Every export, report, download or dump endpoint requires an authenticated caller, is rate limited and leaves an audit record. No AI engine is involved: the verdict is reproducible from the source alone.
Inputs
Non-test code files of the checkout (JavaScript, TypeScript, Python, PHP) plus nginx, Terraform, serverless/CloudFormation and wrangler files, analysed statically with the platform kit: tokens, function units, calls, imports and route registrations of Next (app and pages), Express, Fastify, Koa, Hono, Nest, Lambda, Django (views and urls.py), Flask, FastAPI and Laravel. An export endpoint is a route whose path has an export, download, dump, backup, bulk, extract, archive, csv, xlsx, xls, pdf, excel segment or a .csv/.xlsx/.pdf/.zip suffix (not on DELETE), a report, statement or ledger segment on a GET route, a handler or controller named export/download/dump/backup/toCsv/toExcel/generatePdf, or a handler that produces a file (Content-Disposition attachment, json2csv, csv-stringify, exceljs, xlsx, pdfkit, pandas to_csv/to_excel, openpyxl, reportlab, Maatwebsite Excel, League Csv, fputcsv, Dompdf, StreamingHttpResponse, FileResponse, res.download, send_file, response()->download, a CSV/XLSX/PDF/zip/octet-stream content type). Three controls per endpoint, each searched on the route (middleware, decorators), on its class or controller, in the handler and the functions it calls within 2 module hops, in a gate registered earlier in the same file (app.use before the route), and framework-wide: authentication (requireAuth*, getServerSession, auth(), verifyToken, a service secret, login_required, permission_classes, Depends, Laravel auth:, a Next.js middleware/proxy whose matcher covers the route and whose route map does not declare it public, APP_GUARD, DRF DEFAULT_PERMISSION_CLASSES, Laravel Kernel groups), rate limiting (express-rate-limit, throttle, @Throttle, ThrottlerGuard, @limiter.limit, rateLimiter.check, an in-handler counter answering 429, a limiter in the Next.js middleware, DRF DEFAULT_THROTTLE_CLASSES, Flask-Limiter defaults, Laravel throttle:, nginx limit_req for the location, a WAF rate rule) and audit (audit_log/auditLog/logAccess/logActivity/recordEvent/activity log/LogEntry/Spatie activitylog/auditlog calls, an audit interceptor or middleware, a model auditing package, a logger.info/warn line naming the export). Paths listed in excludes are never analysed. Nothing of the checkout is executed.
Decision rule
Not applicable when no export endpoint exists. FAIL (HIGH, export-unauthorised) when an export endpoint has no authentication gate on the route, its class, the handler or its callees within 2 module hops, earlier in its file, or framework-wide. No rate limiter in the same places is MEDIUM (export-not-rate-limited); no audit record in the same places is MEDIUM (export-not-audited); this check runs in an Extended suite, so MEDIUM blocks. PASS when every export endpoint carries the three controls (the summary names each endpoint and where each control lives). Not judged by this check (declared): authorisation beyond authentication (whether the caller owns or has the role for the exported set — idor and multi-tenant-isolation), single-record downloads the caller owns (an invoice PDF of one order is treated like any export), exports reachable only with a service secret (an internal endpoint consumed by another service; listed in the trace and in the not-applicable reason, never reported), and limiters or audit trails in infrastructure not versioned in the checkout.
Type
deterministic
1.1.1: a callee whose root is a name that `Object.prototype` also carries (`build().toString()` tokenizes to the bare callee `toString`; also `constructor`, `valueOf`, `hasOwnProperty`) was looked up in the plain object that holds the imported names, so it resolved to the INHERITED FUNCTION instead of to nothing and the whole check died with "name.includes is not a function". Only a real binding counts now, and the name of a unit is always read as a string. Found on a 1 319-file checkout (2fa-available and session-expiry-rotation, 2026-09-24); the same line was in the 15 scripts that walk the call graph, so all fifteen ship the fix. (1.1.0: deterministic: the rule runs over the static analysis kit (tokens, function units, calls, imports, routes) with no AI engine; exact decisionRule and languages published; not-applicable with the reason when the checkout gives nothing to evaluate. Export endpoints by path segment (report only on GET), handler name or file-producing code; authentication, rate limit and audit decided with the same per-route coverage rules as rate-limit 1.1.0. Not judged: service-to-service exports, ownership, single-record downloads. (1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)))
// an export endpoint is a route FUNCTION UNIT (kit) with an export/download/dump/backup/csv/xlsx/pdf segment, a report segment on GET, an export-named handler, or a handler that produces a file
// three controls per route with the same coverage rules (route middleware -> class -> handler and callees <= 2 module hops -> app.use before the route -> framework-wide):
// auth missing -> HIGH (CWE-862); rate limiter missing -> MEDIUM (CWE-770); audit record missing -> MEDIUM (CWE-778); no export endpoint -> not-applicable
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.