Auditor
The root HTML and its assets reference only HTTPS resources.
1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)
| const ATTRIBUTE_REF = /<\s*(script|link|iframe|object|embed|form|img|source|video|audio|track|picture)\b[^>]*?\b(src|href|srcset|poster|action|data)\s*=\s*["']?\s*http:\/\/([A-Za-z0-9.-]+)/gi; |
| const ACTIVE = new Set(['script', 'link', 'iframe', 'object', 'embed', 'form']); // HIGH; the rest MEDIUM |
| // deployed root HTML + up to 5 same-origin stylesheets, then the templates of the checkout |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.