- secret and high-entropy credential detection;
- dependency integrity, confusion, and license policy;
- language/toolchain security analyzers when present;
- CodeQL/provider alert ingestion when licensed and enabled;
- configuration and infrastructure checks;
- build, test, reproduction, behavior-differential, and oracle evidence;
- model review passes grounded in repository and execution context.
Repository intelligence
Analyzer catalog
Deterministic and evidence-producing repository checks
The effective catalog depends on language, repository files, tier, policy, and
worker capability. It includes:
Last modified on July 28, 2026
⌘I

