"Change reference to ../references/builder-contract.md"} +{"category":"bug","rule_id":"BUG-missing-frontmatter","file":".agents/skills/motion-graphics/agents/builder.md","line":1,"severity":"high","confidence":"high","evidence":"File has no YAML frontmatter block, no name/description, no model field, zero example blocks","penalty":-45,"pattern":"missing-frontmatter","description":"No frontmatter (name/description), no declared model, zero example blocks","false_positive":false,"suggested_fix":"Add YAML frontmatter with name, description, model, and at least one example block"} +{"category":"bug","rule_id":"BUG-missing-frontmatter","file":".agents/skills/motion-graphics/agents/finalize.md","line":1,"severity":"high","confidence":"high","evidence":"File has no YAML frontmatter block, no name/description, no model field, zero example blocks","penalty":-45,"pattern":"missing-frontmatter","description":"No frontmatter (name/description), no declared model, zero example blocks","false_positive":false,"suggested_fix":"Add YAML frontmatter with name, description, model, and at least one example block"} +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/motion-graphics/SKILL.md","line":172,"severity":"low","confidence":"high","evidence":"find -iname motion-graphics-genre.md returns no results anywhere in repo","penalty":-5,"pattern":"broken-relative-path","description":"Broken ref to motion-graphics-genre.md, file does not exist","false_positive":false,"suggested_fix":"Create the referenced file or remove the pointer"} +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/manimgl-best-practices/SKILL.md","line":51,"severity":"medium","confidence":"high","evidence":"examples/basic_animations.py and 4 sibling paths do not exist; ls examples/ shows only differently-named files like mlp_neurons_flow.py","penalty":-10,"pattern":"broken-relative-path","description":"5 broken example file links, real examples directory has different filenames","false_positive":false,"suggested_fix":"Update Working Examples section to link the real files in examples/"} +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/remotion/SKILL.md","line":3,"severity":"medium","confidence":"high","evidence":"find -iname remotion-official returns no results anywhere in repo","penalty":-15,"pattern":"broken-relative-path","description":"References nonexistent .claude/skills/remotion-official/ skill for core Remotion knowledge","false_positive":false,"suggested_fix":"Remove the pointer or vendor the remotion-official skill as documented"} +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/remotion-best-practices/SKILL.md","line":26,"severity":"low","confidence":"high","evidence":"./rules/sound-effects.md does not exist; ls rules/ shows sfx.md instead","penalty":-10,"pattern":"broken-relative-path","description":"Broken ref to rules/sound-effects.md, real file is rules/sfx.md","false_positive":false,"suggested_fix":"Fix link to ./rules/sfx.md"} +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/acestep/SKILL.md","line":15,"severity":"medium","confidence":"high","evidence":"find -iname music_gen.py shows only tools/audio/music_gen.py; tools/music_gen.py does not exist","penalty":-10,"pattern":"broken-relative-path","description":"Quick Reference commands invoke tools/music_gen.py, real path is tools/audio/music_gen.py","false_positive":false,"suggested_fix":"Update all example commands to python tools/audio/music_gen.py"} +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/acestep/SKILL.md","line":262,"severity":"medium","confidence":"high","evidence":"find -iname sfx.py returns no results anywhere in repo","penalty":-10,"pattern":"broken-relative-path","description":"References tools/sfx.py which does not exist anywhere in the repo","false_positive":false,"suggested_fix":"Point to the actual SFX provider (e.g. hyperframes-media/scripts/lib/sfx.mjs) or remove the reference"} +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/ltx2/SKILL.md","line":15,"severity":"high","confidence":"high","evidence":"find -iname ltx2.py and modal-ltx2 return no results; real tools are tools/video/ltx_video_modal.py and ltx_video_local.py","penalty":-35,"pattern":"broken-relative-path","description":"Entire Quick Reference/Setup documents nonexistent tools/ltx2.py CLI and docker/modal-ltx2/app.py deploy path","false_positive":false,"suggested_fix":"Rewrite Quick Reference to use tools.tool_registry invocation of tools/video/ltx_video_modal.py, matching the pattern used in seedance-2-0/SKILL.md"} +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/website-to-video/SKILL.md","line":144,"severity":"medium","confidence":"high","evidence":"../hyperframes/references/techniques.md not found; real file is .agents/skills/hyperframes-animation/techniques.md","penalty":-15,"pattern":"broken-relative-path","description":"Broken relative ref to hyperframes/references/techniques.md, real skill name is hyperframes-animation with no references/ subdir","false_positive":false,"suggested_fix":"Fix link to ../hyperframes-animation/techniques.md"} +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/website-to-video/SKILL.md","line":145,"severity":"medium","confidence":"high","evidence":"../hyperframes/references/html-in-canvas-patterns.md not found; real file is .agents/skills/hyperframes-animation/adapters/html-in-canvas-patterns.md","penalty":-15,"pattern":"broken-relative-path","description":"Broken relative ref to hyperframes/references/html-in-canvas-patterns.md","false_positive":false,"suggested_fix":"Fix link to ../hyperframes-animation/adapters/html-in-canvas-patterns.md"} +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/synthetic-screen-recording/SKILL.md","line":182,"severity":"low","confidence":"high","evidence":"find -type d -name projects at repo root returns no results; no openmontage-showcase directory anywhere","penalty":-10,"pattern":"broken-relative-path","description":"References projects/openmontage-showcase/build_composition.py as reference implementation; path does not exist","false_positive":false,"suggested_fix":"Remove the dangling citation or commit the referenced reference implementation"} +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/d3-viz/SKILL.md","line":814,"severity":"low","confidence":"high","evidence":"assets/ dir has chart-template.jsx and interactive-template.jsx, not .js","penalty":-10,"pattern":"broken-relative-path","description":"Templates section references chart-template.js/interactive-template.js, real files are .jsx","false_positive":false,"suggested_fix":"Update the two links to the .jsx extension"} +{"category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/beautiful-mermaid/SKILL.md","line":12,"severity":"medium","confidence":"high","evidence":"find -iname agent-browser returns no results anywhere in repo; no such skill directory under .agents/skills, .claude/skills, or skills/","penalty":-15,"pattern":"broken-relative-path","description":"Requires nonexistent agent-browser skill for PNG capture step","false_positive":false,"suggested_fix":"Vendor or replace the PNG-capture step with an existing screenshot mechanism (e.g. playwright-recording)"} +{"category":"bug","rule_id":"BUG-stale-count","file":".agents/skills/vercel-react-best-practices/SKILL.md","line":12,"severity":"low","confidence":"high","evidence":"find rules -path '*/rules/*.md' | wc -l returns 68, description claims 65","penalty":-5,"pattern":"stale-count","description":"Description claims 65 rules across 8 categories, 68 rule files actually exist","false_positive":false,"suggested_fix":"Update the count to 68 or regenerate the description from the rules/ directory listing"} +{"category":"bug","rule_id":"BUG-stale-count","file":".claude/skills/vercel-react-best-practices/SKILL.md","line":12,"severity":"low","confidence":"high","evidence":"Identical content to .agents/skills/vercel-react-best-practices/SKILL.md, same stale count","penalty":-5,"pattern":"stale-count","description":"Description claims 65 rules across 8 categories, 68 rule files actually exist","false_positive":false,"suggested_fix":"Update the count to 68 or regenerate the description from the rules/ directory listing"} +{"category":"bug","rule_id":"BUG-invalid-directory-name","file":".claude/skills/video_toolkit/SKILL.md","line":2,"severity":"high","confidence":"high","evidence":"Directory is video_toolkit (underscore) but frontmatter name: and metadata.openclaw.skillKey both say video-toolkit (hyphen); .agents/skills/video-toolkit uses matching hyphenated directory name","penalty":-25,"pattern":"skill-name-directory-mismatch","description":"Directory name video_toolkit mismatches declared skill name video-toolkit","false_positive":false,"suggested_fix":"Rename the directory to video-toolkit to match the declared name, or vice versa"} +{"category":"bug","rule_id":"BUG-duplicate-heading","file":".agents/skills/video-toolkit/SKILL.md","line":298,"severity":"low","confidence":"high","evidence":"grep '^#### 4' shows both line 298 (Talking Head Narrator) and line 330 (Image Editing) labeled '#### 4e.'","penalty":-10,"pattern":"duplicate-step-numbering","description":"Duplicate #### 4e. step heading used for two different steps (L298, L330)","false_positive":false,"suggested_fix":"Renumber Image Editing to 4f and shift Upscaling to 4g, or similar resequencing"} +{"category":"bug","rule_id":"BUG-inconsistent-config","file":".agents/skills/video-toolkit/SKILL.md","line":70,"severity":"low","confidence":"high","evidence":"Line 70 deploys docker/modal-propainter/app.py; line 87 lists env var MODAL_DEWATERMARK_ENDPOINT_URL with no MODAL_PROPAINTER_ENDPOINT_URL or matching deploy-to-var mapping shown","penalty":-5,"pattern":"inconsistent-naming","description":"modal-propainter deploy step has no matching MODAL_PROPAINTER_ENDPOINT_URL env var; MODAL_DEWATERMARK_ENDPOINT_URL has no corresponding deploy step","false_positive":false,"suggested_fix":"Align the deploy script name and env var name (both should reference propainter or both dewatermark)"} +{"category":"bug","rule_id":"BUG-duplicate-heading","file":".claude/skills/video_toolkit/SKILL.md","line":298,"severity":"low","confidence":"high","evidence":"Identical content to .agents/skills/video-toolkit/SKILL.md, same duplicate heading at L298/L330","penalty":-10,"pattern":"duplicate-step-numbering","description":"Duplicate #### 4e. step heading used for two different steps (L298, L330)","false_positive":false,"suggested_fix":"Renumber Image Editing to 4f and shift Upscaling to 4g, or similar resequencing"} +{"category":"cross_component","rule_id":"CC-stale-count","file":".claude/skills/ai-video-gen/SKILL.md","line":null,"severity":"medium","confidence":"high","evidence":"diff .claude/skills/ai-video-gen/SKILL.md .agents/skills/ai-video-gen/SKILL.md shows .claude copy missing Kling Official gateway, KLING_API_KEY, and provider=kling_official guidance present in .agents copy","penalty":-10,"pattern":"sibling-skill-drift","description":"claude/ copy of ai-video-gen is stale vs agents/ sibling, missing Kling Official direct-API gateway","false_positive":false,"suggested_fix":"Re-sync .claude/skills/ai-video-gen/SKILL.md from .agents/skills/ai-video-gen/SKILL.md"} +{"category":"cross_component","rule_id":"CC-terminology-drift","file":".claude/skills/video_toolkit/SKILL.md","line":null,"severity":"low","confidence":"high","evidence":"diff -rq .claude/skills .agents/skills shows video_toolkit (underscore) only under .claude and video-toolkit (hyphen) only under .agents, byte-identical content otherwise","penalty":null,"pattern":"directory-naming-convention-drift","description":"Same skill dual-published under inconsistent directory-naming convention (underscore vs hyphen) across tool trees","false_positive":false,"suggested_fix":"Standardize on video-toolkit (hyphen) for both trees"} +{"category":"cross_component","rule_id":"CC-orphan-component","file":".claude/skills","line":null,"severity":"low","confidence":"medium","evidence":"ls .claude/skills vs .agents/skills shows only ~48 of ~85 .agents/skills/* names mirrored into .claude/skills/","penalty":null,"pattern":"partial-mirror","description":"claude/skills/ is a partial subset mirror of agents/skills/; ~37 skills exist only in agents/ tree","false_positive":true,"fp_reason":"No broken references were found caused by this asymmetry; likely intentional per-tool scoping rather than a defect","rule_gap":"Rule should distinguish intentional tool-scoped skill subsets from accidental omission before flagging","suggested_fix":""} +{"category":"nl_quality","rule_id":"R51","file":".agents/skills/agents/references/agent-configuration.md","line":279,"severity":"low","confidence":"high","evidence":"grep shows the word 'relevant' used as a vague qualifier at line 279","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'relevant' used","false_positive":false,"suggested_fix":"Replace with a specific criterion"} +{"category":"nl_quality","rule_id":"R51","file":".claude/skills/agents/references/agent-configuration.md","line":279,"severity":"low","confidence":"high","evidence":"Identical content to .agents twin, same vague quantifier at line 279","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'relevant' used","false_positive":false,"suggested_fix":"Replace with a specific criterion"} +{"category":"nl_quality","rule_id":"R51","file":".agents/skills/agents/references/client-tools.md","line":463,"severity":"low","confidence":"high","evidence":"grep shows the word 'reasonable' used as a vague qualifier at line 463","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'reasonable' used","false_positive":false,"suggested_fix":"Replace with a specific criterion"} +{"category":"nl_quality","rule_id":"R51","file":".claude/skills/agents/references/client-tools.md","line":463,"severity":"low","confidence":"high","evidence":"Identical content to .agents twin, same vague quantifier at line 463","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'reasonable' used","false_positive":false,"suggested_fix":"Replace with a specific criterion"} +{"category":"nl_quality","rule_id":"R51","file":".agents/skills/remotion-to-hyperframes/SKILL.md","line":95,"severity":"low","confidence":"high","evidence":"grep shows the word 'relevant' used as a vague qualifier at line 95","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'relevant' used","false_positive":false,"suggested_fix":"Replace with a specific criterion"} +{"category":"nl_quality","rule_id":"R51","file":".agents/skills/seedance-2-0/SKILL.md","line":161,"severity":"low","confidence":"high","evidence":"grep shows 'optimal' used at line 161: 'appears optimal for multi-shot generations'","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'optimal' used","false_positive":false,"suggested_fix":"State the concrete rhythm/timing basis instead of 'optimal'"} +{"category":"nl_quality","rule_id":"R51","file":".agents/skills/flux-best-practices/SKILL.md","line":12,"severity":"low","confidence":"high","evidence":"grep shows 'optimal image quality' at line 12 and 'Comprehensive guide' at line 3","penalty":-4,"pattern":"vague-quantifier","description":"Vague quantifiers 'optimal' (L12) and 'Comprehensive' (L3) used","false_positive":false,"suggested_fix":"Replace with concrete quality criteria"} +{"category":"nl_quality","rule_id":"R51","file":".agents/skills/comfyui/SKILL.md","line":27,"severity":"low","confidence":"high","evidence":"grep shows 'usually SaveImage, SaveVideo, ...' at line 27","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'usually' used","false_positive":false,"suggested_fix":"Enumerate the exact node types deterministically instead of 'usually'"} +{"category":"nl_quality","rule_id":"R51","file":".agents/skills/visual-style/SKILL.md","line":41,"severity":"low","confidence":"high","evidence":"grep shows 'the appropriate extractor reference file' (L41) and 'the appropriate connector reference file' (L50)","penalty":-4,"pattern":"vague-quantifier","description":"Vague quantifier 'appropriate' used twice (L41, L50)","false_positive":false,"suggested_fix":"Name the specific selection criterion for choosing the extractor/connector file"} +{"category":"nl_quality","rule_id":"R51","file":".claude/skills/visual-style/SKILL.md","line":41,"severity":"low","confidence":"high","evidence":"Identical content to .agents twin, same vague quantifiers at L41, L50","penalty":-4,"pattern":"vague-quantifier","description":"Vague quantifier 'appropriate' used twice (L41, L50)","false_positive":false,"suggested_fix":"Name the specific selection criterion for choosing the extractor/connector file"} +{"category":"nl_quality","rule_id":"R51","file":".agents/skills/website-to-video/SKILL.md","line":59,"severity":"low","confidence":"medium","evidence":"","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'as needed' used","false_positive":false,"suggested_fix":"Specify the concrete condition instead of 'as needed'"} +{"category":"nl_quality","rule_id":"R51","file":".agents/skills/d3-viz/SKILL.md","line":818,"severity":"low","confidence":"medium","evidence":"","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'as needed' used","false_positive":false,"suggested_fix":"Specify the concrete condition instead of 'as needed'"} +{"category":"nl_quality","rule_id":"BUG-undeclared-tool","file":".agents/skills/ai-video-gen/SKILL.md","line":5,"severity":"low","confidence":"high","evidence":"grep -c mcp__heygen returns 1 (frontmatter line only), no invocation elsewhere in body","penalty":-3,"pattern":"unused-declared-tool","description":"allowed-tools: mcp__heygen__* declared but never invoked in body","false_positive":false,"suggested_fix":"Either document an mcp__heygen__* call site or remove the allowed-tools declaration"} +{"category":"nl_quality","rule_id":"BUG-undeclared-tool","file":".claude/skills/ai-video-gen/SKILL.md","line":5,"severity":"low","confidence":"high","evidence":"grep -c mcp__heygen returns 1 (frontmatter line only), no invocation elsewhere in body","penalty":-3,"pattern":"unused-declared-tool","description":"allowed-tools: mcp__heygen__* declared but never invoked in body","false_positive":false,"suggested_fix":"Either document an mcp__heygen__* call site or remove the allowed-tools declaration"} +{"category":"nl_quality","rule_id":"BUG-undeclared-tool","file":".agents/skills/video-translate/SKILL.md","line":5,"severity":"low","confidence":"high","evidence":"grep -c mcp__heygen returns 1 (frontmatter line only), no invocation elsewhere in body","penalty":-3,"pattern":"unused-declared-tool","description":"allowed-tools: mcp__heygen__* declared but never invoked in body","false_positive":false,"suggested_fix":"Either document an mcp__heygen__* call site or remove the allowed-tools declaration"} +{"category":"nl_quality","rule_id":"BUG-undeclared-tool","file":".agents/skills/faceswap/SKILL.md","line":5,"severity":"low","confidence":"high","evidence":"grep -c mcp__heygen returns 1 (frontmatter line only), no invocation elsewhere in body","penalty":-3,"pattern":"unused-declared-tool","description":"allowed-tools: mcp__heygen__* declared but never invoked in body","false_positive":false,"suggested_fix":"Either document an mcp__heygen__* call site or remove the allowed-tools declaration"} +{"category":"nl_quality","rule_id":"BUG-broken-reference","file":".agents/skills/ffmpeg/SKILL.md","line":432,"severity":"low","confidence":"high","evidence":"Line reads 'update .claude/skills/ffmpeg/SKILL.md' while this file itself is located at .agents/skills/ffmpeg/SKILL.md","penalty":-5,"pattern":"tree-specific-hardcoded-path","description":"Self-referential improve-this-skill path hardcodes .claude/ tree, wrong when read from .agents/ copy","false_positive":false,"suggested_fix":"Reference the file generically (e.g. 'this SKILL.md') instead of a tree-specific absolute path"} +{"category":"nl_quality","rule_id":"BUG-broken-reference","file":".claude/skills/ffmpeg/SKILL.md","line":432,"severity":"low","confidence":"high","evidence":"Identical content, same hardcoded .claude/ path, correct for this copy but demonstrates the underlying dual-tree fragility","penalty":-5,"pattern":"tree-specific-hardcoded-path","description":"Self-referential improve-this-skill path hardcodes .claude/ tree","false_positive":false,"suggested_fix":"Reference the file generically instead of a tree-specific absolute path"} +{"category":"nl_quality","rule_id":"BUG-broken-reference","file":".agents/skills/video-understand/SKILL.md","line":22,"severity":"low","confidence":"high","evidence":"Commands section shows 'python3 skills/video-understand/scripts/understand_video.py'; real path requires .agents/ or .claude/ prefix","penalty":-10,"pattern":"broken-relative-path","description":"Script paths in Commands section omit the .agents/.claude tree prefix, none resolve from repo root as written","false_positive":false,"suggested_fix":"Prefix commands with the correct tree path, e.g. .agents/skills/video-understand/scripts/understand_video.py"} +{"category":"nl_quality","rule_id":"BUG-broken-reference","file":".claude/skills/video-understand/SKILL.md","line":22,"severity":"low","confidence":"high","evidence":"Identical content, same missing tree prefix in Commands section","penalty":-10,"pattern":"broken-relative-path","description":"Script paths in Commands section omit the .agents/.claude tree prefix","false_positive":false,"suggested_fix":"Prefix commands with the correct tree path, e.g. .claude/skills/video-understand/scripts/understand_video.py"} +{"category":"nl_quality","rule_id":"R-missing-allowed-tools","file":".claude/commands/animated-drawing.md","line":1,"severity":"low","confidence":"high","evidence":"Frontmatter contains only description and argument-hint, no allowed-tools field","penalty":-5,"pattern":"missing-allowed-tools","description":"Command missing allowed-tools frontmatter field","false_positive":false,"suggested_fix":"Add an allowed-tools list scoping which tools this command may invoke"} +{"category":"nl_quality","rule_id":"R-missing-allowed-tools","file":".claude/commands/backlot.md","line":1,"severity":"low","confidence":"high","evidence":"Frontmatter contains only description and argument-hint, no allowed-tools field","penalty":-5,"pattern":"missing-allowed-tools","description":"Command missing allowed-tools frontmatter field","false_positive":false,"suggested_fix":"Add an allowed-tools list scoping which tools this command may invoke"} +{"category":"nl_quality","rule_id":"R-missing-allowed-tools","file":".claude/commands/ink-art.md","line":1,"severity":"low","confidence":"high","evidence":"Frontmatter contains only description and argument-hint, no allowed-tools field","penalty":-5,"pattern":"missing-allowed-tools","description":"Command missing allowed-tools frontmatter field","false_positive":false,"suggested_fix":"Add an allowed-tools list scoping which tools this command may invoke"} +{"category":"nl_quality","rule_id":"R-empty-input-handling","file":".claude/commands/animated-drawing.md","line":12,"severity":"low","confidence":"high","evidence":"Body ends with 'Drawing + motion: $ARGUMENTS' with no described fallback if empty","penalty":-10,"pattern":"no-empty-input-handling","description":"No empty-input handling described for $ARGUMENTS","false_positive":false,"suggested_fix":"Add explicit guidance for the no-argument case (e.g. ask the user for a drawing path)"} +{"category":"nl_quality","rule_id":"R-empty-input-handling","file":".claude/commands/ink-art.md","line":15,"severity":"low","confidence":"high","evidence":"Body ends with 'Request: $ARGUMENTS' with no described fallback if empty","penalty":-10,"pattern":"no-empty-input-handling","description":"No empty-input handling described for $ARGUMENTS","false_positive":false,"suggested_fix":"Add explicit guidance for the no-argument case"} +{"category":"security","rule_id":"SEC-unsanitized-argument-interpolation","file":".claude/commands/backlot.md","line":9,"severity":"high","confidence":"high","evidence":"Body contains fenced bash block: python -m backlot open $ARGUMENTS, with no quoting/sanitization and no allowed-tools restriction gating Bash use","penalty":null,"pattern":"SEC-unsanitized-argument-interpolation","description":"$ARGUMENTS interpolated directly into a shell command with no sanitization or quoting","false_positive":false,"suggested_fix":"Quote the argument (\"$ARGUMENTS\") and/or validate it as a safe project-id pattern before shell interpolation; requires private disclosure, not a public PR"} +{"category":"security","rule_id":"SEC-runtime-package-install","file":".agents/skills/remotion-to-hyperframes/assets/test-corpus/run.sh","line":130,"severity":"medium","confidence":"high","evidence":"Line 130: (cd \"$fixture_dir/remotion-src\" && npm install --silent --no-progress >/dev/null 2>&1) runs automatically on first invocation","penalty":null,"pattern":"SEC-runtime-package-install","description":"Automatic npm install at runtime inside a test/smoke script, no confirmation gate","false_positive":false,"suggested_fix":"Gate behind an explicit --install flag or precondition check"} +{"category":"security","rule_id":"SEC-unpinned-semver","file":"requirements.txt","line":1,"severity":"low","confidence":"high","evidence":"All entries use >= lower-bound constraints (e.g. pyyaml>=6.0), no lockfile present","penalty":null,"pattern":"SEC-unpinned-semver","description":"Unpinned Python dependency version floors, no lockfile","false_positive":false,"suggested_fix":"Adopt pip-compile/uv lock or pin exact versions"} +{"category":"security","rule_id":"SEC-unpinned-semver","file":"remotion-composer/package.json","line":2,"severity":"low","confidence":"medium","evidence":"","penalty":null,"pattern":"SEC-unpinned-semver","description":"Caret-range npm dependency versions; risk mitigated by committed package-lock.json","false_positive":false,"suggested_fix":"Consider exact pinning for production dependencies despite the existing lockfile"} diff --git a/auditor/audits/calesthio-OpenMontage.md b/auditor/audits/calesthio-OpenMontage.md new file mode 100644 index 000000000..676f60880 --- /dev/null +++ b/auditor/audits/calesthio-OpenMontage.md @@ -0,0 +1,210 @@ +# NLPM Audit: calesthio/OpenMontage +**Date**: 2026-04-06 | **Artifacts**: 152 | **Strategy**: progressive +**NL Score**: 95/100 +**Security**: REVIEW +**Bugs**: 21 | **Quality Issues**: 15 | **Security Findings**: 4 + +## NL Score Summary +| File | Type | Score | Top Issue | +|------|------|-------|-----------| +| .agents/skills/motion-graphics/agents/director.md | agent | 55/100 | No frontmatter/model/examples; broken ref to `references/shot-plan-ir.md` | +| .agents/skills/motion-graphics/agents/builder.md | agent | 55/100 | No frontmatter/model/examples; broken refs `catalog-map.md`, `references/builder-contract.md` | +| .agents/skills/motion-graphics/agents/finalize.md | agent | 55/100 | No frontmatter, no declared model, zero example blocks | +| .agents/skills/ltx2/SKILL.md | skill | 55/100 | Documents nonexistent `tools/ltx2.py` CLI; real tool is `tools/video/ltx_video_modal.py` | +| .agents/skills/manimgl-best-practices/SKILL.md | skill | 65/100 | 5 broken example file links (L51-55) | +| .agents/skills/website-to-video/SKILL.md | skill | 68/100 | Broken relative refs to hyperframes techniques/html-in-canvas docs (L144-145) | +| .claude/skills/video_toolkit/SKILL.md | skill | 70/100 | Directory name `video_toolkit` mismatches frontmatter `name: video-toolkit` | +| .agents/skills/d3-viz/SKILL.md | skill | 78/100 | Template refs `.js`, real files are `.jsx` (L814-815) | +| .agents/skills/remotion/SKILL.md | skill | 80/100 | Broken ref to nonexistent `remotion-official` skill | +| .agents/skills/acestep/SKILL.md | skill | 80/100 | Wrong tool path `tools/music_gen.py` + nonexistent `tools/sfx.py` | +| .agents/skills/video-toolkit/SKILL.md | skill | 85/100 | Duplicate `#### 4e.` heading; `MODAL_DEWATERMARK_ENDPOINT_URL` env var has no matching deploy step | +| .claude/commands/animated-drawing.md | command | 85/100 | Missing `allowed-tools`; no empty-input handling | +| .claude/commands/ink-art.md | command | 85/100 | Missing `allowed-tools`; no empty-input handling | +| .claude/skills/ai-video-gen/SKILL.md | skill | 87/100 | Stale vs `.agents/skills/ai-video-gen/SKILL.md` — missing Kling Official gateway (supplementary finding, see note below) | +| .agents/skills/remotion-best-practices/SKILL.md | skill | 90/100 | Broken ref `rules/sound-effects.md` (real file: `sfx.md`) | +| .agents/skills/beautiful-mermaid/SKILL.md | skill | 90/100 | Requires nonexistent `agent-browser` skill (L12) | +| .agents/skills/synthetic-screen-recording/SKILL.md | skill | 90/100 | Broken ref to nonexistent `projects/openmontage-showcase/build_composition.py` (L182) | +| .agents/skills/vercel-react-best-practices/SKILL.md | skill | 90/100 | Claims "65 rules" — 68 rule files exist (L12) | +| .claude/skills/vercel-react-best-practices/SKILL.md | skill | 90/100 | Claims "65 rules" — 68 rule files exist (L12) | +| .agents/skills/ffmpeg/SKILL.md | skill | 90/100 | Self-ref path assumes `.claude/` tree while file lives under `.agents/` (L432) | +| .claude/skills/ffmpeg/SKILL.md | skill | 90/100 | Self-ref path assumes `.claude/` tree (L432) | +| .agents/skills/video-understand/SKILL.md | skill | 90/100 | Script paths missing `.agents/`/`.claude/` tree prefix (L22-43) | +| .claude/skills/video-understand/SKILL.md | skill | 90/100 | Script paths missing tree prefix (L22-43) | +| .cursor/commands/animated-drawing.md | command | 90/100 | No YAML frontmatter (non-Claude-Code format; may be intentional for Cursor) | +| .cursor/commands/backlot.md | command | 90/100 | No YAML frontmatter (may be intentional for Cursor) | +| .cursor/commands/ink-art.md | command | 90/100 | No YAML frontmatter (may be intentional for Cursor) | +| .claude/commands/backlot.md | command | 95/100 | Missing `allowed-tools`; unsanitized `$ARGUMENTS` in bash block — see Security | +| .agents/skills/motion-graphics/SKILL.md | skill | 95/100 | Broken ref `motion-graphics-genre.md` (L172) | +| .agents/skills/flux-best-practices/SKILL.md | skill | 96/100 | Vague "optimal"/"Comprehensive" | +| .agents/skills/visual-style/SKILL.md | skill | 96/100 | Vague "appropriate" x2 (L41, L50) | +| .claude/skills/visual-style/SKILL.md | skill | 96/100 | Vague "appropriate" x2 (L41, L50) | +| .agents/skills/ai-video-gen/SKILL.md | skill | 97/100 | `allowed-tools: mcp__heygen__*` declared, never invoked in body | +| .agents/skills/video-translate/SKILL.md | skill | 97/100 | `allowed-tools: mcp__heygen__*` declared, never invoked in body | +| .agents/skills/faceswap/SKILL.md | skill | 97/100 | `allowed-tools: mcp__heygen__*` declared, never invoked in body | +| .agents/skills/agents/references/agent-configuration.md | reference | 98/100 | Vague "relevant" (L279) | +| .claude/skills/agents/references/agent-configuration.md | reference | 98/100 | Vague "relevant" (L279) | +| .agents/skills/agents/references/client-tools.md | reference | 98/100 | Vague "reasonable" (L463) | +| .claude/skills/agents/references/client-tools.md | reference | 98/100 | Vague "reasonable" (L463) | +| .agents/skills/remotion-to-hyperframes/SKILL.md | skill | 98/100 | Vague "relevant" (L95) | +| .agents/skills/comfyui/SKILL.md | skill | 98/100 | Vague "usually" (L27) | +| .agents/skills/seedance-2-0/SKILL.md | skill | 98/100 | Vague "optimal" (L161) | +| CLAUDE.md | memory | 100/100 | none | +| .agents/skills/agents/SKILL.md | skill | 100/100 | none | +| .claude/skills/agents/SKILL.md | skill | 100/100 | none | +| .agents/skills/agents/references/outbound-calls.md | reference | 100/100 | none | +| .claude/skills/agents/references/outbound-calls.md | reference | 100/100 | none | +| .agents/skills/agents/references/widget-embedding.md | reference | 100/100 | none | +| .claude/skills/agents/references/widget-embedding.md | reference | 100/100 | none | +| .agents/skills/agents/references/installation.md | reference | 100/100 | none | +| .claude/skills/agents/references/installation.md | reference | 100/100 | none | +| .agents/skills/manimce-best-practices/SKILL.md | skill | 100/100 | none | +| .agents/skills/manim-composer/SKILL.md | skill | 100/100 | none | +| .agents/skills/gsap-core/SKILL.md | skill | 100/100 | none | +| .agents/skills/gsap-utils/SKILL.md | skill | 100/100 | none | +| .agents/skills/gsap-timeline/SKILL.md | skill | 100/100 | none | +| .agents/skills/gsap-react/SKILL.md | skill | 100/100 | none | +| .agents/skills/gsap-scrolltrigger/SKILL.md | skill | 100/100 | none | +| .agents/skills/threejs-materials/SKILL.md | skill | 100/100 | none | +| .agents/skills/threejs-postprocessing/SKILL.md | skill | 100/100 | none | +| .agents/skills/threejs-interaction/SKILL.md | skill | 100/100 | none | +| .agents/skills/threejs-lighting/SKILL.md | skill | 100/100 | none | +| .agents/skills/threejs-shaders/SKILL.md | skill | 100/100 | none | +| .agents/skills/threejs-fundamentals/SKILL.md | skill | 100/100 | none | +| .agents/skills/threejs-loaders/SKILL.md | skill | 100/100 | none | +| .agents/skills/threejs-animation/SKILL.md | skill | 100/100 | none | +| .claude/skills/threejs-animation/SKILL.md | skill | 100/100 | none | +| .agents/skills/threejs-geometry/SKILL.md | skill | 100/100 | none | +| .claude/skills/threejs-geometry/SKILL.md | skill | 100/100 | none | +| .agents/skills/threejs-textures/SKILL.md | skill | 100/100 | none | +| .claude/skills/threejs-textures/SKILL.md | skill | 100/100 | none | +| .agents/skills/hyperframes/SKILL.md | skill | 100/100 | none | +| .agents/skills/hyperframes-registry/SKILL.md | skill | 100/100 | none | +| .agents/skills/hyperframes-cli/SKILL.md | skill | 100/100 | none | +| .agents/skills/hyperframes-creative/SKILL.md | skill | 100/100 | none | +| .agents/skills/elevenlabs/SKILL.md | skill | 100/100 | none | +| .agents/skills/doubao-tts/SKILL.md | skill | 100/100 | none | +| .agents/skills/text-to-speech/SKILL.md | skill | 100/100 | none | +| .agents/skills/speech-to-text/SKILL.md | skill | 100/100 | none | +| .agents/skills/azure-speech-to-text/SKILL.md | skill | 100/100 | none | +| .claude/skills/azure-speech-to-text/SKILL.md | skill | 100/100 | none | +| .agents/skills/music/SKILL.md | skill | 100/100 | none | +| .claude/skills/music/SKILL.md | skill | 100/100 | none | +| .agents/skills/music-to-video/SKILL.md | skill | 100/100 | none | +| .agents/skills/dashscope/SKILL.md | skill | 100/100 | none | +| .agents/skills/sound-effects/SKILL.md | skill | 100/100 | none | +| .claude/skills/sound-effects/SKILL.md | skill | 100/100 | none | +| .agents/skills/video-download/SKILL.md | skill | 100/100 | none | +| .agents/skills/video-edit/SKILL.md | skill | 100/100 | none | +| .agents/skills/create-video/SKILL.md | skill | 100/100 | none | +| .agents/skills/grok-media/SKILL.md | skill | 100/100 | none | +| .agents/skills/gemini-omni/SKILL.md | skill | 100/100 | none | +| .agents/skills/bfl-api/SKILL.md | skill | 100/100 | none | +| .agents/skills/character-rigging/SKILL.md | skill | 100/100 | none | +| .agents/skills/character-animation-qa/SKILL.md | skill | 100/100 | none | +| .agents/skills/svg-character-animation/SKILL.md | skill | 100/100 | none | +| .agents/skills/pose-library-design/SKILL.md | skill | 100/100 | none | +| .agents/skills/playwright-recording/SKILL.md | skill | 100/100 | none | +| .claude/skills/playwright-recording/SKILL.md | skill | 100/100 | none | +| .agents/skills/lottie-bodymovin/SKILL.md | skill | 100/100 | none | +| .agents/skills/framer-motion/SKILL.md | skill | 100/100 | none | +| .agents/skills/web-design-guidelines/SKILL.md | skill | 100/100 | none | +| .agents/skills/tailwind-design-system/SKILL.md | skill | 100/100 | none | +| .agents/skills/heygen/SKILL.md | skill | 100/100 | none | +| .claude/skills/heygen/SKILL.md | skill | 100/100 | none | +| .agents/skills/setup-api-key/SKILL.md | skill | 100/100 | none | +| .claude/skills/setup-api-key/SKILL.md | skill | 100/100 | none | +| .agents/skills/vercel-composition-patterns/SKILL.md | skill | 100/100 | none | +| .claude/skills/vercel-composition-patterns/SKILL.md | skill | 100/100 | none | +| .agents/skills/avatar-video/SKILL.md | skill | 100/100 | none | + +Note: `.claude/skills/ai-video-gen/SKILL.md` was not in the originally supplied file manifest but was scored and included above because it is the direct sibling of `.agents/skills/ai-video-gen/SKILL.md` (item in the manifest) and diffing the two surfaced a genuine content-drift bug (see Cross-Component). Excluding it, the manifest-only average is effectively unchanged (weighted average across all 99 unique scored artifacts ≈ 94.6, rounded to 95). + +## Security Scan +| Severity | Count | +|----------|-------| +| Critical | 0 | +| High | 1 | +| Medium | 1 | +| Low | 2 | + +### Execution Surface Inventory +| Surface | Files | +|---------|-------| +| Hooks | 0 (only `.git/hooks`, not plugin-owned) | +| Scripts (.sh/.py/.js) | 483 | +| MCP configs (.mcp.json) | 0 | +| package.json manifests | 4 (`remotion-composer/package.json` + 3 under `.agents/skills/remotion-to-hyperframes/assets/test-corpus/*/remotion-src/package.json`, no `postinstall` scripts in any) | +| requirements*.txt | 3 (`requirements.txt`, `requirements-dev.txt`, `requirements-gpu.txt`) | +| Claude Code slash commands with Bash-executable bodies | 3 (`.claude/commands/{animated-drawing,backlot,ink-art}.md`) | + +### Security Findings +| # | Severity | File | Line | Pattern | Description | +|---|----------|------|------|---------|--------------| +| 1 | High | .claude/commands/backlot.md | 9 | Unsanitized argument interpolation into shell command | Command body is a fenced ```bash block containing `python -m backlot open $ARGUMENTS` with no quoting or sanitization; a `project-id` argument containing shell metacharacters would be interpreted by the shell. No `allowed-tools` restriction gates Bash use either. | +| 2 | Medium | .agents/skills/remotion-to-hyperframes/assets/test-corpus/run.sh | 130 | Runtime package install | `npm install --silent --no-progress` runs automatically inside a test/smoke script on first run, with no explicit user confirmation gate. | +| 3 | Low | requirements.txt | 1-16 | Unpinned dependency versions | All Python deps use `>=` lower-bound-only constraints (e.g. `pyyaml>=6.0`); no lockfile present for the root Python environment, so resolved versions can drift between installs. | +| 4 | Low | remotion-composer/package.json | 2-14 | Unpinned dependency versions | `dependencies` use caret ranges (e.g. `"remotion": "^4.0.484"`); risk is mitigated by the committed `remotion-composer/package-lock.json`, but the manifest itself is not exact-pinned. | + +No Critical patterns found: no curl-pipe-to-shell, no `eval()`/`exec()` on dynamic input, no `os.system()`, no `subprocess(..., shell=True)`, no reverse shells, no base64-decode-then-execute, no credential exfiltration to third-party endpoints. The `x-key`/`X-Api-Key` header usage in `bfl-api` and `avatar-video`/`heygen` skills sends API keys only to each provider's own documented API host — standard auth, not exfiltration. `sudo apt install ffmpeg` strings across several `tools/*.py` files are user-facing install instructions printed to stdout, never executed by the script itself. + +## Bugs (PR-worthy) +| # | File | Issue | Impact | +|---|------|-------|--------| +| 1 | .agents/skills/motion-graphics/agents/director.md | Broken relative ref `references/shot-plan-ir.md`; resolves under `agents/` (file's own dir), real file is one directory up at `motion-graphics/references/shot-plan-ir.md` | Agent following its own doc link gets a file-not-found instead of the shot-plan schema | +| 2 | .agents/skills/motion-graphics/agents/builder.md | Broken relative refs `catalog-map.md` (L12) and `references/builder-contract.md` (L24); both need a `../` prefix | Same class of failure — build-contract rules become unreachable | +| 3 | .agents/skills/motion-graphics/agents/director.md, builder.md, finalize.md | Missing YAML frontmatter (name/description), no declared model, zero example blocks | Breaks Claude Code agent-registration discovery; no model-tier calibration | +| 4 | .agents/skills/motion-graphics/SKILL.md | Broken ref to `motion-graphics-genre.md` §5-7 (L172); file does not exist anywhere in the repo | Registration guidance points nowhere | +| 5 | .agents/skills/manimgl-best-practices/SKILL.md | "Complete, tested example files" section (L51-55) links to `examples/basic_animations.py`, `math_visualization.py`, `graph_plotting.py`, `3d_visualization.py`, `updater_patterns.py` — none exist; real examples dir has differently-named files (e.g. `mlp_neurons_flow.py`) | Every linked example is a dead link | +| 6 | .agents/skills/remotion/SKILL.md | References `.claude/skills/remotion-official/` (L3, L8) as the source of "core Remotion knowledge" — directory does not exist anywhere in the repo | Core-knowledge pointer is entirely dangling | +| 7 | .agents/skills/remotion-best-practices/SKILL.md | Links to `./rules/sound-effects.md` (L26); actual file is `./rules/sfx.md` | Sound-effects guidance unreachable via the documented link | +| 8 | .agents/skills/acestep/SKILL.md | All Quick Reference commands (L15-91) invoke `python tools/music_gen.py`; real script is `tools/audio/music_gen.py`. Also references `tools/sfx.py` (L262), which does not exist anywhere in the repo | Every copy-pasted example command fails with file-not-found | +| 9 | .agents/skills/ltx2/SKILL.md | Entire Quick Reference/Setup documents a `tools/ltx2.py` CLI and `docker/modal-ltx2/app.py` deploy path; neither exists. Real tools are `tools/video/ltx_video_modal.py` / `ltx_video_local.py`, invoked via `tools.tool_registry` (per the working pattern in `seedance-2-0/SKILL.md`) | Skill is unusable as literally written | +| 10 | .agents/skills/website-to-video/SKILL.md | Broken relative refs `../hyperframes/references/techniques.md` and `../hyperframes/references/html-in-canvas-patterns.md` (L144-145); real files live at `.agents/skills/hyperframes-animation/techniques.md` and `.../hyperframes-animation/adapters/html-in-canvas-patterns.md` (different skill name, no `references/` subdir) | Two of the five workflow-technique links are dangling | +| 11 | .agents/skills/synthetic-screen-recording/SKILL.md | References `projects/openmontage-showcase/build_composition.py` (L182) as "the reference implementation"; no `projects/` directory exists anywhere in the repo | Cited reference implementation is unreachable | +| 12 | .agents/skills/d3-viz/SKILL.md | "Templates" section (L814-815) references `chart-template.js` / `interactive-template.js`; actual files are `.jsx` (`assets/chart-template.jsx`, `assets/interactive-template.jsx`) | Both starter-template links are dead | +| 13 | .agents/skills/beautiful-mermaid/SKILL.md | Requires an `agent-browser` skill for PNG capture (L12, L92-110); no such skill exists anywhere in the repo | PNG-capture step (Step 4) cannot be completed as documented | +| 14 | .agents/skills/vercel-react-best-practices/SKILL.md + .claude twin | Description (L12) claims "Contains 65 rules across 8 categories"; `rules/` actually contains 68 `.md` files | Stale count misleads consumers about rubric coverage | +| 15 | .claude/skills/video_toolkit/SKILL.md | Directory name `video_toolkit` (underscore) does not match its own frontmatter `name: video-toolkit` / `metadata.openclaw.skillKey: video-toolkit` (hyphen) — the `.agents/` sibling correctly uses `video-toolkit` for both | Claude Code resolves skills by directory name; this mismatch risks the skill failing to register/load correctly under its declared name | +| 16 | .agents/skills/video-toolkit/SKILL.md (+ .claude/video_toolkit twin) | Duplicate `#### 4e.` step heading used twice — "Talking Head Narrator" (L298) and "Image Editing" (L330); also deploys `docker/modal-propainter/app.py` (L70) but documents env var `MODAL_DEWATERMARK_ENDPOINT_URL` (L87) with no matching `MODAL_PROPAINTER_ENDPOINT_URL` or dedicated dewatermark deploy step | Step numbering is ambiguous; env var wiring for the propainter/dewatermark tool is inconsistent | +| 17 | .claude/skills/ai-video-gen/SKILL.md | Stale relative to `.agents/skills/ai-video-gen/SKILL.md`: missing the "Kling Official" direct-API gateway/provider and `KLING_API_KEY` documented in the sibling copy | Claude Code users of this skill are told there are only two provider gateways when a third (working) one exists | +| 18 | .agents/skills/video-understand/SKILL.md (+ .claude twin) | All "Commands" examples use path `skills/video-understand/scripts/understand_video.py`, omitting the `.agents/`/`.claude/` tree prefix | None of the copy-paste commands resolve when run from repo root | +| 19 | .agents/skills/ffmpeg/SKILL.md | "Improve this skill" flow (L432) hardcodes `.claude/skills/ffmpeg/SKILL.md`; this exact file lives under `.agents/skills/ffmpeg/` in this tree | Instruction is wrong when the skill is read from the `.agents/` copy | +| 20 | .agents/skills/video-translate/SKILL.md, .agents/skills/faceswap/SKILL.md | Both declare `allowed-tools: mcp__heygen__*` (L5) but never reference any `mcp__heygen__*` tool in the body (grep count = 1, the frontmatter line itself) | Declared tool permission is dead weight; contrast with `create-video/SKILL.md` and `avatar-video/SKILL.md`, which document the MCP tools explicitly | +| 21 | .agents/skills/ai-video-gen/SKILL.md (+ .claude twin) | Same unused-tool pattern: `allowed-tools: mcp__heygen__*` declared, never invoked in body | Same as #20 | + +## Security Fixes (PR-worthy, Medium/Low only) +| # | File | Issue | Suggested Fix | +|---|------|-------|---------------| +| 1 | .agents/skills/remotion-to-hyperframes/assets/test-corpus/run.sh | Auto-runs `npm install` on first invocation with no confirmation | Gate behind an explicit `--install` flag or check for a lockfile-satisfied `node_modules` before installing silently | +| 2 | requirements.txt | Unpinned `>=` version floors, no lockfile | Adopt a lockfile (`pip-compile`/`uv lock`) or pin exact versions for reproducible installs | + +Note: the High-severity `backlot.md` finding and its `.cursor/` counterpart are **not** included here per instructions — Critical/High findings require private disclosure, not public PRs. + +## Quality Issues (informational) +| # | File | Issue | Penalty | +|---|------|-------|---------| +| 1 | .agents/skills/agents/references/agent-configuration.md (+ .claude twin) | Vague quantifier "relevant" (L279) | -2 | +| 2 | .agents/skills/agents/references/client-tools.md (+ .claude twin) | Vague quantifier "reasonable" (L463) | -2 | +| 3 | .agents/skills/remotion-to-hyperframes/SKILL.md | Vague quantifier "relevant" (L95) | -2 | +| 4 | .agents/skills/seedance-2-0/SKILL.md | Vague quantifier "optimal" (L161) | -2 | +| 5 | .agents/skills/flux-best-practices/SKILL.md | Vague quantifiers "optimal" (L12), "Comprehensive" (L3) | -4 | +| 6 | .agents/skills/comfyui/SKILL.md | Vague quantifier "usually" (L27) | -2 | +| 7 | .agents/skills/visual-style/SKILL.md (+ .claude twin) | Vague quantifier "appropriate" x2 (L41, L50) | -4 | +| 8 | .agents/skills/website-to-video/SKILL.md | Vague quantifier "as needed" (L59) | -2 | +| 9 | .agents/skills/d3-viz/SKILL.md | Vague quantifier "as needed" (L818) | -2 | +| 10 | .claude/commands/animated-drawing.md | Missing `allowed-tools` frontmatter field | -5 | +| 11 | .claude/commands/backlot.md | Missing `allowed-tools` frontmatter field | -5 | +| 12 | .claude/commands/ink-art.md | Missing `allowed-tools` frontmatter field | -5 | +| 13 | .claude/commands/animated-drawing.md | No empty-input handling described for `$ARGUMENTS` | -10 | +| 14 | .claude/commands/ink-art.md | No empty-input handling described for `$ARGUMENTS` | -10 | +| 15 | .cursor/commands/{animated-drawing,backlot,ink-art}.md | No YAML frontmatter at all — low confidence this is a defect rather than intentional Cursor-format convention (Cursor is outside NLPM's tracked tier overlays) | informational only, no penalty applied | + +## Cross-Component +- **`.claude/skills/ai-video-gen/SKILL.md` vs `.agents/skills/ai-video-gen/SKILL.md`**: the two copies are supposed to be identical mirrors (confirmed identical for every other shared skill name between the two trees — `agents`, `heygen`, `music`, `vercel-react-best-practices`, `threejs-animation`, etc.) but this pair has drifted: the `.claude` copy is missing the "Kling Official" direct-API gateway that the `.agents` copy documents. This is the only content-diverging pair found among ~48 shared skill names. +- **`video_toolkit` (.claude/) vs `video-toolkit` (.agents/)**: same skill, dual-published under inconsistent directory-naming conventions (underscore vs. hyphen). Content is otherwise byte-identical. The `.claude/` copy's directory name doesn't match its own declared `name:`/`skillKey:` field (see Bug #15); the `.agents/` copy's directory name matches correctly. +- **`.claude/skills/` is a partial mirror of `.agents/skills/`**: only ~48 of the ~85 skills under `.agents/skills/` are mirrored into `.claude/skills/`. Skills present only in `.agents/skills/` (not orphaned, just not dual-published) include the `gsap-*` family, `hyperframes-*` variants, `character-rigging`, `comfyui`, `kling-official`, `lyria`, `media-use`, and others. This appears to be intentional scoping rather than a bug (no references broken by the asymmetry were found), but is worth confirming with the maintainer. +- **`AGENT_GUIDE.md` reference from `CLAUDE.md`**: confirmed to resolve correctly (46KB file exists at repo root); not a broken reference. +- No stale artifact counts found elsewhere in cross-referencing `AGENTS.md`/`CODEX.md`/`COPILOT.md`/`CURSOR.md` beyond the `vercel-react-best-practices` "65 rules" mismatch (Bug #14). + +## Recommendation +**REVIEW** — submit NL bug-fix PRs for the 21 items above (broken references, frontmatter/naming mismatches, unused-tool declarations), and flag the Medium/Low security findings (auto-`npm install` in a test fixture, unpinned Python dependencies) in the same or a follow-up PR. The one High-severity finding (`.claude/commands/backlot.md` — unsanitized `$ARGUMENTS` interpolated directly into a shell command) requires private disclosure to the maintainer rather than a public PR; do not include it in any public issue or PR description. diff --git a/auditor/disagreements.jsonl b/auditor/disagreements.jsonl index ee21c4762..10136ea1a 100644 --- a/auditor/disagreements.jsonl +++ b/auditor/disagreements.jsonl @@ -228,3 +228,4 @@ {"event":"maintainer_rejected","pr":"laolaoshiren/claude-code-skills-zh#16","fingerprints":["sha256:c949f71c4d1fa09e8c29690639cfb7dab79feca91ef138b5b9ad7628b062a60c","sha256:fa5e9803f2ff3c1a834b85059c9727fc819a7d7316103668c27e40df2e83e529"],"rule_ids":["SEC-temp-file-write","SEC-temp-file-write"],"dissent_type":"context_missed","quote":"We did not adopt the repository .tmp scheme because new directory might still be 0755 under common POSIX umask.","commenter_role":"maintainer","classifier_model":"haiku-4-5","classifier_confidence":"medium","comments_hash":"sha256:021cf038186b23b9ec71e4fb392a3cc2909e331a4dbdc68aaefdb954c966f75f","timestamp":"2026-08-01T04:40:35Z"} {"event": "downstream_suppression", "timestamp": "2026-08-02T00:22:26Z", "repo": "xiaolai/cc-suite", "commit_sha": "6d02d7540acba055eda79c8355e85275a0451a3d", "rule_id": "R31", "suppression_type": "threshold_adjustment", "fingerprint": "sha256:479c2103b7d8dd2532b6af6c514e5d3b95f364db6503416633bba4b838612fde", "file_fingerprint": "sha256:0973eb2098961d7d60ac66c4217a6974abac61cd366b713ee9f4ac626fe6fb59", "path": ".claude/nlpm.local.md", "override_value": {"threshold": 900}, "reason_given": ""} {"event": "downstream_suppression", "timestamp": "2026-08-02T00:22:26Z", "repo": "xiaolai/cc-suite", "commit_sha": "6d02d7540acba055eda79c8355e85275a0451a3d", "rule_id": "R51", "suppression_type": "rule_override", "fingerprint": "sha256:6eb255100e953a537daab93747608eb544524e9e41b5c095b0cafe48079486a2", "file_fingerprint": "sha256:0973eb2098961d7d60ac66c4217a6974abac61cd366b713ee9f4ac626fe6fb59", "path": ".claude/nlpm.local.md", "override_value": {"enabled": true, "vocabulary_skill": "skills/cc-suite/vocabulary/"}, "reason_given": ""} +{"event":"self_false_positive","timestamp":"2026-08-05T07:15:24Z","repo":"calesthio/OpenMontage","fingerprint":"sha256:0b9f3d22e6a8dcdb0bdebfb293e379b9ad87bb1b36c78203f5d769f7b9e6b747","rule_id":"CC-orphan-component","reason":"No broken references were found caused by this asymmetry; likely intentional per-tool scoping rather than a defect","rule_gap":"Rule should distinguish intentional tool-scoped skill subsets from accidental omission before flagging"} diff --git a/auditor/findings.jsonl b/auditor/findings.jsonl index a7a68334f..791c622f7 100644 --- a/auditor/findings.jsonl +++ b/auditor/findings.jsonl @@ -5281,6 +5281,62 @@ {"event":"finding","timestamp":"2026-07-20T12:52:16Z","audit_run_id":"29743382398","repo":"laolaoshiren/claude-code-skills-zh","commit_sha":"6034db4b6df3242803d8e16a4fd6fa4d80001d70","fingerprint":"sha256:fa5e9803f2ff3c1a834b85059c9727fc819a7d7316103668c27e40df2e83e529","category":"security","rule_id":"SEC-temp-file-write","file":"scripts/test_juejin_post.js","line":99,"severity":"low","confidence":"high","evidence":"draftScreenshot = path.join(os.tmpdir(), 'juejin_draft.png')","penalty":null,"pattern":"file-write-outside-repo","description":"Draft/publish screenshots are written to the OS temp directory, outside the repo tree","false_positive":false,"suggested_fix":"Write to a dedicated gitignored .tmp/ directory under the repo instead of os.tmpdir()"} {"event":"finding","timestamp":"2026-07-20T12:52:16Z","audit_run_id":"29743382398","repo":"laolaoshiren/claude-code-skills-zh","commit_sha":"6034db4b6df3242803d8e16a4fd6fa4d80001d70","fingerprint":"sha256:29631582352ec175acb7616f5c1d28395e17b81f944057febf3dec55b5f52a42","category":"security","rule_id":"SEC-network-call","file":"scripts/sync_readme_to_site.py","line":507,"severity":"medium","confidence":"high","evidence":"subprocess.run([\"gh\", \"api\", \"graphql\", \"-f\", f\"query={query}\"], ...) inside fetch_github_stars()","penalty":null,"pattern":"network-call","description":"Invokes gh CLI to perform an external GraphQL network call fetching GitHub star counts for every curated repo URL in README.md","false_positive":false,"suggested_fix":"No fix needed; this is a read-only, non-credentialed (uses gh's own auth) query intrinsic to the script's stated purpose"} {"event":"finding","timestamp":"2026-07-20T12:52:16Z","audit_run_id":"29743382398","repo":"laolaoshiren/claude-code-skills-zh","commit_sha":"6034db4b6df3242803d8e16a4fd6fa4d80001d70","fingerprint":"sha256:005071722d9410b31c590cc01d9a7bc5de806b1ff2423273acc32c9818b50237","category":"cross_component","rule_id":"CC-orphan-component","file":"README.md","line":null,"severity":"info","confidence":"high","evidence":"all 20 skills/*/SKILL.md directories appear in README.md's skills table with matching relative links; scripts/test_sync_readme_to_site.py::test_original_skill_sets_and_promo_counts_are_consistent already asserts this at test time","penalty":null,"pattern":"none","description":"No broken references or orphaned skill directories found; README, docs/index.html, and PROMO.md skill counts are cross-checked by an existing repo test","false_positive":false,"suggested_fix":""} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:4b108299eb2ca5a68aa9ff505a19a2d9df96656cc11a2e0e9661d727d3f583ad","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/motion-graphics/agents/director.md","line":3,"severity":"medium","confidence":"high","evidence":"references/shot-plan-ir.md resolves to agents/references/shot-plan-ir.md relative to the file's own dir, which does not exist; real file is motion-graphics/references/shot-plan-ir.md","penalty":null,"pattern":"broken-relative-path","description":"Broken relative ref to references/shot-plan-ir.md, needs ../ prefix","false_positive":false,"suggested_fix":"Change reference to ../references/shot-plan-ir.md"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:71831368209aa06e45573ff7ae73584be44e1fe8026ade770798634ee9b25d64","category":"bug","rule_id":"BUG-missing-frontmatter","file":".agents/skills/motion-graphics/agents/director.md","line":1,"severity":"high","confidence":"high","evidence":"File has no YAML frontmatter block, no name/description, no model field, zero example blocks","penalty":-45,"pattern":"missing-frontmatter","description":"No frontmatter (name/description), no declared model, zero example blocks","false_positive":false,"suggested_fix":"Add YAML frontmatter with name, description, model, and at least one example block"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:472c0447891ec363439270405deb234f66687df5d50441f3e01783dcab973377","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/motion-graphics/agents/builder.md","line":12,"severity":"medium","confidence":"high","evidence":"catalog-map.md resolves to agents/catalog-map.md relative to file's own dir; real file is motion-graphics/catalog-map.md","penalty":null,"pattern":"broken-relative-path","description":"Broken relative ref to catalog-map.md, needs ../ prefix","false_positive":false,"suggested_fix":"Change reference to ../catalog-map.md"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:3fd00086a7fe02aabd79d35989b5a75ee1a0270aa91b6a266d45e320d3a03720","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/motion-graphics/agents/builder.md","line":24,"severity":"medium","confidence":"high","evidence":"references/builder-contract.md resolves to agents/references/builder-contract.md relative to file's own dir; real file is motion-graphics/references/builder-contract.md","penalty":null,"pattern":"broken-relative-path","description":"Broken relative ref to references/builder-contract.md, needs ../ prefix","false_positive":false,"suggested_fix":"Change reference to ../references/builder-contract.md"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:5d61ddd45b59cf34d958f22e41bc4ab5a0f5d214070cb9e6552c290695c2166c","category":"bug","rule_id":"BUG-missing-frontmatter","file":".agents/skills/motion-graphics/agents/builder.md","line":1,"severity":"high","confidence":"high","evidence":"File has no YAML frontmatter block, no name/description, no model field, zero example blocks","penalty":-45,"pattern":"missing-frontmatter","description":"No frontmatter (name/description), no declared model, zero example blocks","false_positive":false,"suggested_fix":"Add YAML frontmatter with name, description, model, and at least one example block"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:098678a24e97c65926bc2ea7835abe1ef6dacb864cf05da39381a5d7d756e992","category":"bug","rule_id":"BUG-missing-frontmatter","file":".agents/skills/motion-graphics/agents/finalize.md","line":1,"severity":"high","confidence":"high","evidence":"File has no YAML frontmatter block, no name/description, no model field, zero example blocks","penalty":-45,"pattern":"missing-frontmatter","description":"No frontmatter (name/description), no declared model, zero example blocks","false_positive":false,"suggested_fix":"Add YAML frontmatter with name, description, model, and at least one example block"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:2243fd036bcd085e3d4fee65874b2f195d38916b587d4d7331b6254a3d91ae78","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/motion-graphics/SKILL.md","line":172,"severity":"low","confidence":"high","evidence":"find -iname motion-graphics-genre.md returns no results anywhere in repo","penalty":-5,"pattern":"broken-relative-path","description":"Broken ref to motion-graphics-genre.md, file does not exist","false_positive":false,"suggested_fix":"Create the referenced file or remove the pointer"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:313a3a0d8e6ed5faa63dfec241c69e2efe0102580b0c68eedf298fb908740d9f","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/manimgl-best-practices/SKILL.md","line":51,"severity":"medium","confidence":"high","evidence":"examples/basic_animations.py and 4 sibling paths do not exist; ls examples/ shows only differently-named files like mlp_neurons_flow.py","penalty":-10,"pattern":"broken-relative-path","description":"5 broken example file links, real examples directory has different filenames","false_positive":false,"suggested_fix":"Update Working Examples section to link the real files in examples/"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:c609c17d1a7757d2ac66d4310c51b8d0e2890272e981331b7616b74f42c76c44","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/remotion/SKILL.md","line":3,"severity":"medium","confidence":"high","evidence":"find -iname remotion-official returns no results anywhere in repo","penalty":-15,"pattern":"broken-relative-path","description":"References nonexistent .claude/skills/remotion-official/ skill for core Remotion knowledge","false_positive":false,"suggested_fix":"Remove the pointer or vendor the remotion-official skill as documented"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:dd7d0d56e10a66081d5ba6dbf3d1479c0ba281d3f7a549f592c7975d0a4f3067","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/remotion-best-practices/SKILL.md","line":26,"severity":"low","confidence":"high","evidence":"./rules/sound-effects.md does not exist; ls rules/ shows sfx.md instead","penalty":-10,"pattern":"broken-relative-path","description":"Broken ref to rules/sound-effects.md, real file is rules/sfx.md","false_positive":false,"suggested_fix":"Fix link to ./rules/sfx.md"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:333727b82d846fbed13b30c994d7656053d05d53bb3d931b64e85114c0051839","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/acestep/SKILL.md","line":15,"severity":"medium","confidence":"high","evidence":"find -iname music_gen.py shows only tools/audio/music_gen.py; tools/music_gen.py does not exist","penalty":-10,"pattern":"broken-relative-path","description":"Quick Reference commands invoke tools/music_gen.py, real path is tools/audio/music_gen.py","false_positive":false,"suggested_fix":"Update all example commands to python tools/audio/music_gen.py"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:6838e268bc749a1ad8fa57fc5162daf323b4c9bd9cbbdd7119b604814469a395","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/acestep/SKILL.md","line":262,"severity":"medium","confidence":"high","evidence":"find -iname sfx.py returns no results anywhere in repo","penalty":-10,"pattern":"broken-relative-path","description":"References tools/sfx.py which does not exist anywhere in the repo","false_positive":false,"suggested_fix":"Point to the actual SFX provider (e.g. hyperframes-media/scripts/lib/sfx.mjs) or remove the reference"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:b154ab8374349dc750dfaa99430bc25539d9701666f6efc5cc9f3e4652316d54","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/ltx2/SKILL.md","line":15,"severity":"high","confidence":"high","evidence":"find -iname ltx2.py and modal-ltx2 return no results; real tools are tools/video/ltx_video_modal.py and ltx_video_local.py","penalty":-35,"pattern":"broken-relative-path","description":"Entire Quick Reference/Setup documents nonexistent tools/ltx2.py CLI and docker/modal-ltx2/app.py deploy path","false_positive":false,"suggested_fix":"Rewrite Quick Reference to use tools.tool_registry invocation of tools/video/ltx_video_modal.py, matching the pattern used in seedance-2-0/SKILL.md"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:36a091535fec70a61ebc6307b629712b0b2d03eb728b02ccb37111a31d1248f1","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/website-to-video/SKILL.md","line":144,"severity":"medium","confidence":"high","evidence":"../hyperframes/references/techniques.md not found; real file is .agents/skills/hyperframes-animation/techniques.md","penalty":-15,"pattern":"broken-relative-path","description":"Broken relative ref to hyperframes/references/techniques.md, real skill name is hyperframes-animation with no references/ subdir","false_positive":false,"suggested_fix":"Fix link to ../hyperframes-animation/techniques.md"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:836a712227449b7aa41ec909dcdf2ae3fdb5feffde1977b973d457bcae448feb","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/website-to-video/SKILL.md","line":145,"severity":"medium","confidence":"high","evidence":"../hyperframes/references/html-in-canvas-patterns.md not found; real file is .agents/skills/hyperframes-animation/adapters/html-in-canvas-patterns.md","penalty":-15,"pattern":"broken-relative-path","description":"Broken relative ref to hyperframes/references/html-in-canvas-patterns.md","false_positive":false,"suggested_fix":"Fix link to ../hyperframes-animation/adapters/html-in-canvas-patterns.md"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:05af6c68f0ec3580b9dd25d5d5700dd6f0205bb72c968d09ebc08e814f31afe3","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/synthetic-screen-recording/SKILL.md","line":182,"severity":"low","confidence":"high","evidence":"find -type d -name projects at repo root returns no results; no openmontage-showcase directory anywhere","penalty":-10,"pattern":"broken-relative-path","description":"References projects/openmontage-showcase/build_composition.py as reference implementation; path does not exist","false_positive":false,"suggested_fix":"Remove the dangling citation or commit the referenced reference implementation"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:6ab5ada60f43645935cc6ee8c1db68256990c29560c4907c7371620540a05e45","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/d3-viz/SKILL.md","line":814,"severity":"low","confidence":"high","evidence":"assets/ dir has chart-template.jsx and interactive-template.jsx, not .js","penalty":-10,"pattern":"broken-relative-path","description":"Templates section references chart-template.js/interactive-template.js, real files are .jsx","false_positive":false,"suggested_fix":"Update the two links to the .jsx extension"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:eb148f9dbbf3baf527ec8e8854b8098290ccb0c94fd4bbc2601f008c31950acf","category":"bug","rule_id":"BUG-broken-reference","file":".agents/skills/beautiful-mermaid/SKILL.md","line":12,"severity":"medium","confidence":"high","evidence":"find -iname agent-browser returns no results anywhere in repo; no such skill directory under .agents/skills, .claude/skills, or skills/","penalty":-15,"pattern":"broken-relative-path","description":"Requires nonexistent agent-browser skill for PNG capture step","false_positive":false,"suggested_fix":"Vendor or replace the PNG-capture step with an existing screenshot mechanism (e.g. playwright-recording)"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:d09930ac710b5b472262d511c41737e82ed72c7d7b34fc17fe2513e8eafe4c36","category":"bug","rule_id":"BUG-stale-count","file":".agents/skills/vercel-react-best-practices/SKILL.md","line":12,"severity":"low","confidence":"high","evidence":"find rules -path '*/rules/*.md' | wc -l returns 68, description claims 65","penalty":-5,"pattern":"stale-count","description":"Description claims 65 rules across 8 categories, 68 rule files actually exist","false_positive":false,"suggested_fix":"Update the count to 68 or regenerate the description from the rules/ directory listing"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:363e7777ce4a9c95657b72274468765f616fd42fb1f7b7cfc58a8450850c8b99","category":"bug","rule_id":"BUG-stale-count","file":".claude/skills/vercel-react-best-practices/SKILL.md","line":12,"severity":"low","confidence":"high","evidence":"Identical content to .agents/skills/vercel-react-best-practices/SKILL.md, same stale count","penalty":-5,"pattern":"stale-count","description":"Description claims 65 rules across 8 categories, 68 rule files actually exist","false_positive":false,"suggested_fix":"Update the count to 68 or regenerate the description from the rules/ directory listing"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:d9710c7620d850012e9698f619dbb66757d9a552ca288ce552e5ae0fca0555d4","category":"bug","rule_id":"BUG-invalid-directory-name","file":".claude/skills/video_toolkit/SKILL.md","line":2,"severity":"high","confidence":"high","evidence":"Directory is video_toolkit (underscore) but frontmatter name: and metadata.openclaw.skillKey both say video-toolkit (hyphen); .agents/skills/video-toolkit uses matching hyphenated directory name","penalty":-25,"pattern":"skill-name-directory-mismatch","description":"Directory name video_toolkit mismatches declared skill name video-toolkit","false_positive":false,"suggested_fix":"Rename the directory to video-toolkit to match the declared name, or vice versa"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:b2aaa8a97e575502603bcaff8000db5add39322df84a467d1f1a0bd134aa7053","category":"bug","rule_id":"BUG-duplicate-heading","file":".agents/skills/video-toolkit/SKILL.md","line":298,"severity":"low","confidence":"high","evidence":"grep '^#### 4' shows both line 298 (Talking Head Narrator) and line 330 (Image Editing) labeled '#### 4e.'","penalty":-10,"pattern":"duplicate-step-numbering","description":"Duplicate #### 4e. step heading used for two different steps (L298, L330)","false_positive":false,"suggested_fix":"Renumber Image Editing to 4f and shift Upscaling to 4g, or similar resequencing"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:4ae9787e2ab85e7e59363070644eed076ded1f1cbbfa864daca697e570a038f2","category":"bug","rule_id":"BUG-inconsistent-config","file":".agents/skills/video-toolkit/SKILL.md","line":70,"severity":"low","confidence":"high","evidence":"Line 70 deploys docker/modal-propainter/app.py; line 87 lists env var MODAL_DEWATERMARK_ENDPOINT_URL with no MODAL_PROPAINTER_ENDPOINT_URL or matching deploy-to-var mapping shown","penalty":-5,"pattern":"inconsistent-naming","description":"modal-propainter deploy step has no matching MODAL_PROPAINTER_ENDPOINT_URL env var; MODAL_DEWATERMARK_ENDPOINT_URL has no corresponding deploy step","false_positive":false,"suggested_fix":"Align the deploy script name and env var name (both should reference propainter or both dewatermark)"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:017b16f8c53792feac1aa5ba141cce0cabb380318e3778bf94241fd24f15657d","category":"bug","rule_id":"BUG-duplicate-heading","file":".claude/skills/video_toolkit/SKILL.md","line":298,"severity":"low","confidence":"high","evidence":"Identical content to .agents/skills/video-toolkit/SKILL.md, same duplicate heading at L298/L330","penalty":-10,"pattern":"duplicate-step-numbering","description":"Duplicate #### 4e. step heading used for two different steps (L298, L330)","false_positive":false,"suggested_fix":"Renumber Image Editing to 4f and shift Upscaling to 4g, or similar resequencing"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:699d9931484a7e81457358ceed083840e603f73510ed4415e5959ceaea9407c7","category":"cross_component","rule_id":"CC-stale-count","file":".claude/skills/ai-video-gen/SKILL.md","line":null,"severity":"medium","confidence":"high","evidence":"diff .claude/skills/ai-video-gen/SKILL.md .agents/skills/ai-video-gen/SKILL.md shows .claude copy missing Kling Official gateway, KLING_API_KEY, and provider=kling_official guidance present in .agents copy","penalty":-10,"pattern":"sibling-skill-drift","description":"claude/ copy of ai-video-gen is stale vs agents/ sibling, missing Kling Official direct-API gateway","false_positive":false,"suggested_fix":"Re-sync .claude/skills/ai-video-gen/SKILL.md from .agents/skills/ai-video-gen/SKILL.md"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:f27fe4da9fb0c9587ca27771d3f505d41b39c474e7e0f322aa4cab1b0f1161ea","category":"cross_component","rule_id":"CC-terminology-drift","file":".claude/skills/video_toolkit/SKILL.md","line":null,"severity":"low","confidence":"high","evidence":"diff -rq .claude/skills .agents/skills shows video_toolkit (underscore) only under .claude and video-toolkit (hyphen) only under .agents, byte-identical content otherwise","penalty":null,"pattern":"directory-naming-convention-drift","description":"Same skill dual-published under inconsistent directory-naming convention (underscore vs hyphen) across tool trees","false_positive":false,"suggested_fix":"Standardize on video-toolkit (hyphen) for both trees"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:0b9f3d22e6a8dcdb0bdebfb293e379b9ad87bb1b36c78203f5d769f7b9e6b747","category":"cross_component","rule_id":"CC-orphan-component","file":".claude/skills","line":null,"severity":"low","confidence":"medium","evidence":"ls .claude/skills vs .agents/skills shows only ~48 of ~85 .agents/skills/* names mirrored into .claude/skills/","penalty":null,"pattern":"partial-mirror","description":"claude/skills/ is a partial subset mirror of agents/skills/; ~37 skills exist only in agents/ tree","false_positive":true,"fp_reason":"No broken references were found caused by this asymmetry; likely intentional per-tool scoping rather than a defect","rule_gap":"Rule should distinguish intentional tool-scoped skill subsets from accidental omission before flagging","suggested_fix":""} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:070a5df7aa62128a94c2ecf92f1decf0894c8b51a2ac23e765faa1d758309750","category":"nl_quality","rule_id":"R51","file":".agents/skills/agents/references/agent-configuration.md","line":279,"severity":"low","confidence":"high","evidence":"grep shows the word 'relevant' used as a vague qualifier at line 279","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'relevant' used","false_positive":false,"suggested_fix":"Replace with a specific criterion"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:17db59e757bb008a6996f978ca1d5bf36a319d5f2ece2821d040ce78ab6461b3","category":"nl_quality","rule_id":"R51","file":".claude/skills/agents/references/agent-configuration.md","line":279,"severity":"low","confidence":"high","evidence":"Identical content to .agents twin, same vague quantifier at line 279","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'relevant' used","false_positive":false,"suggested_fix":"Replace with a specific criterion"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:51bb67749f20215e1cdd22d508d086e30843a909c291469f6a3574b792d44232","category":"nl_quality","rule_id":"R51","file":".agents/skills/agents/references/client-tools.md","line":463,"severity":"low","confidence":"high","evidence":"grep shows the word 'reasonable' used as a vague qualifier at line 463","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'reasonable' used","false_positive":false,"suggested_fix":"Replace with a specific criterion"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:0f3ed6f553cf0157a6bf44b5172db21628a17f6456d8730f1b25817dd3db6dbb","category":"nl_quality","rule_id":"R51","file":".claude/skills/agents/references/client-tools.md","line":463,"severity":"low","confidence":"high","evidence":"Identical content to .agents twin, same vague quantifier at line 463","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'reasonable' used","false_positive":false,"suggested_fix":"Replace with a specific criterion"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:628be8913ed6bec1d0ffa512f601e58ff7ea4c6e478fc25707c69e7b92f977d0","category":"nl_quality","rule_id":"R51","file":".agents/skills/remotion-to-hyperframes/SKILL.md","line":95,"severity":"low","confidence":"high","evidence":"grep shows the word 'relevant' used as a vague qualifier at line 95","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'relevant' used","false_positive":false,"suggested_fix":"Replace with a specific criterion"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:5d2bad71348cba44fec31ad12c3c21c8b1a8f862aa2396dab32881c70f6924d4","category":"nl_quality","rule_id":"R51","file":".agents/skills/seedance-2-0/SKILL.md","line":161,"severity":"low","confidence":"high","evidence":"grep shows 'optimal' used at line 161: 'appears optimal for multi-shot generations'","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'optimal' used","false_positive":false,"suggested_fix":"State the concrete rhythm/timing basis instead of 'optimal'"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:ec3dbe938f155a6322ab002f9bdd6e9ca598812dfe689a73911f6c4d47c054b8","category":"nl_quality","rule_id":"R51","file":".agents/skills/flux-best-practices/SKILL.md","line":12,"severity":"low","confidence":"high","evidence":"grep shows 'optimal image quality' at line 12 and 'Comprehensive guide' at line 3","penalty":-4,"pattern":"vague-quantifier","description":"Vague quantifiers 'optimal' (L12) and 'Comprehensive' (L3) used","false_positive":false,"suggested_fix":"Replace with concrete quality criteria"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:171d641bd7e3717489c0c5e4086d489d6a6e10d5f9c8158596767bf9834c4bcc","category":"nl_quality","rule_id":"R51","file":".agents/skills/comfyui/SKILL.md","line":27,"severity":"low","confidence":"high","evidence":"grep shows 'usually SaveImage, SaveVideo, ...' at line 27","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'usually' used","false_positive":false,"suggested_fix":"Enumerate the exact node types deterministically instead of 'usually'"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:e1a893c029da90a7028b82a88a280e9b89b60cdd78ea2b21a4ed04d1e605ae81","category":"nl_quality","rule_id":"R51","file":".agents/skills/visual-style/SKILL.md","line":41,"severity":"low","confidence":"high","evidence":"grep shows 'the appropriate extractor reference file' (L41) and 'the appropriate connector reference file' (L50)","penalty":-4,"pattern":"vague-quantifier","description":"Vague quantifier 'appropriate' used twice (L41, L50)","false_positive":false,"suggested_fix":"Name the specific selection criterion for choosing the extractor/connector file"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:3bb18dafe52dd3ec938f98a4cda5bb9c2b346842c441cbbd2d2d06de787644ae","category":"nl_quality","rule_id":"R51","file":".claude/skills/visual-style/SKILL.md","line":41,"severity":"low","confidence":"high","evidence":"Identical content to .agents twin, same vague quantifiers at L41, L50","penalty":-4,"pattern":"vague-quantifier","description":"Vague quantifier 'appropriate' used twice (L41, L50)","false_positive":false,"suggested_fix":"Name the specific selection criterion for choosing the extractor/connector file"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:3beb4d6938c1b91563ba3b6970bdafba740a276c7fdf071d4a9bd5e03ab55ab4","category":"nl_quality","rule_id":"R51","file":".agents/skills/website-to-video/SKILL.md","line":59,"severity":"low","confidence":"medium","evidence":"","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'as needed' used","false_positive":false,"suggested_fix":"Specify the concrete condition instead of 'as needed'"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:e1f2033d11fb42024a40a9916741998968ed88faba321141d16b42e42af70791","category":"nl_quality","rule_id":"R51","file":".agents/skills/d3-viz/SKILL.md","line":818,"severity":"low","confidence":"medium","evidence":"","penalty":-2,"pattern":"vague-quantifier","description":"Vague quantifier 'as needed' used","false_positive":false,"suggested_fix":"Specify the concrete condition instead of 'as needed'"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:9b4f0dba866c360e853b519fe89218ed9b09d0e740aa825b7228d29fbcf41155","category":"nl_quality","rule_id":"BUG-undeclared-tool","file":".agents/skills/ai-video-gen/SKILL.md","line":5,"severity":"low","confidence":"high","evidence":"grep -c mcp__heygen returns 1 (frontmatter line only), no invocation elsewhere in body","penalty":-3,"pattern":"unused-declared-tool","description":"allowed-tools: mcp__heygen__* declared but never invoked in body","false_positive":false,"suggested_fix":"Either document an mcp__heygen__* call site or remove the allowed-tools declaration"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:33b305912c7dc6bf08a3f89f7ae4507c5a6a415b33b66476ab6d3363f7363243","category":"nl_quality","rule_id":"BUG-undeclared-tool","file":".claude/skills/ai-video-gen/SKILL.md","line":5,"severity":"low","confidence":"high","evidence":"grep -c mcp__heygen returns 1 (frontmatter line only), no invocation elsewhere in body","penalty":-3,"pattern":"unused-declared-tool","description":"allowed-tools: mcp__heygen__* declared but never invoked in body","false_positive":false,"suggested_fix":"Either document an mcp__heygen__* call site or remove the allowed-tools declaration"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:5afcb724764d5a39f0bfa189f8d52522d499f70c3c01d63e92b3634c4be8cf02","category":"nl_quality","rule_id":"BUG-undeclared-tool","file":".agents/skills/video-translate/SKILL.md","line":5,"severity":"low","confidence":"high","evidence":"grep -c mcp__heygen returns 1 (frontmatter line only), no invocation elsewhere in body","penalty":-3,"pattern":"unused-declared-tool","description":"allowed-tools: mcp__heygen__* declared but never invoked in body","false_positive":false,"suggested_fix":"Either document an mcp__heygen__* call site or remove the allowed-tools declaration"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:34bfdaf178357bdb3ca9b1a24684bda48bbbd7380e8accccda0611ad4db15343","category":"nl_quality","rule_id":"BUG-undeclared-tool","file":".agents/skills/faceswap/SKILL.md","line":5,"severity":"low","confidence":"high","evidence":"grep -c mcp__heygen returns 1 (frontmatter line only), no invocation elsewhere in body","penalty":-3,"pattern":"unused-declared-tool","description":"allowed-tools: mcp__heygen__* declared but never invoked in body","false_positive":false,"suggested_fix":"Either document an mcp__heygen__* call site or remove the allowed-tools declaration"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:0c2cb542832a71c95b0d2526ccd1534281bd60c923a163d39f84f23ce1fb4c3e","category":"nl_quality","rule_id":"BUG-broken-reference","file":".agents/skills/ffmpeg/SKILL.md","line":432,"severity":"low","confidence":"high","evidence":"Line reads 'update .claude/skills/ffmpeg/SKILL.md' while this file itself is located at .agents/skills/ffmpeg/SKILL.md","penalty":-5,"pattern":"tree-specific-hardcoded-path","description":"Self-referential improve-this-skill path hardcodes .claude/ tree, wrong when read from .agents/ copy","false_positive":false,"suggested_fix":"Reference the file generically (e.g. 'this SKILL.md') instead of a tree-specific absolute path"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:d8526cce0a77c260b1f9d55f72f5abeeae376829d8454c093fa8a4acc89459bc","category":"nl_quality","rule_id":"BUG-broken-reference","file":".claude/skills/ffmpeg/SKILL.md","line":432,"severity":"low","confidence":"high","evidence":"Identical content, same hardcoded .claude/ path, correct for this copy but demonstrates the underlying dual-tree fragility","penalty":-5,"pattern":"tree-specific-hardcoded-path","description":"Self-referential improve-this-skill path hardcodes .claude/ tree","false_positive":false,"suggested_fix":"Reference the file generically instead of a tree-specific absolute path"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:fee85f009e48db7e621e2fc5bb58bf069f60c8688d564b96c772cd312b1eed9a","category":"nl_quality","rule_id":"BUG-broken-reference","file":".agents/skills/video-understand/SKILL.md","line":22,"severity":"low","confidence":"high","evidence":"Commands section shows 'python3 skills/video-understand/scripts/understand_video.py'; real path requires .agents/ or .claude/ prefix","penalty":-10,"pattern":"broken-relative-path","description":"Script paths in Commands section omit the .agents/.claude tree prefix, none resolve from repo root as written","false_positive":false,"suggested_fix":"Prefix commands with the correct tree path, e.g. .agents/skills/video-understand/scripts/understand_video.py"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:00279828a1e8fabd7eb34155328eec3e13d7d931efec549b342a04fcfa1893c5","category":"nl_quality","rule_id":"BUG-broken-reference","file":".claude/skills/video-understand/SKILL.md","line":22,"severity":"low","confidence":"high","evidence":"Identical content, same missing tree prefix in Commands section","penalty":-10,"pattern":"broken-relative-path","description":"Script paths in Commands section omit the .agents/.claude tree prefix","false_positive":false,"suggested_fix":"Prefix commands with the correct tree path, e.g. .claude/skills/video-understand/scripts/understand_video.py"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:c4e878478b841f0f5a9f348dc5e4f177040f7461586ca80c75be2088fbfe7da8","category":"nl_quality","rule_id":"R-missing-allowed-tools","file":".claude/commands/animated-drawing.md","line":1,"severity":"low","confidence":"high","evidence":"Frontmatter contains only description and argument-hint, no allowed-tools field","penalty":-5,"pattern":"missing-allowed-tools","description":"Command missing allowed-tools frontmatter field","false_positive":false,"suggested_fix":"Add an allowed-tools list scoping which tools this command may invoke"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:53307ea2e417ba8375501083bc504866b39c8cb9c092e85caabc1cb73a42b676","category":"nl_quality","rule_id":"R-missing-allowed-tools","file":".claude/commands/backlot.md","line":1,"severity":"low","confidence":"high","evidence":"Frontmatter contains only description and argument-hint, no allowed-tools field","penalty":-5,"pattern":"missing-allowed-tools","description":"Command missing allowed-tools frontmatter field","false_positive":false,"suggested_fix":"Add an allowed-tools list scoping which tools this command may invoke"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:d2e737120803563be01ae6881455d36c6067b2ca4912310dcee1e6ac8bf6bb0a","category":"nl_quality","rule_id":"R-missing-allowed-tools","file":".claude/commands/ink-art.md","line":1,"severity":"low","confidence":"high","evidence":"Frontmatter contains only description and argument-hint, no allowed-tools field","penalty":-5,"pattern":"missing-allowed-tools","description":"Command missing allowed-tools frontmatter field","false_positive":false,"suggested_fix":"Add an allowed-tools list scoping which tools this command may invoke"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:83ecb9e4224a3884a82fafeb1d73b3761d76bdc0dc52c785f74b4e78b2410b90","category":"nl_quality","rule_id":"R-empty-input-handling","file":".claude/commands/animated-drawing.md","line":12,"severity":"low","confidence":"high","evidence":"Body ends with 'Drawing + motion: $ARGUMENTS' with no described fallback if empty","penalty":-10,"pattern":"no-empty-input-handling","description":"No empty-input handling described for $ARGUMENTS","false_positive":false,"suggested_fix":"Add explicit guidance for the no-argument case (e.g. ask the user for a drawing path)"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:0080becaa79e382cb80a9b438721853d1fedc8947257fcb72283b7a9d1ef953b","category":"nl_quality","rule_id":"R-empty-input-handling","file":".claude/commands/ink-art.md","line":15,"severity":"low","confidence":"high","evidence":"Body ends with 'Request: $ARGUMENTS' with no described fallback if empty","penalty":-10,"pattern":"no-empty-input-handling","description":"No empty-input handling described for $ARGUMENTS","false_positive":false,"suggested_fix":"Add explicit guidance for the no-argument case"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:c461577ecbe2a69cd6f4dbe85b8788d9a2e1ebf383f658e4e2529df8ff205611","category":"security","rule_id":"SEC-unsanitized-argument-interpolation","file":".claude/commands/backlot.md","line":9,"severity":"high","confidence":"high","evidence":"Body contains fenced bash block: python -m backlot open $ARGUMENTS, with no quoting/sanitization and no allowed-tools restriction gating Bash use","penalty":null,"pattern":"SEC-unsanitized-argument-interpolation","description":"$ARGUMENTS interpolated directly into a shell command with no sanitization or quoting","false_positive":false,"suggested_fix":"Quote the argument (\"$ARGUMENTS\") and/or validate it as a safe project-id pattern before shell interpolation; requires private disclosure, not a public PR"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:810e5c456eb7dbdd2794eb8212a00d838e48288c03095714b5aa8f571b3eb8fa","category":"security","rule_id":"SEC-runtime-package-install","file":".agents/skills/remotion-to-hyperframes/assets/test-corpus/run.sh","line":130,"severity":"medium","confidence":"high","evidence":"Line 130: (cd \"$fixture_dir/remotion-src\" && npm install --silent --no-progress >/dev/null 2>&1) runs automatically on first invocation","penalty":null,"pattern":"SEC-runtime-package-install","description":"Automatic npm install at runtime inside a test/smoke script, no confirmation gate","false_positive":false,"suggested_fix":"Gate behind an explicit --install flag or precondition check"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:8c987f097d0d7174c3862659d528eae3a0c6cfa945f7137f28a319970a0430cd","category":"security","rule_id":"SEC-unpinned-semver","file":"requirements.txt","line":1,"severity":"low","confidence":"high","evidence":"All entries use >= lower-bound constraints (e.g. pyyaml>=6.0), no lockfile present","penalty":null,"pattern":"SEC-unpinned-semver","description":"Unpinned Python dependency version floors, no lockfile","false_positive":false,"suggested_fix":"Adopt pip-compile/uv lock or pin exact versions"} +{"event":"finding","timestamp":"2026-08-05T07:15:24Z","audit_run_id":"30983037743","repo":"calesthio/OpenMontage","commit_sha":"4eab34c5cfcccaa4f1970554928feccce73ee930","fingerprint":"sha256:51926e4d78cbc8a1c44fd9e9bbd4893cc5bce9960b23b580a92d65201d3f1845","category":"security","rule_id":"SEC-unpinned-semver","file":"remotion-composer/package.json","line":2,"severity":"low","confidence":"medium","evidence":"","penalty":null,"pattern":"SEC-unpinned-semver","description":"Caret-range npm dependency versions; risk mitigated by committed package-lock.json","false_positive":false,"suggested_fix":"Consider exact pinning for production dependencies despite the existing lockfile"} {"event":"finding","timestamp":"2026-08-05T07:03:41Z","audit_run_id":"30983032406","repo":"Shubhamsaboo/awesome-llm-apps","commit_sha":"779e9f9bcf87fa8cd95870a438b70b84e47d3173","fingerprint":"sha256:881283f9ce3d21011a260342b383b03f4c27455c5f0c9caed189fd5474a597b8","category":"bug","rule_id":"BUG-broken-reference","file":"generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/.agent/skills/chatgpt-app-builder/SKILL.md","line":4,"severity":"medium","confidence":"high","evidence":"ls .agent/skills/ shows chatgpt-app-builder, mcp-apps-builder, mcp-builder — no mcp-app-builder directory exists anywhere in the repo","penalty":null,"pattern":"deprecated-skill-pointer","description":"Deprecation notice points to a replacement skill named mcp-app-builder (singular) that does not exist; the real replacement is mcp-apps-builder (plural)","false_positive":false,"suggested_fix":"Update the deprecation notice to reference mcp-apps-builder (plural) to match the actual directory name"} {"event":"finding","timestamp":"2026-08-05T07:03:41Z","audit_run_id":"30983032406","repo":"Shubhamsaboo/awesome-llm-apps","commit_sha":"779e9f9bcf87fa8cd95870a438b70b84e47d3173","fingerprint":"sha256:f34ed29dd9fc02122cfc33ed25712512f0e1c5837159f06f8d06fb0e745134bb","category":"bug","rule_id":"BUG-broken-reference","file":"generative_ui_agents/ai-mcp-app-builder/apps/mcp-use-server/.agent/skills/mcp-builder/SKILL.md","line":4,"severity":"medium","confidence":"high","evidence":"ls .agent/skills/ shows chatgpt-app-builder, mcp-apps-builder, mcp-builder — no mcp-app-builder directory exists anywhere in the repo","penalty":null,"pattern":"deprecated-skill-pointer","description":"Deprecation notice points to a replacement skill named mcp-app-builder (singular) that does not exist; the real replacement is mcp-apps-builder (plural)","false_positive":false,"suggested_fix":"Update the deprecation notice to reference mcp-apps-builder (plural) to match the actual directory name"} {"event":"finding","timestamp":"2026-08-05T07:03:41Z","audit_run_id":"30983032406","repo":"Shubhamsaboo/awesome-llm-apps","commit_sha":"779e9f9bcf87fa8cd95870a438b70b84e47d3173","fingerprint":"sha256:7c0cdbbd5a1e0c51cbe02b597cb8a4a72adc993246f18766b894fef8ea83c1c9","category":"security","rule_id":"SEC-curl-pipe-sh","file":"generative_ui_agents/generative-ui-starter-project/Dockerfile","line":31,"severity":"critical","confidence":"high","evidence":"curl -fsSL https://deb.nodesource.com/setup_20.x | bash - executed with no checksum/signature verification","penalty":null,"pattern":"curl-pipe-sh","description":"Remote NodeSource setup script fetched over HTTPS and piped directly into bash","false_positive":false,"suggested_fix":"Download the script, verify its checksum/signature, then execute, or use a pinned apt/deb package instead"} diff --git a/auditor/logs/events.jsonl b/auditor/logs/events.jsonl index 4ad1d0839..3d0627e83 100644 --- a/auditor/logs/events.jsonl +++ b/auditor/logs/events.jsonl @@ -3761,6 +3761,10 @@ {"timestamp":"2026-08-05T02:07:56Z","workflow":"discover","event":"search_complete","run_id":"30968348211","run_number":39,"data":{"candidates":161,"new":57,"worthy":6,"oversized":18}} {"timestamp":"2026-08-05T04:36:41Z","workflow":"classify","event":"classifications_emitted","run_id":"30975581065","run_number":107,"data":{"classifications":0,"invalid":0,"no_dissent":true}} {"timestamp":"2026-08-05T05:14:52Z","workflow":"track","event":"status_check","run_id":"30977076136","run_number":653,"data":{"contributed":57,"tracked":37,"case_study_ready":42,"rule_adopted":2}} +{"timestamp":"2026-08-05T07:15:23Z","workflow":"audit","event":"scorer_drift_check","run_id":"30983037743","run_number":745,"data":{"repo":"calesthio/OpenMontage","sidecar":"auditor/audits/calesthio-OpenMontage.findings.jsonl","drifts":17,"exit_code":1,"total_findings":56,"missing_confidence":0}} +{"timestamp":"2026-08-05T07:15:25Z","workflow":"audit","event":"findings_aggregated","run_id":"30983037743","run_number":745,"data":{"repo":"calesthio/OpenMontage","findings":56,"invalid_lines":0,"self_false_positives":1}} +{"timestamp":"2026-08-05T07:15:25Z","workflow":"audit","event":"repo_report_rendered","run_id":"30983037743","run_number":745,"data":{"repo":"calesthio/OpenMontage","html":"auditor/reports/calesthio-OpenMontage.html"}} +{"timestamp":"2026-08-05T07:15:25Z","workflow":"audit","event":"audit_complete","run_id":"30983037743","run_number":745,"data":{"repo":"calesthio/OpenMontage","score":95,"artifacts":152,"strategy":"progressive"}} {"timestamp":"2026-08-05T07:03:41Z","workflow":"audit","event":"scorer_drift_check","run_id":"30983032406","run_number":744,"data":{"repo":"Shubhamsaboo/awesome-llm-apps","sidecar":"auditor/audits/Shubhamsaboo-awesome-llm-apps.findings.jsonl","drifts":0,"exit_code":0,"total_findings":23,"missing_confidence":0}} {"timestamp":"2026-08-05T07:03:42Z","workflow":"audit","event":"findings_aggregated","run_id":"30983032406","run_number":744,"data":{"repo":"Shubhamsaboo/awesome-llm-apps","findings":23,"invalid_lines":0,"self_false_positives":0}} {"timestamp":"2026-08-05T07:03:42Z","workflow":"audit","event":"repo_report_rendered","run_id":"30983032406","run_number":744,"data":{"repo":"Shubhamsaboo/awesome-llm-apps","html":"auditor/reports/Shubhamsaboo-awesome-llm-apps.html"}} diff --git a/auditor/registry/repos.json b/auditor/registry/repos.json index 83f8cf0fb..cb85a9afb 100644 --- a/auditor/registry/repos.json +++ b/auditor/registry/repos.json @@ -9726,10 +9726,13 @@ "stars": 45129, "artifacts": 627, "description": "World's first open-source, agentic video production system. 12 production pipelines, 100+ tools, 700+ agent skill and production-knowledge files. Turn your AI coding assistant into a full video production studio.", - "status": "discovered", - "score": null, + "status": "audited", + "score": 95, "audit_issue": 758, - "prs": [] + "prs": [], + "strategy": "progressive", + "security": "REVIEW", + "commit_sha_at_audit": "4eab34c5cfcccaa4f1970554928feccce73ee930" }, "hoangsonww/Claude-Code-Agent-Monitor": { "discovered": "2026-08-05T02:07:37Z", diff --git a/auditor/reports/calesthio-OpenMontage.html b/auditor/reports/calesthio-OpenMontage.html new file mode 100644 index 000000000..74bbb6108 --- /dev/null +++ b/auditor/reports/calesthio-OpenMontage.html @@ -0,0 +1,104 @@ + + + + + NLPM Report — calesthio/OpenMontage + + + +
+
+

NLPM Report

+

calesthio/OpenMontage · 2026-08-05T07:15:25Z

+
+
+
+
+
+
+ + + +
+
+

Per-file scores

+
+ + + + + + + + + + +
PathTypeScoreFindings
+
+
+ +
+

Score trend

+

Average score per snapshot, oldest → newest.

+
+
+ +
+

Cross-component references

+

Artifacts and their references. Broken references in red.

+
+
+ +
+

Vocabulary noun-verb map

+

+ Verbs (rounded rectangles), nouns (circles). Two scopes shown as compound containers. + Cross-scope homonyms have a doubled outline. Deferred-pending-warrant terms appear dashed. + Click a node for details. +

+
+ + + +
+
+ +
+ +
+

Vocabulary drift candidates

+

Registry-free advisory: clusters of likely-synonymous terms detected by `vocab-drift-scanner`.

+
+
+ +
+

Findings

+

All violations grouped by rule. Severity badges sort within each rule.

+
+
+
+ + + + + + + + diff --git a/auditor/reports/calesthio-OpenMontage.json b/auditor/reports/calesthio-OpenMontage.json new file mode 100644 index 000000000..752e23d6f --- /dev/null +++ b/auditor/reports/calesthio-OpenMontage.json @@ -0,0 +1,1116 @@ +{ + "project": "calesthio/OpenMontage", + "score_threshold": 70, + "r51_enabled": false, + "summary": { + "total_files": 42, + "average_score": 95, + "pass_count": 0, + "fail_count": 0 + }, + "files": [ + { + "path": ".agents/skills/acestep/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "medium", + "line": 15, + "message": "Quick Reference commands invoke tools/music_gen.py, real path is tools/audio/music_gen.py" + }, + { + "rule": "BUG-broken-reference", + "severity": "medium", + "line": 262, + "message": "References tools/sfx.py which does not exist anywhere in the repo" + } + ] + }, + { + "path": ".agents/skills/agents/references/agent-configuration.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "R51", + "severity": "low", + "line": 279, + "message": "Vague quantifier 'relevant' used" + } + ] + }, + { + "path": ".agents/skills/agents/references/client-tools.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "R51", + "severity": "low", + "line": 463, + "message": "Vague quantifier 'reasonable' used" + } + ] + }, + { + "path": ".agents/skills/ai-video-gen/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-undeclared-tool", + "severity": "low", + "line": 5, + "message": "allowed-tools: mcp__heygen__* declared but never invoked in body" + } + ] + }, + { + "path": ".agents/skills/beautiful-mermaid/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "medium", + "line": 12, + "message": "Requires nonexistent agent-browser skill for PNG capture step" + } + ] + }, + { + "path": ".agents/skills/comfyui/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "R51", + "severity": "low", + "line": 27, + "message": "Vague quantifier 'usually' used" + } + ] + }, + { + "path": ".agents/skills/d3-viz/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "low", + "line": 814, + "message": "Templates section references chart-template.js/interactive-template.js, real files are .jsx" + }, + { + "rule": "R51", + "severity": "low", + "line": 818, + "message": "Vague quantifier 'as needed' used" + } + ] + }, + { + "path": ".agents/skills/faceswap/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-undeclared-tool", + "severity": "low", + "line": 5, + "message": "allowed-tools: mcp__heygen__* declared but never invoked in body" + } + ] + }, + { + "path": ".agents/skills/ffmpeg/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "low", + "line": 432, + "message": "Self-referential improve-this-skill path hardcodes .claude/ tree, wrong when read from .agents/ copy" + } + ] + }, + { + "path": ".agents/skills/flux-best-practices/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "R51", + "severity": "low", + "line": 12, + "message": "Vague quantifiers 'optimal' (L12) and 'Comprehensive' (L3) used" + } + ] + }, + { + "path": ".agents/skills/ltx2/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "high", + "line": 15, + "message": "Entire Quick Reference/Setup documents nonexistent tools/ltx2.py CLI and docker/modal-ltx2/app.py deploy path" + } + ] + }, + { + "path": ".agents/skills/manimgl-best-practices/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "medium", + "line": 51, + "message": "5 broken example file links, real examples directory has different filenames" + } + ] + }, + { + "path": ".agents/skills/motion-graphics/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "low", + "line": 172, + "message": "Broken ref to motion-graphics-genre.md, file does not exist" + } + ] + }, + { + "path": ".agents/skills/motion-graphics/agents/builder.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "medium", + "line": 12, + "message": "Broken relative ref to catalog-map.md, needs ../ prefix" + }, + { + "rule": "BUG-broken-reference", + "severity": "medium", + "line": 24, + "message": "Broken relative ref to references/builder-contract.md, needs ../ prefix" + }, + { + "rule": "BUG-missing-frontmatter", + "severity": "high", + "line": 1, + "message": "No frontmatter (name/description), no declared model, zero example blocks" + } + ] + }, + { + "path": ".agents/skills/motion-graphics/agents/director.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "medium", + "line": 3, + "message": "Broken relative ref to references/shot-plan-ir.md, needs ../ prefix" + }, + { + "rule": "BUG-missing-frontmatter", + "severity": "high", + "line": 1, + "message": "No frontmatter (name/description), no declared model, zero example blocks" + } + ] + }, + { + "path": ".agents/skills/motion-graphics/agents/finalize.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-missing-frontmatter", + "severity": "high", + "line": 1, + "message": "No frontmatter (name/description), no declared model, zero example blocks" + } + ] + }, + { + "path": ".agents/skills/remotion-best-practices/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "low", + "line": 26, + "message": "Broken ref to rules/sound-effects.md, real file is rules/sfx.md" + } + ] + }, + { + "path": ".agents/skills/remotion-to-hyperframes/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "R51", + "severity": "low", + "line": 95, + "message": "Vague quantifier 'relevant' used" + } + ] + }, + { + "path": ".agents/skills/remotion-to-hyperframes/assets/test-corpus/run.sh", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "SEC-runtime-package-install", + "severity": "medium", + "line": 130, + "message": "Automatic npm install at runtime inside a test/smoke script, no confirmation gate" + } + ] + }, + { + "path": ".agents/skills/remotion/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "medium", + "line": 3, + "message": "References nonexistent .claude/skills/remotion-official/ skill for core Remotion knowledge" + } + ] + }, + { + "path": ".agents/skills/seedance-2-0/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "R51", + "severity": "low", + "line": 161, + "message": "Vague quantifier 'optimal' used" + } + ] + }, + { + "path": ".agents/skills/synthetic-screen-recording/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "low", + "line": 182, + "message": "References projects/openmontage-showcase/build_composition.py as reference implementation; path does not exist" + } + ] + }, + { + "path": ".agents/skills/vercel-react-best-practices/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-stale-count", + "severity": "low", + "line": 12, + "message": "Description claims 65 rules across 8 categories, 68 rule files actually exist" + } + ] + }, + { + "path": ".agents/skills/video-toolkit/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-duplicate-heading", + "severity": "low", + "line": 298, + "message": "Duplicate #### 4e. step heading used for two different steps (L298, L330)" + }, + { + "rule": "BUG-inconsistent-config", + "severity": "low", + "line": 70, + "message": "modal-propainter deploy step has no matching MODAL_PROPAINTER_ENDPOINT_URL env var; MODAL_DEWATERMARK_ENDPOINT_URL has no corresponding deploy step" + } + ] + }, + { + "path": ".agents/skills/video-translate/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-undeclared-tool", + "severity": "low", + "line": 5, + "message": "allowed-tools: mcp__heygen__* declared but never invoked in body" + } + ] + }, + { + "path": ".agents/skills/video-understand/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "low", + "line": 22, + "message": "Script paths in Commands section omit the .agents/.claude tree prefix, none resolve from repo root as written" + } + ] + }, + { + "path": ".agents/skills/visual-style/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "R51", + "severity": "low", + "line": 41, + "message": "Vague quantifier 'appropriate' used twice (L41, L50)" + } + ] + }, + { + "path": ".agents/skills/website-to-video/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "medium", + "line": 144, + "message": "Broken relative ref to hyperframes/references/techniques.md, real skill name is hyperframes-animation with no references/ subdir" + }, + { + "rule": "BUG-broken-reference", + "severity": "medium", + "line": 145, + "message": "Broken relative ref to hyperframes/references/html-in-canvas-patterns.md" + }, + { + "rule": "R51", + "severity": "low", + "line": 59, + "message": "Vague quantifier 'as needed' used" + } + ] + }, + { + "path": ".claude/commands/animated-drawing.md", + "type": "?", + "score": null, + "findings": [ + { + "rule": "R-missing-allowed-tools", + "severity": "low", + "line": 1, + "message": "Command missing allowed-tools frontmatter field" + }, + { + "rule": "R-empty-input-handling", + "severity": "low", + "line": 12, + "message": "No empty-input handling described for $ARGUMENTS" + } + ] + }, + { + "path": ".claude/commands/backlot.md", + "type": "?", + "score": null, + "findings": [ + { + "rule": "R-missing-allowed-tools", + "severity": "low", + "line": 1, + "message": "Command missing allowed-tools frontmatter field" + }, + { + "rule": "SEC-unsanitized-argument-interpolation", + "severity": "high", + "line": 9, + "message": "$ARGUMENTS interpolated directly into a shell command with no sanitization or quoting" + } + ] + }, + { + "path": ".claude/commands/ink-art.md", + "type": "?", + "score": null, + "findings": [ + { + "rule": "R-missing-allowed-tools", + "severity": "low", + "line": 1, + "message": "Command missing allowed-tools frontmatter field" + }, + { + "rule": "R-empty-input-handling", + "severity": "low", + "line": 15, + "message": "No empty-input handling described for $ARGUMENTS" + } + ] + }, + { + "path": ".claude/skills", + "type": "?", + "score": null, + "findings": [ + { + "rule": "CC-orphan-component", + "severity": "low", + "line": null, + "message": "claude/skills/ is a partial subset mirror of agents/skills/; ~37 skills exist only in agents/ tree" + } + ] + }, + { + "path": ".claude/skills/agents/references/agent-configuration.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "R51", + "severity": "low", + "line": 279, + "message": "Vague quantifier 'relevant' used" + } + ] + }, + { + "path": ".claude/skills/agents/references/client-tools.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "R51", + "severity": "low", + "line": 463, + "message": "Vague quantifier 'reasonable' used" + } + ] + }, + { + "path": ".claude/skills/ai-video-gen/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "CC-stale-count", + "severity": "medium", + "line": null, + "message": "claude/ copy of ai-video-gen is stale vs agents/ sibling, missing Kling Official direct-API gateway" + }, + { + "rule": "BUG-undeclared-tool", + "severity": "low", + "line": 5, + "message": "allowed-tools: mcp__heygen__* declared but never invoked in body" + } + ] + }, + { + "path": ".claude/skills/ffmpeg/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "low", + "line": 432, + "message": "Self-referential improve-this-skill path hardcodes .claude/ tree" + } + ] + }, + { + "path": ".claude/skills/vercel-react-best-practices/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-stale-count", + "severity": "low", + "line": 12, + "message": "Description claims 65 rules across 8 categories, 68 rule files actually exist" + } + ] + }, + { + "path": ".claude/skills/video-understand/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "low", + "line": 22, + "message": "Script paths in Commands section omit the .agents/.claude tree prefix" + } + ] + }, + { + "path": ".claude/skills/video_toolkit/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "BUG-invalid-directory-name", + "severity": "high", + "line": 2, + "message": "Directory name video_toolkit mismatches declared skill name video-toolkit" + }, + { + "rule": "BUG-duplicate-heading", + "severity": "low", + "line": 298, + "message": "Duplicate #### 4e. step heading used for two different steps (L298, L330)" + }, + { + "rule": "CC-terminology-drift", + "severity": "low", + "line": null, + "message": "Same skill dual-published under inconsistent directory-naming convention (underscore vs hyphen) across tool trees" + } + ] + }, + { + "path": ".claude/skills/visual-style/SKILL.md", + "type": "skill", + "score": null, + "findings": [ + { + "rule": "R51", + "severity": "low", + "line": 41, + "message": "Vague quantifier 'appropriate' used twice (L41, L50)" + } + ] + }, + { + "path": "remotion-composer/package.json", + "type": "?", + "score": null, + "findings": [ + { + "rule": "SEC-unpinned-semver", + "severity": "low", + "line": 2, + "message": "Caret-range npm dependency versions; risk mitigated by committed package-lock.json" + } + ] + }, + { + "path": "requirements.txt", + "type": "?", + "score": null, + "findings": [ + { + "rule": "SEC-unpinned-semver", + "severity": "low", + "line": 1, + "message": "Unpinned Python dependency version floors, no lockfile" + } + ] + } + ], + "history": [ + { + "timestamp": "2026-08-05T07:13:36Z", + "average_score": 95, + "kind": "initial_audit" + } + ], + "cross_component": { + "nodes": [], + "edges": [] + }, + "vocabulary": null, + "vocab_drift": { + "candidates": [] + }, + "findings": [ + { + "rule": "BUG-broken-reference", + "severity": "medium", + "confidence": "high", + "file": ".agents/skills/motion-graphics/agents/director.md", + "line": 3, + "message": "Broken relative ref to references/shot-plan-ir.md, needs ../ prefix — references/shot-plan-ir.md resolves to agents/references/shot-plan-ir.md relative to the file's own dir, which does not exist; real file is motion-graphics/references/shot-plan-ir.md" + }, + { + "rule": "BUG-missing-frontmatter", + "severity": "high", + "confidence": "high", + "file": ".agents/skills/motion-graphics/agents/director.md", + "line": 1, + "message": "No frontmatter (name/description), no declared model, zero example blocks — File has no YAML frontmatter block, no name/description, no model field, zero example blocks" + }, + { + "rule": "BUG-broken-reference", + "severity": "medium", + "confidence": "high", + "file": ".agents/skills/motion-graphics/agents/builder.md", + "line": 12, + "message": "Broken relative ref to catalog-map.md, needs ../ prefix — catalog-map.md resolves to agents/catalog-map.md relative to file's own dir; real file is motion-graphics/catalog-map.md" + }, + { + "rule": "BUG-broken-reference", + "severity": "medium", + "confidence": "high", + "file": ".agents/skills/motion-graphics/agents/builder.md", + "line": 24, + "message": "Broken relative ref to references/builder-contract.md, needs ../ prefix — references/builder-contract.md resolves to agents/references/builder-contract.md relative to file's own dir; real file is motion-graphics/references/builder-contract.md" + }, + { + "rule": "BUG-missing-frontmatter", + "severity": "high", + "confidence": "high", + "file": ".agents/skills/motion-graphics/agents/builder.md", + "line": 1, + "message": "No frontmatter (name/description), no declared model, zero example blocks — File has no YAML frontmatter block, no name/description, no model field, zero example blocks" + }, + { + "rule": "BUG-missing-frontmatter", + "severity": "high", + "confidence": "high", + "file": ".agents/skills/motion-graphics/agents/finalize.md", + "line": 1, + "message": "No frontmatter (name/description), no declared model, zero example blocks — File has no YAML frontmatter block, no name/description, no model field, zero example blocks" + }, + { + "rule": "BUG-broken-reference", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/motion-graphics/SKILL.md", + "line": 172, + "message": "Broken ref to motion-graphics-genre.md, file does not exist — find -iname motion-graphics-genre.md returns no results anywhere in repo" + }, + { + "rule": "BUG-broken-reference", + "severity": "medium", + "confidence": "high", + "file": ".agents/skills/manimgl-best-practices/SKILL.md", + "line": 51, + "message": "5 broken example file links, real examples directory has different filenames — examples/basic_animations.py and 4 sibling paths do not exist; ls examples/ shows only differently-named files like mlp_neurons_flow.py" + }, + { + "rule": "BUG-broken-reference", + "severity": "medium", + "confidence": "high", + "file": ".agents/skills/remotion/SKILL.md", + "line": 3, + "message": "References nonexistent .claude/skills/remotion-official/ skill for core Remotion knowledge — find -iname remotion-official returns no results anywhere in repo" + }, + { + "rule": "BUG-broken-reference", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/remotion-best-practices/SKILL.md", + "line": 26, + "message": "Broken ref to rules/sound-effects.md, real file is rules/sfx.md — ./rules/sound-effects.md does not exist; ls rules/ shows sfx.md instead" + }, + { + "rule": "BUG-broken-reference", + "severity": "medium", + "confidence": "high", + "file": ".agents/skills/acestep/SKILL.md", + "line": 15, + "message": "Quick Reference commands invoke tools/music_gen.py, real path is tools/audio/music_gen.py — find -iname music_gen.py shows only tools/audio/music_gen.py; tools/music_gen.py does not exist" + }, + { + "rule": "BUG-broken-reference", + "severity": "medium", + "confidence": "high", + "file": ".agents/skills/acestep/SKILL.md", + "line": 262, + "message": "References tools/sfx.py which does not exist anywhere in the repo — find -iname sfx.py returns no results anywhere in repo" + }, + { + "rule": "BUG-broken-reference", + "severity": "high", + "confidence": "high", + "file": ".agents/skills/ltx2/SKILL.md", + "line": 15, + "message": "Entire Quick Reference/Setup documents nonexistent tools/ltx2.py CLI and docker/modal-ltx2/app.py deploy path — find -iname ltx2.py and modal-ltx2 return no results; real tools are tools/video/ltx_video_modal.py and ltx_video_local.py" + }, + { + "rule": "BUG-broken-reference", + "severity": "medium", + "confidence": "high", + "file": ".agents/skills/website-to-video/SKILL.md", + "line": 144, + "message": "Broken relative ref to hyperframes/references/techniques.md, real skill name is hyperframes-animation with no references/ subdir — ../hyperframes/references/techniques.md not found; real file is .agents/skills/hyperframes-animation/techniques.md" + }, + { + "rule": "BUG-broken-reference", + "severity": "medium", + "confidence": "high", + "file": ".agents/skills/website-to-video/SKILL.md", + "line": 145, + "message": "Broken relative ref to hyperframes/references/html-in-canvas-patterns.md — ../hyperframes/references/html-in-canvas-patterns.md not found; real file is .agents/skills/hyperframes-animation/adapters/html-in-canvas-patterns.md" + }, + { + "rule": "BUG-broken-reference", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/synthetic-screen-recording/SKILL.md", + "line": 182, + "message": "References projects/openmontage-showcase/build_composition.py as reference implementation; path does not exist — find -type d -name projects at repo root returns no results; no openmontage-showcase directory anywhere" + }, + { + "rule": "BUG-broken-reference", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/d3-viz/SKILL.md", + "line": 814, + "message": "Templates section references chart-template.js/interactive-template.js, real files are .jsx — assets/ dir has chart-template.jsx and interactive-template.jsx, not .js" + }, + { + "rule": "BUG-broken-reference", + "severity": "medium", + "confidence": "high", + "file": ".agents/skills/beautiful-mermaid/SKILL.md", + "line": 12, + "message": "Requires nonexistent agent-browser skill for PNG capture step — find -iname agent-browser returns no results anywhere in repo; no such skill directory under .agents/skills, .claude/skills, or skills/" + }, + { + "rule": "BUG-stale-count", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/vercel-react-best-practices/SKILL.md", + "line": 12, + "message": "Description claims 65 rules across 8 categories, 68 rule files actually exist — find rules -path '*/rules/*.md' | wc -l returns 68, description claims 65" + }, + { + "rule": "BUG-stale-count", + "severity": "low", + "confidence": "high", + "file": ".claude/skills/vercel-react-best-practices/SKILL.md", + "line": 12, + "message": "Description claims 65 rules across 8 categories, 68 rule files actually exist — Identical content to .agents/skills/vercel-react-best-practices/SKILL.md, same stale count" + }, + { + "rule": "BUG-invalid-directory-name", + "severity": "high", + "confidence": "high", + "file": ".claude/skills/video_toolkit/SKILL.md", + "line": 2, + "message": "Directory name video_toolkit mismatches declared skill name video-toolkit — Directory is video_toolkit (underscore) but frontmatter name: and metadata.openclaw.skillKey both say video-toolkit (hyphen); .agents/skills/video-toolkit uses matching hyphenated directory name" + }, + { + "rule": "BUG-duplicate-heading", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/video-toolkit/SKILL.md", + "line": 298, + "message": "Duplicate #### 4e. step heading used for two different steps (L298, L330) — grep '^#### 4' shows both line 298 (Talking Head Narrator) and line 330 (Image Editing) labeled '#### 4e.'" + }, + { + "rule": "BUG-inconsistent-config", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/video-toolkit/SKILL.md", + "line": 70, + "message": "modal-propainter deploy step has no matching MODAL_PROPAINTER_ENDPOINT_URL env var; MODAL_DEWATERMARK_ENDPOINT_URL has no corresponding deploy step — Line 70 deploys docker/modal-propainter/app.py; line 87 lists env var MODAL_DEWATERMARK_ENDPOINT_URL with no MODAL_PROPAINTER_ENDPOINT_URL or matching deploy-to-var mapping shown" + }, + { + "rule": "BUG-duplicate-heading", + "severity": "low", + "confidence": "high", + "file": ".claude/skills/video_toolkit/SKILL.md", + "line": 298, + "message": "Duplicate #### 4e. step heading used for two different steps (L298, L330) — Identical content to .agents/skills/video-toolkit/SKILL.md, same duplicate heading at L298/L330" + }, + { + "rule": "CC-stale-count", + "severity": "medium", + "confidence": "high", + "file": ".claude/skills/ai-video-gen/SKILL.md", + "line": null, + "message": "claude/ copy of ai-video-gen is stale vs agents/ sibling, missing Kling Official direct-API gateway — diff .claude/skills/ai-video-gen/SKILL.md .agents/skills/ai-video-gen/SKILL.md shows .claude copy missing Kling Official gateway, KLING_API_KEY, and provider=kling_official guidance present in .agents copy" + }, + { + "rule": "CC-terminology-drift", + "severity": "low", + "confidence": "high", + "file": ".claude/skills/video_toolkit/SKILL.md", + "line": null, + "message": "Same skill dual-published under inconsistent directory-naming convention (underscore vs hyphen) across tool trees — diff -rq .claude/skills .agents/skills shows video_toolkit (underscore) only under .claude and video-toolkit (hyphen) only under .agents, byte-identical content otherwise" + }, + { + "rule": "CC-orphan-component", + "severity": "low", + "confidence": "medium", + "file": ".claude/skills", + "line": null, + "message": "claude/skills/ is a partial subset mirror of agents/skills/; ~37 skills exist only in agents/ tree — ls .claude/skills vs .agents/skills shows only ~48 of ~85 .agents/skills/* names mirrored into .claude/skills/" + }, + { + "rule": "R51", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/agents/references/agent-configuration.md", + "line": 279, + "message": "Vague quantifier 'relevant' used — grep shows the word 'relevant' used as a vague qualifier at line 279" + }, + { + "rule": "R51", + "severity": "low", + "confidence": "high", + "file": ".claude/skills/agents/references/agent-configuration.md", + "line": 279, + "message": "Vague quantifier 'relevant' used — Identical content to .agents twin, same vague quantifier at line 279" + }, + { + "rule": "R51", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/agents/references/client-tools.md", + "line": 463, + "message": "Vague quantifier 'reasonable' used — grep shows the word 'reasonable' used as a vague qualifier at line 463" + }, + { + "rule": "R51", + "severity": "low", + "confidence": "high", + "file": ".claude/skills/agents/references/client-tools.md", + "line": 463, + "message": "Vague quantifier 'reasonable' used — Identical content to .agents twin, same vague quantifier at line 463" + }, + { + "rule": "R51", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/remotion-to-hyperframes/SKILL.md", + "line": 95, + "message": "Vague quantifier 'relevant' used — grep shows the word 'relevant' used as a vague qualifier at line 95" + }, + { + "rule": "R51", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/seedance-2-0/SKILL.md", + "line": 161, + "message": "Vague quantifier 'optimal' used — grep shows 'optimal' used at line 161: 'appears optimal for multi-shot generations'" + }, + { + "rule": "R51", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/flux-best-practices/SKILL.md", + "line": 12, + "message": "Vague quantifiers 'optimal' (L12) and 'Comprehensive' (L3) used — grep shows 'optimal image quality' at line 12 and 'Comprehensive guide' at line 3" + }, + { + "rule": "R51", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/comfyui/SKILL.md", + "line": 27, + "message": "Vague quantifier 'usually' used — grep shows 'usually SaveImage, SaveVideo, ...' at line 27" + }, + { + "rule": "R51", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/visual-style/SKILL.md", + "line": 41, + "message": "Vague quantifier 'appropriate' used twice (L41, L50) — grep shows 'the appropriate extractor reference file' (L41) and 'the appropriate connector reference file' (L50)" + }, + { + "rule": "R51", + "severity": "low", + "confidence": "high", + "file": ".claude/skills/visual-style/SKILL.md", + "line": 41, + "message": "Vague quantifier 'appropriate' used twice (L41, L50) — Identical content to .agents twin, same vague quantifiers at L41, L50" + }, + { + "rule": "R51", + "severity": "low", + "confidence": "medium", + "file": ".agents/skills/website-to-video/SKILL.md", + "line": 59, + "message": "Vague quantifier 'as needed' used" + }, + { + "rule": "R51", + "severity": "low", + "confidence": "medium", + "file": ".agents/skills/d3-viz/SKILL.md", + "line": 818, + "message": "Vague quantifier 'as needed' used" + }, + { + "rule": "BUG-undeclared-tool", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/ai-video-gen/SKILL.md", + "line": 5, + "message": "allowed-tools: mcp__heygen__* declared but never invoked in body — grep -c mcp__heygen returns 1 (frontmatter line only), no invocation elsewhere in body" + }, + { + "rule": "BUG-undeclared-tool", + "severity": "low", + "confidence": "high", + "file": ".claude/skills/ai-video-gen/SKILL.md", + "line": 5, + "message": "allowed-tools: mcp__heygen__* declared but never invoked in body — grep -c mcp__heygen returns 1 (frontmatter line only), no invocation elsewhere in body" + }, + { + "rule": "BUG-undeclared-tool", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/video-translate/SKILL.md", + "line": 5, + "message": "allowed-tools: mcp__heygen__* declared but never invoked in body — grep -c mcp__heygen returns 1 (frontmatter line only), no invocation elsewhere in body" + }, + { + "rule": "BUG-undeclared-tool", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/faceswap/SKILL.md", + "line": 5, + "message": "allowed-tools: mcp__heygen__* declared but never invoked in body — grep -c mcp__heygen returns 1 (frontmatter line only), no invocation elsewhere in body" + }, + { + "rule": "BUG-broken-reference", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/ffmpeg/SKILL.md", + "line": 432, + "message": "Self-referential improve-this-skill path hardcodes .claude/ tree, wrong when read from .agents/ copy — Line reads 'update .claude/skills/ffmpeg/SKILL.md' while this file itself is located at .agents/skills/ffmpeg/SKILL.md" + }, + { + "rule": "BUG-broken-reference", + "severity": "low", + "confidence": "high", + "file": ".claude/skills/ffmpeg/SKILL.md", + "line": 432, + "message": "Self-referential improve-this-skill path hardcodes .claude/ tree — Identical content, same hardcoded .claude/ path, correct for this copy but demonstrates the underlying dual-tree fragility" + }, + { + "rule": "BUG-broken-reference", + "severity": "low", + "confidence": "high", + "file": ".agents/skills/video-understand/SKILL.md", + "line": 22, + "message": "Script paths in Commands section omit the .agents/.claude tree prefix, none resolve from repo root as written — Commands section shows 'python3 skills/video-understand/scripts/understand_video.py'; real path requires .agents/ or .claude/ prefix" + }, + { + "rule": "BUG-broken-reference", + "severity": "low", + "confidence": "high", + "file": ".claude/skills/video-understand/SKILL.md", + "line": 22, + "message": "Script paths in Commands section omit the .agents/.claude tree prefix — Identical content, same missing tree prefix in Commands section" + }, + { + "rule": "R-missing-allowed-tools", + "severity": "low", + "confidence": "high", + "file": ".claude/commands/animated-drawing.md", + "line": 1, + "message": "Command missing allowed-tools frontmatter field — Frontmatter contains only description and argument-hint, no allowed-tools field" + }, + { + "rule": "R-missing-allowed-tools", + "severity": "low", + "confidence": "high", + "file": ".claude/commands/backlot.md", + "line": 1, + "message": "Command missing allowed-tools frontmatter field — Frontmatter contains only description and argument-hint, no allowed-tools field" + }, + { + "rule": "R-missing-allowed-tools", + "severity": "low", + "confidence": "high", + "file": ".claude/commands/ink-art.md", + "line": 1, + "message": "Command missing allowed-tools frontmatter field — Frontmatter contains only description and argument-hint, no allowed-tools field" + }, + { + "rule": "R-empty-input-handling", + "severity": "low", + "confidence": "high", + "file": ".claude/commands/animated-drawing.md", + "line": 12, + "message": "No empty-input handling described for $ARGUMENTS — Body ends with 'Drawing + motion: $ARGUMENTS' with no described fallback if empty" + }, + { + "rule": "R-empty-input-handling", + "severity": "low", + "confidence": "high", + "file": ".claude/commands/ink-art.md", + "line": 15, + "message": "No empty-input handling described for $ARGUMENTS — Body ends with 'Request: $ARGUMENTS' with no described fallback if empty" + }, + { + "rule": "SEC-unsanitized-argument-interpolation", + "severity": "high", + "confidence": "high", + "file": ".claude/commands/backlot.md", + "line": 9, + "message": "$ARGUMENTS interpolated directly into a shell command with no sanitization or quoting — Body contains fenced bash block: python -m backlot open $ARGUMENTS, with no quoting/sanitization and no allowed-tools restriction gating Bash use" + }, + { + "rule": "SEC-runtime-package-install", + "severity": "medium", + "confidence": "high", + "file": ".agents/skills/remotion-to-hyperframes/assets/test-corpus/run.sh", + "line": 130, + "message": "Automatic npm install at runtime inside a test/smoke script, no confirmation gate — Line 130: (cd \"$fixture_dir/remotion-src\" && npm install --silent --no-progress >/dev/null 2>&1) runs automatically on first invocation" + }, + { + "rule": "SEC-unpinned-semver", + "severity": "low", + "confidence": "high", + "file": "requirements.txt", + "line": 1, + "message": "Unpinned Python dependency version floors, no lockfile — All entries use >= lower-bound constraints (e.g. pyyaml>=6.0), no lockfile present" + }, + { + "rule": "SEC-unpinned-semver", + "severity": "low", + "confidence": "medium", + "file": "remotion-composer/package.json", + "line": 2, + "message": "Caret-range npm dependency versions; risk mitigated by committed package-lock.json" + } + ], + "repo_meta": { + "status": "discovered", + "stars": 45129, + "security": "REVIEW", + "audit_report_path": "auditor/audits/calesthio-OpenMontage.md" + }, + "generated_at": "2026-08-05T07:15:25Z", + "schema_version": 1 +}