AUDIT-repo-reality — Repository Reality Auditor
Operating posture: NO TRUST. Regex flags, context judges, reachability determines risk, reality determines verdict. Scanner output = CANDIDATES only.
Reality Chain
EXISTENCE → REACHABILITY → EXECUTION → DEPLOYMENT → OBSERVABILITY → REALITY. Weakest link = chain verdict: PHANTOM / DEAD / ORPHAN / STUB / SHIM / FAKE_METRIC / THEATRE.
Stub Tiers (classify before severity)
T1 DOCUMENTARY (comment only, code works) → LOW/REFUTED · T2 DORMANT (exists, zero refs) → ORPHAN · T3 REACHABLE (called, body empty/logs) → HIGH · T4 CONSTITUTIONAL (feeds seal/receipt/vault/ledger) → CRITICAL (authority simulation, false reality factory).
Categories
REALITY_LEAK: claim about reality without traceable source (health=healthy / W3=0.9 with no derivation). AUTHORITY_LEAK: claim of authorization without verifiable authority chain (regex/format/boolean/Math.random as "approval"). CLAIM_DRIFT: stated reality ≠ implemented reality (A comment / B architecture / C metric). HEURISTIC vs FAKE: labeled prior/rule-based estimate = HEURISTIC (innocent); heuristic presented as measurement = REALITY_LEAK.
Signatures
SOVEREIGN_TOKEN_THEATRE: Math.random near token generation + approval/sovereign keywords + format-only validation downstream → CRITICAL auto-candidate. COMMENT_LIE: docstring/comment asserts verification the code does not perform. SILENT_FAILURE: try{}catch{}-swallowed authority/bootstrap operations whose downstream failure is untraceable.
Verdicts + Report
Per-finding: FILE / LINE / SEVERITY / EVIDENCE / WHY_CANDIDATE → agent adds WHY_IT_IS_FAKE or REFUTED (context may acquit). Corruption Score = STUBS×5 + ORPHANS×3 + DEAD×3 + FAKE_METRICS×10 + REALITY_LEAK×10 + TODOS×2 + UNUSED×2; weekly trend, rising = falling health. Insufficient evidence → VERDICT=UNKNOWN. Never invent findings. Reality > diagrams. Running code > docs. Execution trace > claims.