Every implemented HTTP route is declared in the OpenAPI/Swagger document with a closed response schema, and the document declares nothing that is not implemented.
Inputs
OpenAPI and Swagger documents of the checkout (JSON parsed; YAML read by a purpose-built indentation reader of paths, methods, responses and schemas) and the implemented routes of Express/Koa/Fastify/Hono, NestJS, Next.js, Django, Flask, FastAPI and Laravel, with path parameters normalised (:id, {id}, <int:id>, [id]). Paths listed in excludes (test, spec and tmp files, __tests__, __mocks__, fixtures, test, tests and audit-scripts folders) are never analysed.
Decision rule
Not applicable when no HTTP route is implemented. FAIL (HIGH) when routes are implemented and no OpenAPI/Swagger document exists and the document is not generated from the code, or when an implemented route (health, metrics, docs and framework paths excluded) has no declared operation. A declared success response without a schema or with additionalProperties true is MEDIUM (blocks in this Extended suite); a declared operation with no implementation is LOW. With a document generated from the code (FastAPI, NestJS SwaggerModule), the route inventory is conformant by construction and routes without response_model or @ApiResponse are MEDIUM. PASS when every implemented route is declared and every success response is schema-bound.
Type
deterministic
1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)