Skip to main content
The effective catalog depends on language, repository files, tier, policy, and worker capability. It includes:
  • secret and high-entropy credential detection;
  • dependency integrity, confusion, and license policy;
  • language/toolchain security analyzers when present;
  • CodeQL/provider alert ingestion when licensed and enabled;
  • configuration and infrastructure checks;
  • build, test, reproduction, behavior-differential, and oracle evidence;
  • model review passes grounded in repository and execution context.
Every requested analyzer has a receipt: passed, findings, failed, disabled by policy, unsupported, or cannot run. Required tools in workspace policy cannot be disabled by repository config.
Last modified on July 28, 2026