Example report · synthetic source
From source evidence to a clear next step.
Hand-authored example using synthetic source. No customer repository or model review was used, no agents ran, and no cryptographic seal was minted. Scores are illustrative.
Read the five acts, open the source receipts, and download the Markdown report. No account or email is needed.
Inspect the complete synthetic source
example/wallet.js
export function debit(wallet, quantity) {
wallet.balance -= quantity;
return wallet.balance;
}
The Table
synthetic source · a worked exampleExample scope
A debit should reduce the supplied wallet balance by a positive quantity. Inspect the helper, then distinguish its demonstrated behavior from claims about unprovided callers.
synthetic-example/wallet-helpersimulation
The source and support assessments in this example were written for demonstration. No model or agent swarm ran, and no customer repository was used.
The Friction
why the same quote can support different conclusionsThe next act tests three claims against the same small source sample. A verified quote supports a bounded defect; it does not establish a public attack path.
The caller is intentionally outside the example’s source scope. That becomes an inspection task. The assessments below were written for this example. Act II of a live audit shows the recorded technical and business assessments.
The Anchor
the findings, their support, and what remains unknownThis example score is illustrative. No model audit produced it, and it does not predict your repository’s result.
1 confirmed finding · 1 coverage gap · 1 suspected finding
Potential impact describes severity. Confidence describes support for the allegation. A coverage gap is an inspection task, not a confirmed vulnerability.
Confirmed findings
1Review the supported scope before choosing a fix.
- Confirmed findinghigh confidencePotential impact · HIGH
01A negative debit increases the supplied wallet balance
Impact scope: Support applies to this finding as stated. Additional consequences require a separate assessment.
Support assessment & source receipts · 1
Executing debit({ balance: 100 }, -25) returns 125 and changes that supplied object's balance to 125. The complete helper performs no quantity validation before subtraction.
Counterevidence considered: A caller could reject negative quantities. That would constrain reachability but would not change the demonstrated behavior of this helper when called directly.
A verified receipt authenticates quoted source or records a structural query. It does not independently establish the allegation.
E1 · example/wallet.js:1
export function debit(wallet, quantity) { wallet.balance -= quantity; return wallet.balance; }
Needs verification
2Inspect the missing evidence before proposing a patch.
- Suspected findinglow confidencePotential impact · CRITICAL
02Unauthenticated visitors can edit every wallet
Impact scope: Impact remains unconfirmed; establish the allegation before acting.
Support assessment & source receipts · 1
The same authentic quote only mutates an object supplied by its caller. It contains no HTTP entry point, account lookup or evidence of access to other wallets, so it does not support this allegation.
Counterevidence considered: A protected caller can check authentication and ownership before invoking this helper. The quote is compatible with that design; no public exploit has been reproduced.
A verified receipt authenticates quoted source or records a structural query. It does not independently establish the allegation.
E1 · example/wallet.js:1
export function debit(wallet, quantity) { wallet.balance -= quantity; return wallet.balance; } - Coverage gaplow confidencePotential impact · HIGH
03The caller's authorization and input validation remain unverified
Inspect before changing code
- example/caller.js (intentionally not supplied)
No patch before verification.
Impact scope: Impact remains unconfirmed until the missing source is inspected.
Support assessment & source receipts
This example deliberately provides only the helper. The caller source is unavailable, so its authentication, ownership and input checks cannot be assessed.
Counterevidence considered: No conclusion about absent protection follows from the omitted caller. Its checks may reject the negative quantity or block unauthorized requests.
A verified receipt authenticates quoted source or records a structural query. It does not independently establish the allegation.
No verified source receipt is available for this allegation.
The Mandate
ranked triage — capital-firstConfirm each task against current source before changing code. Coverage gaps require inspection. Impact and effort grades, when shown, are model estimates for the listed task.
- 1Validate and remediate the supported finding: A negative debit increases the supplied wallet balanceinference — beyond sealed evidence
- 2Inspect the relevant source and protections to test this allegation: Unauthenticated visitors can edit every wallet. Establish support and counterevidence before changing code.inference — beyond sealed evidence
- 3Inspect example/caller.js (intentionally not supplied) to test this allegation: The caller's authorization and input validation remain unverified. Establish support and counterevidence before changing code.inference — beyond sealed evidence
- 1Which caller checks authentication, ownership and positive quantities before invoking debit?
The Seal
proof · the loopThis is a zero-spend example. No digital signature was created. For a live report, check its receipt for the verification method and scope.
1 file · 0.1 KB read1/1 exhibits verified
Receipt chips verify quote authenticity or identify a structural query. They do not prove an allegation. Finding status and confidence describe the separate support assessment.
The constellation · every file this verdict rests on
1 file · 99 bytes in example · drag to orbit — star heat = file size
Audit the code you are about to hand off.
Bring a repository you own or have permission to audit. You choose a plan or credits when you start.