Skip to content
CAI
Software that uses CAICheck a score

jblanc86-maker/auditready-vulnfix-mr-agent

69.0

Adequate · 22 September 2026

1.3k

lines of production code

Python

primary language

6

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is an automated security remediation service that generates tamper-evident audit packets from SAST reports. It safely renders system prompts, enforces patch size limits, and uploads evidence to Google Cloud Storage for external audit trails.

Features

Introduce automated audit packet generation and GCS upload for security remediation

The scripts directory now includes a complete pipeline for automated security remediation evidence. A new Python script, build\_auditfix\_prompt.py, safely renders system prompts from untrusted context data, replacing previous shell-based substitution. A diff-size guard (diff\_guard.py/sh) enforces a 50-line patch limit to prevent over-patching. The auditfix\_make\_packet.py script generates tamper-evident audit packets containing verdicts and evidence links. Additionally, GCS upload capabilities are introduced via gcs\_upload.py and upload\_to\_gcs.py, allowing audit packets to be stored in Google Cloud Storage for external audit trails. Demo scripts (demo\_gcs.sh, demo\_local.sh, demo\_screencast.sh) and a SAST context builder (sast\_context\_builder.py) provide end-to-end validation of these new capabilities.

scripts · high confidence

Test coverage

Added tests for AuditFix pipeline components

Added comprehensive test coverage for the AuditFix pipeline, including the SAST context builder (parsing GitLab SAST reports, severity ranking, and identifier mapping), the prompt builder (template rendering and error handling), the diff-size guard (enforcing LLM patch limits), the packet maker (schema v0.1, signer block, and telemetry), and GCS upload functionality. A JSON fixture for GitLab SAST reports was also added to support these tests.

tests · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 70 → 69 (-1.3)
  • Rubric changed (rubric-2026.08.19 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 99 → 100 (+0.2)
  • Architecture 69 → 69 (+0.0)
  • Maturity 65 → 63 (-1.7)
  • Readiness 74 → 68 (-6.0)
  • Security 83 → 89 (+5.6)

Resolved (6)

  • Coverage not included — suite not readable by the collector
  • Dependency hygiene not measured — dependency manifest found but not parsed for hygiene
  • LLM evaluation failed
  • No exposed public API
  • Test reliability not included
  • single-maintainer — knowledge-concentration (bus factor) risk

New (5)

  • Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • No dependency advisory monitoring
  • Orphaned files with no living knowledge

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

jblanc86-maker/auditready-vulnfix-mr-agent was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 22 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 0e82fa1f6817e887fe7fc3c1b8119a6fe752cea9 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-821afab8930d.