Auditor
Plain HTTP requests are redirected to HTTPS, never answered with content.
1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)
| for (const p of paths) { const res = await origin.fetch(`http://${host}${p}`); // redirect: 'manual' |
| // 3xx + Location https:// -> ok; 2xx -> FAIL (content over HTTP); 3xx elsewhere -> FAIL; refused -> not served } |
| // no deployed origin -> not applicable |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.