Talk to one agent. Ship with a crew.
This report presents the forensic synthetic code analysis of kunchenguid/firstmate, a Shell project with 3,055 GitHub stars. SynthScan v2.0 examined 157,845 lines of code across 373 source files, recording 1146 pattern matches distributed across 9 syntactic categories. The overall adjusted score of 15.1 places this repository in the Moderate AI signal band.
The scanner applied 160+ deterministic lexical heuristics, multi-line block detectors, abstract syntax tree depth profilers, and a cross-file Jaccard similarity matrix to construct a statistically normalised synthetic code estimate. All matches are individually weighted by severity coefficient and contextual multiplier before summation, and the resulting headline score is temporally discounted to account for the repository's development history relative to the commercial emergence of large language model coding tooling (November 2022 onward).
Longitudinal tracking requires multiple scan runs. Once this repository is re-scanned after new commits land, this chart will visualise how the synthetic code signal evolves over time — enabling you to detect whether AI authorship is growing, stabilising, or being actively corrected by human engineers.
Classifies detected patterns by their diagnostic confidence and structural impact. CRITICAL patterns (coefficient 10) represent definitive synthetic signatures — hallucinated imports, explicit LLM attribution metadata — virtually never produced by human authors. HIGH (5) indicates strong structural tells such as cross-file repetition or cross-linguistic idioms. MEDIUM (2) covers recognisable conversational padding and AI-specific vocabulary. LOW (1) captures subtle indicators like tautological comments and generic boilerplate that require density to carry independent signal.
This horizontal bar chart decomposes the repository's raw synthetic code score by top-level directory, allowing you to pinpoint precisely which modules or components carry the highest AI authorship density. Directories with disproportionately high scores relative to their size warrant targeted manual review: concentrated AI signatures often trace back to mass-generated configuration layers, auto-ported test suites, LLM-scaffolded boilerplate classes, or entire subsystems authored under heavy copilot assistance. Use this view to prioritise your human code-review effort.
The scanner identified 1146 distinct pattern matches across 9 syntactic categories. Each entry below represents a discrete location in the source code where the engine recorded a statistically significant AI authorship indicator. Expand any category row to inspect the individual file paths, line numbers, code snippets, and the lexical context (CODE, COMMENT, or STRING) in which each match was detected.
Reading the findings table: The Severity column indicates the diagnostic confidence level (CRITICAL / HIGH / MEDIUM / LOW). The Context column identifies whether the match occurred inside executable code, an inline comment, or a string literal — comment-context matches receive a ×1.5 weight because LLMs systematically over-annotate. The ⚡ bolt icon marks clustered matches: three or more patterns within a 10-line window, each receiving an additional ×1.5 density multiplier as dense clusters constitute far stronger evidence of synthetic authorship than isolated hits.
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | bin/fm-gate-refuse-lib.sh | 93 | # own test harness sets FM_GATE_REFUSE_BYPASS=1 (see the header). | COMMENT |
| MEDIUM | bin/fm-afk-start.sh | 2 | # Enter away mode and run the sub-supervisor daemon in a harness-tracked | COMMENT |
| MEDIUM | bin/fm-afk-start.sh | 21 | # background process differs by harness/backend and is owned elsewhere: | COMMENT |
| MEDIUM | bin/fm-tmux-lib.sh | 18 | # Ghost text (incident composer-robust): claude renders a predicted-next-prompt | COMMENT |
| MEDIUM | bin/fm-tmux-lib.sh | 29 | # (fm-peek and every human/LLM-facing path stay plain). This is harness-generic: | COMMENT |
| MEDIUM | bin/fm-tmux-lib.sh | 30 | # any harness that de-emphasises placeholder/ghost text | COMMENT |
| MEDIUM | bin/fm-tmux-lib.sh | 41 | # the Enter-retry budget is spent: a busy pane means the harness accepted and | COMMENT |
| MEDIUM | bin/fm-tmux-lib.sh | 56 | # stays harness-scoped so one harness's output cannot make another read busy. | COMMENT |
| MEDIUM⚡ | bin/fm-tmux-lib.sh | 69 | # Delivery-only rendered busy footers per harness. claude/codex: "esc to | COMMENT |
| MEDIUM⚡ | bin/fm-tmux-lib.sh | 74 | # enough to classify arbitrary harness output safely. | COMMENT |
| MEDIUM⚡ | bin/fm-tmux-lib.sh | 76 | # ordinary output must not classify another harness as busy. Leading whitespace is | COMMENT |
| MEDIUM | bin/fm-tmux-lib.sh | 93 | fm_busy_lines_match() { # [harness] | CODE |
| MEDIUM | bin/fm-tmux-lib.sh | 108 | # A supplied harness must never borrow another harness's signature. | COMMENT |
| MEDIUM | bin/fm-tmux-lib.sh | 375 | fm_pane_is_busy() { # <target> [harness] | CODE |
| MEDIUM | bin/fm-tmux-lib.sh | 387 | # Busy-queued Enter (opencode 1.18.4): the harness accepts Enter while mid-turn | COMMENT |
| MEDIUM | bin/fm-tmux-lib.sh | 413 | # If the pane is busy (agent mid-turn), the harness accepted the Enter | COMMENT |
| MEDIUM | bin/fm-claude-stop-autoarm.sh | 13 | # - Identity: only when THIS session's harness ancestor holds state/.lock. | COMMENT |
| MEDIUM | bin/fm-claude-stop-autoarm.sh | 14 | # When an existing numeric owner fails the shared harness-liveness predicate, | COMMENT |
| MEDIUM | bin/fm-claude-stop-autoarm.sh | 90 | # A prior session may have died after leaving its numeric harness pid in .lock. | COMMENT |
| MEDIUM | bin/fm-claude-stop-autoarm.sh | 156 | # NO shell &: this hook process tree is the harness-owned lifecycle. The arm | COMMENT |
| MEDIUM | bin/fm-cd-pretool-check.sh | 11 | # harness payload, invokes that policy, and renders the established harness | COMMENT |
| MEDIUM⚡ | bin/fm-wake-lib.sh | 129 | # Print the supervision model of this home's PRIMARY harness: | COMMENT |
| MEDIUM⚡ | bin/fm-wake-lib.sh | 133 | # persistent every other harness (codex foreground checkpoint, opencode/pi/grok | COMMENT |
| MEDIUM⚡ | bin/fm-wake-lib.sh | 137 | # the harness). Otherwise bin/fm-harness.sh is the single detection owner, so this | COMMENT |
| MEDIUM⚡ | bin/fm-wake-lib.sh | 138 | # stays consistent with the harness-specific repair line the guards already emit. | COMMENT |
| MEDIUM | bin/fm-transition-lib.sh | 75 | # status today: herdr reports it precisely when a harness is | COMMENT |
| MEDIUM | bin/fm-test-run.sh | 348 | # secondmate lifecycle, bootstrap, live-harness opt-in, GUI-backend, and other | COMMENT |
| MEDIUM | bin/fm-test-run.sh | 909 | # The run tier's two harness-supplied facts (source vocabulary and | COMMENT |
| MEDIUM | bin/fm-test-run.sh | 910 | # context-reset stdout injection) only show up against a real harness. | COMMENT |
| MEDIUM | bin/fm-lock.sh | 3 | # Writes the harness (agent) process PID found by walking the shell's ancestry, | COMMENT |
| MEDIUM | bin/fm-trace-context-lib.sh | 7 | # backend and every harness for ship, scout, and secondmate spawns), and records | COMMENT |
| MEDIUM⚡ | bin/fm-sessionstart-run.sh | 9 | # skill has its own read-only path. When the harness injects hook stdout into | COMMENT |
| MEDIUM⚡ | bin/fm-sessionstart-run.sh | 14 | # --source The harness's own session-open source. When omitted, the source is | COMMENT |
| MEDIUM⚡ | bin/fm-sessionstart-run.sh | 20 | # Source routing (see docs/sessionstart-nudge.md for the per-harness names): | COMMENT |
| MEDIUM | bin/fm-remote-secondmate-control.sh | 5 | # fm-remote-secondmate-control.sh launch <id> <harness> <model|-> <effort|-> herdr [traceparent] | COMMENT |
| MEDIUM⚡ | bin/fm-arm-pretool-check.sh | 5 | # standalone verified harness call. | COMMENT |
| MEDIUM⚡ | bin/fm-arm-pretool-check.sh | 8 | # This wrapper only acquires the harness payload, discovers the active roots, | COMMENT |
| MEDIUM⚡ | bin/fm-arm-pretool-check.sh | 9 | # invokes that policy, and renders the established harness-specific responses. | COMMENT |
| MEDIUM⚡ | bin/fm-arm-pretool-check.sh | 21 | # --background remains accepted for compatibility, but harness-native tracked | COMMENT |
| MEDIUM | bin/fm-sessionstart-nudge.sh | 3 | # primary whose current harness session has not already acquired the home lock. | COMMENT |
| MEDIUM⚡ | bin/fm-composer-lib.sh | 19 | # container - a bordered composer box, where the harness draws its own prompt | COMMENT |
| MEDIUM⚡ | bin/fm-composer-lib.sh | 27 | # depending on how its harness happens to colour the row. | COMMENT |
| MEDIUM⚡ | bin/fm-composer-lib.sh | 30 | # afk-herdr-false-pending): a harness fills an otherwise-empty composer with | COMMENT |
| MEDIUM | bin/fm-composer-lib.sh | 41 | # drift into per-harness one-off strips again; the previous herdr-only faint | COMMENT |
| MEDIUM | bin/fm-composer-lib.sh | 84 | # no fleet harness uses it for ghost text, so it is kept (real text wins: | COMMENT |
| MEDIUM | bin/fm-composer-lib.sh | 179 | # [idle_re] optional per-harness idle-placeholder regex (e.g. grok's | COMMENT |
| MEDIUM | bin/fm-composer-lib.sh | 207 | # Shell prompt glyph: empty ONLY inside a composer box (the harness's own | COMMENT |
| MEDIUM | bin/fm-vendor-auth-probe.sh | 5 | # This script collects a FACT and renders no verdict. It takes no harness, model, | COMMENT |
| MEDIUM | bin/fm-vendor-auth-probe.sh | 8 | # plus each harness's authoritative model catalog; the decision procedure is | COMMENT |
| MEDIUM | bin/fm-vendor-auth-probe.sh | 24 | # carries no harness, model, provider, credential-store, or provider-family | COMMENT |
| MEDIUM⚡ | bin/fm-supervise-daemon.sh | 560 | # harness's composer box borders, so an aligned ghost-only or idle bordered | COMMENT |
| MEDIUM⚡ | bin/fm-supervise-daemon.sh | 569 | # harness selects exactly one signature, so output from another harness cannot | COMMENT |
| MEDIUM⚡ | bin/fm-supervise-daemon.sh | 572 | # Resolved lazily and memoized: harness detection walks process ancestry, which | COMMENT |
| MEDIUM | bin/fm-supervise-daemon.sh | 132 | # harness's box borders before deciding, so a | COMMENT |
| MEDIUM | bin/fm-supervise-daemon.sh | 188 | # harness-verification discipline. Selecting one refuses loudly at startup | COMMENT |
| MEDIUM | bin/fm-supervise-daemon.sh | 207 | # Composer-empty detection, submit acknowledgement, and the harness-scoped | COMMENT |
| MEDIUM | bin/fm-supervise-daemon.sh | 764 | # or herdr or a captain-supplied command. This is the one injection point the test harness forces to a recorder | COMMENT |
| MEDIUM | bin/fm-supervise-daemon.sh | 1361 | # harness-verification discipline). This is the clear refusal the task calls | COMMENT |
| MEDIUM⚡ | bin/fm-pending-reply-lib.sh | 644 | # It stays harness-scoped (fm_busy_lines_match with the recorded harness, no | COMMENT |
| MEDIUM⚡ | bin/fm-pending-reply-lib.sh | 645 | # global OR of every vendor signature), so one harness's output cannot make | COMMENT |
| 438 more matches not shown… | ||||
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | .no-mistakes.yaml | 1 | # Per-repo no-mistakes overrides. | COMMENT |
| LOW | .no-mistakes.yaml | 21 | For changed prose, verify audience, authoritative owner, current relevance, | COMMENT |
| LOW | bin/fm-secondmate-registry-lib.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-gate-refuse-lib.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-gate-refuse-lib.sh | 21 | # 1. NO_MISTAKES_GATE set - the durable env marker no-mistakes stamps into every | COMMENT |
| LOW | bin/fm-gate-refuse-lib.sh | 41 | # must exercise the REAL fm-spawn/fm-send/fm-teardown, but the no-mistakes gate | COMMENT |
| LOW | bin/fm-remote-file.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-lint.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-lint.sh | 21 | # Explicit paths always bypass this file-set selection and lint exactly the | COMMENT |
| LOW | bin/fm-herdr-lab.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-ensure-agents-md.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-timing-lib.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-timing-lib.sh | 21 | # being measured run in bin/fm-bootstrap.sh and | COMMENT |
| LOW | bin/fm-afk-start.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-afk-start.sh | 21 | # background process differs by harness/backend and is owned elsewhere: | COMMENT |
| LOW | bin/fm-afk-start.sh | 41 | COMMENT | |
| LOW | bin/fm-backlog-handoff.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-backlog-handoff.sh | 21 | # active home, or the firstmate repo; | COMMENT |
| LOW | bin/fm-backlog-handoff.sh | 41 | # everywhere; the `config/backlog-backend=manual` knob only governs firstmate's | COMMENT |
| LOW | bin/fm-procevent-lavish.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-procevent-lavish.sh | 21 | # and restart recovery all belong to bin/fm-procevent.sh. | COMMENT |
| LOW | bin/fm-x-reply.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-x-reply.sh | 21 | # Optional --image <path> attaches one local image file to the answer or followup | COMMENT |
| LOW | bin/fm-x-reply.sh | 41 | # it exits non-zero so the caller knows the post did not land. The confirmed | COMMENT |
| LOW | bin/fm-x-reply.sh | 61 | # 9) rather than posting with a locally defaulted budget - firstmate holds and | COMMENT |
| LOW | bin/fm-config-push.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-project-mode.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-project-mode.sh | 21 | # direct-PR push + PR via gh-axi, no pipeline | COMMENT |
| LOW | bin/fm-remote-home-provision.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-procevent-remote-reply.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-procevent-remote-reply.sh | 21 | # canonical source id instead of the secondmate id and is called by the runner | COMMENT |
| LOW | bin/fm-x-lib.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-x-lib.sh | 21 | # no local inbox payload survives | COMMENT |
| LOW | bin/fm-x-lib.sh | 41 | # fmx_post_json <endpoint> <payload-file> [body-file] - POST JSON to the relay, | COMMENT |
| LOW | bin/fm-x-lib.sh | 361 | # context without using a local platform or budget default. | COMMENT |
| LOW | bin/fm-x-lib.sh | 401 | fi | COMMENT |
| LOW | bin/fm-x-lib.sh | 901 | # x_request=<request_id> the relay-issued id the follow-up posts against | COMMENT |
| LOW | bin/fm-tmux-lib.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-tmux-lib.sh | 21 | # idle pane as holding pending input and the daemon deferred injection / firstmate | COMMENT |
| LOW | bin/fm-tmux-lib.sh | 41 | # the Enter-retry budget is spent: a busy pane means the harness accepted and | COMMENT |
| LOW | bin/fm-tmux-lib.sh | 61 | # Composer-content classification (empty|pending|unknown, and the fleet-wide | COMMENT |
| LOW | bin/fm-tmux-lib.sh | 301 | fi | COMMENT |
| LOW | bin/fm-tmux-lib.sh | 381 | COMMENT | |
| LOW | bin/fm-claude-stop-autoarm.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-claude-stop-autoarm.sh | 21 | # - Need: arms only while work is in flight (state/*.meta) or X mode has a | COMMENT |
| LOW | bin/fm-claude-stop-autoarm.sh | 41 | # | COMMENT |
| LOW | bin/fm-cd-pretool-check.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-cd-pretool-check.sh | 21 | # extract the exact command string. | COMMENT |
| LOW | bin/fm-tasks-axi-lib.sh | 1 | # shellcheck shell=bash | COMMENT |
| LOW | bin/fm-tasks-axi-lib.sh | 21 | # | COMMENT |
| LOW | bin/fm-wake-lib.sh | 121 | # that - it decides whether to start, attach to, or replace a real watcher | COMMENT |
| LOW | bin/fm-transition-lib.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-transition-lib.sh | 21 | # and `pane.agent_status_changed` report. | COMMENT |
| LOW | bin/fm-transition-lib.sh | 61 | printf '%s' "$1" | cut -d"$FM_TRANSITION_FIELD_SEP" -f"$2" | COMMENT |
| LOW | bin/fm-transition-lib.sh | 81 | # (a crew resumed/started a turn) is the clearing edge. | COMMENT |
| LOW | bin/fm-lock-lib.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-x-followup.sh | 1 | #!/usr/bin/env bash | COMMENT |
| LOW | bin/fm-x-followup.sh | 21 | # fm-x-followup.sh --clear <task-id> | COMMENT |
| LOW | bin/fm-x-followup.sh | 41 | # recoverable rather than posting with a local default. | COMMENT |
| LOW | bin/fm-decision-hold.sh | 1 | #!/usr/bin/env bash | COMMENT |
| 470 more matches not shown… | ||||
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | bin/fm-supervise-daemon.sh | 1295 | # ============================================================================ | COMMENT |
| MEDIUM | bin/fm-supervise-daemon.sh | 1298 | # ============================================================================ | COMMENT |
| MEDIUM | bin/fm-busy-lib.sh | 260 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM⚡ | tests/fm-secondmate-harness.test.sh | 67 | # =========================================================================== | COMMENT |
| MEDIUM⚡ | tests/fm-secondmate-harness.test.sh | 69 | # =========================================================================== | COMMENT |
| MEDIUM⚡ | tests/fm-secondmate-harness.test.sh | 103 | # =========================================================================== | COMMENT |
| MEDIUM⚡ | tests/fm-secondmate-harness.test.sh | 105 | # =========================================================================== | COMMENT |
| MEDIUM⚡ | tests/fm-secondmate-harness.test.sh | 393 | # =========================================================================== | COMMENT |
| MEDIUM⚡ | tests/fm-secondmate-harness.test.sh | 396 | # =========================================================================== | COMMENT |
| MEDIUM⚡ | tests/fm-secondmate-harness.test.sh | 565 | # =========================================================================== | COMMENT |
| MEDIUM⚡ | tests/fm-secondmate-harness.test.sh | 568 | # =========================================================================== | COMMENT |
| MEDIUM⚡ | tests/fm-secondmate-harness.test.sh | 924 | # =========================================================================== | COMMENT |
| MEDIUM⚡ | tests/fm-secondmate-harness.test.sh | 928 | # =========================================================================== | COMMENT |
| MEDIUM | tests/fm-secondmate-harness.test.sh | 141 | # =========================================================================== | COMMENT |
| MEDIUM | tests/fm-secondmate-harness.test.sh | 143 | # =========================================================================== | COMMENT |
| MEDIUM | tests/fm-secondmate-harness.test.sh | 257 | # =========================================================================== | COMMENT |
| MEDIUM | tests/fm-secondmate-harness.test.sh | 259 | # =========================================================================== | COMMENT |
| MEDIUM | tests/fm-secondmate-harness.test.sh | 1609 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-secondmate-harness.test.sh | 1611 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-x-mode.test.sh | 128 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-afk-launch.test.sh | 43 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-afk-launch.test.sh | 45 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-afk-launch.test.sh | 121 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-afk-launch.test.sh | 124 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-afk-launch.test.sh | 150 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-afk-launch.test.sh | 153 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-afk-launch.test.sh | 825 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-afk-launch.test.sh | 827 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-afk-launch.test.sh | 886 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-afk-launch.test.sh | 889 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-crew-state.test.sh | 345 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-backend-herdr-presentation-e2e.test.sh | 936 | # ------------------------------------------------------------------ | COMMENT |
| MEDIUM | tests/fm-backend-herdr-presentation-e2e.test.sh | 939 | # ------------------------------------------------------------------ | COMMENT |
| MEDIUM | tests/fm-subagent-pretool-check.test.sh | 74 | # --------------------------------------------------------------------------- | COMMENT |
| MEDIUM | tests/fm-subagent-pretool-check.test.sh | 76 | # --------------------------------------------------------------------------- | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | bin/fm-remote-file.sh | 4 | # Usage: | COMMENT |
| LOW | bin/fm-lint.sh | 32 | # Usage: | COMMENT |
| LOW | bin/fm-herdr-lab.sh | 5 | # Usage: | COMMENT |
| LOW | bin/fm-procevent-lavish.sh | 4 | # Usage: | COMMENT |
| LOW | bin/fm-remote-home-provision.sh | 4 | # Usage: | COMMENT |
| LOW | bin/fm-procevent-remote-reply.sh | 4 | # Usage: | COMMENT |
| LOW | bin/fm-cd-pretool-check.sh | 15 | # Usage: | COMMENT |
| LOW | bin/fm-decision-hold.sh | 19 | # Usage: | COMMENT |
| LOW | bin/fm-install-shellcheck.sh | 4 | # Usage: | COMMENT |
| LOW | bin/fm-secondmate-report.sh | 10 | # Usage: | COMMENT |
| LOW | bin/fm-remote-inherit.sh | 4 | # Usage: | COMMENT |
| LOW | bin/fm-backlog-receive.sh | 4 | # Usage: | COMMENT |
| LOW | bin/fm-remote-secondmate-control.sh | 4 | # Usage: | COMMENT |
| LOW | bin/fm-public-followup-emit.sh | 15 | # Usage: | COMMENT |
| LOW | bin/fm-startup-memory-budget.sh | 3 | # Usage: | COMMENT |
| LOW⚡ | bin/fm-arm-pretool-check.sh | 13 | # Usage: | COMMENT |
| LOW | bin/fm-install-treehouse.sh | 9 | # Usage: | COMMENT |
| LOW | bin/fm-herdr-ci-cleanup.sh | 14 | # Usage: | COMMENT |
| LOW | bin/fm-remote-home-seed.sh | 4 | # Usage: | COMMENT |
| LOW | bin/fm-vendor-auth-probe.sh | 56 | # Usage: | COMMENT |
| LOW | bin/fm-afk-return.sh | 4 | # Usage: | COMMENT |
| LOW | bin/fm-test-isolation-proof.sh | 15 | # Usage: | COMMENT |
| LOW | bin/fm-on.sh | 4 | # Usage: | COMMENT |
| LOW | bin/fm-public-followup.sh | 27 | # Usage: | COMMENT |
| LOW | bin/fm-procevent.sh | 6 | # Usage: | COMMENT |
| LOW | bin/fm-install-herdr.sh | 8 | # Usage: | COMMENT |
| LOW | bin/fm-kimi-turnend-hook.sh | 15 | # Usage: | COMMENT |
| LOW | bin/fm-remote-doctor.sh | 4 | # Usage: | COMMENT |
| LOW | bin/fm-doc-audience-check.sh | 4 | # Usage: | COMMENT |
| LOW | bin/fm-remote-delta-read.sh | 4 | # Usage: | COMMENT |
| LOW | bin/fm-subagent-pretool-check.sh | 33 | # Usage: | COMMENT |
| LOW | bin/fm-afk-launch.sh | 22 | # Usage: | COMMENT |
| LOW | bin/fm-home-seed.sh | 4 | # Usage: | COMMENT |
| LOW | tests/remote-herdr-fixture.sh | 20 | # Usage: | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | .no-mistakes.yaml | 3 | # firstmate is an agent-orchestration repo: its AGENTS.md installs a fleet-captain | COMMENT |
| MEDIUM | bin/fm-backlog-handoff.sh | 547 | # Seed the destination with firstmate's standard three-section scaffold when it | COMMENT |
| MEDIUM | bin/fm-backlog-handoff.sh | 561 | # cleanup is a scaffold we just created. tasks-axi writes both its success and | COMMENT |
| MEDIUM | bin/fm-brief.sh | 27 | # The flag must be explicit because {TASK} is filled after scaffolding and the | COMMENT |
| MEDIUM | bin/fm-brief.sh | 48 | # Every scaffold's status protocol distinguishes the configured | COMMENT |
| MEDIUM | bin/fm-brief.sh | 140 | # missing or invalid value stops the scaffold rather than silently defaulting. | COMMENT |
| MEDIUM | bin/fm-brief.sh | 271 | # shellcheck disable=SC2016 # single quotes are deliberate: these lines are literal brief text whose backtick-wrapped $ | COMMENT |
| MEDIUM | bin/fm-brief.sh | 393 | When starting no-mistakes, make \`--intent\` preserve all relevant content from this brief's \`# Task\` section plus eve | CODE |
| MEDIUM | bin/fm-public-followup.sh | 36 | # public-followup add` + `bind-work`. This is the event-driven | COMMENT |
| MEDIUM | tests/fm-muse-harness.test.sh | 60 | # --- spawn scaffolding ------------------------------------------------------ | COMMENT |
| MEDIUM | tests/fm-brief.test.sh | 182 | # scaffold ignores the registered posture (test_ship_mode_is_explicit_not_registry). | COMMENT |
| MEDIUM | tests/fm-brief.test.sh | 221 | # unusable value must stop the scaffold instead of silently defaulting. The | COMMENT |
| MEDIUM | tests/fm-brief.test.sh | 248 | # scaffold must follow the explicit flag even when the project is registered | COMMENT |
| MEDIUM | tests/fm-brief.test.sh | 693 | # Scout and secondmate paths still scaffold well-formed briefs. | COMMENT |
| MEDIUM | tests/fm-backlog-handoff.test.sh | 164 | # in the standard three-section scaffold the handoff seeds for a fresh home. | COMMENT |
| MEDIUM | tests/fm-backlog-handoff.test.sh | 393 | # sub scaffold has In flight / Queued / Done | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| MEDIUM | bin/fm-afk-start.sh | 15 | # This file is sourceable: its BASH_SOURCE guard keeps main from running, while | COMMENT |
| MEDIUM | bin/fm-x-lib.sh | 9 | # This file is sourced, never executed. It defines: | COMMENT |
| MEDIUM | bin/fm-tasks-axi-lib.sh | 19 | # This file is the single owner of FM_TASKS_AXI_MIN. bin/fm-bootstrap.sh turns a | COMMENT |
| MEDIUM | bin/fm-primary-scope-lib.sh | 4 | # This file is sourced by hook entrypoints and has no side effects on source. | COMMENT |
| MEDIUM | bin/fm-operational-input.sh | 4 | # This file is both a source-safe shell library and the cross-language CLI used | COMMENT |
| MEDIUM | bin/fm-pending-reply-lib.sh | 231 | # Create a durable pending-reply expectation. Prints corr_id on success. | COMMENT |
| MEDIUM⚡ | bin/fm-session-lock-lib.sh | 9 | # This file is sourced by scripts and has no side effects on source. | COMMENT |
| MEDIUM | bin/fm-quota-axi-lib.sh | 8 | # This file is the single owner of that version number. bin/fm-bootstrap.sh | COMMENT |
| MEDIUM | tests/fm-afk-inject-e2e.test.sh | 154 | # Create a fake crewmate window (the watcher lists fm-* windows for stale | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | bin/fm-kimi-turnend-hook.sh | 201 | def validate_firstmate_files_for_remove() -> None: | STRING |
| LOW | bin/fm-bootstrap.sh | 1020 | def malformed_optional_fields($items): | CODE |
| LOW | .opencode/plugins/fm-primary-watch-arm.js | 238 | async function restoreAfterActionableClose(paths, sessionID, client, predecessorArmPid) { | CODE |
| LOW | .opencode/plugins/lib/fm-operational-input.js | 10 | export function encodeFirstmateOperationalInput(root, kind, content) { | CODE |
| LOW | tests/fm-backend-herdr-eventwait.test.py | 51 | def test_deadline_is_clean_timeout(self): | CODE |
| LOW | tests/fm-backend-herdr-eventwait.test.py | 62 | def test_peer_closure_is_runtime_failure(self): | CODE |
| LOW⚡ | tests/fm-backend-herdr-eventwait.test.py | 75 | def test_receive_error_is_runtime_failure(self): | CODE |
| LOW⚡ | tests/fm-backend-herdr-eventwait.test.py | 84 | def test_main_reports_early_stream_closure(self): | CODE |
| LOW⚡ | tests/fm-backend-herdr-eventwait.test.py | 93 | def test_main_does_not_signal_readiness_before_valid_ack(self): | CODE |
| LOW | .pi/extensions/fm-calm.ts | 113 | function installCalmPresentationAdapter(name: string, install: () => void): void { | CODE |
| LOW | .pi/extensions/fm-primary-pi-watch.ts | 294 | async function restoreAfterActionableClose(owner: SessionGeneration, predecessorArmPid: string): Promise<string> { | CODE |
| LOW | .pi/extensions/lib/fm-operational-input.ts | 21 | function runOperationalInputCommand( | CODE |
| LOW | .pi/extensions/lib/fm-operational-input.ts | 36 | export function encodeFirstmateOperationalInput( | CODE |
| LOW | .pi/extensions/lib/fm-operational-input.ts | 47 | export function classifyFirstmateOperationalText(content: string): string | undefined { | CODE |
| LOW | .pi/extensions/lib/fm-operational-input.ts | 51 | export function classifyFirstmateCurrentOperationalText( | CODE |
| LOW | .pi/extensions/lib/fm-calm-assistant-layout.ts | 27 | export function installCalmAssistantLayout(): void { | CODE |
| LOW | .pi/extensions/lib/fm-calm-operational-user-layout.ts | 62 | export function installCalmOperationalUserLayout(): void { | CODE |
| LOW | .pi/extensions/lib/fm-calm-working-ship.ts | 85 | export function createCalmWorkingShipAnimation(): CalmWorkingShipAnimation { | CODE |
| LOW | .pi/extensions/lib/fm-calm-working-ship.ts | 219 | export function createCalmWorkingShipWidget( | CODE |
| LOW | .pi/extensions/lib/fm-calm-visibility.ts | 66 | export function calmTranscriptClassIsVisible(itemClass: CalmTranscriptClass): boolean { | CODE |
| LOW | .pi/extensions/lib/fm-calm-visibility.ts | 74 | export function setCalmStockExportRendering(active: boolean): void { | CODE |
| LOW | .pi/extensions/lib/fm-calm-visibility.ts | 86 | export function registerFirstmateSyntheticPresentation(pi: ExtensionAPI): void { | CODE |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | bin/fm-bootstrap.sh | 94 | # Set FM_BOOTSTRAP_NETWORK to split this run by whether a step talks to | COMMENT |
| Severity | File | Line | Snippet | Context |
|---|---|---|---|---|
| LOW | bin/fm-kimi-turnend-hook.sh | 191 | except Exception: | STRING |