No log statement, debug hook, analytics event or error-tracker call of the messaging feature receives a message payload (plaintext or ciphertext) or identifying metadata. No AI engine is involved: the verdict is reproducible from the source alone.
Inputs
Non-test code files of the checkout (JavaScript, TypeScript, Python, PHP) that belong to the messaging feature by path or content, analysed statically with the static analysis kit (tokens, function units, calls with their arguments). The unit of analysis is every CALL to a sink — console, logger, logging, print, Log::, error_log, var_dump, Sentry, Bugsnag, Rollbar, analytics, PostHog, Mixpanel, Amplitude, gtag, dataLayer, debug — in a messaging file; its arguments are read as tokens: identifiers and member chains, object and dict keys, PHP array keys, Python keyword arguments, and the expressions interpolated in template literals and f-strings. The parameters of socket or channel event handlers (.on('message', …), .onAny, .subscribe, addEventListener of a message event) are message frames. Paths listed in excludes (test, spec and tmp files, __tests__, __mocks__, fixtures, test, tests and audit-scripts folders) are never analysed. Nothing of the checkout is executed.
Decision rule
Not applicable when the checkout has no messaging feature: a messaging feature exists only with a message or conversation model, a chat transport, a messaging protocol library, a chat UI or end-to-end keys in a messaging folder somewhere in the checkout; messaging vocabulary alone is not-applicable with the reason. FAIL (HIGH, with the call line) when a sink call in a messaging file receives a message object, body, text, content, ciphertext, plaintext, payload, packet, frame, envelope or attachment — as an identifier, the last significant member of a chain (req.body, msg.text.slice(…)), an object or dict key, a spread, a JSON.stringify argument or an interpolation — or a parameter of a socket event handler. Two or more identifier classes among sender (senderId, fromId, authorId…), the acting user (userId, actorId…), recipient (recipientId, toUserId, targetUserId, peerId…), conversation (conversationId, chatId…), room (roomId, channelId, groupId…), thread and device in one sink call is MEDIUM (blocks in Extended suites); the same to an analytics sink is message-to-analytics with the same severities. Never reported: an error's TEXT — a root that is an error by its whole name (err, error, e, ex, exception, reason, cause, result, response...) or by its LAST WORD (parseErr, s3Err, publishErr, uploadError, caught_exception: real code names its errors after what failed, 1.1.2) —, a count, an identifier or a state alone (message.id, messages.length, msg.type), a string literal, a value passed through a helper named like a redaction (redact, sanitize, mask, scrub, summarize, hash, truncate, omit, pick, anonymize...), a name assigned only FROM AN ERROR (1.1.2: a name whose every assignment in the file derives from an error, as in `const message = error instanceof Error ? error.message : String(error)`, is a failure's text, and the trace names it and the line of its declaration), a bare parameter of a PRINTER OF THE CHECKOUT (1.1.2: a function that is a printer by its own name, by the name of the object it belongs to or by the name of its class — log, logger, info, warn, error, debug, print, write, echo, output, report, status, step, ui, console, terminal... — does not READ a message: it re-prints the text its caller chose, as in `const logger = { info: (msg) => console.log(msg) }` or `updateStatus(message)` of a console UI, so what it prints is judged where it is CALLED and the trace names the parameter. Only a BARE parameter: `console.log(msg.text)` inside the same printer still fails, and a socket frame parameter is never a printer parameter, so `.on('message', (data) => console.log(data))` keeps failing), and a LITERAL OF THE FILE — a name whose every assignment in that file derives from literals declared there (a string or a template without interpolation, an array or object of such strings, or an index or pick over one of them, as in `const randomMessages = ['…','…']; const message = randomMessages[Math.floor(Math.random() * randomMessages.length)]`): it is a fixed text of the release, not somebody's message, and the trace names the value and the line of its declaration. A name assigned anywhere in the file from anything else (a request, a parameter, a store, a call that is not an index or pick over a literal collection) is not a literal and is reported as before. PASS when every sink call of every messaging file was analysed and none receives a payload, a frame or two identifier classes. Not judged by this check (declared): whether a redaction helper really strips the payload, logs written by infrastructure outside the checkout (proxies, transport debug flags, log shipping), custom loggers whose name is not in the sink list, and a collection passed through a method call (messages.map(…)) is reported by its name.
Type
deterministic
1.1.2: three values that are NOT somebody's message stop being reported, each by what the file itself says. (a) An error's TEXT: the exemption of err.message read the root as a whole word, and real code names its errors after what failed (parseErr, s3Err, publishErr, uploadError, caught_exception), so ${parseErr.message} in a build log came out as the message payload; a root is an error by its whole name or by its LAST WORD (err, error, exception, ex, exc, failure, fault). (b) A name assigned only FROM AN ERROR: mirroring the literals of the file of 1.1.1, a name whose every assignment derives from an error (const message = error instanceof Error ? error.message : String(error)) is a failure's text, and the trace names it and the line of its declaration. (c) A bare parameter of a PRINTER OF THE CHECKOUT: a function that is a printer by its own name, by the name of the object it belongs to or by the name of its class (log, logger, info, warn, error, debug, print, write, echo, output, report, status, step, ui, console, terminal…) does not READ a message, it re-prints the text its caller chose (const logger = { info: (msg) => console.log(msg) }, updateStatus(message) of a console UI), so what it prints is judged where it is CALLED. Only a BARE parameter: console.log(msg.text) inside the same printer still fails, and a socket frame parameter is never a printer parameter, so .on('message', (data) => console.log(data)) keeps failing. (1.1.1: false positive of the attestation of platform/apps/auth (2026-09-24), fixed in the script: un valor que es LITERAL DEL FICHERO (todas sus asignaciones derivan de literales declarados ahí: una cadena, una plantilla sin interpolación, un array u objeto de esas cadenas, o un índice o selección sobre uno de ellos) es un texto fijo de la release, nunca el mensaje de nadie, y no se reporta (la traza lo nombra con la línea de su declaración). (1.1.0: deterministic: the rule runs over the static analysis kit (tokens, function units, calls, imports, routes) with no AI engine; exact decisionRule and languages published; not-applicable with the reason when the checkout gives nothing to evaluate. La unidad es la LLAMADA al sink en un fichero de mensajería; payload = HIGH, dos clases de identificador = MEDIUM.))
// the unit of analysis is the CALL to a sink in a messaging file; its arguments are read as tokens (identifiers, member chains, keys, template and f-string interpolations)
const PAYLOAD_ID = /^(?:message|msg|payload|packet|frame|envelope|body|text|content|ciphertext|plaintext|encrypted|chatMessage)$/i; // the last significant member of a chain -> HIGH
const METADATA_CLASS = ['sender', 'user', 'recipient', 'conversation', 'room', 'thread', 'device']; // two or more classes in one call -> MEDIUM
// err.message, parseErr.message (an error by its LAST WORD), message.id, messages.length, a string literal, redact(message) -> never reported
const PRINTER_WORD = /^(?:log|logger|info|warn|error|debug|print|write|echo|output|report|status|step|ui|console|terminal)$/; // `const logger = { info: (msg) => console.log(msg) }` re-prints the text its caller chose: a bare parameter of a printer is not a message
// a parameter of .on('message', (data) => …) or socket.onAny((event, ...args) => …) reaching a sink -> HIGH (the frame)
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.