Repository Analysis

AtalayaLabs/OxiCloud

☁️ Ultra-fast, secure & lightweight self-hosted cloud storage — your files, photos, calendars & contacts, all in one place. Built in Rust.

16.0 Moderate AI signal View on GitHub

Analysis Overview

This report presents the forensic synthetic code analysis of AtalayaLabs/OxiCloud, a Rust project with 3,455 GitHub stars. SynthScan v2.0 examined 335,130 lines of code across 996 source files, recording 2575 pattern matches distributed across 13 syntactic categories. The overall adjusted score of 16.0 places this repository in the Moderate AI signal band.

The scanner applied 160+ deterministic lexical heuristics, multi-line block detectors, abstract syntax tree depth profilers, and a cross-file Jaccard similarity matrix to construct a statistically normalised synthetic code estimate. All matches are individually weighted by severity coefficient and contextual multiplier before summation, and the resulting headline score is temporally discounted to account for the repository's development history relative to the commercial emergence of large language model coding tooling (November 2022 onward).

16.0
Adjusted Score
16.0
Raw Score
100%
Time Factor
2026-08-01
Last Push
3.5K
Stars
Rust
Language
335.1K
Lines of Code
996
Files
2.6K
Pattern Hits
2026-08-02
Scan Date
0.00
HC Hit Rate

What These Metrics Mean

Adjusted Score
Primary synthetic code indicator. Raw score normalised per 1,000 lines of code and multiplied by the temporal discount factor. This is the definitive comparative metric — use it to rank repositories by AI authorship density.
Raw Score
The unmodified sum of all severity-weighted, context-multiplied pattern match scores before temporal discounting. Reflects the absolute signal strength independent of when the repository was last active.
Time Factor
The temporal discount multiplier (0–100%) applied to the raw score. Repositories last updated before ChatGPT's launch (Nov 2022) receive a 5% factor. Full signal is only assigned to repositories active in the post-adoption era (Jan 2024+).
Pattern Hits
Total count of individual pattern matches across all files and categories. A high hit count with a low score may indicate a very large codebase with isolated AI snippets; a low count with a high score indicates dense, concentrated AI signatures.
HC Hit Rate
High+Critical pattern hits per file, averaged across the repository. This orthogonal signal catches repositories where a few files are densely packed with high-severity AI tells — a strong indicator even when the normalised score appears moderate due to codebase size.
Lines of Code / Files
Total lines and files analysed. The scanner examines 94 file extensions. These denominators are used to normalise the score, enabling fair comparison between repositories of vastly different sizes.

Score History

Longitudinal tracking requires multiple scan runs. Once this repository is re-scanned after new commits land, this chart will visualise how the synthetic code signal evolves over time — enabling you to detect whether AI authorship is growing, stabilising, or being actively corrected by human engineers.

No multi-scan history yet — run the scanner again to build trend data.

Severity Breakdown

Classifies detected patterns by their diagnostic confidence and structural impact. CRITICAL patterns (coefficient 10) represent definitive synthetic signatures — hallucinated imports, explicit LLM attribution metadata — virtually never produced by human authors. HIGH (5) indicates strong structural tells such as cross-file repetition or cross-linguistic idioms. MEDIUM (2) covers recognisable conversational padding and AI-specific vocabulary. LOW (1) captures subtle indicators like tautological comments and generic boilerplate that require density to carry independent signal.

CRITICAL 0HIGH 1MEDIUM 1422LOW 1152

Directory Score Breakdown

This horizontal bar chart decomposes the repository's raw synthetic code score by top-level directory, allowing you to pinpoint precisely which modules or components carry the highest AI authorship density. Directories with disproportionately high scores relative to their size warrant targeted manual review: concentrated AI signatures often trace back to mass-generated configuration layers, auto-ported test suites, LLM-scaffolded boilerplate classes, or entire subsystems authored under heavy copilot assistance. Use this view to prioritise your human code-review effort.

Pattern Findings

The scanner identified 2575 distinct pattern matches across 13 syntactic categories. Each entry below represents a discrete location in the source code where the engine recorded a statistically significant AI authorship indicator. Expand any category row to inspect the individual file paths, line numbers, code snippets, and the lexical context (CODE, COMMENT, or STRING) in which each match was detected.

Reading the findings table: The Severity column indicates the diagnostic confidence level (CRITICAL / HIGH / MEDIUM / LOW). The Context column identifies whether the match occurred inside executable code, an inline comment, or a string literal — comment-context matches receive a ×1.5 weight because LLMs systematically over-annotate. The ⚡ bolt icon marks clustered matches: three or more patterns within a 10-line window, each receiving an additional ×1.5 density multiplier as dense clusters constitute far stronger evidence of synthetic authorship than isolated hits.

Decorative Section Separators1401 hits · 4210 pts
SeverityFileLineSnippetContext
MEDIUMCargo.toml299# Round-4 battery ─────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml350# Round-5 battery ─────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml366# Round-29 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml377# Round-27 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml388# Round-26 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml414# Round-25 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml435# Round-24 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml450# Round-23 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml471# Round-22 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml487# Round-21 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml502# Round-20 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml518# Round-19 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml532# Round-18 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml545# Round-17 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml558# Round-16 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml569# Round-15 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml587# Round-14 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml605# Round-13 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml621# Round-12 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml646# Round-11 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml674# Round-10 battery ────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml693# Round-9 battery ─────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml744# Round-8 battery ─────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml754# Round-7 battery ─────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml771# Round-6 battery ─────────────────────────────────────────────────────────────COMMENT
MEDIUMCargo.toml800# Round-3 battery ─────────────────────────────────────────────────────────────COMMENT
MEDIUMbench.sh35# ── Server PID ───────────────────────────────────────────────────────────────COMMENT
MEDIUMbench.sh43# ── Memory (KB) ─────────────────────────────────────────────────────────────COMMENT
MEDIUMbench.sh49# ── CPU jiffies ──────────────────────────────────────────────────────────────COMMENT
MEDIUMbench.sh52# ── Background monitor ──────────────────────────────────────────────────────COMMENT
MEDIUMbench.sh253# ============================================================================COMMENT
MEDIUMbench.sh255# ============================================================================COMMENT
MEDIUMbench.sh264# ============================================================================COMMENT
MEDIUMbench.sh266# ============================================================================COMMENT
MEDIUMbench.sh2# ============================================================================COMMENT
MEDIUMbench.sh11# ============================================================================COMMENT
MEDIUMbench.sh24# ── Colours ──────────────────────────────────────────────────────────────────COMMENT
MEDIUMbench.sh87# ── Auth ─────────────────────────────────────────────────────────────────────COMMENT
MEDIUMbench.sh97# ── File gen ─────────────────────────────────────────────────────────────────COMMENT
MEDIUMbench.sh122# ── Inject large blob (bypass upload handler) ──────────────────────────────COMMENT
MEDIUMbench.sh156# ── Setup ────────────────────────────────────────────────────────────────────COMMENT
MEDIUMbench.sh174# ── Upload sizes (safe for the buffering handler) ───────────────────────────COMMENT
MEDIUMbench.sh195# ── Generate upload test files ──────────────────────────────────────────────COMMENT
MEDIUMbench.sh209# ============================================================================COMMENT
MEDIUMbench.sh211# ============================================================================COMMENT
MEDIUMbench.sh304# ============================================================================COMMENT
MEDIUMbench.sh306# ============================================================================COMMENT
MEDIUMbench.sh338# ============================================================================COMMENT
MEDIUMbench.sh340# ============================================================================COMMENT
MEDIUMbench.sh373# ============================================================================COMMENT
MEDIUMbench.sh375# ============================================================================COMMENT
MEDIUMbench.sh407# ============================================================================COMMENT
MEDIUMbench.sh409# ============================================================================COMMENT
MEDIUMbuild.rs15// ═══════════════════════════════════════════════════════════════════════════════COMMENT
MEDIUMbuild.rs18// ═══════════════════════════════════════════════════════════════════════════════COMMENT
MEDIUMfrontend/static/workers/deltaWorker.js83 // ── Shared pipeline state ─────────────────────────────────────COMMENT
MEDIUMfrontend/static/workers/deltaWorker.js198 // ── Negotiate stage ───────────────────────────────────────────COMMENT
MEDIUMfrontend/static/workers/deltaWorker.js239 // ── Chunking stage (drives the other two) ────────────────────COMMENT
MEDIUMfrontend/static/workers/deltaWorker.js285 // ── Drain: negotiations → uploads → commit ───────────────COMMENT
MEDIUMfrontend/src/lib/stores/preferences.svelte.ts80 // ── Typed accessors ──────────────────────────────────────────COMMENT
1341 more matches not shown…
Over-Commented Block1098 hits · 1020 pts
SeverityFileLineSnippetContext
LOWCargo.toml21tracing = "0.1.44"COMMENT
LOWCargo.toml121ndarray = { version = "0.17.2", optional = true }COMMENT
LOWCargo.toml461COMMENT
LOWCargo.toml501COMMENT
LOWCargo.toml521# the per-request `format!("{u}:{p}")` String), WOPI validate/generate prebuiltCOMMENT
LOWCargo.toml881# actually need on a long-running server) while dropping the rest ofCOMMENT
LOWbench.sh1#!/usr/bin/env bashCOMMENT
LOWTODO-STORAGE-BACKENDS.prompt.md81 pub backend_type: String,COMMENT
LOWdocker-compose.wopi.yml21COMMENT
LOWdocker-compose.yml21 oxicloud:COMMENT
LOWentrypoint.sh1#!/bin/shCOMMENT
LOWtools/perf-audit/gc_manifest_batch.rs1//! Reproducible audit harness for `DedupService::garbage_collect_with_grace`COMMENT
LOWtools/perf-audit/admin_user_listing_e2e.rs1//! Component-faithful A/B for `GET /api/admin/users`.COMMENT
LOWfrontend/svelte.config.js1import adapter from '@sveltejs/adapter-static';COMMENT
LOWfrontend/vite.config.ts1import { sveltekit } from '@sveltejs/kit/vite';COMMENT
LOWfrontend/static/sw.js1// Self-unregistering stub — replaces the legacy vanilla-frontendCOMMENT
LOWfrontend/src/lib/stores/preferences.svelte.ts41 * preserved on upload, matching Nextcloud / ownCloud / Seafile.COMMENT
LOWfrontend/src/lib/components/round14.bench.test.ts1// Round-14 frontend micro-pack (benches/ROUND14.md §F1, §F2).COMMENT
LOWfrontend/src/lib/components/round13.bench.test.ts1// Round-13 §V1 — grouped views are windowed (benches/ROUND13.md).COMMENT
LOWfrontend/src/lib/components/AppShell.svelte341 // Stale-response guard (same family as the search page): the debounceCOMMENT
LOWfrontend/src/lib/components/ResourceList.svelte481 // even if the user's global preference is on.COMMENT
LOWfrontend/src/lib/components/ResourceList.svelte621 const a = order.indexOf(anchorId);COMMENT
LOWfrontend/src/lib/components/ResourceList.svelte701 }COMMENT
LOWfrontend/src/lib/components/ResourceList.svelte721 e.preventDefault();COMMENT
LOWfrontend/src/lib/components/ResourceList.svelte841 for (const id of nextSelection) if (!selected.has(id)) selected.add(id);COMMENT
LOWfrontend/src/lib/components/ResourceList.svelte981 // * `enableSystemDrop = true`: the page has an upload code pathCOMMENT
LOWfrontend/src/lib/components/QuotaEditor.svelte1<script lang="ts">COMMENT
LOWfrontend/src/lib/components/FolderBreadcrumb.svelte161 // facing surface for a public-link session.COMMENT
LOWfrontend/src/lib/components/AdminJobsPanel.svelte461 }COMMENT
LOWfrontend/src/lib/components/round18.bench.test.ts1// Round-18 frontend micro-pack (benches/ROUND18.md §F1).COMMENT
LOWfrontend/src/routes/config/drive/[uuid]/+page.svelte181 // Drive policies are OxiCloud-admin-only for mutation (§8), butCOMMENT
LOWfrontend/src/routes/favorites/+page.svelte41COMMENT
LOWfrontend/src/routes/shared-with-me/+page.svelte41 let error = $state<string | null>(null);COMMENT
LOWfrontend/src/routes/admin/[[tab]]/+page.svelte441 // MigrationCOMMENT
LOWfrontend/src/routes/admin/[[tab]]/+page.svelte521 // The old target-name picker state was retired — the entriesCOMMENT
LOWfrontend/src/routes/admin/[[tab]]/+page.svelte1061 // Owner user record for each PERSONAL drive, keyed by drive id.COMMENT
LOWfrontend/src/routes/admin/[[tab]]/+page.svelte1361 }COMMENT
LOWfrontend/src/routes/trash/+page.svelte41 // timer to permanent deletion without ever being visible forCOMMENT
LOWfrontend/src/routes/search/+page.svelte41 // "Everywhere" — so they can toggle back to "This folder" withoutCOMMENT
LOWfrontend/src/routes/search/+page.svelte61 // query time / result count into the title string because ResourceListCOMMENT
LOWfrontend/src/routes/search/+page.svelte101 // Sort dimension + direction are surfaced through ResourceList'sCOMMENT
LOWfrontend/src/routes/search/+page.svelte121 // stdlib `URLSearchParams`, and we don't need reactivity here.COMMENT
LOWfrontend/src/routes/search/+page.svelte641 onreload={() => {COMMENT
LOWfrontend/src/routes/files/[...path]/+page.svelte61 const fileViewer = lazyComponent(() => import('$lib/components/FileViewer.svelte'));COMMENT
LOWfrontend/src/routes/files/[...path]/+page.svelte101 let listing = $state<FolderListing>({ folders: [], files: [] });COMMENT
LOWfrontend/src/routes/files/[...path]/+page.svelte121 // at the top of the list. The swimlane clears on next folder nav.COMMENT
LOWfrontend/src/routes/files/[...path]/+page.svelte141 // — same UX as macOS Finder.COMMENT
LOWfrontend/src/routes/files/[...path]/+page.svelte281 // on the new folder — must clear or the first append wouldCOMMENT
LOWfrontend/src/routes/files/[...path]/+page.svelte301 // load. `/files/A/B/C` still resolves (router matches `[...path]`)COMMENT
LOWfrontend/src/routes/files/[...path]/+page.svelte1201COMMENT
LOWfrontend/src/routes/files/[...path]/+page.svelte1241 // modifier key) picks the effective operation and the OSCOMMENT
LOWfrontend/src/routes/files/[...path]/+page.svelte1621 // (the previous `$state` + two `$effect` mirror was fragile — aCOMMENT
LOWfrontend/src/routes/files/[...path]/+page.svelte1661 // GROUP_BYS toolbar emits, so <ResourceList>'s onreload gets theCOMMENT
LOWfrontend/src/routes/files/[...path]/+page.svelte1781 const onDown = (e: MouseEvent) => {COMMENT
LOWfrontend/src/routes/photos/+page.svelte81 }).format(d);COMMENT
LOWfrontend/src/routes/login/+page.svelte81 // magic-link path. When the password is empty (and the server offersCOMMENT
LOWfrontend/src/routes/login/+page.svelte101 // `bind:this` on the first input of each mode's form so the effectCOMMENT
LOWwasm/oxicloud-plugin-hello/src/lib.rs1//! Example OxiCloud plugin — ABI v0 (M0 walking skeleton).COMMENT
LOWwasm/oxicloud-hash/src/lib.rs1//! BLAKE3 for the OxiCloud web frontend.COMMENT
LOWwasm/oxicloud-hash/src/lib.rs61/// One-shot convenience for small buffers.COMMENT
1038 more matches not shown…
AI Slop Vocabulary17 hits · 48 pts
SeverityFileLineSnippetContext
MEDIUMCargo.toml142# Performance benchmark harness (Phase 0). Exposes `bench_support` + thin publicCOMMENT
MEDIUMCargo.toml154# Round-11 L1 harness only (bench_log_writer): the non-blocking writer wasCOMMENT
MEDIUMCargo.toml178# Phase 0 perf harness — Task 0.2 (criterion latency + output-size bench).COMMENT
MEDIUMCargo.toml185# Phase 0 perf harness — Task 0.3 (peak-RAM + saturated-throughput baseline).COMMENT
MEDIUMtools/perf-audit/run_gc_manifest_batch.sh19# avoiding localhost/SSL negotiation keeps the harness independent of hostCOMMENT
MEDIUMfrontend/src/lib/i18n/i18n.bench.test.ts160 // is more robust to noise than `mean`/`median` because the noiseCOMMENT
MEDIUMtests/load/smoke.sh4# diff. Goal is harness liveness - does the server still boot and does k6 stillCOMMENT
MEDIUMtests/api/run.sh117# test harness itself reads via $OXICLOUD_* stays available; dotenvy won'tCOMMENT
MEDIUMtests/webdav/run.sh80# test harness itself reads via $OXICLOUD_* stays available; dotenvy won'tCOMMENT
MEDIUMtests/webdav/test_nextcloud_chunked_upload_propfind.sh87# and a plain grep is robust enough for the assertions we need.COMMENT
MEDIUM.cargo/audit.toml63 # the `--cfg integration_tests` harness to spin up throwaway PostgresCOMMENT
MEDIUM.cargo/audit.toml66 # official Postgres images the test harness pulls. testcontainers 0.25.2COMMENT
MEDIUMexamples/bench_thumbnails_mem.rs204 println!("# Thumbnail render harness — current working tree");CODE
MEDIUM.github/workflows/load-smoke.yml3# PR-tier liveness check. Verifies the k6 load harness still builds and aCOMMENT
MEDIUMsrc/application/services/trash_service.rs118 // Use empty MIME type to leverage extension fallback; oneCOMMENT
MEDIUMsrc/infrastructure/services/swappable_blob_backend.rs92 // swap — recover the guard to keep the swap surface robustCOMMENT
MEDIUMsrc/interfaces/api/handlers/webdav_handler.rs3766 // but the helper still has to be robust to a path thatCOMMENT
Hyper-Verbose Identifiers28 hits · 28 pts
SeverityFileLineSnippetContext
LOWfrontend/src/routes/admin/[[tab]]/+page.svelte1198 async function searchManageOwnersCandidates(q: string) {CODE
LOWtests/caldav/test_report.py100def test_calendar_query_time_range_returns_events_in_window(STRING
LOWtests/caldav/test_report.py138def test_calendar_query_time_range_after_all_events_returns_empty(CODE
LOWtests/caldav/test_report.py162def test_calendar_query_time_range_before_all_events_returns_empty(CODE
LOWtests/caldav/test_report.py180def test_calendar_query_no_filter_returns_every_event(CODE
LOWtests/caldav/test_report.py204def test_calendar_multiget_by_href_returns_the_targeted_events(CODE
LOWtests/caldav/test_report.py240def test_calendar_multiget_unknown_href_is_silently_absent(CODE
LOWtests/caldav/test_ical_coverage.py93def test_description_with_escaped_chars_round_trips(STRING
LOWtests/caldav/test_ical_coverage.py124def test_location_survives_round_trip(fresh_calendar: caldav.Calendar) -> None:CODE
LOWtests/caldav/test_ical_coverage.py136def test_uid_and_dtstamp_are_preserved(fresh_calendar: caldav.Calendar) -> None:CODE
LOWtests/caldav/test_ical_coverage.py160def test_attendee_survives_round_trip(fresh_calendar: caldav.Calendar) -> None:CODE
LOWtests/caldav/test_ical_coverage.py176def test_organizer_survives_round_trip(fresh_calendar: caldav.Calendar) -> None:CODE
LOWtests/caldav/test_ical_coverage.py189def test_categories_survive_round_trip(fresh_calendar: caldav.Calendar) -> None:CODE
LOWtests/caldav/test_ical_coverage.py202def test_status_and_transp_survive_round_trip(CODE
LOWtests/caldav/test_ical_coverage.py221def test_valarm_survives_round_trip(fresh_calendar: caldav.Calendar) -> None:CODE
LOWtests/caldav/test_ical_coverage.py255def test_custom_x_property_survives_round_trip(STRING
LOWtests/caldav/test_recurring.py97def test_non_recurring_event_round_trip(fresh_calendar: caldav.Calendar) -> None:CODE
LOWtests/caldav/test_recurring.py126def test_recurring_master_plus_exception_preserves_master(STRING
LOWtests/caldav/test_recurring.py206def test_exception_only_put_does_not_wipe_master(STRING
LOWtests/caldav/test_recurring.py297def test_all_day_recurring_master_plus_exception(STRING
LOWtests/caldav/test_carddav.py103def test_vcard_basic_round_trip(STRING
LOWtests/caldav/test_carddav.py121def test_vcard_email_survives_round_trip(CODE
LOWtests/caldav/test_carddav.py140def test_vcard_delete_removes_it(CODE
LOWtests/caldav/test_carddav.py160def test_addressbook_shows_up_in_propfind(CODE
LOWtests/caldav/test_carddav.py202def test_vcard_org_and_title_survive_round_trip(CODE
LOWtests/caldav/test_carddav.py224def test_vcard_note_survives_round_trip(CODE
LOWtests/caldav/test_carddav.py241def test_vcard_tel_uri_form_survives_round_trip(CODE
LOWtests/caldav/test_carddav.py262def test_vcard_adr_survives_round_trip(CODE
Structural Annotation Overuse6 hits · 10 pts
SeverityFileLineSnippetContext
LOWsrc/application/services/delta_upload_service.rs236 /// Step 1: which of these chunks must the caller upload?COMMENT
LOWsrc/application/services/delta_upload_service.rs256 /// Step 2: store uploaded chunk frames. Hashes are computedCOMMENT
LOWsrc/application/services/delta_upload_service.rs271 /// Step 3: pin → verify → attach manifest → create/update the file row.COMMENT
LOWsrc/application/services/file_retrieval_service.rs544 // NOTE: This method does NOT perform any authorization check. CallersCOMMENT
LOWsrc/application/services/file_management_service.rs600 // Step 1: Try trash (soft delete — file row stays, blob stays referenced)COMMENT
LOWsrc/application/services/file_management_service.rs625 // Step 2: Permanent delete — trigger handles blob ref_countCOMMENT
Verbosity Indicators5 hits · 8 pts
SeverityFileLineSnippetContext
LOWsrc/application/services/delta_upload_service.rs236 /// Step 1: which of these chunks must the caller upload?COMMENT
LOWsrc/application/services/delta_upload_service.rs256 /// Step 2: store uploaded chunk frames. Hashes are computedCOMMENT
LOWsrc/application/services/delta_upload_service.rs271 /// Step 3: pin → verify → attach manifest → create/update the file row.COMMENT
LOWsrc/application/services/file_management_service.rs600 // Step 1: Try trash (soft delete — file row stays, blob stays referenced)COMMENT
LOWsrc/application/services/file_management_service.rs625 // Step 2: Permanent delete — trigger handles blob ref_countCOMMENT
Modern AI Meta-Vocabulary3 hits · 8 pts
SeverityFileLineSnippetContext
MEDIUMdocs/DESIGN-SYSTEM.md83## 4. CI guardrails (what keeps the score from regressing)COMMENT
MEDIUMdocs/guide/trash.md115. **Trash on a read-only drive is paused** — see [Drives → Read-only](/guide/drives#policies-per-drive-guardrails). TheCODE
MEDIUMdocs/guide/drives.md73## Policies — per-drive guardrailsCOMMENT
AI Response Leakage1 hit · 8 pts
SeverityFileLineSnippetContext
HIGHdocs/plan/plan-ReBAC-Permissions-Grants-Cascading.md574### `GET /api/grants/outgoing` — grants I have createdCOMMENT
Fake / Example Data7 hits · 6 pts
SeverityFileLineSnippetContext
LOWfrontend/static/locales/en.json1536 "placeholder": "Type a command or search…",CODE
LOWfrontend/static/locales/ko.json1604 "placeholder": "명령을 입력하거나 검색하세요…",CODE
LOWexamples/bench_round11_micro.rs728 email_home: "ada@example.org".into(),CODE
LOWsrc/application/adapters/carddav_adapter_test.rs32 full_name: Some("John Doe".to_string()),CODE
LOWsrc/application/adapters/carddav_adapter_test.rs54 street: Some("123 Main St".to_string()),CODE
LOWsrc/application/adapters/carddav_adapter_test.rs62 organization: Some("Acme Corp".to_string()),CODE
LOWsrc/application/adapters/carddav_adapter_test.rs604 assert!(vcard.contains("123 Main St"), "Should have street");CODE
Unused Imports5 hits · 5 pts
SeverityFileLineSnippetContext
LOWtests/caldav/conftest.py13CODE
LOWtests/caldav/test_report.py23CODE
LOWtests/caldav/test_ical_coverage.py24CODE
LOWtests/caldav/test_recurring.py27CODE
LOWtests/caldav/test_carddav.py27CODE
Self-Referential Comments1 hit · 3 pts
SeverityFileLineSnippetContext
MEDIUMtests/webdav/common.sh20# Create the first admin account if the server is freshly initialised.COMMENT
Excessive Try-Catch Wrapping2 hits · 2 pts
SeverityFileLineSnippetContext
LOWtests/caldav/conftest.py126 except Exception:CODE
LOWtests/caldav/conftest.py225 except Exception:CODE
TODO Padding1 hit · 2 pts
SeverityFileLineSnippetContext
LOWsrc/infrastructure/services/azure_blob_backend.rs393 // TODO: implement `list_blob_hashes` viaCOMMENT