{"generated_at":"2026-09-11T21:09:08Z","services":[{"slug":"a11y-quick","domain":"a11y-quick.0crawl.com","mesh":"0crawl","host_port":8272,"category":"domains","title":"A11y Quick","summary":"Microservice for A11y Quick","tags":["domains","go"],"health_url":"https://a11y-quick.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_a11y_quick","url":"https://a11y-quick.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"700-domain live audit (paired old/HEAD binaries against real fleet JS-render infra). Fixed a UTF-8 truncation bug corrupting non-Latin-script evidence text (verified on 2 real domains). Confirmed production is 3 commits stale with a known live false-negative. See github.com/baditaflorin/go_a11y_quick PR #7.","trl_ceiling":6,"trl_ceiling_reason":"Requires headless browser, DOM rendering","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"accessibility-audit","domain":"accessibility-audit.0crawl.com","mesh":"0crawl","host_port":18301,"category":"web_analysis","title":"Accessibility Audit","summary":"WCAG accessibility audit: a11y quick checks, accessibility score, color contrast ratio, image alt coverage, heading outline — 5 analyzers covering the main WCAG 2.x success criteria.","tags":["go","kind-container"],"health_url":"https://accessibility-audit.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_accessibility_audit","url":"https://accessibility-audit.0crawl.com","example":"/?target=stripe.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"5/5 OK on stripe.com; accessibility_score grade A+. Public at accessibility-audit.0crawl.com.","trl_ceiling":7,"trl_ceiling_reason":"Reaches TRL 7 with WCAG criterion-to-issue mapping.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"accessibility-score","domain":"accessibility-score.0crawl.com","mesh":"0crawl","host_port":8273,"category":"domains","title":"Accessibility Score","summary":"Microservice for Accessibility Score","tags":["domains","go"],"health_url":"https://accessibility-score.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_accessibility_score","url":"https://accessibility-score.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Incremental hardening fix, not a new capability -- the substantive TRL-7 case was already made in PR #2/#4/#5/#7 (real WCAG contrast math, honest indeterminate/unknown reporting, conditional JS-render for SPA shells). This pass adds full transient-retry coverage across every SSRF/fetch call site and removes a dead httpClient. Live-tested against a 60-domain random sample from production domain_accessibility rows (49/60 = 82% scored successfully, 11 genuine dead targets). See github.com/baditaflorin/go_accessibility_score PR #9.","trl_ceiling":8,"trl_ceiling_reason":"Reaches TRL 8 with WCAG 2.2 full corpus + CSS-derived contrast estimation.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"ad-density","domain":"ad-density.0crawl.com","mesh":"0crawl","host_port":8274,"category":"domains","title":"Ad Density","summary":"Microservice for Ad Density","tags":["domains","go"],"health_url":"https://ad-density.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_ad_density","url":"https://ad-density.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Confirmed honestly earned. Found and fixed a real production bug: domain-parking 'for sale' pages return HTML for every path including /ads.txt, and a permissive parser accepted raw HTML/JS as bogus ads.txt data -- 88% of a 400-domain flagged sample had zero real parsed records, 98.6% leaked raw HTML. Fixed with an IAB-directive allowlist + HTML-body rejection; 0/400 false positives after. TCFv2/CMP consent-detection ceiling condition independently re-verified as real. See github.com/baditaflorin/go_ad_density PR #11.","trl_ceiling":7,"trl_ceiling_reason":"Reaches TRL 7 with TCFv2 consent banner + sentinel-class detection.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"address-extractor","domain":"address-extractor.0crawl.com","mesh":"0crawl","host_port":8275,"category":"domains","title":"Address Extractor","summary":"Multi-locale address extractor with coherent component validation and localized schema.org evidence.","tags":["domains","go"],"health_url":"https://address-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_address_extractor","url":"https://address-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Cleared a stale trl_ceiling_reason (\"CPU-only tops at TRL 5\") that contradicted this record's own already-null trl_ceiling -- no technical basis for a TRL-5 ceiling; the service runs CPU-only at production scale (\u003e1M domain_address rows). This pass: mined domain_address (1,024,085 rows) and re-crawled 400 real business domains. Fixed a completeness bug (comma-required road/city separator dropped full addresses to bare STATE/ZIP fragments), a new false-positive it exposed (phone digits misread as house numbers), added unit/suite splitting and PO Box support. Held at trl:6 per this repo's own ADR 0001, which reserves TRL 7 for cross-checking against an authoritative postal dataset (not added here). See github.com/baditaflorin/go_address_extractor PR #8.","trl_ceiling":5,"trl_ceiling_reason":"Real multi-country address extraction needs libpostal trained data (~400MB) or per-country gazetteers at ~1 person-week each. CPU-only without them tops at TRL 5.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"admin-finder","domain":"admin-finder.0crawl.com","mesh":"0crawl","host_port":8335,"category":"recon","title":"Admin Finder","summary":"Microservice for Admin Finder","tags":["go","recon"],"health_url":"https://admin-finder.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_admin_finder","url":"https://admin-finder.0crawl.com","example":"/go_admin_finder?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"v1.6.0 — TRL 5→6 uplift.\n- Bundled curated wordlist (~150 paths from SecLists + OWASP CMS + vendor docs)\n  via go:embed; deduped, sorted, comment-stripped at parse time.\n- Per-probe: HEAD then GET fallback (for 405/400 and body sniffing on 2xx);\n  follows up to 2 manual redirects; per-request 3s, total 60s, worker pool 8.\n- Login-form sniffer (password / username / sign in / log in / type=password)\n  with strong-signal short-circuit (\"password\" alone) and 2-of-N rule.\n- First-hop Location preserved across follow chain so \"302 to /wp-admin/login\"\n  classifies as present even when the followed target is 404.\n- Optional ?wordlist_url= composes with sibling go-pentest-wordlists\n  (cap 500 entries, 256 KiB fetch budget, SSRF-safe via go-common/safehttp).\n- SCOPE_GUARD_URL env (comma list, supports *.example.com) gates which\n  hosts may be probed; off when unset.\n- Backward-compat: ?target= alias for ?url=.\n- Tests: handler_test.go + classify_test.go + wordlist_test.go;\n  httptest fake server covers 200-with-form / 302-to-login / 401 /\n  200-generic / 302-to-home / 404. `go test ./...` green.","trl_ceiling":6,"trl_ceiling_reason":"Authenticated admin discovery requires site-specific credentials or session state.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"analyze-headers","domain":"analyze-headers.0crawl.com","mesh":"0crawl","host_port":8081,"category":"domains","title":"Analyze Headers","summary":"Browser-facing security-header auditor with deterministic duplicate handling, HEAD/GET comparison, and edge attribution.","tags":["domains","go"],"health_url":"https://analyze-headers.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_analyze_headers","url":"https://analyze-headers.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Tested against domain_analyze_headers (1,023,840 rows) and a fresh 1,000-domain sample. Fixed: TLS certificate-verification failures returned an opaque 502 instead of a graded response (4.3% of live domains); 3xx redirect stubs graded as the final page causing false CSP-missing criticals (corpus FP rate 4%-\u003e0%). See github.com/baditaflorin/go_analyze_headers PR #5.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"api-extractor","domain":"api-extractor.0crawl.com","mesh":"0crawl","host_port":8336,"category":"recon","title":"Api Extractor","summary":"Microservice for Api Extractor","tags":["go","recon"],"health_url":"https://api-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_api_extractor","url":"https://api-extractor.0crawl.com","example":"/go_api_extractor?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"v1.4.5 extracts API-endpoint surface from HTML/JS via static scan + BaaS-host gazetteer + auth-scheme inference + evidence trail. Root-cause FP: primary fetch was pinned to fleetfetch.RenderJS, routing every request through the down-fleet-wide chromedp render-cache, so 502s masqueraded as status=1/zero-endpoints (61.3% zero-rate on 1000 v1.4.3 rows). Switched to RenderDefault + WithFallbackOnTimeout. On 40 originally-502-blocked domains: before 40/40 hard-502+zero, after 36/40 (90%) honest 200 (3 recovered real endpoints, 33 confirmed true-negatives); github/stripe/vercel went 502-\u003e200 with 3/90/12 endpoints. Tests: TestCapUTF8RuneSafe + TestHandlerNonLatinBodyExtraction.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"api-first","domain":"api-first.0crawl.com","mesh":"0crawl","host_port":8276,"category":"domains","title":"Api First","summary":"Scores domains 0-100 for API-first maturity: OpenAPI/GraphQL spec detection, versioned REST endpoint probing, developer portal/path detection, SDK scanning, evidence trail","tags":["domains","go"],"health_url":"https://api-first.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_api_first","url":"https://api-first.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh 55-domain sample): found and fixed a real fetch-cache-masking bug, live-proved to silently inflate a real zero-API-surface domain's score from 8 ('no_api') to a fabricated 86 ('api_available') via cache replay. trl_ceiling was previously unset; added ceiling=8 -- this is a heuristic HTTP-probe/regex detector with no JS rendering or ground-truth API registry, structurally capped below 9. See PR #12 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"apikey-scanner","domain":"apikey-scanner.0crawl.com","mesh":"0crawl","host_port":8230,"category":"security","title":"Apikey Scanner","summary":"Microservice for Apikey Scanner","tags":["go","security"],"health_url":"https://apikey-scanner.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_apikey_scanner","url":"https://apikey-scanner.0crawl.com","example":"/go_apikey_scanner?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Entropy-based + pattern-matched API key detection in HTML+JS.","trl_ceiling":7,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"asn-lookup","domain":"asn-lookup.0crawl.com","mesh":"0crawl","host_port":8337,"category":"recon","title":"Asn Lookup","summary":"Microservice for Asn Lookup","tags":["go","recon"],"health_url":"https://asn-lookup.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_asn_lookup","url":"https://asn-lookup.0crawl.com","example":"/go_asn_lookup?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Multi-resolver Team Cymru DNS client (1.1.1.1 + 8.8.8.8) via miekg/dns with parallel-fanout / first-non-empty-wins semantics; RDAP fallback via openrdap when Cymru is unreachable; per-IP 24h in-memory TTL cache; bulk endpoint with 10-worker pool, per-lookup 2s and total 30s caps; private/reserved IPs refused unless ALLOW_PRIVATE=1. TRL-7: hosting-attribution guard against CDN/WAF edge IP false positives (Cloudflare, Fastly, Akamai, Incapsula) flagged as hosting_attribution=cdn_fronted with CDN label and LOW confidence; hyperscaler ASNs (AWS/Google/Azure/Alibaba) marked cloud_ambiguous at MEDIUM confidence; honest error taxonomy (status=no_data / status=unreachable, never a service error); transient resolver failures retried once, deadline-bounded; /selftest exercises CDN-attribution guard offline; ≥25 hermetic test cases including CDN-fronted-vs-direct in both directions and full resolve-failure taxonomy. Fleet fetch-cache-opt-out audit (2026-08-08): confirmed the safehttp client's options slice (main.go, extracted into buildSafeHTTPOptions in the fix) omitted WithoutFetchCache()/WithForceHTTP2() -- same bug class as the 2026-07 go_page_load_metrics incident, whereby a client without either opt-out is silently eligible for the fleet-wide DefaultFetchDelegate and gets answered from cached bytes instead of a live origin fetch. Added both options plus a regression test (TestBuildSafeHTTPOptions_OptsOutOfFetchCache) verified to fail without the fix and pass with it. Live-verified against real RIPEStat/Cymru lookups (1.1.1.1, 8.8.8.8, AS13335) post-fix: correct ASN/org/country data returned. IMPORTANT caveat: this service's safeHTTP client is not currently wired into any live call path -- RIPEStat/RDAP/quorum calls all use separate plain http.Client instances (see main.go's pre-existing comment) -- so the fix has zero live blast-radius today; it is pre-work for when those call sites get rewired onto safeHTTP. Bumped 1.5.6-\u003e1.5.7. trl/trl_ceiling unchanged (fix doesn't affect current live behavior). See github.com/baditaflorin/go_asn_lookup PR #10 (open, not merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"biz-classifier","domain":"biz-classifier.0crawl.com","mesh":"0crawl","host_port":8277,"category":"domains","title":"Biz Classifier","summary":"Microservice for Biz Classifier","tags":["domains","go"],"health_url":"https://biz-classifier.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_biz_classifier","url":"https://biz-classifier.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh, disjoint 650-domain sample): confirmed genuinely differentiated from sibling go_google_taxonomy. Found and fixed 2 new false-friend/alias bugs: German 'Rezept' (medical prescription) misclassifying a real pharmacy as Food\u0026Beverage, and a generic 'technology'/'software' meta/nav-slug alias misclassifying a real measurement-instrument manufacturer as SaaS at high confidence. trl_ceiling was previously unset; added ceiling=8 -- keyword-frequency architecture has a structural ceiling (can't distinguish 'is X' from 'serves/reports on X') requiring semantic understanding to clear toward 9. See PR #14 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"blocklist-checker","domain":"blocklist-checker.0crawl.com","mesh":"0crawl","host_port":8338,"category":"recon","title":"Blocklist Checker","summary":"Microservice for Blocklist Checker","tags":["go","recon"],"health_url":"https://blocklist-checker.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_blocklist_checker","url":"https://blocklist-checker.0crawl.com","example":"/go_blocklist_checker?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"~30 curated DNSBL/RBL/URIBL zones across spam, phishing, malware,\ntor, and open-proxy categories. Per-list 127.0.0.x return-code\ndecode tables (operator-sourced). Concurrent worker-pool fan-out\n(10) using miekg/dns directly so we distinguish NXDOMAIN /\nSERVFAIL / \"got 127.0.0.x\". In-process miekg/dns test server with\n≥10 cases (clean, listed, multi-listed, domain-list, ipv6, private\nIP refusal, ?lists= filter). Reputation score is explainable\n(per-list weight + per-category bonus, capped at 100). See\ndocs/adr/0001-trl-uplift-to-6.md.","trl_ceiling":5,"trl_ceiling_reason":"Without continuous feed mirroring, this is 80% external-data dependency. Real upgrade is a feed-sync daemon, not algorithm work.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"brand-color-palette","domain":"brand-color-palette.0crawl.com","mesh":"0crawl","host_port":18288,"category":"content","title":"Brand Color Palette","summary":"Extract a brand colour palette (hex + role) from a site's CSS custom properties, theme-color meta, and logo pixels via k-means","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://brand-color-palette.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_brand_color_palette","url":"https://brand-color-palette.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (fresh 220-domain sample): found and fixed 2 real bugs -- (1) role-keyword substring collision (\"ink\" matching inside \"pink\"/\"link\", \"main\" inside \"domain\") misclassified WordPress's stock pink swatch as the primary text-role color on 46/220 (20.9%) of domains, silently evicting the real brand color; (2) fetch-cache masking on the logo-image fetch. Both fixed and live-confirmed (46-\u003e0 false pairs). trl lowered 7-\u003e6 to reflect real gaps found; trl_ceiling=7 added (no ground-truth registry for 'brand color', no JS rendering -- ~50% empty-palette rate on a random sample is a structural limit, not a bug). See PR #3 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"brand-logo-extractor","domain":"brand-logo-extractor.0crawl.com","mesh":"0crawl","host_port":18287,"category":"content","title":"Brand Logo Extractor","summary":"Resolve a website's primary brand logo URL, dimensions, format and provenance (header DOM + schema.org + web-app-manifest + og:image)","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://brand-logo-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_brand_logo_extractor","url":"https://brand-logo-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (fresh 300-domain sample): found and fixed 3 real bugs -- a substring class-match false positive letting unrelated body content (GitHub/Wix compound utility classes) outrank the real logo; a regression its own first fix introduced against Elementor's header convention (caught live, corrected in the same pass); and descriptive alt-text alone being sufficient to misidentify unrelated images as logos. Net: 9/300 domains corrected, 0 regressions. Also fixed fetch-cache masking on the image-validation fetch. Known gap: inline-SVG logos (e.g. github.com) are structurally invisible to this img/schema/manifest/og method. trl lowered 7-\u003e6, trl_ceiling=7 added. See PR #3 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"broken-links","domain":"broken-links.0crawl.com","mesh":"0crawl","host_port":8192,"category":"web_analysis","title":"Broken Links","summary":"Microservice for Broken Links","tags":["go","web-analysis"],"health_url":"https://broken-links.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_broken_links","url":"https://broken-links.0crawl.com","example":"/go_broken_links?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"900-domain live audit against the actual scan pipeline. Fixed 4 real bugs: an SSRF gap where the HEAD probe bypassed the fetch-cache's SSRF-safe path entirely; soft-404 false positives from truncated-length collisions on bodies \u003e64KiB (one domain: 100/100 links misclassified); mailto:/tel: redirects misclassified as broken; malformed href resolution. broken_count -51.0%, soft_404 -81.8%, unknown -75.0% across ~23.5K checked links. See github.com/baditaflorin/go_broken_links PR #10.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"bucket-finder","domain":"bucket-finder.0crawl.com","mesh":"0crawl","host_port":8339,"category":"recon","title":"Bucket Finder","summary":"Microservice for Bucket Finder","tags":["go","recon"],"health_url":"https://bucket-finder.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_bucket_finder","url":"https://bucket-finder.0crawl.com","example":"/go_bucket_finder?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"v1.4.0 adds permutation-based discovery (?name=acme): generates a\nbounded candidate set (≤200) from base + corp/inc + role suffixes\n(backup, prod, staging, assets, internal, …), probes every candidate\nacross AWS S3 (vhost + path), GCS (vhost + path), Azure Blob/File,\nand DigitalOcean Spaces (5 regions) in parallel via a 16-worker pool\nwith a 4s per-probe and 90s total budget. Per-provider response\nclassification distinguishes listable / exists / denied / not_exists\n(via NoSuchBucket vs AccessDenied / Azure AuthenticationFailed) and\nattaches sample object keys + counts when a ListBucketResult or\nEnumerationResults body is present. Optional WORDLISTS_URL extension\nhook for go-pentest-wordlists. Test coverage: permute_test.go (8\ncases), detect_test.go (12 cases), handler_test.go (httptest server\nwith canned XML returning listable/denied/NoSuchBucket/404). Backward\ncompatibility preserved for the legacy ?url= page-scan path. Pure Go,\nCGO-free, SSRF-safe via go-common/safehttp. ADR:\ndocs/adr/0001-trl-uplift-to-6.md.\n\n2026-08-20 audit (claude-sonnet-5-trl-audit-2026-08-20): fresh clone of origin/main (ebdd85c) reviewed end-to-end. Confirmed two real, live-verified bugs, both fixed in PR https://github.com/baditaflorin/go_bucket_finder/pull/10 (open, not merged):\n(1) fetch-cache staleness: fetchClient/probeClient in fetch.go were bare safehttp.NewClient() calls with no .WithoutFetchCache(), so once FLEET_FETCH_CACHE_URL is set (fleet-wide since go-common@v0.88.0), every probe GET is eligible for DefaultFetchDelegate and can be served a stale cached response instead of the live origin state -- directly undermining this tool's core promise of reporting CURRENT bucket exposure. This is the documented 'live probe semantics where freshness \u003c cache TTL matters' case go-common/fleetfetch's own doc comment says must not use the cache.\n(2) false-positive classification: verified live against real AWS S3, GCS, DO Spaces, Wasabi, Linode, Vultr, and Backblaze B2 endpoints with curl. Backblaze B2's S3-compatible API (\u003cname\u003e.s3.\u003cregion\u003e.backblazeb2.com) returns an identical 403 'Unauthenticated requests are not allowed for this api' for every bucket name -- real, nonexistent, public, or private alike -- so the legacy ?url= page-scan path's bespoke status-code-only classifier (any 403 -\u003e exists_not_listable, any 200 -\u003e public_accessible, no body inspection) reported a false 'bucket exists' finding for every Backblaze reference and every generic 200 fallback page detected in a scanned page. Fixed by having that path reuse the already-tested, evidence-based classifyResponse from the ?name= permutation path, plus a new Backblaze-specific non-signal branch. Two regression tests added (fail on pre-fix code, pass after, confirmed via git stash bisection).\nAll other providers (AWS S3 vhost+path, GCS vhost+path, Azure Blob/File, DO Spaces x5 regions, Wasabi, Linode, Vultr) verified live to behave exactly as the existing classifier expects (404 NoSuchBucket for nonexistent, 200+ListBucketResult for public-listable). TRL left at 6: the permutation-probing architecture and provider matrix work as claimed once these two bugs are patched; PR #10 is the pending fix, not yet on main.","trl_ceiling":5,"trl_ceiling_reason":"Enumeration (proving bucket exists, listing contents) requires paid threat intel, leaked wordlists, or HackerOne project data.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"caa-checker","domain":"caa-checker.0crawl.com","mesh":"0crawl","host_port":8325,"category":"infrastructure","title":"Caa Checker","summary":"Microservice for Caa Checker","tags":["go","infrastructure"],"health_url":"https://caa-checker.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_caa_checker","url":"https://caa-checker.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":8,"trl_evidence":"Fresh-clone audit (go_caa_checker@v1.4.7, go-common@v0.88.0, tip df43b5d). Fetch-cache bug class N/A: service does raw DNS via miekg/dns over UDP/TCP straight to 1.1.1.1/8.8.8.8/9.9.9.9, confirmed zero safehttp/outbound-net-http usage in non-vendor code -- no HTTP fetch path exists to be cached. Live cross-checked RFC 8659 CAA resolution vs dig ground truth on 2026-08-20 for 6 cases, all exact matches: google.com (issue=pki.goog, records/restricted), wikipedia.org (issue=letsencrypt.org+pki.goog), github.com (issue+issuewild across digicert/globalsign/letsencrypt/sectigo, restricted), example.com (climbs example.com-\u003ecom, correctly no_caa not misreported as error), www.reddit.com (4-hop CNAME chain reddit.map.fastly.net-\u003emap.fastly.net-\u003efastly.net, CAA correctly resolved at fastly.net apex per RFC 8659 CNAME-then-climb order), nonexistent domain (nxdomain, correctly not conflated with no_caa). No correctness bug found -- prior hardening (PR#3 TRL3 taxonomy, PR#4 meshresult honesty, PR#5 malformed-issuer sanitization, PR#9 CNAME-before-parent fix, merged through 2026-08-13) already covers the RFC edge cases. No code changes made this pass. TRL raised 7-\u003e8: real cross-checks against live DNS ground truth performed, comprehensive existing test coverage (dns_test.go/handler_test.go/trl3_test.go + live-network /selftest), SLA-grade evidence trail.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"captcha-detector","domain":"captcha-detector.0crawl.com","mesh":"0crawl","host_port":8209,"category":"web_analysis","title":"Captcha Detector","summary":"Microservice for Captcha Detector","tags":["go","web-analysis"],"health_url":"https://captcha-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_captcha_detector","url":"https://captcha-detector.0crawl.com","example":"/go_captcha_detector?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Sitekey extraction, provider fingerprinting across reCAPTCHA v2/v3/hCaptcha/Turnstile/etc.","trl_ceiling":7,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"cas","domain":"cas.0crawl.com","mesh":"0crawl","host_port":8279,"category":"domains","title":"Cas","summary":"Microservice for Cas","tags":["domains","go"],"health_url":"https://cas.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_cas","url":"https://cas.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Re-validated the x/net/html parser + CTA lexicon (PR #2-#4, merged 2026-06-01) against 900 real domains sampled via TABLESAMPLE from the production `domains` table (11.9M rows). No persisted go_cas results table exists in production. Found and fixed 3 real bug classes: (1) duplicated CTA text from SVG \u003ctitle\u003e tooltips and hover-swap \u003cspan\u003e duplicates concatenating verbatim; (2) English-only kind-signal lists caused 327 real multilingual e-commerce CTAs to be extracted but misclassified as \"generic\" (DE/ES/FR/IT phrases added); (3) Japanese CTA-verb blindness caused false zero-CTA verdicts on real small-business pages (fixed with a Japanese + Russian/Ukrainian CTA-verb table). On a clean re-crawl of 623 domains with substantive content in both runs: zero-CTA rate improved 10.3%-\u003e9.1% (7 genuine new detections, 0 regressions); duplicated-text CTAs 22-\u003e0; multilingual misclassification 327-\u003e0. 11 new tests added reproducing real failure modes; 34 total tests pass. See github.com/baditaflorin/go_cas PR #5 for full writeup.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"cdn-detector","domain":"cdn-detector.0crawl.com","mesh":"0crawl","host_port":8326,"category":"infrastructure","title":"Cdn Detector","summary":"Microservice for Cdn Detector","tags":["go","infrastructure"],"health_url":"https://cdn-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_cdn_detector","url":"https://cdn-detector.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":8,"trl_evidence":"Re-audited 2026-08-20 on a fresh clone at go_cdn_detector@535f4f3 (go-common@v0.88.0 tip). Confirmed the fleet-wide bare-safehttp.NewClient()/DefaultFetchDelegate stale-cache footgun does NOT apply here: fetch.go uses fleetfetch.NewHTTPClient (WithRender(RenderDefault)+WithFallbackOnTimeout), a distinct, deliberately-cached client whose own fallback path already calls safehttp.WithoutFetchCache() internally (go-common fleetfetch/client.go:271, hardened further in go-common v0.86.0's fallback-recursion fix) -- not the bare-client mis-route pattern. Cache freshness is surfaced, not hidden: every response carries a fetch.render_mode/cache_hit/age_seconds/via_fallback provenance block (fetch.go FetchProvenance) so a stale-cache hit is visible to the caller rather than silently misreported as live. Live-curl-verified (2026-08-20, --max-time 6-8s) header-fingerprint accuracy against real current CDN edges: cloudflare.com (cf-ray), vercel.com (x-vercel-id/x-vercel-cache), netlify.com (x-nf-request-id), bunny.net (cdn-pullzone/cdn-cachedat), and fastly.com/github.io/azure.microsoft.com via the x-served-by cache- prefix rule (fastly.com's Server: 'Artisanal bits' deliberately does not match the server-substring rule, correctly falling through to the x-served-by signal) -- all matched the code's headerRules table with no misattribution observed. go build + go test ./... green on go1.26.5 (9.8s, all pass), no code change required. TRL 8 self-assessment stands: the false-positive corroboration gate (correlate.go), DNS label-boundary fix, and cache/timeout-doubling fixes from prior sessions are all still in place and covered by regression tests plus a /selftest liveness check pinning the FP guard.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"citation-reference-extractor","domain":"citation-reference-extractor.0crawl.com","mesh":"0crawl","host_port":18263,"category":"content","title":"Citation Reference Extractor","summary":"Extract academic and web citations from a page or raw HTML/text — \u003ccite\u003e elements, reference/bibliography list items, footnote/endnote targets, and structured identifiers (DOI, arXiv ids, checksum-validated ISBN-10/13, PMID, and reference-context URLs), normalised into typed citation objects with a by-type summary.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://citation-reference-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_citation_reference_extractor","url":"https://citation-reference-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Real DOM walk over a fetched/pasted page (golang.org/x/net/html tokenizer, no regex over HTML structure): prunes script/style/noscript/svg/template/head/iframe subtrees, then runs four ordered passes — (1) reference/bibliography list items: \u003col\u003e/\u003cul\u003e \u003cli\u003e contents inside a section whose heading text or container id/class matches a reference token (references / bibliography / works cited / literature cited / further reading); (2) every \u003ccite\u003e element's text; (3) footnote/endnote \u003cli\u003e targets keyed by id prefix (fn / footnote / endnote / note / cite_note / ref-) with the trailing number lifted into a marker; (4) an inline sweep for structured identifiers in running prose not already captured. Each citation's raw text is matched for identifiers with anchored regexes (pattern-matching within text, not HTML parsing): DOI (10.\u003c4-9 digits\u003e/\u003csuffix\u003e), arXiv new (NNNN.NNNNN[vN]) and old (archive.subclass/NNNNNNN) schemes normalised to arXiv:\u003cid\u003e, PMID (label-required), http/https URLs (DOI-resolver and arXiv URLs de-duplicated against their id forms), and ISBN-10/ISBN-13 validated by their mod-11 / mod-10 checksums (labelled and bare 978/979 forms; checksum-failing candidates dropped). Output is a typed citation list (raw text + detected type + extracted identifiers) plus a by-type + by-identifier summary. Input fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so many producers scanning the same URL trigger one upstream fetch; plain-HTML render mode; 4 MiB body cap. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode scans pasted content with no fetch. Per-failure notes pushed to a non-nil degraded[] (no_references, fetch_failed:\u003cerr\u003e) instead of failing the response. ~30 unit + handler tests cover DOI extraction, both arXiv id forms, ISBN-10 and ISBN-13 valid + invalid checksums, PMID, \u003ccite\u003e extraction, reference-list detection by heading and by container id/class, URL-in-reference extraction, footnote markers, type classification, summary counts, parse-input aliases, missing-param 400, SSRF rejection, no-references→degraded, and text= mode. TRL-4 ceiling: heuristic section detection (no full CSL / citation-style parsing, no author/title/year field decomposition), English-centric reference-section headings, and no DOI/ISBN registry resolution (checksum validity only, not 'this identifier exists'). /selftest exercises the pure-logic pipeline (DOI/arXiv parse, ISBN checksum, reference-list + \u003ccite\u003e DOM detection, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"clickjacking-tester","domain":"clickjacking-tester.0crawl.com","mesh":"0crawl","host_port":8225,"category":"security","title":"Clickjacking Tester","summary":"Microservice for Clickjacking Tester","tags":["go","security"],"health_url":"https://clickjacking-tester.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_clickjacking_tester","url":"https://clickjacking-tester.0crawl.com","example":"/go_clickjacking_tester?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"2026-08-20 audit against a fresh clone of origin/main (8a30ace): found and live-confirmed a real HTML-escaping bug in buildFrameTestHTML() (handler.go), the builder for the frame_test_html field returned by ?probe_frame=1 -- README documents this HTML as meant to be opened directly in a browser 'for analyst-side browser verification only'. The function escaped only '\"' (strings.ReplaceAll) before splicing the caller-supplied target into both an HTML text-content position (\u003ch3\u003e) and an HTML attribute position (iframe src). net/url's Parse/String round-trip does NOT percent-encode '\u003c', '\u003e', or '\"' in the query/fragment components (verified directly: url.Parse+String on `https://example.com/?q=x\"\u003e\u003cscript\u003e...` round-trips those bytes unchanged), so a target of https://example.com/?q=x\"\u003e\u003cscript\u003ealert(document.domain)\u003c/script\u003e survived into frame_test_html as a live, executable \u003cscript\u003e tag rather than inert text. Live-reproduced end-to-end: built the binary, ran it, and hit /?api_key=default_token\u0026target=\u003cpayload\u003e\u0026probe_frame=1 -- the service fetched real https://example.com and returned the unescaped \u003cscript\u003e verbatim in the JSON response body. This is a genuine XSS/script-injection bug in the tool's own analyst-facing report output, for a tool whose entire purpose is safely reporting on other sites' clickjacking exposure. Fixed via html.EscapeString (safe in both the text-content and quoted-attribute positions the target is spliced into) in PR https://github.com/baditaflorin/go_clickjacking_tester/pull/13 (open, NOT merged as of this audit) with a regression test (TestBuildFrameTestHTMLEscapesTarget) verified to fail pre-fix and pass post-fix; version bumped 1.3.3-\u003e1.3.4 in that PR. Separately checked the fleet's recurring safehttp.NewClient()-without-.WithoutFetchCache() bug class: not applicable here -- this repo has no direct safehttp import; it fetches exclusively via fleetfetch.NewClient() (go-common's higher-level client, intentionally designed to route through the shared 60s-TTL fetch cache with singleflight dedup, falling back to an SSRF-safe direct fetch on cache failure), which is the intended architecture, not an instance of the bug class. Core clickjacking-detection logic (XFO/CSP frame-ancestors parsing, meta-tag-is-not-enforcement handling, framebust-JS heuristic, final-response HTTPS/HTML gating) was untouched by this pass and is unaffected by the bug above -- it lives entirely in the optional analyst-verification helper. TRL held at 6/6: the core detection technology's readiness is unchanged, and the fix (once merged) closes the one concrete correctness/security gap found, but the ceiling reason (no real browser rendering for unusual CSP/sandbox cases) still stands independently of this finding.","trl_ceiling":6,"trl_ceiling_reason":"Browser-level frame behavior needs real rendering for unusual CSP/sandbox cases.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"cognitive-load","domain":"cognitive-load.0crawl.com","mesh":"0crawl","host_port":8280,"category":"domains","title":"Cognitive Load","summary":"Microservice for Cognitive Load","tags":["domains","go"],"health_url":"https://cognitive-load.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_cognitive_load","url":"https://cognitive-load.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Re-earned with new, independently-verified evidence: the previous registry trl=7 rested solely on an unrelated v1.6.0 DOM chrome-exclusion fix and predated the readability-engine bugs found and fixed here (sentence-boundary blindness + non-Latin-script mis-scoring). See github.com/baditaflorin/go_cognitive_load PR #7.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"color-contrast-checker","domain":"color-contrast-checker.0crawl.com","mesh":"0crawl","host_port":18261,"category":"content","title":"Color Contrast Checker","summary":"WCAG 2.x color-contrast checker for a web page or raw HTML — resolves declared foreground/background color pairs (inline style= and \u003cstyle\u003e-block rules), computes the relative-luminance contrast ratio for each, and reports AA/AAA pass/fail for normal and large text plus a failing-pairs summary.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://color-contrast-checker.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_color_contrast_checker","url":"https://color-contrast-checker.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Real WCAG 2.x contrast engine over a golang.org/x/net/html DOM walk (no regex over HTML structure): collects foreground/background color declarations from (1) inline style= attributes and (2) \u003cstyle\u003e-block CSS rules parsed by a small brace-matching tokenizer that strips /* */ comments and flattens one level of @media/@supports nesting. Colors are resolved by a curated ~148-entry CSS named-color map plus #rgb/#rrggbb (and #rgba/#rrggbbaa alpha-drop) hex and rgb()/rgba() functional notation (comma or space/slash separated, integer or percentage channels, alpha parsed-then-dropped). For each resolved fg+bg pair it computes the exact sRGB relative luminance (channel/255, piecewise \u003c=0.03928 ? /12.92 : ((c+0.055)/1.055)^2.4; L = 0.2126R+0.7152G+0.0722B) and the contrast ratio (L_lighter+0.05)/(L_darker+0.05) — verified against the canonical black-on-white = 21.0 and white-on-white = 1.0. Verdicts use \u003e= thresholds at the WCAG boundaries: AA normal 4.5, AAA normal 7, AA large 3, AAA large 4.5. Output is de-duplicated, sorted worst-ratio-first, with a summary (total pairs, # failing AA normal, skipped/unparseable color count, min ratio). Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so N producers checking the same URL trigger one upstream fetch; plain-HTML render mode. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode scores pasted HTML with no fetch. Per-failure notes pushed to a non-nil degraded[] (fetch_failed, no_color_pairs, unparseable_colors_skipped:\u003cn\u003e) instead of failing the response. Documented TRL-4 ceiling: it scores only directly-declared color pairs on the same element/rule — NO computed-style cascade, inheritance, or specificity resolution, so it does not reconstruct the fg/bg a browser would actually composite; no JS-applied styles; no opacity/alpha compositing; CSS variables, gradients, currentColor, and hsl() are reported as skipped rather than guessed. ~40 table-driven unit + handler tests cover luminance of black/white/mid-gray, the 21.0 and 1.0 anchor ratios, hex (#fff/#ffffff) and rgb()/rgba() parsing, named-color resolution, inline-style and \u003cstyle\u003e-block pair extraction, AA/AAA verdicts at the boundaries, missing-param 400, SSRF rejection (handler + parseInput), and degraded[] population on a no-colors page. /selftest exercises the pure-logic pipeline (luminance/ratio anchors, parsing, inline + stylesheet extraction, threshold verdicts, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"comment-extractor","domain":"comment-extractor.0crawl.com","mesh":"0crawl","host_port":8340,"category":"recon","title":"Comment Extractor","summary":"Microservice for Comment Extractor","tags":["go","recon"],"health_url":"https://comment-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_comment_extractor","url":"https://comment-extractor.0crawl.com","example":"/go_comment_extractor?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh 260-domain sample, 217 successful real fetches, ~9,500 comments extracted): confirmed fetch-cache masking does not apply (uses fleetfetch with cache/render provenance surfaced to callers) and confirmed HTML5-spec-correct tokenizer behavior on IE-conditional-comment/nested-comment/CDATA edge cases (not bugs). Found and fixed a real finding-suppression bug: isBoilerplate()'s escape hatch only re-checked raw text for a bare TODO/FIXME/RFC1918 IP, never the severity ClassifyComment had already computed -- so a genuine credential leak wrapped in JSDoc/license-shaped comment text was correctly classified credential_leak/high internally but then silently dropped from interesting_comments, the exact field the fleet's leak-bounty-policy/findings-store integrations key off. Fixed by trusting the already-computed severity. trl bumped 6-\u003e7; trl_ceiling held at 7 -- direct-fetch-only design (RenderJS deliberately reverted due to fleet-wide proxy degradation) is a real structural ceiling for a passive recon tool. See PR #7 (merged).","trl_ceiling":7,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"company-size","domain":"company-size.0crawl.com","mesh":"0crawl","host_port":8281,"category":"domains","title":"Company Size","summary":"Microservice for Company Size","tags":["domains","go"],"health_url":"https://company-size.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_company_size","url":"https://company-size.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Confirmed honestly earned on the core band-fusion engine (400-domain live audit, no false-positive/negative patterns beyond documented guards). Found a significant gap: sibling-service composition (go_team_size/go_founding_year, the ADR's claimed 'primary source of truth') has been completely broken in production for 2.5 months -- 4 compounding bugs (missing env vars, no auth, wrong envelope format, field type mismatch), proven by employees_source='team-size-compose' recording zero hits across ~725k rows. Fixed and verified live against the real deployed sibling containers. See github.com/baditaflorin/go_company_size PR #20.","trl_ceiling":7,"trl_ceiling_reason":"Authoritative headcount needs a paid data provider (LinkedIn / Clearbit / Crunchbase). CPU-only static-HTML inference plateaus at principled multi-signal banding with confidence -- it cannot certify an exact employee count.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"compression-tester","domain":"compression-tester.0crawl.com","mesh":"0crawl","host_port":8327,"category":"infrastructure","title":"Compression Tester","summary":"Microservice for Compression Tester","tags":["go","infrastructure"],"health_url":"https://compression-tester.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_compression_tester","url":"https://compression-tester.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Pass-3 found the prior probe client used fleetfetch.NewHTTPClient(RenderDefault), which despite its name routes every GET through the shared Redis fetch-cache, silently ignoring Transport.DisableCompression and collapsing the five independent Accept-Encoding negotiations into one warm cached body. On 1000 real v1.6.1 rows this produced 344/1000 (34%) recording supports_gzip=false while supports_br=true (implausible; gzip is the universal fallback). Replaced with a direct *http.Transport using safehttp.GuardedDialer (same SSRF/DNS-rebind guard, no new dep) + DisableCompression=true + ProxyFromEnvironment, so each offer and the raw wire bytes reach the origin. Re-probed the FP cohort live against deployed v1.6.2: 18/20 (90%) now correctly report gzip honored, 2 are genuine true negatives. 27 unit tests green.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"consent-simulator","domain":"consent-simulator.0crawl.com","mesh":"0crawl","host_port":18208,"category":"domains","title":"Consent Simulator","summary":"Active consent-reject simulation: clicks a page's cookie-reject control in a real browser and checks whether trackers keep firing","tags":["domains","go"],"health_url":"https://consent-simulator.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_consent_simulator","url":"https://consent-simulator.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":4,"trl_evidence":"First ship + first real batch test 2026-08-24 (109 diverse EU domains, not the original Austria-gambling sample). Reject/accept control classification now covers EN/DE/FR/IT/ES/NL/PL/PT/SV/DA/FI canonical phrasing plus a handful of named CMP vendor ids; no vendor-specific CSS-selector table beyond that. Tracker signature list is a small set of ~20 major vendors, not a full tracker-radar dataset. Single page load, single interaction only. Known gap: Didomi-fronted sites (orf.at, kurier.at, nrc.nl confirmed) did not render their consent banner in this hosting environment even after 25s wait -- see README Scope and limitations. proxy_read_timeout raised 120s-\u003e200s to match the service-side timeout increase (serverWriteTimeout now 175s).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"content-fingerprint","domain":"content-fingerprint.0crawl.com","mesh":"0crawl","host_port":18265,"category":"content","title":"Content Fingerprint","summary":"Near-duplicate-detection fingerprints for a web page or raw text — a 64-bit Charikar SimHash over k-gram word shingles, a 64-permutation MinHash signature for Jaccard estimation, and a normalized SHA-256 exact-match digest, plus shingle and token counts.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://content-fingerprint.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_content_fingerprint","url":"https://content-fingerprint.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Near-duplicate fingerprinting over a real HTML text extractor (golang.org/x/net/html tokenizer, no regex): prunes script/style/noscript/svg/template/head/iframe subtrees, prefers the first \u003carticle\u003e/\u003cmain\u003e region then falls back to \u003cbody\u003e, collapses whitespace and inserts block-element boundaries so words aren't glued. Computes three standard fingerprints over the normalized lowercased text: a 64-bit Charikar SimHash over k=3 word shingles (FNV-64a per shingle, +1/-1 column sums, sign bit) — near-identical documents have a small Hamming distance, unrelated documents ~half the bits; a 64-permutation MinHash signature (universal-hash multiply-xor scramble with a splitmix64 avalanche per permutation, min per permutation) whose matching-fraction estimates Jaccard similarity (identical sets 1.0, disjoint ~0 within ~12% sampling error); and a whitespace-collapsed, lowercased SHA-256 hex exact-match digest. Shingle and token counts are returned alongside. A hammingDistanceHex helper documents how to compare two SimHash values. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so 20 producers fingerprinting the same URL trigger one upstream fetch; plain-HTML render mode. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode fingerprints pasted content with no fetch. Per-failure notes pushed to degraded[] (fetch_failed, no_extractable_text, low_sample:\u003cn\u003e_tokens) instead of failing the response; \u003c20-token inputs flagged as statistically unstable. ~30 unit tests cover SimHash determinism/case-insensitivity/empty, near-duplicate small-Hamming stability and unrelated large-Hamming divergence, the Hamming helper, MinHash signature length/determinism, Jaccard identical=1.0/disjoint~0/similarity-ordering/mismatched-length, normalized SHA-256 exact match plus case/whitespace insensitivity and content-change sensitivity, shingle generation at the k boundary/below-k/dedup, token+shingle counts, parse-input aliases, low-sample degraded, missing-param 400, SSRF rejection, and text= mode. TRL-4 ceiling: fixed k=3 shingle width, no language-aware tokenization, FNV/universal-hash heuristics rather than cryptographic locality-sensitive guarantees, and fingerprints estimate surface/lexical similarity not semantic meaning. /selftest exercises the pure-logic pipeline (identical→identical fingerprints, one-word→small SimHash Hamming distance but different SHA, unrelated→large Hamming, MinHash Jaccard sanity, extraction, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"cookie-checker","domain":"cookie-checker.0crawl.com","mesh":"0crawl","host_port":8226,"category":"security","title":"Cookie Checker","summary":"Microservice for Cookie Checker","tags":["go","security"],"health_url":"https://cookie-checker.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_cookie_checker","url":"https://cookie-checker.0crawl.com","example":"/go_cookie_checker?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Live-probe Set-Cookie auditor (RFC 6265bis hand-written parser, per-cookie evidence trail, CMP/tracker/anti-bot gazetteer, real table-driven tests). Pass-3 closed a geographic-coverage bias: the Pass-1/2 gazetteer knew only Anglo-centric CMPs (OneTrust/Cookiebot/Quantcast/TrustArc) and fell through to class=other on the entire EU/non-US consent ecosystem. Added 15 EU/non-US CMPs + WordPress consent-plugin ecosystem (Complianz/Borlabs/CookieYes/Axeptio/tarteaucitron/consentmanager.net/Cookie Information/Klaro/Osano/CookieScript/Real Cookie Banner/CookieFirst/Cookiehub/Clickio/Secure Privacy), IAB consent strings (addtl_consent/usprivacy/GPP), CIS/Russia anti-bot WAFs (DDoS-Guard/Qrator/Variti), and Shopify telemetry. Fixed a consentmanager.net-vs-Quantcast prefix collision and a geo-specific FP where a non-English consent cookie containing 'token' was mis-flagged session_missing_httponly. 7 new table-driven tests with real German Borlabs/Complianz and French Axeptio/tarteaucitron banner fixtures; FP corpus gate unchanged (fp=0,fn=0). Verified live on real domains: lacompagniedescartes.fr 5 Shopify cookies other-\u003etracker, dearchitect.nl didomi_interaction other-\u003ecmp, dreamjob.ru qrator_ssid2 mis-classed session-\u003eanti_bot. domain_cookies stores aggregate tallies not per-cookie names and has no tool_version column, so measurement was live-probe over geo-diverse real domains.","trl_ceiling":7,"trl_ceiling_reason":"Header-only fetcher with no JS engine; a large share of CMP/consent cookies (OneTrust OptanonConsent, Cookiebot, most banners) are JS-set after the consent click and never appear in Set-Cookie headers, so a header-only audit structurally under-observes CMP cookies regardless of gazetteer breadth. Closing that needs a headless browser, out of scope for a CPU-only pure-Go service.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"cors-scanner","domain":"cors-scanner.0crawl.com","mesh":"0crawl","host_port":8239,"category":"security","title":"Cors Scanner","summary":"Microservice for Cors Scanner","tags":["go","security"],"health_url":"https://cors-scanner.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_cors_scanner","url":"https://cors-scanner.0crawl.com","example":"/go_cors_scanner?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Endpoint discovery, CORS preflight testing, credential+wildcard checks, risk categorization.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"cors-tester","domain":"cors-tester.0crawl.com","mesh":"0crawl","host_port":8141,"category":"security","title":"Cors Tester","summary":"Microservice for Cors Tester","tags":["go","security"],"health_url":"https://cors-tester.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_cors_tester","url":"https://cors-tester.0crawl.com","example":"/go_cors_tester?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"7-variant active prober (reflection, null, subdomain-suffix-bypass,\nprefix-confusion, port-attack, case-fold, http-vs-https). Each variant\nsends an OPTIONS preflight + GET, records the full ACAO/ACAC/Vary/\nmethods/headers surface, and feeds a documented severity matrix\n(reflection x credentials, null x credentials, etc.). Worker pool of\n4, per-probe 4s, total 30s. Composes with go-pentest-cors-misconfig-\nprober via CORS_MISCONFIG_URL; gateable on bug-bounty scope via\nSCOPE_GUARD_URL. Tests: probes_test (variant table, downgrade skip,\nscheme preservation), evaluate_test (isReflection, isTrueACAC,\nhasVaryOrigin, Classify matrix), handler_test (httptest servers for\nreflective+credentials critical, wildcard-only low, suffix-bypass\ncritical, null-origin critical, safe server, case-fold, full JSON\nshape) — 20+ test cases across 3 files. ADR docs/adr/0001-trl-uplift-\nto-6.md captures the variant taxonomy and severity matrix.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"crawl-web-application","domain":"crawl-web-application.0crawl.com","mesh":"0crawl","host_port":8082,"category":"domains","title":"Crawl Web Application","summary":"Microservice for Crawl Web Application","tags":["domains","go"],"health_url":"https://crawl-web-application.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_crawl_web_application","url":"https://crawl-web-application.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Registry previously showed trl:6 with a generic description, unsynced since this repo's iteration-3 work. A BFS web crawler with worker pool, RFC-9309 robots.txt enforcement, URL canonicalization+dedup, per-host rate limiting, SSRF-safe outbound HTTP, soft-404 fingerprint probing, and a calendar/pagination-loop guard. Stateless recon primitive invoked ad hoc by sitemap-finder, redirect-tracer, apikey-scanner, and broken-links -- no dedicated production table of its own. This pass: real production-data audit found and fixed 3 real classification bugs. Not TRL 8: one audit against a one-time 400-800 domain sample, not sustained operational/SLA track record. See github.com/baditaflorin/go_crawl_web_application PR #5.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"crlf-tester","domain":"crlf-tester.0crawl.com","mesh":"0crawl","host_port":8142,"category":"security","title":"Crlf Tester","summary":"Microservice for Crlf Tester","tags":["go","security"],"health_url":"https://crlf-tester.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_crlf_tester","url":"https://crlf-tester.0crawl.com","example":"/go_crlf_tester?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Marker-based detection (8-byte per-scan unique hex marker) replaces\nstatic-string echo checks; inspect() classifies header reflection\n(critical), raw-newline-in-header (high), and body reflection (medium)\nseparately. Probes inject across query params, path segments, and four\nreflected headers (User-Agent, Referer, X-Forwarded-For, X-Forwarded-Host;\nHost gated by ALLOW_HOST_INJECT=1). Payload corpus is 20 variants\ncovering hex-case, double-encoding, Unicode/UTF-8 overlong, fragment-\nprefixed, raw \\r vs \\n vs \\r\\n; corpus extensible via PAYLOADS_URL\n(go-pentest-payloads). Per-request 4 s, total 60 s budget, worker pool\n4. SCOPE_GUARD_URL fail-closed gate. ≥9 unit + integration tests\nincluding httptest.Server vulnerable + safe backends.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"crux-field-vitals","domain":"crux-field-vitals.0crawl.com","mesh":"0crawl","host_port":18290,"category":"infrastructure","title":"Crux Field Vitals","summary":"Real-user p75 LCP/CLS/INP/TTFB + good/needs-improvement/poor histograms from the Chrome UX Report API","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://crux-field-vitals.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_crux_field_vitals","url":"https://crux-field-vitals.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Uses the official Chrome UX Report API to map real-user p75 and histogram data for LCP, CLS, INP, and TTFB, with explicit no-data/upstream-error handling, SSRF-safe egress, fixtures, and selftests.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"crypto-finder","domain":"crypto-finder.0crawl.com","mesh":"0crawl","host_port":8341,"category":"recon","title":"Crypto Finder","summary":"Microservice for Crypto Finder","tags":["go","recon"],"health_url":"https://crypto-finder.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_crypto_finder","url":"https://crypto-finder.0crawl.com","example":"/go_crypto_finder?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (fresh ~300-domain sample): found and fixed 2 real false-positive bugs. (1) BTC/LTC/TRX legacy detectors only checked base58 shape, never the checksum -- 78 false 'findings' across 28 real domains (Builder.io CMS block IDs, Bitrix element IDs, analytics IDs), fixed with real Base58Check checksum verification. (2) The SOL detector's own anti-false-positive gate was itself broken -- an unanchored substring match on 'sol'/'spl' matched inside ordinary words like 'display'/'console'/'absolute'/'solution', confirmed flagging a Bitrix storefront with zero crypto integration purely from style=\"display:...\"; fixed with a word-boundary-anchored regex. Confirmed fetch-cache masking does not apply (uses fleetfetch, already hardened in a prior fix). trl/trl_ceiling held at 6/6 -- brings the legacy detector up to the bar TRL 6 already claims, doesn't unlock new headroom (TRL 7 needs revoked-key cross-checking, default-on verification, a WASM client). Flagged a catalog/repo TRL mismatch (repo's own service.yaml says 7) for reconciliation. See PR #6 (merged).","trl_ceiling":6,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"css-framework-detector","domain":"css-framework-detector.0crawl.com","mesh":"0crawl","host_port":18257,"category":"content","title":"Css Framework Detector","summary":"Detects which CSS framework(s) a web page or raw HTML uses (Bootstrap, Tailwind, Bulma, Foundation, Materialize, Semantic/Fomantic UI, UIkit, Pure.css, Tachyons, Skeleton, Milligram) from three independent static-markup signals: linked-stylesheet / CDN hrefs (strong, often versioned), distinctive class-name signatures, and a generator meta hint. Returns frameworks[] (each name + confidence 0..1 + extracted version + evidence[]) sorted by confidence, the top framework, and a raw-signal summary.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://css-framework-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_css_framework_detector","url":"https://css-framework-detector.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Real DOM walk over golang.org/x/net/html (no regex over HTML structure): parses the whole document and recursively collects three independent signal families per candidate framework. (1) CDN / linked-stylesheet signal: every \u003clink rel=stylesheet|preload href\u003e and \u003cscript src\u003e is matched case-insensitively against a curated needle table (bootstrap, tailwindcss/tailwind, bulma, foundation, materialize, fomantic/semantic-ui, uikit, purecss/pure-min, tachyons, skeleton, milligram) covering jsdelivr/cdnjs/unpkg/self-hosted filenames; this is the strong, author-declared signal and frequently carries an exact pinned version. (2) Class-name signatures: distinctive tokens (navbar, col-*, btn-*, d-flex; tailwind md:/lg:/sm:/pt-/px- prefixes + text-sm/bg-blue-500; bulma columns/is-*; foundation grid-x/callout; materialize waves-effect; uikit uk-*; pure-*; tachyons pa3/f6) are separated from generic shared tokens (container, row, flex, button, column, hero) that are flagged weak so a single one never yields a confident detection; Semantic UI's generic 'ui' token only counts as distinctive when it co-occurs with a real SUI partner (button/grid/menu/segment/...) on the same element. (3) \u003cmeta name=generator\u003e naming a framework adds a soft corroborating hint. Version extraction: a single regexp pulls the dotted version from the common CDN shapes bootstrap@5.3.0, /bootstrap/5.3.0/, and bootstrap-5.3.0.min.css (stdlib regexp is used ONLY for class-token/CDN/version pattern matching, never to parse HTML structure). Confidence is a documented heuristic blend (scoreFramework): CDN hit base 0.80 plus 0.15 when a version was extracted; first distinctive class +0.25 with diminishing +0.10 each for the next two (class-only contribution capped at ~0.45 so class signatures alone never reach CDN-level certainty); weak classes +0.05 each capped at 0.10; generator +0.10; clamped to [0,1], 2dp; results below a 0.15 floor (e.g. a lone weak class) are dropped, and the list is sorted by confidence desc with a deterministic framework-order tie-break. Honest TRL-4 ceiling: this is a pure static-markup heuristic over a finite curated framework set; it cannot see browser-computed CSS, and minified / renamed / content-purged class names (e.g. a Tailwind build that purges unused utilities and inlines arbitrary values) can defeat the class-signature path entirely, leaving the CDN/link signal as the reliable one — frameworks outside the curated list are not guessed but reported as an empty frameworks[] with no_framework_detected in degraded[]. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so many producers scanning the same URL trigger one upstream fetch; plain-HTML render mode (static DOM, no JS). SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) plus localhost/.local names, with cache-side and safehttp-fallback dial-time guards catching DNS-resolved private IPs; the input guard is OUTBOUND-only and never inspects hrefs/srcs embedded in the markup. Direct text= mode scans pasted HTML with no fetch. Per-failure notes pushed to degraded[] (fetch_failed, empty_body, no_framework_detected) instead of failing the response; degraded[] is always a non-nil slice and frameworks[] is always non-nil. 36 unit + handler tests cover bootstrap by CDN and by classes, tailwind by utility classes and by CDN, bulma, foundation, materialize, semantic-ui by distinctive pair (and the bare-ui non-detection), uikit, pure.css, tachyons, skeleton + milligram by CDN, version extraction at @ / path / dash shapes and two-component versions, multiple frameworks on one page, confidence ordering and the class-below-CDN ceiling, the cap-at-one blend, generator meta hint, evidence de-duplication, raw-signal counts, single-weak-class rejection, protocol-relative CDN, garbage/empty input safety, plus handler text-mode, parse-input aliases, missing-param 400, and SSRF rejection. /selftest exercises the pure-logic pipeline (bootstrap CDN+version, tailwind classes, class-below-CDN ceiling, confidence ordering, no-framework, non-nil result, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"currency-detector","domain":"currency-detector.0crawl.com","mesh":"0crawl","host_port":8282,"category":"domains","title":"Currency Detector","summary":"Microservice for Currency Detector","tags":["domains","go"],"health_url":"https://currency-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_currency_detector","url":"https://currency-detector.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh sample, zero commits since prior wave): found and fixed a real fetch-cache-masking bug, confirmed both via docker inspect (FLEET_FETCH_CACHE_URL set in production) and live cache-warming latency signature (7.86s-\u003e5.87s-\u003e4.23s pre-fix vs flat ~5.8s post-fix). See PR #7 (merged).","trl_ceiling":7,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"customer-logos","domain":"customer-logos.0crawl.com","mesh":"0crawl","host_port":8283,"category":"domains","title":"Customer Logos","summary":"Microservice for Customer Logos","tags":["domains","go"],"health_url":"https://customer-logos.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_customer_logos","url":"https://customer-logos.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Confirmed honestly earned; no trl\u003eceiling contradiction. 720-domain live audit found and fixed 3 real false-positive classes: Wix CDN media-hash leaks (27-\u003e0), numbered generic placeholders like 'Client 8' (22-\u003e0), color-variant social icon labels like 'Facebook - Black' (3-\u003e0). One domain's verdict corrected from social_proof to the honest weak_signal. See github.com/baditaflorin/go_customer_logos PR #15.","trl_ceiling":7,"trl_ceiling_reason":"CPU-only DOM heuristics plateau at principled multilingual structural extraction; exact brand disambiguation / image recognition (vs structural alt/anchor/grid signals) and SLA-grade live verdicts would need a browser engine or paid logo-recognition feed. No persisted logo-detail table exists to certify live accuracy against.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"data-format-converter","domain":"data-format-converter.0crawl.com","mesh":"0crawl","host_port":18294,"category":"content","title":"Data Format Converter","summary":"Convert payloads between CSV/JSON/XML/YAML/TOML (wraps go-common/dataformat)","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://data-format-converter.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_data_format_converter","url":"https://data-format-converter.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"First-pass audit: found and fixed a real XML-injection bug in the shared go-common/dataformat library (used by ~220 fleet services) -- object keys were written straight into XML element/attribute names with no validation, letting a key like 'a\u003c/root\u003e\u003cevil\u003einjected' splice arbitrary markup into output. Fixed at the library level (go-common PR #54) plus a consumer-side bump and regression tests (PR #1). Also flagged (not fixed, too broad a blast radius for a single-service audit) a JSON large-integer precision-loss issue affecting 64-bit IDs across every non-JSON output format. trl held at 7; trl_ceiling=9 -- a deterministic, pure in-process converter over mature stdlib/well-established format libraries with no external dependencies, nothing structurally caps it below production-grade. See PR #1 + go-common PR #54 (both merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"data-inventory","domain":"data-inventory.0crawl.com","mesh":"0crawl","host_port":8284,"category":"domains","title":"Data Inventory","summary":"Microservice for Data Inventory","tags":["domains","go"],"health_url":"https://data-inventory.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_data_inventory","url":"https://data-inventory.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Tested against 200 real domains confirmed to have a privacy_policy page. Fixed a broken word-boundary guard that let 'AWS' match inside 'laws'/'applicable laws' (13%-\u003e1% false positive rate), a case-insensitive Spanish regex mismatching the Polish word 'nie' as a sensitive ID-document flag, and a port config drift (8154 vs actual 8284) across 4 files. See github.com/baditaflorin/go_data_inventory PR #7.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"debug-detector","domain":"debug-detector.0crawl.com","mesh":"0crawl","host_port":8227,"category":"security","title":"Debug Detector","summary":"Microservice for Debug Detector","tags":["go","security"],"health_url":"https://debug-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_debug_detector","url":"https://debug-detector.0crawl.com","example":"/go_debug_detector?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"TRL 5 (2026-08-20 fleet TRL audit; corrected DOWN from stale registry TRL 6 dated 2026-05-16). Fresh clone of origin/main (github.com/baditaflorin/go_debug_detector @ a1ab247, go-common@v0.88.0) read end to end.\n\nLive-reproduced a real 3-root-cause false-positive engine by fetching https://vercel.com directly and then running the detector's own probe/scan logic against it: the tool scored vercel.com CRITICAL for phantom Spring Boot (/actuator/env, /actuator/heapdump) and WordPress (/xmlrpc.php) findings that do not exist on that target. Root causes, all confirmed by direct curl+grep against the live target before touching any code: (1) several body-signature \"needles\" in signatures.go were bare substrings of the probe path itself (bare \"actuator\", \"xmlrpc.php\", \"/debug/pprof/\"); Vercel's dashboard is a client-side catch-all router that returns 200 for any unmatched path and echoes the requested path back into breadcrumbs/router-state JSON in the shell it serves (confirmed via grep: the literal strings \"actuator\", \"xmlrpc.php\", \"/debug/pprof\" each appeared multiple times in the live response bodies, purely as reflected URL/router-slug text) - a pattern common to many SPA frameworks, not specific to Vercel - so any such host trivially \"confirms\" these signatures regardless of the real framework; (2) severity.go's severityForFinding() returned \"critical\" unconditionally whenever a probe's default severity was \"critical\", ignoring the confirmed argument entirely, so /actuator/env and /xmlrpc.php were reported CRITICAL on any 200 response at all; (3) /actuator/heapdump had no Confirm signature whatsoever in probes.go - a bare 200 status (Vercel returns 200 HTML, confirmed live) was treated as sufficient proof of a raw JVM heap dump.\n\nFixed all three: tightened signatures.go needles to require actually-diagnostic content (Spring Boot's HAL `\"_links\":{\"self\":{\"href\"` shape, WordPress's literal XML-RPC banner text, real pprof index-page strings, and a \"heapdump\" signature requiring the genuine HPROF magic header \"JAVA PROFILE\"); severity.go now gates ALL severities (including critical) on confirmation, downgrading one rank when unconfirmed; probe.go now reports Framework \"unknown\" rather than asserting an unconfirmed framework identity. Added false_positive_regression_test.go reproducing the vercel.com-shape false positive against an httptest catch-all server; confirmed via `git stash` that each new test fails on the pre-fix code and passes after. All pre-existing tests still pass (one fixture updated: the heapdump mock now serves a real HPROF-magic-prefixed body).\n\nSeparately fixed the recurring fleet fetch-cache bug class: buildClient() called fleetfetch.NewHTTPClient() without .WithoutCache(); every scan fans out dozens of speculative, mostly-nonexistent probe paths against an arbitrary caller-supplied target - exactly fleetfetch.WithoutCache()'s documented \"one-shot lookups\" case. Without it, every probe both paid a round trip through the shared cache and could serve a stale cached response instead of the target's current state, undermining a live security probe's core premise. Added WithoutCache().\n\nVersion bumped 2.0.5 -\u003e 2.1.0 (accuracy fix with three root causes, not patch-level). Fix shipped as PR github.com/baditaflorin/go_debug_detector/pull/8 (open, NOT merged per audit policy) - main still contains the false-positive bug as of this writing, hence the TRL is corrected DOWN to 5 rather than reaffirmed at 6: a debug/vuln detector whose \"body-signature confirmation reduces false positives\" claim (the prior trl_evidence's central claim) was, on live evidence, actively producing critical false positives against a real, well-known, unauthenticated target. Detection coverage and methodology for genuinely-present frameworks were not in question - only the confirmation gate's soundness was. TRL will be reassessed to 6 once PR #8 is merged and re-verified live against vercel.com (or an equivalent generic-catch-all target).","trl_ceiling":7,"trl_ceiling_reason":"TRL 6 once PR #8 (false-positive fix) is merged and re-verified live; TRL 7 would need sustained production false-positive-rate history across diverse real targets, not just the one live-reproduced case.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"dependency-counter","domain":"dependency-counter.0crawl.com","mesh":"0crawl","host_port":8285,"category":"domains","title":"Dependency Counter","summary":"Microservice for Dependency Counter","tags":["domains","go"],"health_url":"https://dependency-counter.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_dependency_counter","url":"https://dependency-counter.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Probes 24 publicly-exposed manifest paths across 9 ecosystems (Node/Go/Python/Ruby/PHP/Java/.NET/Rust + CycloneDX/SPDX SBOMs); per-ecosystem parsers count direct vs transitive deps, classify pin types, and flag leaked secrets in package.json. SSRF-safe outbound, 4s per fetch / 20s total / 8-worker pool / 512KiB body cap. Graded severity model (info/low/medium/high/critical): an additive risk score over real signals -- exposure breadth, dependency volume (banded), version-pin hygiene, lockfile authority, per-ecosystem weighting, and decisive secret exposure -- emitted with a per-grade evidence trail (resp.risk). Rollup feeds info-leakage and dependency-cve composer. \u003e=6 httptest cases per ecosystem covering 200/404/parse-error matrix, plus table-driven grading + score-boundary tests. Fleet fetch-cache-opt-out audit (2026-08-08): the registry's trl_evidence field for this service was a literal placeholder (a bare greater-than sign, HTML-escaped as \u0026gt;) -- not real evidence -- and has been replaced with the above capability description (pulled from the service's own service.yaml, which had never been synced here) plus this finding. Confirmed against go-common v0.80.0 source (safehttp/fetchcache.go, safehttp/safehttp_with.go) that handler.go's package-level httpClient -- the sole client used by every live manifest probe via doProbe -- was built with a bare safehttp.NewClient() omitting WithoutFetchCache()/WithForceHTTP2(), the same bug class as the 2026-07 go_page_load_metrics incident: on any host with FLEET_FETCH_CACHE_URL set, live probes silently route through the process-wide fleet fetch-cache delegate instead of the origin, so a stale cached response can report a manifest as exposed long after removal (or hide one newly exposed), and the missing WithForceHTTP2() lets HTTP/2-only origins silently fall back to HTTP/1.1 under the SSRF-guard dialer. Fixed in github.com/baditaflorin/go_dependency_counter PR #12 (open, not merged): added safehttp.WithoutFetchCache() + safehttp.WithForceHTTP2() to the httpClient constructor in handler.go. Added TestHTTPClient_BypassesProcessWideFetchCache, a regression test that installs a stub safehttp.FetchDelegate returning a stale cached 200 + package.json body, points the real production httpClient at a live loopback server returning 404, and asserts the live 404 wins and the delegate is never consulted -- confirmed this test fails against the pre-fix bare constructor (200, cache-masked) and passes with the fix (404, live truth). Live-verified the fixed client end-to-end against 8 real production sites (example.com, vuejs.org, prettier.io, babeljs.io, webpack.js.org, rollupjs.org, vitejs.dev, astro.build): all correctly report zero manifests exposed via real live network round-trips through the fixed client. Version bumped 3.2.0 -\u003e 3.2.2 (service.yaml had already drifted to 3.2.1; resynced both). trl/trl_ceiling left unchanged -- this is a live-probe correctness fix (the probe now reliably observes the real origin instead of a possibly-stale cache), not a new capability.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"dir-listing","domain":"dir-listing.0crawl.com","mesh":"0crawl","host_port":8342,"category":"recon","title":"Dir Listing","summary":"Microservice for Dir Listing","tags":["go","recon"],"health_url":"https://dir-listing.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_dir_listing","url":"https://dir-listing.0crawl.com","example":"/go_dir_listing?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"First-pass audit (250-domain sample, two independent live before/after runs, ~1000 live HTTP calls): found and fixed 3 real bugs -- fetch-cache masking; a hard failure on HTTPS transport errors that gave up entirely instead of retrying over HTTP, missing real live Apache directory listings on a domain whose HTTPS timed out (confirmed live, opensimulator.org); and classic (non-table) Apache mod_autoindex output being misclassified as nginx (confirmed on 2 live production Apache servers). trl bumped 6-\u003e7; trl_ceiling=8 added -- known gaps (custom-themed autoindex tools, cloud storage bucket listings, IIS only synthetically tested) are real but bounded. See PR #3 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"dns-record","domain":"dns-record.0crawl.com","mesh":"0crawl","host_port":8084,"category":"recon","title":"Dns Record","summary":"Microservice for Dns Record","tags":["go","recon"],"health_url":"https://dns-record.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_dns_record","url":"https://dns-record.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"First-pass audit (fresh 250-domain sample, cross-checked against dig on 3 public resolvers): found and fixed a real bug -- flattenAnswers sorted MX/SRV records lexicographically as strings instead of numerically by preference/priority, scrambling any RRset mixing single- and double-digit values (confirmed on 17% of sampled domains with MX records, e.g. a Google Workspace MX set [1,5,5,10,10] emitted as [1,10,10,5,5]). Confirmed no fetch-cache layer sits in front of DNS lookups, and NXDOMAIN-vs-transient-error handling is already correct. trl bumped 6-\u003e7 given the live-validated fix; trl_ceiling=7 added -- structurally capped by dependence on shared public resolvers (1.1.1.1/8.8.8.8/9.9.9.9) for both answers and DNSSEC trust, no local validator. See PR #10 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"dom-complexity-metrics","domain":"dom-complexity-metrics.0crawl.com","mesh":"0crawl","host_port":18262,"category":"content","title":"Dom Complexity Metrics","summary":"Structural DOM-complexity metrics for a web page or raw HTML — total element-node and text-node counts, maximum nesting depth, maximum sibling breadth, per-tag frequency histogram, distinct-tag count, average children per element, high-fan-out element count, the deepest element path, text-to-element ratio, total DOM size in bytes, and a combined complexity score.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://dom-complexity-metrics.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_dom_complexity_metrics","url":"https://dom-complexity-metrics.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Real single-pass DOM tree walk over golang.org/x/net/html's tokenizing parser (no regex over HTML structure): malformed markup is normalised into a well-formed tree, then one depth-first traversal in document order computes total element-node count, total text-node count, maximum element-nesting depth, maximum sibling breadth (widest direct-element-child fan at any parent), a per-lowercase-tag frequency histogram, distinct-tag count, average direct-element-children per element, count of elements exceeding the \u003e60-child high-fan-out threshold (threshold echoed in the response), the deepest element path (root-to-deepest tag chain, first-in-document-order on ties), text-to-element ratio, total DOM size in bytes, and a documented combined complexity score (max_depth + max_breadth + element_nodes/100). The whole served document is counted including head/script/style — DOM weight is a property of the markup as a whole, distinct from prose extraction. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so 20 producers analysing the same URL trigger one upstream fetch; plain-HTML render mode. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode analyses pasted markup with no fetch. Per-failure notes pushed to a non-nil degraded[] (empty_document, fetch_failed, parse_failed) instead of failing the response. ~30 unit tests cover nested-div depth, N-sibling breadth, node counts, tag histogram, distinct-tag count, deepest-path chain (including first-wins-on-tie), high-fan-out threshold boundary (60 vs 61), text-node vs element-node counting, malformed-HTML normalisation, script/style inclusion, average-children and ratio math, complexity-score monotonicity, empty-document degraded, missing-param 400, SSRF rejection, and text= mode. /selftest exercises the pure-logic pipeline (hand-built known depth/breadth, node counts, deepest path, fan-out, empty-document, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal. TRL-4 ceiling: metrics describe the STATIC server-rendered DOM only — no JS-expanded/hydrated DOM, no computed layout/CSSOM, no render-tree or paint cost; a headless-browser engine would be required to advance further.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-ad-network","domain":"domain-ad-network.0crawl.com","mesh":"0crawl","host_port":18214,"category":"web_analysis","title":"Domain Ad Network","summary":"Ad-network detector with validated ads.txt seller records and executable-context matching for 18 in-page advertising providers.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-ad-network.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_ad_network","url":"https://domain-ad-network.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"1,266-domain live audit (ads.txt + 18 in-page ad-network signatures). Fixed a real bug: Google Ad Manager out-of-page/interstitial slots were detected but their network code was never extracted. Zero false positives on manual spot-check across the full sample. Independently re-validated this repo's own pre-existing trl:7 self-claim rather than assuming it. See github.com/baditaflorin/go_domain_ad_network PR #5.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-amp-detector","domain":"domain-amp-detector.0crawl.com","mesh":"0crawl","host_port":18222,"category":"web_analysis","title":"Domain Amp Detector","summary":"Strict AMP detector requiring the root marker, official runtime, same-site canonical, and verified AMP alternatives.","health_url":"https://domain-amp-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_amp_detector","url":"https://domain-amp-detector.0crawl.com","example":"/?domain=www.bbc.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"967-domain live audit against real DOM-parser-based AMP detection (no regex). Fixed a false-positive bug: broken/placeholder canonical links (href='domain.com', href='##') were accepted as valid AMP evidence -- 2.9% of currently-flagged AMP pages were false positives, one live-reproduced during the audit. Also patched a real CVE (x/net HTML-parser DoS). See github.com/baditaflorin/go_domain_amp_detector PR #5.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-analytics-stack","domain":"domain-analytics-stack.0crawl.com","mesh":"0crawl","host_port":18215,"category":"web_analysis","title":"Domain Analytics Stack","summary":"Analytics stack detector - GA4/GTM/Segment/Mixpanel/Plausible/Fathom/Heap/Amplitude/Matomo/Hotjar/FullStory SDK IDs.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-analytics-stack.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_analytics_stack","url":"https://domain-analytics-stack.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Live 180-domain production sample (restricted to current tool_version) found one real false negative: buildahog.com ships the classic ga.js/urchin.js `_gaq.push(['_setAccount', ...])` snippet, whose loader script is JS-constructed (never a literal src= tag), giving the static detection floor zero signal -- a true tool_count=0 miss on real production markup. Fixed (v0.6.3) by adding the classic _gaq shape as a third alternative alongside the existing modern ga()/gtag() patterns, with a regression test pinned to the real production fixture. See github.com/baditaflorin/go_domain_analytics_stack PR #12 (merged). Rows with tool_version\u003c0.6.3 are re-crawl candidates.","trl_ceiling":7,"trl_ceiling_reason":"Consent-gated tags, WAF pages, and analytics loaded only after interaction remain outside a single homepage snapshot.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-anycast-footprint","domain":"domain-anycast-footprint.0crawl.com","mesh":"0crawl","host_port":18220,"category":"infrastructure","title":"Domain Anycast Footprint","summary":"Anycast vs unicast routing detector (multi-resolver IP convergence + ASN check).","health_url":"https://domain-anycast-footprint.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_anycast_footprint","url":"https://domain-anycast-footprint.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Live production-DB audit (~466K rows) found 44.1% of anycast verdicts had unique_ip_count\u003c=1 -- textbook unicast/inconclusive signature, not anycast. Root-caused: 99.25% was stale data predating an already-shipped convergence fix, but 1,370 rows on the then-current tool_version were a live bug -- the ASN-corroboration path granted 'anycast' from bare membership in broad, mixed-traffic ASNs (Microsoft 8075, Hetzner 24940) with zero multi-resolver corroboration, verified via live whois ASN lookups against a random production sample. Fixed (v0.1.3) by removing both ASNs from the allowlist, matching the precedent already set for Amazon's ASNs. See github.com/baditaflorin/go_domain_anycast_footprint PR #7 (merged). Rows with tool_version\u003c0.1.3 are re-crawl candidates.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-app-render-mode","domain":"domain-app-render-mode.0crawl.com","mesh":"0crawl","host_port":18224,"category":"web_analysis","title":"Domain App Render Mode","summary":"Front-end framework + render mode (SSR/CSR/SSG) detector.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-app-render-mode.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_app_render_mode","url":"https://domain-app-render-mode.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"866-domain 3-way replay (deployed prod vs pre-fix main vs fix, on identical HTML bytes). Fixed two real classification bugs: positive framework detections (e.g. Next.js at high confidence) reported as 'unknown'; an earlier merged fix over-corrected and lost legitimate same-origin framework fingerprints (Astro, Gatsby). ~1.1% of verdicts corrected, zero regressions. Also patched a real CVE. Flagged: production is 2 real-bug generations behind main. See github.com/baditaflorin/go_domain_app_render_mode PR #4.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-backlink-profile","domain":"domain-backlink-profile.0crawl.com","mesh":"0crawl","host_port":18210,"category":"seo","title":"Domain Backlink Profile","summary":"Inbound-link / referring-domain estimator (Common Crawl + Web Archive).","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-backlink-profile.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_backlink_profile","url":"https://domain-backlink-profile.0crawl.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":4,"trl_evidence":"First-ever audit re-validated the v0.3.0 honesty-gate architecture against 200 live production domains and the full 349,747-row production table; confirmed the fleet-common safehttp fetch-cache bug class does not apply (plain net/http, no safehttp import). Found and fixed a real evidence-integrity bug: fetchBytesOnce only special-cased \u003e=500/404, so any other non-2xx response (403 auth-wall, 400 on IDN domains) had its HTML error body fed to the line parsers as fabricated real data -- reproduced live for web.archive.org's 403 on nytimes.com and a 400 on cafe.com/moskva.rf/nihon.jp (no punycode encoding before outbound URL construction). Fixed by hard-failing any non-2xx status at the shared fetch layer. Also surfaced two upstream/ops gaps (Common Crawl index-query endpoint failing fleet-wide, OPEN_PAGE_RANK_KEY unprovisioned in production) as follow-ups, not code bugs. trl/trl_ceiling held at 4/4 -- the no-paid-backlink-feed ceiling rationale still holds. See github.com/baditaflorin/go_domain_backlink_profile PR #10 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-bimi-checker","domain":"domain-bimi-checker.0crawl.com","mesh":"0crawl","host_port":18218,"category":"domains","title":"Domain Bimi Checker","summary":"BIMI logo record + VMC certificate checker (brand email indicators).","health_url":"https://domain-bimi-checker.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_bimi_checker","url":"https://domain-bimi-checker.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh 399-domain sample): found and fixed 2 real bugs -- (1) fetch-cache masking, confirmed live via docker inspect showing FLEET_FETCH_CACHE_URL set in production; (2) multiple BIMI/DMARC TXT records were silently resolved to 'whichever came first' instead of correctly treated as a discovery failure per spec (BIMI + RFC 7489 6.6.3) -- live-confirmed on 5 real domains including brandfinish.com and vos.health. See PR #6 (merged). trl bumped 6-\u003e7, now at ceiling.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-breadcrumb-schema","domain":"domain-breadcrumb-schema.0crawl.com","mesh":"0crawl","host_port":18230,"category":"web_analysis","title":"Domain Breadcrumb Schema","summary":"schema.org BreadcrumbList JSON-LD + microdata detector + validator.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-breadcrumb-schema.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_breadcrumb_schema","url":"https://domain-breadcrumb-schema.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"900-domain live audit (real HTML parser across JSON-LD/microdata/RDFa Lite). Fixed 4 real bugs: a cross-host false positive, a vacuous-truth path_aligned check that hit 78% of well-formed breadcrumb lists (mostly Yoast/RankMost/WooCommerce single-item homepage breadcrumbs), a missing nested item.name extraction path, and total JSON-LD parse failure on embedded control characters. Also fixed a dead selftest check that never ran and a false live-probe claim in trl_evidence/README. See github.com/baditaflorin/go_domain_breadcrumb_schema PR #5.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-cache-policy","domain":"domain-cache-policy.0crawl.com","mesh":"0crawl","host_port":18235,"category":"web_analysis","title":"Domain Cache Policy","summary":"HTTP cache hygiene scorer (RFC 7234/9111).","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-cache-policy.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_cache_policy","url":"https://domain-cache-policy.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"900-domain live audit uncovered a severe fetch-cache-masking bug: the service was never opted out of the fleet's shared fetch-cache delegate, proven live via 3 requests to stripe.com 20+ seconds apart returning byte-identical frozen timestamps -- scoring stale, replayed responses instead of live headers. Also fixed a body-decompression bug present since v0.1.0 (explicit Accept-Encoding disabled Go's auto-decompression, feeding raw compressed bytes to the parser) -- static-asset discovery jumped 3.5%-\u003e69.2%, mean score 36.1-\u003e43.4 across 900 domains. See github.com/baditaflorin/go_domain_cache_policy PR #4.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-cms-version","domain":"domain-cms-version.0crawl.com","mesh":"0crawl","host_port":18216,"category":"web_analysis","title":"Domain Cms Version","summary":"CMS core + version detector (WordPress/Drupal/Joomla/Ghost/Next.js/etc.).","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-cms-version.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_cms_version","url":"https://domain-cms-version.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Live production-DB audit (~1.4M rows) found 0/2,337 Joomla rows had a version extracted, vs 88% WordPress and 87% Drupal. Root-caused: every Joomla release since the 1.6 rewrite intentionally omits the version from the generator meta tag by design, and the service had no fallback path. Fixed (v0.4.3) by adding a legacy-meta regex plus an opportunistic probe of the public administrator/manifests/files/joomla.xml core manifest, mirroring the existing Drupal CHANGELOG.txt probe -- live-verified against a 40-domain sample: 62.5% now yield a version. See github.com/baditaflorin/go_domain_cms_version PR #11 (merged). Rows with tool_version\u003c0.4.3 are re-crawl candidates.","trl_ceiling":7,"trl_ceiling_reason":"Plugin/theme-level depth needs a Wappalyzer-grade signature database; bot-protected and fingerprint-less sites remain outside reliable CPU-only detection.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-dane-tlsa","domain":"domain-dane-tlsa.0crawl.com","mesh":"0crawl","host_port":18219,"category":"domains","title":"Domain Dane Tlsa","summary":"DANE/TLSA record presence + cert binding validation (RFC 6698).","health_url":"https://domain-dane-tlsa.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_dane_tlsa","url":"https://domain-dane-tlsa.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Tested against 913 real domains (700 random + 80 .cz + 80 .nl + 53 known-DANE-positive from prod data). Fixed: (1) matches_served_cert was a plain bool silently conflating 'never checked' (e.g. a real dial timeout) with 'genuine mismatch' -- now nullable, affected 7/913 domains; (2) added new dane_verified field distinguishing DANE matches on DNSSEC-signed zones from unsigned ones -- 16/52 real matches were on unsigned zones (DANE without the RFC 6698 guarantee). Independently reproduced 51/53 of the DB's existing recorded DANE positives from a fresh build. See github.com/baditaflorin/go_domain_dane_tlsa PR #3.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-deployment-fingerprint","domain":"domain-deployment-fingerprint.0crawl.com","mesh":"0crawl","host_port":18241,"category":"web_analysis","title":"Domain Deployment Fingerprint","summary":"Unified deployment fingerprint (PaaS + serverless + edge-compute detector).","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-deployment-fingerprint.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_deployment_fingerprint","url":"https://domain-deployment-fingerprint.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Confirmed today's earlier merged fetch-cache fix is genuinely in place, then found and fixed one more real live false negative: the render PaaS rule only recognized a .onrender.com CNAME or an x-render-origin-server header, missing Render-hosted domains behind Cloudflare (CNAME hidden, Server header overwritten) -- live-verified via an independent ground-truth signal (hosting_asn_name='RENDER'), 6/20 (30%) of a targeted sample were misses. Fixed (v0.2.10) by adding Render's own rndr-id request-id header as a strong signal, re-verified live against all 6 domains plus a fresh 150-domain random sample with zero new mismatches. See github.com/baditaflorin/go_domain_deployment_fingerprint PR #17 (merged). Rows with tool_version\u003c0.2.10 are re-crawl candidates.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-details","domain":"domain-details.0crawl.com","mesh":"0crawl","host_port":8085,"category":"recon","title":"Domain Details","summary":"Microservice for Domain Details","tags":["go","recon"],"health_url":"https://domain-details.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_details","url":"https://domain-details.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Live production-DB audit (~1.1M rows) found 74,371 rows with status=1 (success) yet age_days=0, almost always paired with empty registrar/expires/nameservers -- literally claiming 74K+ domains were registered on their scan date. Root-caused: age_days defaulted to Go's int zero-value instead of NULL when a WHOIS creation date failed to parse, while status stayed 'ok'. Confirmed live: 3,361 of these rows were checked after an earlier related fix already shipped, proving this is a live, still-present gap. Fixed (v1.3.0) with a new 'partial' result classification whenever no usable Created date exists, plus a normaliseWhoisDate fix that no longer leaks raw unparsed date strings into a documented-RFC3339 field. See github.com/baditaflorin/go_domain_details PR #10 (merged). Rows with tool_version\u003c1.3.0 are re-crawl candidates.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-ecommerce-platform","domain":"domain-ecommerce-platform.0crawl.com","mesh":"0crawl","host_port":18212,"category":"web_analysis","title":"Domain Ecommerce Platform","summary":"E-commerce platform detector (Shopify/Magento/Woo/BigCommerce/etc.).","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-ecommerce-platform.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_ecommerce_platform","url":"https://domain-ecommerce-platform.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Confirmed this repo's own trl:7 claim via independent audit rather than self-assessment. Found a real regression from an earlier merged PR: a demotion meant to catch one specific false-positive shape was over-broadly capping the weight of every platform-exclusive backend/CDN host match, systemically under-detecting 9 platforms (VTEX had only 12 detections fleet-wide vs. 10,041 for Shopify). Confirmed live: a real operating VTEX storefront was reported as having no e-commerce platform despite 7 independent VTEX asset references. Fixed by narrowing the demotion to only its intended tag shape. See github.com/baditaflorin/go_domain_ecommerce_platform PR #15.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-error-monitoring","domain":"domain-error-monitoring.0crawl.com","mesh":"0crawl","host_port":18225,"category":"web_analysis","title":"Domain Error Monitoring","summary":"Front-end error monitoring detector - Sentry/Datadog RUM/Bugsnag/Rollbar/Raygun/etc.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-error-monitoring.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_error_monitoring","url":"https://domain-error-monitoring.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Investigated the same 'false written on failed fetch' pattern (7.9% of rows). Found this repo has no has_error_monitoring field in its response contract at all -- confirmed via source inspection and a live NXDOMAIN test against current main, which correctly reports status/result/reason with an empty detected array. A fresh DB query found the same status codes split inconsistently between false and NULL, only possible if a separate ingestion component (not this deterministic service) is the source. No fix forced, no PR opened. Third of 4 sibling services confirming the same root cause -- see the fleet-wide note below. Note: this repo's own service.yaml self-reports trl=7 while the prior catalog entry showed trl=6 -- registry now aligned to 7, flagging the discrepancy for awareness.","trl_ceiling":7,"trl_ceiling_reason":"First-party bundled SDKs with no static or response-header fingerprint require reliable post-hydration browser execution.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-events-platform","domain":"domain-events-platform.0crawl.com","mesh":"0crawl","host_port":18226,"category":"web_analysis","title":"Domain Events Platform","summary":"Events / webinar platform detector - Zoom/Hopin/Luma/Eventbrite/Bevy/Cvent/etc.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-events-platform.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_events_platform","url":"https://domain-events-platform.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"991-domain live audit. Fixed 6 real bugs: the fetch layer never checked HTTP status codes so WAF/bot-block pages sailed through as clean scans (35+ domains affected); broken ID extraction for On24 (0/7-\u003e6/7) and Eventive (0/8-\u003e2/8) event links; false positives from self-hosted vFairs analytics and Eventbrite's own CDN favicon; plus a real CVE patch. See github.com/baditaflorin/go_domain_events_platform PR #3.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-experimentation-stack","domain":"domain-experimentation-stack.0crawl.com","mesh":"0crawl","host_port":18211,"category":"web_analysis","title":"Domain Experimentation Stack","summary":"A/B-testing + feature-flag stack detector (Optimizely/VWO/LaunchDarkly/Split.io/etc.).","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-experimentation-stack.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_experimentation_stack","url":"https://domain-experimentation-stack.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Investigated the fleet-wide 'has_experimentation=false written despite failed fetch' pattern (17.1% of rows, including optimizely.com itself). Found this repo's own JSON response contract is already correct -- a proper status/result field distinguishes unreachable/error from a genuine no-detection, and the zero-value has_experimentation on a failure path is truthful (nothing was fetched) not a false claim. The actual corruption happens entirely in a separate ingestion/orchestrator component that writes Postgres, outside this repo's code and this initiative's current access. No fix forced, no PR opened. This is the first of 4 sibling services confirming the same root cause -- see the fleet-wide note below.","trl_ceiling":6,"trl_ceiling_reason":"Server-side experimentation can emit no client-observable fingerprint; measured JS rendering recovered almost no additional vendor signal and remains a flaky upstream.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-faq-schema","domain":"domain-faq-schema.0crawl.com","mesh":"0crawl","host_port":18231,"category":"web_analysis","title":"Domain Faq Schema","summary":"schema.org FAQPage JSON-LD + microdata detector + validator.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-faq-schema.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_faq_schema","url":"https://domain-faq-schema.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"This repo's own service.yaml already carried a genuine trl:7 assessment that a later registry-sync commit discarded down to a bare trl:5 -- a registry bookkeeping gap, not a code regression. Re-validated with a fresh 1,000-domain live audit: fixed a real bug affecting the two most common JSON-LD producers on the web (Yoast SEO, RankMath) where @id-reference-style FAQ entries were misread as malformed, zeroing out otherwise-valid FAQ pages (reproduced live on 2 real sites, 6/6 valid questions each, previously misreported as 0). See github.com/baditaflorin/go_domain_faq_schema PR #4.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-favicon-completeness","domain":"domain-favicon-completeness.0crawl.com","mesh":"0crawl","host_port":18232,"category":"web_analysis","title":"Domain Favicon Completeness","summary":"Favicon + Web App Manifest icon-set completeness checker.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-favicon-completeness.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_favicon_completeness","url":"https://domain-favicon-completeness.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"The repo's own prior trl:7 claim was an unvalidated text-only edit the central catalog correctly never trusted. 900-domain live audit found and fixed a real bug: icons declared via inline data: URIs (2.3% of domains) were mis-parsed as unreachable by the URL normalizer, permanently zeroing an otherwise valid favicon score. Zero regressions. Flagged: production is 4+ weeks stale, missing an already-merged fix. See github.com/baditaflorin/go_domain_favicon_completeness PR #4.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-font-stack","domain":"domain-font-stack.0crawl.com","mesh":"0crawl","host_port":18221,"category":"web_analysis","title":"Domain Font Stack","summary":"Web font stack detector - Google Fonts/Adobe Fonts/self-hosted + family count + font-display hygiene.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-font-stack.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_font_stack","url":"https://domain-font-stack.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Independently re-validated this repo's own pre-existing trl:7 claim (earned across two prior real audit rounds, never synced to the central registry) via a fresh 900-domain paired audit. Fixed 4 real bugs: a false positive from a CDN mirror rewriting a Typekit URL, a missed preload-as-style async-loading pattern, an unfetched @import provider reference, and undercounting of fonts.gstatic.com direct-preload assets. Family-count sum improved 403-\u003e408, 2 false positives removed, 0 introduced. See github.com/baditaflorin/go_domain_font_stack PR #5.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-geo-anchor","domain":"domain-geo-anchor.0crawl.com","mesh":"0crawl","host_port":18317,"category":"domain_intelligence","title":"Domain Geo Anchor","summary":"Resolve a domain to country/admin1/admin2/city with per-level confidence (CPU-only, GeoNames); downstream of the domainscope LLM call","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-geo-anchor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_geo_anchor","url":"https://domain-geo-anchor.0crawl.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-gift-card","domain":"domain-gift-card.0crawl.com","mesh":"0crawl","host_port":18239,"category":"web_analysis","title":"Domain Gift Card","summary":"Gift-card offering detector with content-validated URL probes that reject soft 404s and homepage redirects.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-gift-card.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_gift_card","url":"https://domain-gift-card.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"950-domain live audit plus a 39-merchant/20-non-commerce ground-truth set (precision 1.00, recall 0.26). Fixed a real bug: no HTTP fallback on TLS/certificate failure caused 11.4% of homepage fetches to fail entirely even though real content existed over plain HTTP -- errors dropped 108-\u003e23, recovering 2 previously-masked real positives. Also closed a fetch-cache-consistency gap between homepage and probe evidence. See github.com/baditaflorin/go_domain_gift_card PR #5.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-glue-records","domain":"domain-glue-records.0crawl.com","mesh":"0crawl","host_port":18237,"category":"domains","title":"Domain Glue Records","summary":"Glue record presence at parent zone (RFC 1034 3.6.1 / RFC 8499).","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-glue-records.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_glue_records","url":"https://domain-glue-records.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Tested against domain_glue_records (946,788 rows, actively written by this service) and a 200-domain random sample. Fixed 3 real bugs, one already visibly producing wrong production rows: (1) checker trusted only the first-responding parent nameserver, but different authoritative instances of the same TLD zone disagree on glue provisioning -- verified live that forth.gr and nic.sh had real false-negative production rows dated the day of this audit from exactly this cause; fixed by merging glue across all responding parent NS instances; (2) glue_provided_count was inflated by counting opportunistic out-of-bailiwick glue -- 37% of the 200-domain sample affected (e.g. amazon.com); (3) empty glue results couldn't distinguish 'no glue needed' from NXDOMAIN -- 4% of the sample were silently-wrong NXDOMAIN domains reported as clean. All fixed with live-verified before/after numbers. TRL held at 7 rather than inflated further -- re-affirmed with real evidence instead of a fresh bump. See github.com/baditaflorin/go_domain_glue_records PR #4.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-image-alt-coverage","domain":"domain-image-alt-coverage.0crawl.com","mesh":"0crawl","host_port":18223,"category":"web_analysis","title":"Domain Image Alt Coverage","summary":"Image alt-text coverage analyzer (WCAG 1.1.1 signal).","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-image-alt-coverage.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_image_alt_coverage","url":"https://domain-image-alt-coverage.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"800-domain live audit. The DOM parsing/classification logic held up well (no bugs found), but the fetch layer had real defects: no HTTP fallback when HTTPS failed (84/800 domains affected by cert mismatches/refused connections), no status-code check before parsing (Cloudflare 403 challenge pages and domain-parking pages scored as real homepages), and a redirect cap cutting off legitimate chains one hop short. Fetch failure rate dropped 17.9%-\u003e14.2%. See github.com/baditaflorin/go_domain_image_alt_coverage PR #3.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-integration-marketplace","domain":"domain-integration-marketplace.0crawl.com","mesh":"0crawl","host_port":18243,"category":"web_analysis","title":"Domain Integration Marketplace","summary":"Integration / marketplace / app-directory page detector with count estimate.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-integration-marketplace.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_integration_marketplace","url":"https://domain-integration-marketplace.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Live production-DB cross-check found a real, currently-active false-positive class: a shared white-label site-builder/CRM platform injects an identical cross-sell grid of its own 17 product modules into every customer homepage, and the integration_link_grid detector (\u003e=6 distinct same-origin /apps/\u003cslug\u003e links) fired on all of them as if they were third-party integrations -- confirmed live, 3 unrelated production domains served byte-identical HTML; 9/33 (27%) of recent high-confidence positives carried exactly this signature. Fixed (v0.4.5) by denylisting the 17 confirmed platform-owned slugs, verified a genuine devops marketplace (real /integrations/{aws,kubernetes,...} grid) remains unaffected. See github.com/baditaflorin/go_domain_integration_marketplace PR #16 (merged). Rows with tool_version\u003c0.4.5 are re-crawl candidates.","trl_ceiling":7,"trl_ceiling_reason":"Hard bot protection, catalogs hosted on separate ecosystem domains, and authoritative ground-truth counts require platform APIs or different egress.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-interactive-demo","domain":"domain-interactive-demo.0crawl.com","mesh":"0crawl","host_port":18240,"category":"web_analysis","title":"Domain Interactive Demo","summary":"Product-demo / sandbox embed detector (Storylane/Navattic/Arcade/etc.).","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-interactive-demo.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_interactive_demo","url":"https://domain-interactive-demo.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"The repo's own prior trl:7 claim came from a commit that only edited YAML text with elaborate write-up but no data validation -- exactly why the central registry never accepted it and kept trl:5. Re-validated with a live audit against 1,957 real detected instances plus 600 clean domains. Fixed a Vimeo false-positive class from unfilled CMS template placeholders and generic lightbox JS libraries (223-\u003e0 no-id detections), and a host-validation bypass in the inline-script scanner exploitable via lookalike hosts. See github.com/baditaflorin/go_domain_interactive_demo PR #5.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-liveness-state","domain":"domain-liveness-state.0crawl.com","mesh":"0crawl","host_port":18217,"category":"recon","title":"Domain Liveness State","summary":"Domain liveness classifier — live / under-construction / login-wall / parked / default-server-page / error.","health_url":"https://domain-liveness-state.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_liveness_state","url":"https://domain-liveness-state.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Strongest finding of a 30-service production-DB forensics sweep. tool_version=0.2.0 (433K rows) showed a 52.8% false-unreachable rate, including google.com, apple.com, microsoft.com, amazon.com, facebook.com, cloudflare.com, and wikipedia.org all falsely marked unreachable/high-confidence, cross-validated against an independent sibling fetcher (domain_http3) reaching the same hosts same-day. Root-caused to the classic fleet fetch-cache-masking bug: safehttp.NewClient() had no .WithoutFetchCache(), routing every outbound GET through the shared fleet cache instead of probing origins directly. Fixed (v0.2.2), live-verified against all 8 major domains post-fix. See github.com/baditaflorin/go_domain_liveness_state PR #8 (merged). The bulk of the table (tool_version\u003c0.2.2) still needs re-crawl -- this is the highest-priority re-crawl target in this batch.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-martech-stack","domain":"domain-martech-stack.0crawl.com","mesh":"0crawl","host_port":18213,"category":"web_analysis","title":"Domain Martech Stack","summary":"Martech stack detector — HubSpot/Marketo/Pardot/Eloqua/Mailchimp/etc.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-martech-stack.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_martech_stack","url":"https://domain-martech-stack.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Investigated the same 'false written on failed fetch' pattern (6.0% of rows). Found this repo's response contract already includes both a fleet-canonical Result outcome string and a distinguishing non-200 HTTP status code on every fetch-failure path -- everything a downstream consumer needs to correctly gate on failure instead of writing false. No has_martech field or DB-write code exists anywhere in this repo. Fourth of 4 sibling services confirming the same root cause: a shared ingestion/orchestrator component silently converts missing/omitted fields into a confident false on write. No fix forced, no PR opened.","trl_ceiling":8,"trl_ceiling_reason":"Cold heavy-SPA rendering can exceed the enrichment budget and bot/consent gates hide some client-injected tools.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-naptr-enum","domain":"domain-naptr-enum.0crawl.com","mesh":"0crawl","host_port":18236,"category":"domains","title":"Domain Naptr Enum","summary":"NAPTR + ENUM (E.164) record discovery (RFC 3403/2916/6116).","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-naptr-enum.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_naptr_enum","url":"https://domain-naptr-enum.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Tested against domain_naptr_enum (946,853 rows) and a fresh 2,000-domain sample. Confirmed ENUM essentially never occurs on generic web domains (0/946k). Fixed 3 real bugs: (1) exact-string flag matching silently dropped multi-char NAPTR flags -- verified live against apple.com's actual SIP records (flags=\"se\"); (2) no IDNA/punycode encoding meant IDN domains (e.g. muenchen.de) got a false 'verified empty' instead of the real DNS answer; (3) NXDOMAIN was indistinguishable from 'verified empty' -- 2.55% of a fresh 2,000-domain sample were misreported this way. Also fixed a CVE by bumping a vulnerable x/net dependency. See github.com/baditaflorin/go_domain_naptr_enum PR #3.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-pagination-rel","domain":"domain-pagination-rel.0crawl.com","mesh":"0crawl","host_port":18229,"category":"web_analysis","title":"Domain Pagination Rel","summary":"WHATWG rel=next/prev + Link-header pagination detector.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-pagination-rel.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_pagination_rel","url":"https://domain-pagination-rel.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Caught a rubber-stamp: the repo's local trl:7 commit changed only the number, leaving trl_evidence byte-for-byte identical to the prior trl:5 text. 1,000-domain live audit found and fixed a confusing bug where scheme-only mismatches (http vs https, same host) were misreported identically to real cross-domain hijacks (2/3 of all cross-host flags were this false positive), plus a redirect-cap bug breaking legitimate multi-hop chains, plus a CVE patch. Held at trl:6, not 7, specifically to avoid repeating the rubber-stamp pattern this audit was meant to correct. See github.com/baditaflorin/go_domain_pagination_rel PR #5.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-podcast-presence","domain":"domain-podcast-presence.0crawl.com","mesh":"0crawl","host_port":18227,"category":"content","title":"Domain Podcast Presence","summary":"Podcast presence detector — RSS feed + linked platforms + embedded players.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-podcast-presence.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_podcast_presence","url":"https://domain-podcast-presence.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Real-data audit (2026-07-31, previously unsynced to registry despite a merged fix): fetchPage never checked resp.StatusCode, so a non-2xx homepage response (429 rate-limited, 403 WAF/bot-block, 404, 5xx, or an un-followed 3xx) was silently parsed as if it were the real page. Confirmed live: swordandlaser.com (a genuine podcast site) returned a Squarespace 429 during the audit and was scored a confident, error-free is_podcast_site=false, indistinguishable from a real non-podcast page. Verified via a 1050-domain real Postgres sample (900 random + 150 known-true) run against the actual built binary. Confirmed this repo does NOT have the fleet's common fetch-cache-masking bug (it uses a different fleetfetch client wrapper that correctly surfaces the final post-redirect URL). trl bumped 4-\u003e5; trl_ceiling=7 -- the fix is real and verified, but the fleet-wide raw_domain_podcast_presence-always-NULL evidence-column gap (shared downstream-writer issue, out of scope for this repo) caps it below 7 for now. See github.com/baditaflorin/go_domain_podcast_presence PR #8 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-product-count","domain":"domain-product-count.0crawl.com","mesh":"0crawl","host_port":18242,"category":"web_analysis","title":"Domain Product Count","summary":"E-commerce catalog lower-bound estimator with canonicalized sitemap, JSON-LD, Shopify, and homepage product signals.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-product-count.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_product_count","url":"https://domain-product-count.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"900-domain live audit. Fixed a real bug: the sitemap URL classifier only recognized English /product(s)/ path shapes, so any WooCommerce store with a translated permalink slug (Spanish, French, Italian, German, Turkish) was 100% invisible -- 12/12 evidenced live stores across 5 languages returned 0 products (e.g. one site went 0-\u003e1027). Fixed via locale-independent sitemap filename detection plus a translated-slug fallback list; sum of estimates +10.0% on a clean-paired 325-domain subset. See github.com/baditaflorin/go_domain_product_count PR #4.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-ratelimit-headers","domain":"domain-ratelimit-headers.0crawl.com","mesh":"0crawl","host_port":18234,"category":"web_analysis","title":"Domain Ratelimit Headers","summary":"Validated RateLimit and Retry-After detector with evidence-driven endpoint discovery and HEAD-to-GET fallback.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-ratelimit-headers.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_ratelimit_headers","url":"https://domain-ratelimit-headers.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"994-domain live audit superseding a prior trl:7 self-assessment validated only against synthetic fixtures. Found the fetch-cache-masking bug confirmed live via docker inspect -- a service whose entire job is reading current rate-limit counters was eligible to silently serve stale shared-cache data. Also fixed a false negative (rejected a real API's float-format X-Rate-Limit-Limit as malformed) and a false positive (12 unrelated shared-hosting domains flagged present based on a boilerplate RateLimit-Policy header alone). See github.com/baditaflorin/go_domain_ratelimit_headers PR #4.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-tracker-density","domain":"domain-tracker-density.0crawl.com","mesh":"0crawl","host_port":18238,"category":"web_analysis","title":"Domain Tracker Density","summary":"Tracker density + categorization (DuckDuckGo Tracker Radar, CC0).","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-tracker-density.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_tracker_density","url":"https://domain-tracker-density.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"The prior trl:6 was a code-read-only rubric assignment with no real-data evidence. 900-domain live audit found and fixed 2 real bugs: the fetch layer never checked HTTP status codes, so bot-blocked/dead/error pages were scored as clean homepages with 0 trackers (19.5% of the 'clean' bucket was actually non-2xx); and an error-truncation bug cut off the diagnostically useful tail of wrapped error messages (100% of degraded responses hit the identical generic prefix). Flagged: production is running a 4-week-stale rollback image missing 2 already-merged fixes. See github.com/baditaflorin/go_domain_tracker_density PR #5.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-viewport-meta","domain":"domain-viewport-meta.0crawl.com","mesh":"0crawl","host_port":18233,"category":"web_analysis","title":"Domain Viewport Meta","summary":"Viewport meta tag parser + mobile-friendliness scoring.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-viewport-meta.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_viewport_meta","url":"https://domain-viewport-meta.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Corrected an internal contradiction (repo's own service.yaml had drifted to trl:7 above its own ceiling:5). 916-domain live audit proved the fetch-cache-masking bug live: two back-to-back requests for the same domain returned in 5100ms then 454ms, only explainable by a cache hit. Fixed. Also fixed Safari's shrink-to-fit viewport directive being misfiled as unknown (~4% of viewport-present pages) plus a CVE patch. See github.com/baditaflorin/go_domain_viewport_meta PR #4.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-wikidata-entity","domain":"domain-wikidata-entity.0crawl.com","mesh":"0crawl","host_port":18228,"category":"content","title":"Domain Wikidata Entity","summary":"Wikidata + Wikipedia entity linkage for a domain (P856 match).","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://domain-wikidata-entity.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_domain_wikidata_entity","url":"https://domain-wikidata-entity.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Matching/gating logic is demonstrably correct (100% accurate on every spot-check when it resolves), but the service has operated at \u003c1% real-world success rate for over a month across five releases (status=upstream_error on ~99.6% of recent rows). Could not reproduce the failure from outside the production network -- the same SPARQL/API calls succeeded cleanly from two independent external vantage points, including a 20-request burst, pointing to a production-egress-specific block/throttle by Wikimedia rather than a code bug. Fixed two real, concrete gaps regardless (v0.3.6): fetch-cache bypass was missing (could replay a cached error instead of retrying), and HTTP 429 handling ignored Retry-After with a blind fixed backoff. See github.com/baditaflorin/go_domain_wikidata_entity PR #14 (merged). Held below the prior self-reported trl=7 pending an ops-level escalation (egress IP reputation/rotation with Wikimedia) that a code fix alone cannot resolve.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"dtss","domain":"dtss.0crawl.com","mesh":"0crawl","host_port":8286,"category":"domains","title":"Dtss","summary":"Microservice for Dtss","tags":["domains","go"],"health_url":"https://dtss.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_dtss","url":"https://dtss.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Second-pass re-audit (fresh 400+700-domain sample): no regressions since prior fix. Found and fixed a real bug: probeDKIM treated any DNS lookup error (not just confirmed NXDOMAIN) as 'try next selector', unlike probeSPF/probeDMARC which already got this fix -- live-verified reclassifying a false-negative DKIM result to correctly indeterminate. Fetch-cache anti-pattern hardened defensively (safehttp.WithoutFetchCache() added) though FLEET_FETCH_CACHE_URL is not currently set for this service. See PR #8 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"email-extractor","domain":"email-extractor.0crawl.com","mesh":"0crawl","host_port":8287,"category":"domains","title":"Email Extractor","summary":"Microservice for Email Extractor","tags":["domains","go"],"health_url":"https://email-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_email_extractor","url":"https://email-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh 80-domain live re-crawl): explicitly ruled out fetch-cache as a bug (present but deliberate/low-impact for this one-shot crawl pattern). Found and fixed 3 real false-positive bugs: contact-form placeholder text extracted as a real address (worst case: a Cloudflare-obfuscated name@architectink.com reported as top contact at 0.90 confidence), a missing German junk-domain gazetteer entry, and URL userinfo syntax (user@host) misparsed as email. See PR #11 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"email-harvester","domain":"email-harvester.0crawl.com","mesh":"0crawl","host_port":8137,"category":"recon","title":"Email Harvester","summary":"Microservice for Email Harvester","tags":["go","recon"],"health_url":"https://email-harvester.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_email_harvester","url":"https://email-harvester.0crawl.com","example":"/go_email_harvester?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit: confirmed genuinely differentiated from sibling go_email_extractor (light 4-page keyword crawl, no confidence scoring, vs. the extractor's deep 20-page BFS with MX/disposable validation) -- and confirmed via domain_email_contact.tool_name that this service isn't wired into the production enrichment pipeline at all (0 rows attributed vs. the sibling's 1M+). Found and fixed 3 real bugs, all confirmed live: (1) zero local-part placeholder filtering, unlike the sibling -- confirmed on the identical architectink.com domain the sibling's own audit found; (2) 9 missing junk-domain gazetteer entries (company.com, mystore.com, etc, hundreds of live occurrences each); (3) a greedy TLD regex producing malformed run-on domains (gmail.comdisclaimer) -- confirmed this is a SHARED bug also present in go_email_extractor, reproducing identically on the same URL, meaning that sibling's earlier fix did not close this specific gap. trl/trl_ceiling held at 6/7 -- what's blocking 6-\u003e7 isn't these bugs, it's the complete absence of production-scale evidence for this specific service. See PR #6 (merged).","trl_ceiling":7,"trl_ceiling_reason":"Emails hidden behind JavaScript or forms require rendering and interaction.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"embed-iframe-classifier","domain":"embed-iframe-classifier.0crawl.com","mesh":"0crawl","host_port":18255,"category":"content","title":"Embed Iframe Classifier","summary":"Inventories and classifies every \u003ciframe\u003e, \u003cembed\u003e, and \u003cobject\u003e on a web page or raw HTML: resolved-absolute src/data, host, and a curated provider/category label (youtube/vimeo video, google_maps/openstreetmap maps, twitter/facebook social, spotify/soundcloud audio, google_docs/codepen docs, typeform/airtable forms, ads_analytics), plus per-provider and per-category counts.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://embed-iframe-classifier.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_embed_iframe_classifier","url":"https://embed-iframe-classifier.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Real DOM walk over golang.org/x/net/html (no regex over HTML structure): parses the whole document and recursively collects every \u003ciframe\u003e/\u003cembed\u003e/\u003cobject\u003e in document order, descending into \u003cobject\u003e subtrees so a fallback iframe/embed nested as object content is still inventoried. The source attribute is picked per element (src for iframe/embed, data for object) and resolved to an absolute URL against the page's final post-redirect fetched URL via net/url ResolveReference, so a relative or protocol-relative src is reported absolute with a derived lower-cased host. Classification is by registrable-domain host SUFFIX (host == suffix or ends with .suffix) so www./m./player./open. subdomains all land on the same provider, and a couple of path checks disambiguate same-host providers (google.com/maps -\u003e google_maps; docs.google.com/forms -\u003e google_forms ahead of generic google_docs). The curated provider table covers video (youtube incl. youtube-nocookie/youtu.be, vimeo, dailymotion, wistia, loom, twitch), maps (google_maps, openstreetmap), social (twitter incl. x.com, facebook incl. fb/fb.watch/facebook.net, instagram, linkedin, reddit, tiktok), audio (spotify, soundcloud, anchor), docs (google_docs, slideshare, scribd, codepen, jsfiddle, codesandbox, github_gist), forms (typeform, airtable, google_forms), and ads_analytics (doubleclick, googlesyndication, googletagmanager, google-analytics). Anything not on the finite list falls to provider/category other rather than being guessed — the honest TRL-4 ceiling, since novel embed hosts cannot be classified without an external dataset (the TRL-5+ ceiling). A src-less iframe (srcdoc-only / JS-filled) is still counted with provider/category inline and an empty host. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so many producers scanning the same URL trigger one upstream fetch; plain-HTML render mode (static DOM, no JS). SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs; the input guard is OUTBOUND-only and never inspects relative iframe srcs. Direct text= mode scans pasted HTML with no fetch (empty base, so relative srcs stay as-is). Per-failure notes pushed to degraded[] (fetch_failed, empty_body, no_embeds, srcless_embed) instead of failing the response; degraded[] is always a non-nil slice. 30 unit tests cover every provider family, category bucketing, host-suffix subdomain matching, lookalike-host rejection, embed src vs object data, relative + protocol-relative resolution, unresolved-without-base, srcless inline handling, by_provider/by_category counts, document-order preservation, embeds anywhere in the tree, object-nested fallback, no-embeds, garbage/data-URI input safety, plus handler text-mode, parse-input aliases, missing-param 400, and SSRF rejection. /selftest exercises the pure-logic pipeline (youtube/vimeo classification, relative resolution, object data, srcless inline, host-suffix subdomains, by_provider/by_category counts, unknown-\u003eother, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"emotional-tone","domain":"emotional-tone.0crawl.com","mesh":"0crawl","host_port":8288,"category":"domains","title":"Emotional Tone","summary":"Microservice for Emotional Tone","tags":["domains","go"],"health_url":"https://emotional-tone.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_emotional_tone","url":"https://emotional-tone.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Corrected DOWNWARD from trl:6, which sat above this record's own documented trl_ceiling of 5 (CPU-only lexicon/cue method, no sarcasm/irony/syntactic context) -- a pre-existing contradiction (registered via PR #30, 'register-emotional-tone-3.3.0', predating this session's audit) not supported by real evidence beyond what the ceiling itself already caps. No code changes needed; this repo's own v3.3.0 chrome/boilerplate-exclusion work is genuine and already reflected in trl_ceiling=5. Pure registry bookkeeping correction, no PR.","trl_ceiling":5,"trl_ceiling_reason":"CPU-only lexicon/cue method: no sarcasm/irony/syntactic context, and per-language cue lists are necessarily positive-skewed; reaching 6 needs RFC-grade evidence trails + production cross-checks beyond a lexicon.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"env-finder","domain":"env-finder.0crawl.com","mesh":"0crawl","host_port":8344,"category":"recon","title":"Env Finder","summary":"Microservice for Env Finder","tags":["go","recon"],"health_url":"https://env-finder.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_env_finder","url":"https://env-finder.0crawl.com","example":"/go_env_finder?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (fresh 260-domain sample, live before/after with 12-way concurrency): found and fixed 2 major bugs. (1) A 98% false-positive rate from blanket WAF/security-plugin 403 pages misread as leaked files -- one domain alone produced 19 fabricated findings from a single generic Sucuri block page; fixed with cross-path dedup (a repeating 403 body across 2+ distinct paths is dropped as a blanket rule), dropping 52-\u003e3 false 403s sample-wide with zero genuine findings lost. (2) proxy_egress: true was a complete no-op since it was enabled -- the metadata flag was set but the hand-rolled http.Client never actually wired a proxy, so HTTPS_PROXY was silently ignored and every probe went out direct from the dockerhost IP since May 2026; fixed by switching to safehttp.NewClient with WithoutFetchCache. Also added 3 missing .env path variants. trl/trl_ceiling held at 6/6, now honestly earned -- pre-fix the uplift's headline FP claim didn't hold against live traffic. See PR #8 (merged).","trl_ceiling":6,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"feed-finder","domain":"feed-finder.0crawl.com","mesh":"0crawl","host_port":8164,"category":"web_analysis","title":"Feed Finder","summary":"Microservice for Feed Finder","tags":["go","web-analysis"],"health_url":"https://feed-finder.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_feed_finder","url":"https://feed-finder.0crawl.com","example":"/go_feed_finder?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"RSS/Atom/JSON autodiscovery, conventional feed probes, WordPress JSON hinting, feed parsing, source/confidence output, and unit tests.","trl_ceiling":7,"trl_ceiling_reason":"Dynamic feed links hidden behind JavaScript need headless rendering for full coverage.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"file-inclusion","domain":"file-inclusion.0crawl.com","mesh":"0crawl","host_port":8221,"category":"security","title":"File Inclusion","summary":"Microservice for File Inclusion","tags":["go","security"],"health_url":"https://file-inclusion.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_file_inclusion","url":"https://file-inclusion.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (60-domain sample, live before/after): found and fixed 2 real bugs. (1) Fetch-cache masking -- for a re-scanning LFI/RFI prober, a domain probed twice within the cache TTL got stale cached bytes back, silently invalidating re-scan results; fixed. (2) A false-positive error_disclosure detector matching bare include(/require( anywhere in the response body -- also the literal CommonJS/webpack/RequireJS module-loader call inlined in countless ordinary sites' JS bundles; reproduced a fixture with zero PHP flagging 'medium severity PHP error disclosure' on all 16 payloads; fixed by requiring genuine PHP warning-dump framing (Warning:/Fatal error:) immediately before the call. Real ceiling correction: trl_ceiling was 5 (equal to trl, i.e. no headroom at all), but the service's own trl_evidence names only non-structural gaps (auth follow-up, SSRF chain pivot, rate adaptation) as the reason for the cap, and comparable single-shot probers in the fleet sit at TRL 6-7 -- corrected to trl_ceiling=8, trl bumped 5-\u003e6. See PR #4 (merged).","trl_ceiling":5,"trl_ceiling_reason":"needs auth state for deeper testing","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"firmographic-profile","domain":"firmographic-profile.0crawl.com","mesh":"0crawl","host_port":18297,"category":"domains","title":"Firmographic Profile","summary":"Clearbit-style company firmographic profile: industry, employee band, founding year, legal entity, revenue model, office locations, funding — 8 fleet analyzers merged via composite-runner.","tags":["go","kind-container"],"health_url":"https://firmographic-profile.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_firmographic_profile","url":"https://firmographic-profile.0crawl.com","example":"/?target=stripe.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Live production-DB audit found employee_band/revenue_model populated on only 3.3% of successful rows, and github.com returned employee_band=1-10 (factually wrong for a company with thousands of staff). Root-caused live: an upstream composite-runner sub-service's weighted-signal-fusion result contradicted its own published evidence (8x 'enterprise_language' signals outweighed by an annotated-as-unreliable 3x 'team_members' signal that still won the verdict). shopify.com/notion.so were confirmed to be stale pre-gate-fix rows, not a live detection gap -- live re-invocation resolves both correctly today. Fixed (v1.2.2) with a symmetric cross-check that abstains when a different band's signals outweigh the one actually returned, verified not to false-abstain on shopify.com's internally-consistent signals. See github.com/baditaflorin/go_firmographic_profile PR #10 (merged).","trl_ceiling":8,"trl_ceiling_reason":"Reaches TRL 8 with real-time funding data integration and structured output validation.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"founding-year","domain":"founding-year.0crawl.com","mesh":"0crawl","host_port":8289,"category":"domains","title":"Founding Year","summary":"Microservice for Founding Year","tags":["domains","go"],"health_url":"https://founding-year.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_founding_year","url":"https://founding-year.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit: found and fixed a live fetch-cache-masking bug, confirmed via before/after debug logging directly on the fleet host showing requests rerouting away from the cache post-fix. Also resolved the founding-year side of a cross-service field-mismatch investigation with go_company_size: the actual contract is data.best_estimate.year (int) / data.consensus_year (int) -- no field named 'founding_year' exists; corrected a stale doc comment. Flagged (not fixed, out of scope) a shared-DB provenance bug where founding-year/company-size/api-first all clobber the same tool_name/tool_version columns. See PR #13 (merged).","trl_ceiling":8,"trl_ceiling_reason":"Live verdict on bot-hostile mega-brands (bmw.de/leroymerlin.fr/decathlon.fr/mango.com) is bounded by the upstream fetch tier: their about/company pages return empty bodies (JS-heavy/bot-blocked), so non-English founding text never reaches the parser and the verdict falls back to whois. There is no domainscope/stored-output table to measure live accuracy against. TRL 8 (SLA-grade live extraction) is not provable without a warmer fetch/render tier or a persisted output table; the extractor logic itself is sound and fully unit-tested.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"funding-detector","domain":"funding-detector.0crawl.com","mesh":"0crawl","host_port":8290,"category":"domains","title":"Funding Detector","summary":"Microservice for Funding Detector","tags":["domains","go"],"health_url":"https://funding-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_funding_detector","url":"https://funding-detector.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh 40+Korean-domain sample): confirmed prior fixes intact and fetch-cache pattern correctly not applicable (uses fleetfetch, live cache_hit:false verified). Found and fixed a real bug: KRW (Korean won) amounts were silently dropped because the currency-prefix matcher checked bare 'kr' (Nordic krona) before the 'KRW' ISO code in an ordered case-insensitive prefix scan. See PR #14 (merged).","trl_ceiling":8,"trl_ceiling_reason":"Production-grade LIVE detection rate is bounded by the upstream fleetfetch RenderJS render-cache (HTTP 502 'no pages reachable' on every probe today, confirmed against stripe/google/github/microsoft), and there is no stored-output table to measure against. Detector logic is sound and fully unit-tested; TRL 8 (SLA-grade live) is not provable without a warmer fetch tier or a persisted output table.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"funding-signal","domain":"funding-signal.0crawl.com","mesh":"0crawl","host_port":18293,"category":"domains","title":"Funding Signal","summary":"Best-effort funding signal (latest round, total, investors, press) for a brand/domain from Crunchbase + brand press pages + Google News RSS","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://funding-signal.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_funding_signal","url":"https://funding-signal.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":4,"trl_evidence":"40/40 real-world audit: before this fix, the only two live sources were producing 0% correct non-zero hits, requiring a brand-mention-in-headline gate before mining news for funding. Corrected DOWNWARD from a previously-claimed trl=7 that was not supported by real evidence -- catalog showed trl:7 with no trl_ceiling prior to this audit. Post-fix: all 40 false positives correctly suppressed to empty while true positives on well-known companies are preserved. See github.com/baditaflorin/go_funding_signal PR #4.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"gdpr-compliance","domain":"gdpr-compliance.0crawl.com","mesh":"0crawl","host_port":8291,"category":"domains","title":"Gdpr Compliance","summary":"Microservice for Gdpr Compliance","tags":["domains","go"],"health_url":"https://gdpr-compliance.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_gdpr_compliance","url":"https://gdpr-compliance.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit: found and fixed a subtle masking bug -- when the JS renderer silently fails/times out and falls back, the response header still claimed render_mode=js, hiding the fallback and turning real renderer failures into false-negative 'no cookie banner' results. Live-confirmed against a real domain with a genuine cookie-consent banner. See PR #14 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"go-oauth-mapper","domain":"go-oauth-mapper.0crawl.com","mesh":"0crawl","host_port":8330,"category":"infrastructure","title":"Go Oauth Mapper","summary":"Microservice for Oauth Mapper","tags":["go","infrastructure"],"health_url":"https://go-oauth-mapper.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_oauth_mapper","url":"https://go-oauth-mapper.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"OIDC/OAuth well-known parsing, JWKS probing, deprecated-flow/security issue triage, endpoint origin checks, SSRF guard, and tests. TRL-uplift audit (2026-08-08) found httpClient (handler.go) built via bare safehttp.NewClient() -- no WithoutFetchCache -- so whenever FLEET_FETCH_CACHE_URL is set (the deploy default), every well-known/JWKS/HTML-fallback GET this service issues silently routed through the process-wide fleet fetch-cache delegate instead of the live issuer: a since-rotated JWKS key or a newly-published code_challenge_methods_supported entry could go unreported with no error or signal that a cache hit (not a live fetch) produced the result. Fixed by adding safehttp.WithoutFetchCache() to httpClient; WithForceHTTP2 deliberately omitted since this service never reads resp.TLS or calls safehttp.NegotiatedProtocol. New regression test handler_fetchcache_test.go installs a stub safehttp.FetchDelegate and proves the fix: fails pre-fix (delegate consulted, stale body returned), passes post-fix (live httptest origin reached). Live-verified post-fix against real providers: accounts.google.com and gitlab.com both resolved live openid-configuration + 17 live JWKS keys each via DiscoverWellKnown. Bumped to v1.5.5. See github.com/baditaflorin/go_oauth_mapper PR #10 (open, not yet merged as of 2026-08-08).","trl_ceiling":7,"trl_ceiling_reason":"Runtime auth-flow verification needs client credentials or interactive login state.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"google-taxonomy","domain":"google-taxonomy.0crawl.com","mesh":"0crawl","host_port":8096,"category":"domains","title":"Google Taxonomy","summary":"Deterministic Google Product Taxonomy lookup, fuzzy search, and TF-IDF classifier with confidence-based abstention.","tags":["domains","go"],"health_url":"https://google-taxonomy.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_google_taxonomy","url":"https://google-taxonomy.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Part of a fleet-wide TRL audit (round 15). Found and fixed a genuine, high-impact bug: closed a generic-head-noun false-positive loophole in the abstain gate. Not bumped to 8: no cross-check mechanism exists and the 852K-row backlog hasn't been reprocessed/validated end-to-end. See github.com/baditaflorin/go_google_taxonomy PR #6.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"graphql-introspection","domain":"graphql-introspection.0crawl.com","mesh":"0crawl","host_port":8147,"category":"security","title":"Graphql Introspection","summary":"Microservice for Graphql Introspection","tags":["go","security"],"health_url":"https://graphql-introspection.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_graphql_introspection","url":"https://graphql-introspection.0crawl.com","example":"/go_graphql_introspection?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"TRL 6 (real). Beyond endpoint discovery + introspection summary,\nv3 adds three orthogonal abuse probes used by every commercial GraphQL\nscanner (Inspectiv, GraphCrawler, InQL): alias-batching DoS multiplier,\nfield-suggestion info-leak, and text/plain CSRF bypass. Findings are\nemitted with stable severity-tagged classes (introspection-enabled,\nalias-batching-unbounded, csrf-possible, field-suggestions-enabled,\nintrospection-partial) so the catalog UI and sibling services\n(api-extractor, swagger-finder) join on `class` strings without any\nper-service mapping table. 21 Go test functions covering ≥6 server-\nbehaviour fixtures (canned introspection, explicit-disabled,\nfield-suggestion typo, alias-batched echo, CSRF accept, CSRF block).\nSee docs/adr/0001-trl-uplift-to-6.md.\n\n2026-08-08: fixed fleet-wide safehttp bug class in the service itself (not the TRL claim above, which stands independently). newClient() in handler.go called safehttp.NewClient() bare, with no fetch-cache/HTTP2 opt-outs, so a process-wide default fetch delegate (when FLEET_FETCH_CACHE_URL is set) could silently serve this scanner stale cached responses instead of the live origin during discover/introspect/abuse probing -- masking real fetch failures as stale \"successes\" (or the reverse), and risking ALPN mishandling against HTTP/2-only GraphQL gateways. Fixed by passing safehttp.WithoutFetchCache() and safehttp.WithForceHTTP2() to the constructor, bumping Version 3.0.3 -\u003e 3.0.4. Added regression test safehttp_client_test.go:TestNewClient_BypassesFetchCacheAndHonorsHTTP2 (installs a fake stale delegate, asserts the client observes the live origin directly; confirmed it fails against the pre-fix bare constructor and passes post-fix). Live-verified scan() against 3 real public GraphQL endpoints post-fix (countries.trevorblades.com, spacex-production.up.railway.app, rickandmortyapi.com/graphql), all returned correct live introspection data. PR (open, unmerged): https://github.com/baditaflorin/go_graphql_introspection/pull/7","trl_ceiling":6,"trl_ceiling_reason":"Authenticated GraphQL schemas need user-supplied tokens and role-aware probing.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"heading-outline-extractor","domain":"heading-outline-extractor.0crawl.com","mesh":"0crawl","host_port":18247,"category":"content","title":"Heading Outline Extractor","summary":"Extracts the heading structure (h1-h6) of a web page or raw HTML and builds a nested document outline plus accessibility diagnostics — per-level counts, max nesting depth, and structure warnings (no_h1, multiple_h1, first_heading_not_h1, skipped_level, empty_heading).","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://heading-outline-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_heading_outline_extractor","url":"https://heading-outline-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Real DOM walk over the golang.org/x/net/html tokenizer (no regex for HTML structure): recurses the parsed document in document order collecting every h1-h6 with its resolved numeric level, collapsed visible text, and id attribute. skipTags subtrees (script/style/noscript/svg/template/head/iframe/object/embed) are pruned before text collection so an h-tag embedded in an inline SVG title or a \u003ctemplate\u003e never pollutes the outline, and script/style text never leaks into a heading's label. The nested outline is built with a single-pass ancestor-stack algorithm (pop until the stack top is a strictly-lower level, attach, push) which is the standard 'nest under the most recent heading of a lower level' rule — it tolerates skipped levels (h1 directly to h3 still nests the h3 under the h1), multiple roots (each h1 starts a new root), and a leading deep heading without losing any node. Reports per-level counts (h1..h6 + total), max nesting depth, and an advisory issues[] of accessibility/structure warnings (no_h1, multiple_h1, first_heading_not_h1, skipped_level:hX-\u003ehY for any deeper-by-more-than-one jump, empty_heading) — all advisory, never fatal. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so N producers analysing the same URL trigger one upstream fetch; plain-HTML render mode (heading structure lives in the served HTML, not a JS-rendered DOM — the documented TRL-4 ceiling for SPAs that build headings client-side). Direct text= mode analyses pasted HTML with no fetch. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Per-failure notes pushed to degraded[] (fetch_failed, no_extractable_text, no_headings) instead of failing the response; a page with zero headings still returns 200. 26 unit tests cover document-order extraction, id capture, whitespace collapse, script/style stripping inside headings, inline-markup flattening, template/svg pruning, outline nesting (simple/deep/skipped-level/multiple-roots/leading-deep), depth measurement, per-level counts, every diagnostic (no_h1, multiple_h1, skipped_level, empty_heading, ascent-is-not-a-skip, clean-document), parse-input aliases, missing-param 400, SSRF rejection, and the handler text-mode + no_headings degraded paths. /selftest exercises the pure-logic pipeline (order, skipped-level, multiple-h1, empty-heading, nested depth, script/style stripping, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"hidden-fields","domain":"hidden-fields.0crawl.com","mesh":"0crawl","host_port":8345,"category":"recon","title":"Hidden Fields","summary":"Microservice for Hidden Fields","tags":["go","recon"],"health_url":"https://hidden-fields.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_hidden_fields","url":"https://hidden-fields.0crawl.com","example":"/go_hidden_fields?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Pure-Go x/net/html DOM walker. Per-field role taxonomy (csrf-token,\nhoneypot, state, id, timestamp, flag, viewstate, session, other) plus\nsix risk rules (csrf-on-get, honeypot-default, sensitive-plaintext,\nstate-without-nonce, timestamp-future/epoch-zero, javascript-action).\nToken-like values masked before serialisation (raw value never escapes\nthe process). 23 unit + integration tests against canned login,\nsignup, OAuth, GET-csrf, javascript:-action, and PII fixtures via\nhttptest.Server. safehttp SSRF guard + 5s per-request / 10s total\nbudget. ADR docs/adr/0001-trl-uplift-to-6.md.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"host-header","domain":"host-header.0crawl.com","mesh":"0crawl","host_port":8240,"category":"security","title":"Host Header","summary":"Microservice for Host Header","tags":["go","security"],"health_url":"https://host-header.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_host_header","url":"https://host-header.0crawl.com","example":"/go_host_header?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"\u003e","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"hsts-checker","domain":"hsts-checker.0crawl.com","mesh":"0crawl","host_port":8328,"category":"infrastructure","title":"Hsts Checker","summary":"Microservice for Hsts Checker","tags":["go","infrastructure"],"health_url":"https://hsts-checker.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_hsts_checker","url":"https://hsts-checker.0crawl.com","example":"/go_hsts_checker?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Pure-Go RFC 6797 directive parser with case-insensitive directive names,\nquoted-string handling, negative/garbage rejection, and whitespace\ntolerance (parse_test.go covers 9 cases). Embedded Chromium HSTS preload\nlist snapshot revision 2026-05-16.1 (~190 entries) with TLD-wide\ntreatment for .gov/.dev/.app/.page/.new and parent-domain inheritance.\nPlaintext HTTP→HTTPS redirect probe captures the full chain (up to 5\nhops) and reports the final scheme. Standalone TLS handshake check\nrecords negotiated version, cipher suite, full chain length, and\nperforms explicit hostname + chain verification against the system\ntrust store. Grading rubric (F/D/C/B/A/A+) per\ndocs/adr/0001-trl-uplift-to-6.md, with A+ requiring corroboration from\nthe bundled snapshot (not just the preload directive on the wire).\nTest surface: parse_test.go + preload_test.go + grade_test.go +\nhandler_test.go (httptest.NewTLSServer for HSTS variants, separate\nhttp test server for the redirect probe).","trl_ceiling":5,"trl_ceiling_reason":"needs real browser DOM for verification","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"http-method-tester","domain":"http-method-tester.0crawl.com","mesh":"0crawl","host_port":8087,"category":"security","title":"Http Method Tester","summary":"Microservice for Http Method Tester","tags":["go","security"],"health_url":"https://http-method-tester.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_http_method_tester","url":"https://http-method-tester.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh 250-domain sample, live before/after): found and fixed a major false-positive bug -- classify() computed a plain-GET baseline but only ever used it for one classification rule (server-fingerprint), ignoring it everywhere else. Result: 86% (430/498) of verb-tampering/http-method-unrestricted-write findings across the sample were CDN/WAF edge servers responding byte-identically to every verb including an impossible one like FOO -- ordinary verb-agnostic edge delivery, not a confirmed bypass, reported as high/medium severity. Fixed with a sameAsGetBaseline + catchAllSuspected corroboration gate (requires an impossible verb to also match GET before downgrading, so one coincidental match can't mask a real bug): verb-tampering high 54-\u003e8, unrestricted-write high 174-\u003e43. Also hardened the scanner's own GET baseline against fetch-cache masking (the write-verb probes themselves were never at risk per go-common's GET-only cache eligibility gate). trl/trl_ceiling held at 7/7 -- reaching 8 would need corroboration beyond a single self-diffing scan (a second fetch or a shared WAF/CDN classifier), not more CPU-only logic. See PR #4 (merged).","trl_ceiling":7,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"http-protocol","domain":"http-protocol.0crawl.com","mesh":"0crawl","host_port":8241,"category":"infrastructure","title":"Http Protocol","summary":"Microservice for Http Protocol","tags":["go","infrastructure"],"health_url":"https://http-protocol.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_http_protocol","url":"https://http-protocol.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"v2.4.0 adds IDNA2008 (RFC 5891 lookup-profile) U-label-\u003eA-label host normalization in validateTargetURL before DNS, the SSRF gate, TLS SNI, the Host header, and the h3 ServerName; before this every Unicode IDN host (munchen.de, japanese, cyrillic .rf, greek .gr) hard-failed with a no-such-host 400 because Go's resolver/crypto-tls require ASCII A-labels and do not auto-encode U-labels. Live before-\u003eafter: 6/6 U-label probes 400'd on 2.3.1; on 2.4.0 4 resolve+probe correctly and 2 fail honestly on the correctly-encoded A-label (hosts lack live A records). Uses golang.org/x/net/idna (already a direct dep, zero new modules). Sits on the existing RFC-compliant 5-protocol probe matrix + negotiated/advertised/inconclusive/unsupported capability classifier with evidence trail. New idn_test.go adds 7 table-driven tests across 4 scripts incl ports/IP literals/malformed-fallback/end-to-end validateTargetURL; go build/test/vet/gofmt all green.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"iban-bic-validator","domain":"iban-bic-validator.0crawl.com","mesh":"0crawl","host_port":18291,"category":"domains","title":"Iban Bic Validator","summary":"Offline IBAN (ISO 13616 MOD-97) and BIC (ISO 9362) validator — domains mesh, TRL-7","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://iban-bic-validator.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_iban_bic_validator","url":"https://iban-bic-validator.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":8,"trl_evidence":"Real 900-URL production-data audit. Fixed a BIC country-code false positive and expanded the IBAN registry 33-\u003e47 countries, cross-checked against a 50/50 real-IBAN sample with zero disagreements. 35 passing tests. See github.com/baditaflorin/go_iban_bic_validator PR #1.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"idor-finder","domain":"idor-finder.0crawl.com","mesh":"0crawl","host_port":8242,"category":"security","title":"Idor Finder","summary":"Microservice for Idor Finder","tags":["go","security"],"health_url":"https://idor-finder.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_idor_finder","url":"https://idor-finder.0crawl.com","example":"/go_idor_finder?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"TRL 7 (2026-08-20 fleet TRL audit; reassessed up from stale registry TRL 6 dated 2026-05-16, which predated this repo self-reporting v3.1/TRL 7 in its own service.yaml on the same date). Fresh clone of origin/main (github.com/baditaflorin/go_idor_finder @ d9fe586, go-common@v0.88.0) read end to end.\n\nDetection logic confirmed sound by direct code review plus the full 28-test suite (all passing): DetectIDs (detect_id.go) classifies path/query fragments into integer/UUID/ObjectId/base64 candidates, gating plain integers on an ID-shaped param name so a page-number query param is not mistaken for an IDOR target; Variations (variants.go) applies shape-appropriate mutations (sequential +/-1, +/-10, +rand; UUID segment rotation plus nil-UUID; ObjectId counter-byte flip plus zero-OID; base64 last-byte flip); ClassifyProbe (classify.go) diffs each mutated response against the authenticated baseline by status/hash/length-similarity/user-data-field sniffing, with an auth-guard-copy check so a 200 login-required page is not misread as a hit. runAuthStrip/runAuthSwap (handler_run.go) and the A/B pair-probe (pair_probe.go, session_id + go-pentest-session-state) provide the auth-bypass and cross-session canonical IDOR proof paths respectively. ALL outbound probe traffic is GET-only with no request body (fetch() in probe.go hardcodes http.MethodGet) - confirmed the tool cannot perform destructive/write operations against a real target, so its methodology is safe to run against live third-party endpoints.\n\nFound and fixed one real, live correctness bug: probe.go's newSafeClient() called bare safehttp.NewClient(), which (per go-common@v0.88.0 safehttp/safehttp_helpers.go: useDefaultFetchCache := !noFetchCache \u0026\u0026 !withoutProxy \u0026\u0026 !forceHTTP2) opts every outbound GET into the process-wide DefaultFetchDelegate whenever FLEET_FETCH_CACHE_URL is set fleet-wide. Every request this scanner sends is an eligible body-less GET. The fetch-cache correctly keys on forwarded headers (auth-strip vs. authenticated baseline do not collide), but a cache hit can still be up to ~60s stale by default - enough to make a just-patched IDOR read as still vulnerable, or a still-vulnerable endpoint read as safe off a replayed auth-guard response, directly undermining this tool's core live baseline-vs-variant diff methodology. This is the same fleet-wide bug class documented in go-common's WithForceHTTP2 doc comment (go_page_load_metrics, 2026-07). Fixed with .WithoutFetchCache() (WithForceHTTP2 not needed - this service does not depend on ALPN signals); added fetchcache_bypass_test.go, a regression test confirmed to fail on the bare client and pass with the fix; bumped service version 3.1.4 -\u003e 3.1.5. Fix shipped as PR github.com/baditaflorin/go_idor_finder/pull/11 (open, not merged per audit policy).\n\nLive external verification against a real target was not practical from this audit environment (idor-finder.0crawl.com not reachable from the sandbox network, and it is API-key gated) - confidence instead rests on the full local test suite plus direct reading of both this repo and the shared safehttp/fleetfetch libraries it depends on. TRL 7 (not lowered) is reaffirmed: the bug was in outbound freshness, not in the vulnerability-detection methodology itself, and is now fixed pending PR merge.","trl_ceiling":8,"trl_ceiling_reason":"True IDOR proof for unauthenticated scans still requires an external verifier/manual confirmation; TRL 8 (field-proven) needs sustained production incident history without the fetch-cache staleness class of bug.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"iframe-analyzer","domain":"iframe-analyzer.0crawl.com","mesh":"0crawl","host_port":8243,"category":"security","title":"Iframe Analyzer","summary":"Microservice for Iframe Analyzer","tags":["go","security"],"health_url":"https://iframe-analyzer.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_iframe_analyzer","url":"https://iframe-analyzer.0crawl.com","example":"/go_iframe_analyzer?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"1.3.1: real CSP3 §6.7.7.7 frame-ancestors source-list parser (none/self/wildcard/scheme/host with port/path/wildcard kinds); X-Frame-Options parser (DENY/SAMEORIGIN/ALLOW-FROM with deprecation flag); ComputeFramingPosture cross-check returning {deny,sameorigin,explicit,open}+Conflicts; client.Fetch. 10/10 corpus PASS; verified: Cloudflare correctly flagged with verdict=deny + conflict 'CSP says deny, XFO disagrees: sameorigin'.","trl_ceiling":7,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"information-leakage","domain":"information-leakage.0crawl.com","mesh":"0crawl","host_port":8083,"category":"security","title":"Information Leakage","summary":"Detects information disclosure patterns: internal paths, version strings, stack traces, build IDs in HTML/headers/error pages.","tags":["go","infoleak"],"health_url":"https://information-leakage.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_information_leakage","url":"https://information-leakage.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"2026-08-20 re-audit of go_information_leakage @ go-common v0.88.0 (fleet-runner rollout tip, commit 3b088f1). Confirmed live bug: scanClient (scan.go) was built via fleetfetch.NewHTTPClient(WithRender, WithFallbackOnTimeout, WithTimeout) with no fleetfetch.WithoutCache(), so every real probe -- baseline, error-triggers, debug routes, AND the content-verified backup checks (/.git/HEAD, /.git/config, /.env, /.DS_Store, /.svn/entries) -- was routed through the shared, Redis-backed, cross-service fleet fetch cache instead of fetching the target live. For a leak detector this is a correctness bug, not an efficiency one: a re-scan inside the cache TTL could replay a since-remediated exposure as still-leaking, or mask a newly-introduced one behind a stale negative-cached miss; a genuine .env hit's secret bytes would also sit in the shared cache readable by any other fleet service requesting the same URL+render. The scanner's own probes (a fresh crypto/rand UUID 404 path per scan, one-shot existence checks) are exactly the case fleetfetch's own WithoutCache doc comment calls out. Fixed by extracting newScanClient() and adding fleetfetch.WithoutCache() (dropped WithRender/WithFallbackOnTimeout as documented no-ops once WithoutCache is set); added TestScanClient_BypassesSharedFetchCache, confirmed failing pre-fix (returned a fake stale-cache body instead of the live target's) and passing post-fix. go build/vet/test all clean (24+ existing tests unaffected). Version bumped 3.0.5-\u003e3.0.6 in main.go + service.yaml. Fix opened as PR https://github.com/baditaflorin/go_information_leakage/pull/9 (not merged, per audit process). Detection design itself holds up: content-verified backup hits defeat SPA catch-all false positives, a generic-error control group defeats WAF-identical-response false positives on debug routes, per-finding severity rubric, SCOPE_GUARD_URL allowlist, 5s/req + 30s total caps. TRL 6 reaffirmed (not raised/lowered): the cache bug was a latent correctness gap under scan-freshness expectations, not a basic-operation failure, and it is now fixed with a regression test pinning it.","trl_ceiling":5,"trl_ceiling_reason":"needs real browser DOM for full JavaScript inspection","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"ipv6-checker","domain":"ipv6-checker.0crawl.com","mesh":"0crawl","host_port":8244,"category":"infrastructure","title":"Ipv6 Checker","summary":"Microservice for Ipv6 Checker","tags":["go","infrastructure"],"health_url":"https://ipv6-checker.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_ipv6_checker","url":"https://ipv6-checker.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"v2.0.0 uplift from TRL 3 to TRL 6:\n- Per-record A/AAAA resolution via miekg/dns with explicit TTL +\n  source-resolver attribution (1.1.1.1 / 8.8.8.8 fallback).\n- Family-pinned TCP probes (tcp4/tcp6) on ports 80 + 443 with a\n  3s connect timeout each; reports open/closed/timeout/skipped.\n- Real TLS handshake on reachable 443 with strict SNI (no\n  InsecureSkipVerify), reports offered + negotiated ALPN.\n- Dual-stack classification (ipv4-only / ipv6-only / dual-stack /\n  no-records).\n- Per-family connect_ms recorded so consumers can compute Happy\n  Eyeballs (RFC 8305) fallback cost.\n- SSRF guard refuses private/loopback/link-local/CGNAT addresses\n  unless ALLOW_PRIVATE=1.\n- Resolver + dialer interfaces injected from tests; 4-case\n  classification matrix + probe + happy-eyeballs unit tests pass.\n- 15s total request budget enforced via context.WithTimeout.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"js-framework-version-extractor","domain":"js-framework-version-extractor.0crawl.com","mesh":"0crawl","host_port":18258,"category":"content","title":"Js Framework Version Extractor","summary":"Detects JavaScript frameworks/libraries and their versions from STATIC markup only (no JS execution) on a web page or raw HTML: parses versioned CDN \u003cscript src\u003e URLs (react@18.2.0, vue@3.4.21, jquery-3.7.1.min.js, bootstrap, htmx.org, alpinejs, gsap, d3, lodash, three), the exact ng-version attribute (gold case), build-tool/framework fingerprints (Next.js /_next/, Nuxt __NUXT__/_nuxt/, Gatsby /page-data/ + ___gatsby, SvelteKit /_app/, Astro astro-island, React data-reactroot, Vue data-v-*), and \u003cmeta name=generator\u003e (Gatsby/WordPress/Hugo). Returns frameworks[] (name, version omitempty, confidence 0..1, evidence[]) sorted by confidence desc, plus top.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://js-framework-version-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_js_framework_version_extractor","url":"https://js-framework-version-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Real DOM walk over golang.org/x/net/html (no regex over HTML structure): parses the whole document and recursively inspects every element for framework signals, accumulating one entry per framework name merged across signals. The gold case is the ng-version attribute carried on a rendered Angular root node, which embeds the EXACT runtime version (e.g. ng-version=\"17.1.0\") and is scored highest (0.97). Versioned \u003cscript src\u003e CDN URLs are the strong case (0.90): a curated regexp table pulls the version out of jsdelivr/unpkg @name@version paths, cdnjs /name/version/ layouts, and classic filename versions (jquery-3.7.1.min.js, bootstrap.bundle-5.3.2.min.js) for react (incl. react-dom -\u003e react), vue, angularjs 1.x, jquery, bootstrap, htmx (htmx.org@1.9.10), alpinejs, gsap, d3, lodash, three; major-only pins (vue@3, d3@7, htmx.org@1.9) and protocol-relative srcs parse correctly. \u003cmeta name=generator\u003e contributes a product + optional version (0.85) for Gatsby/Next/Nuxt/Hugo/WordPress/Astro/Svelte/VuePress/Jekyll/Docusaurus. Structural build-tool fingerprints (0.45-0.60) detect Next.js (id=__NEXT_DATA__, /_next/static/), Nuxt (window.__NUXT__ inline state, /_nuxt/), Gatsby (/page-data/, id=___gatsby), SvelteKit (/_app/), Astro (\u003castro-island\u003e), React (data-reactroot/data-reactid), and Vue (data-v-* scoped-style attrs, data-server-rendered) WITHOUT a version. frameworks[] is sorted by confidence desc then name, every entry carries an evidence[] trail explaining why it fired, and version is omitted when unresolved. The honest TRL-4 ceiling: static markup only — a framework loaded via a dynamic import or bundled+minified with no version token in the URL is detected by fingerprint at best, frequently without a version; this does NOT execute JS or inspect the runtime (window.React.version), and an unversioned generic bundle is reported as nothing rather than guessed. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) in plain-HTML render mode (static DOM). SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs; the guard is OUTBOUND-only. Per-failure notes pushed to degraded[] (fetch_failed, empty_body, no_framework_detected, version_unresolved) instead of failing the response; degraded[] is always a non-nil slice. 40+ unit tests cover every CDN library + version-parsing edge case (.min.js, .slim, .bundle, major-only @N, cdnjs /lib/ver/ layout, protocol-relative, react-dom-\u003ereact, react-router NOT-\u003ereact), ng-version exact + confidence ordering vs fingerprints, every structural fingerprint, generator meta with/without version, multiple frameworks, fingerprint-without-version omitting version, unversioned-bundle-not-guessed, no-framework empty, garbage input safety, plus handler text-mode, parse-input aliases, missing-param 400, SSRF rejection, and the degraded[] notes. /selftest exercises the pure-logic pipeline (react CDN version, ng-version exact, jquery filename version, Next.js fingerprint without version, generator meta, confidence ordering, no-framework empty, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"jsonp-finder","domain":"jsonp-finder.0crawl.com","mesh":"0crawl","host_port":8158,"category":"security","title":"Jsonp Finder","summary":"Microservice for Jsonp Finder","tags":["go","security"],"health_url":"https://jsonp-finder.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_jsonp_finder","url":"https://jsonp-finder.0crawl.com","example":"/go_jsonp_finder?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (220-domain sample, live before/after; 0 JSONP endpoints found either run -- JSONP is largely extinct on the modern web, consistent with expectations, not a bug): found a real, previously-flagged-but-unfixed security gap -- a correct dial-time SSRF guard (safeDialContext/safeTransport) existed in the codebase but was dead code, never wired into the actual httpClient every fetch goes through; a classic check-then-connect DNS-rebind gap already lampshaded (not fixed) in a test-file comment. Live-proved: a loopback dial returned 200 before the fix. Fixed by wiring the guard in. Also patched an open CVE (golang.org/x/net HTML-parser DoS) directly relevant since discover.go feeds attacker-controlled target HTML into that exact tokenizer. trl held at 6; trl_ceiling bumped 6-\u003e7 -- the gap wasn't structural, it was a wiring bug in code that already existed to earn the higher band. See PR #5 (merged).","trl_ceiling":6,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"jwt-debugger","domain":"jwt-debugger.0crawl.com","mesh":"0crawl","host_port":8202,"category":"web_analysis","title":"Jwt Debugger","summary":"Microservice for Jwt Debugger","tags":["go","web-analysis"],"health_url":"https://jwt-debugger.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_jwt_debugger","url":"https://jwt-debugger.0crawl.com","example":"/go_jwt_debugger?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Not a domain crawler -- confirmed via exhaustive DB search that no stored JWT corpus exists in this fleet. Built a 5,242-case corpus from 1,000 real domain names. Fixed 2 security-relevant false negatives: string-typed exp/iat/nbf claims (real-world non-conformant issuers) silently treated as absent, so an already-expired token showed no expiry claim at all; alg=none tokens with a stale non-empty signature attached went unflagged. Also fixed 'Bearer \u003cjwt\u003e' prefix handling. Zero regressions across 5,242 cases. See github.com/baditaflorin/go_jwt_debugger PR #6.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"keyphrase-extractor","domain":"keyphrase-extractor.0crawl.com","mesh":"0crawl","host_port":18286,"category":"nlp","title":"Keyphrase Extractor","summary":"Rank multi-word keyphrases + topics via RAKE candidate generation re-ranked by a TextRank co-occurrence PageRank (pure Go, no external NLP service)","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://keyphrase-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_keyphrase_extractor","url":"https://keyphrase-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"First-pass audit (fresh 310-domain sample, real RAKE-\u003eTextRank pipeline): found and fixed 3 real bugs on live production pages. (1) CJK/full-width punctuation (、，。！？ etc) invisible to the tokenizer, so a whole Chinese/Japanese paragraph with no ASCII punctuation collapsed into one token -\u003e one 'keyphrase'/'topic'. (2) Overlong stopword-free runs silently dropped entirely rather than chunked, returning zero keyphrases/topics on 2 real live pages. (3) A hidden \u003ctextarea style=\"display:none\"\u003e JSON CDN-endpoint leak extracted as visible content and ranked as a keyphrase. Confirmed fetch-cache masking does not apply (uses fleetfetch by design). Live before/after: whole-paragraph blobs dropped 16-\u003e5 domains, 2 domains flipped from zero output to real output. trl held at 7; trl_ceiling=7 added -- genuinely correct and well-tested now, but further gains need architecture-level work (real per-language stopwords, true CJK/Thai segmentation, JS rendering). See PR #2 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"keyword-density","domain":"keyword-density.0crawl.com","mesh":"0crawl","host_port":8292,"category":"domains","title":"Keyword Density","summary":"Microservice for Keyword Density","tags":["domains","go"],"health_url":"https://keyword-density.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_keyword_density","url":"https://keyword-density.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh ~80-domain sample): explicitly verified the fetch-cache pattern here is deliberate/correct (pinned by a dedicated test, negligible TTL for this one-shot use case). Found and fixed a real bug: extractDoc counted never-rendered \u003ciframe\u003e/\u003cobject\u003e/\u003ccanvas\u003e HTML fallback text as page content, producing false 'severe keyword stuffing' verdicts on real small-business sites (confirmed on 35 production rows, one example jumping from 89% density on a mangled Maps-embed artifact to a correct 3.55% on the real top term). See PR #9 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"language-detector","domain":"language-detector.0crawl.com","mesh":"0crawl","host_port":18250,"category":"content","title":"Language Detector","summary":"Detects the dominant natural language and writing system of a web page or raw text: Unicode-range script detection (Latin, Cyrillic, Greek, CJK, Arabic, Hebrew, Devanagari) plus curated-stopword frequency scoring for en/es/fr/de/it/pt/nl, returning an ISO 639-1 language, confidence, and top-5 scores.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://language-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_language_detector","url":"https://language-detector.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Dependency-free, pure-Go language detector over a real HTML text extractor (golang.org/x/net/html tokenizer, no regex): prunes script/style/noscript/svg/template/head/iframe subtrees, prefers the first \u003carticle\u003e/\u003cmain\u003e region then falls back to \u003cbody\u003e, collapses whitespace with block-element boundaries. Two complementary signals. (1) SCRIPT detection — every letter rune is bucketed by its Unicode block into Latin (incl. Latin-1/Extended accents), Cyrillic, Greek (incl. Extended), CJK Han, Japanese kana (hiragana+katakana), Arabic, Hebrew, Devanagari; the dominant writing system by letter count is reported. This is near-certain because scripts occupy disjoint Unicode ranges. (2) STOPWORD-frequency scoring — for Latin-script prose the text is tokenised into lowercased words and, for each scored language (English, Spanish, French, German, Italian, Portuguese, Dutch), score = stopword-hits / total-tokens from curated high-frequency function-word sets; the highest score wins. Confidence is the margin form winner/(winner+runner_up) so a clear separation reads as high-confidence and a tight race reads ~0.5; a sole non-zero scorer reports its raw density. Non-Latin scripts map to a best-effort script→language guess (Cyrillic→ru, Greek→el, Arabic→ar, Hebrew→he, Devanagari→hi, Han→zh, Han+kana→ja) at deliberately modest confidence with a script_guess degraded note (script != language). Per-failure notes go to degraded[] (fetch_failed, no_extractable_text, low_sample:\u003cn\u003e_words for \u003c30-word inputs, undetermined when no stopwords match) rather than failing the response; degraded[] is always a non-null slice. Direct text= mode analyses pasted content with no fetch. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) in plain-HTML render mode; SSRF defense-in-depth (input-time block of literal loopback/private/link-local IPs via safehttp + localhost/.local names, with cache-side + safehttp-fallback dial-time guards). ~30 unit tests cover seven real multi-language Latin sentences mapping to the correct ISO 639-1 code, the es-vs-it and de-vs-nl confusable pairs, six non-Latin script classifications (Cyrillic/Greek/Arabic/Hebrew/Devanagari/Han) plus the kana→Japanese flip, the confidence margin metric, tokenisation, per-rune Unicode bucketing, low-sample + undetermined + no-stopword degraded paths, parse-input aliases, missing-param 400, and SSRF rejection. /selftest runs the pure-logic checks (en/es/fr/de detection, Cyrillic + CJK script, low-sample flag, extraction, SSRF guard) AND a live example.com fetch through the cache (asserting Latin script + no error, since example.com is too short for confident language scoring). Honest TRL-4 ceiling: this is a stopword/script heuristic, NOT a trained character-n-gram model (CLD3, fastText). It cannot separate two languages that share a script and most function words (e.g. Norwegian vs Danish, or any language outside the curated seven on the Latin path), a single short sentence can be misranked, and a CJK/Cyrillic/Arabic script result is a writing-system identification, not a language one. A trained n-gram/byte-model would lift accuracy and language coverage (and TRL) but requires shipping a model artifact and is out of scope for the no-dependency contract.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"leadership-extractor","domain":"leadership-extractor.0crawl.com","mesh":"0crawl","host_port":18252,"category":"content","title":"Leadership Extractor","summary":"Extracts the leadership/executive team from a web page or raw HTML — people whose title matches an executive/leadership keyword set — returning each leader's name, title, normalized rank (c_suite/founder/president/vp/director/board/other_leadership), bio, and profile links, plus a by_rank count map.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://leadership-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_leadership_extractor","url":"https://leadership-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Multi-stage leadership-team extraction over a fetched HTML page. Detection runs three passes in priority order on the parsed DOM (golang.org/x/net/html): (1) schema.org Person JSON-LD carrying a jobTitle — walks every \u003cscript type=application/ld+json\u003e, descends @graph and nested objects, handles @type as string OR array, and reads name/givenName+familyName/description/url/sameAs via stdlib encoding/json; (2) schema.org Person microdata (itemtype=schema.org/Person, http or https), pulling name/jobTitle/description and itemprop=url/sameAs + bare anchor hrefs; (3) a heuristic card walk used only when no structured data is present (flagged heuristic_fallback) — it scans repeated person cards (list items, articles, sections, figures, table cells, and team/staff/member-classed divs), skips grid wrappers that contain nested cards, and derives a name (preferring a heading) plus a title line. Every candidate is then FILTERED to leadership: the title must match a curated keyword set, and survivors are classified into exactly one normalized rank (c_suite, founder, president, vp, director, board, other_leadership) by case-insensitive, word-boundary regexes. Priority order is deliberate — vp is tested before president so 'Vice President' never lands in the president bucket despite containing the substring 'President', and \\b boundaries keep 'Director' from matching inside 'Directory'. c_suite matches the CxO acronyms plus the spelled 'Chief … Officer' shape; founder covers Founder/Co-Founder/Cofounder/Founding Partner; vp covers VP/SVP/EVP and (Senior|Executive )?Vice President; president covers President + Managing Director; director covers Director/Executive Director/Head of; board covers Chair(man|woman|person)/Board Member/Board of Directors/Trustee; other_leadership is a Partner/Principal/Owner/General Manager catch-all. Returns leaders[] (name/title/rank/bio omitempty/links non-nil), count, by_rank (rank→count), and detection (json_ld|microdata|heuristic). Relative profile hrefs/photo URLs are resolved against the final fetched URL; in text= mode (no fetch) they are returned as-authored. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so many producers scanning the same URL trigger one upstream fetch, in plain-HTML render mode. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) plus localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Non-fatal conditions pushed to degraded[] (fetch_failed:\u003cerr\u003e, no_extractable_text, heuristic_fallback, jsonld_parse_error, no_leaders) instead of failing the response; a page with text but no leaders still returns 200. ~30 unit tests cover every rank bucket, the Vice-President-vs-President disambiguation, the Directory-is-not-Director word-boundary guard, non-leadership rejection, case-insensitivity, the JSON-LD Person path (incl. @graph + @type array + missing-jobTitle skip + parse-error degraded), the microdata Person path, the heuristic card fallback + non-leader filtering + card links, by_rank counts, no-leaders degraded, dedupe across passes, omitempty/non-nil JSON shape, relative-link resolution, parse-input aliases, missing-param 400, SSRF rejection, and the text-mode handler. /selftest exercises the full pure-logic pipeline (CEO + VP detected, engineer filtered, ranks asserted) plus a live example.com fetch through the cache so the deploy smoke-gate has a real signal. TRL-4 ceiling vs higher: the structured-data paths are exact, but the heuristic fallback recognises only common team-page shapes — it is not layout-agnostic and does not infer roles from arbitrary running prose, which would need NLP-grade entity/role extraction.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"legal-entity","domain":"legal-entity.0crawl.com","mesh":"0crawl","host_port":8293,"category":"domains","title":"Legal Entity","summary":"Microservice for Legal Entity","tags":["domains","go"],"health_url":"https://legal-entity.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_legal_entity","url":"https://legal-entity.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Second-pass re-audit (fresh sample across 18+ jurisdiction suffixes): found and fixed a real false-positive bug -- Dutch 'NV' and Swedish 'AB' legal-suffix matching collided with US-state/Canadian-province address fragments (e.g. 'Las Vegas, NV', 'Edmonton, AB'), live-confirmed including one confident wrong resolution (brookefarris.com). See PR #24 (merged).","trl_ceiling":7,"trl_ceiling_reason":"Authoritative existence-validation needs jurisdiction-specific registries or paid company-data feeds; CPU-only/no-outbound forbids them, so the service can detect/classify suffixes and validate identifier form but cannot prove a company exists.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"license-extractor","domain":"license-extractor.0crawl.com","mesh":"0crawl","host_port":18270,"category":"content","title":"License Extractor","summary":"Detect the software/content license(s) of a web page or raw HTML/text — walks the DOM for structured signals (link rel=license, license anchors, JSON-LD license fields) and scans extracted text for license names, normalizing to SPDX identifiers (MIT, Apache-2.0, GPL/LGPL/AGPL, BSD, MPL-2.0, ISC, Unlicense, Creative Commons), plus copyright-line extraction.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://license-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_license_extractor","url":"https://license-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Detects software/content licenses from a real HTML document or raw text and normalizes to SPDX identifiers. Two complementary signal paths over golang.org/x/net/html: (1) structured DOM walk for machine-readable signals — link rel=license href, license-rel anchors (href then link text), and JSON-LD license fields (string URL, {@id|url|name} object, arrays, and nested @graph) — mapped to SPDX via a curated URL table (creativecommons.org deed paths carry variant+version, spdx.org/opensource.org/gnu.org/apache.org/mozilla.org/unlicense.org deep links); (2) regex name-scan over the extracted text (script/style/svg-pruned, article-preferring extractor reused from the readability pilot) recognizing MIT, Apache-2.0, GPL-2.0/3.0, LGPL, AGPL-3.0, BSD-2/3-Clause, MPL-2.0, ISC, Unlicense, and Creative Commons variants with version where stated. Per-SPDX dedup keeps the highest-confidence hit; structured signals (link/jsonld) outrank text on merge; results are confidence-sorted. Copyright lines (© / (c) / Copyright with year or year-range + best-effort owner) are extracted and deduped. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs; fetch through the fleet HTTP fetch cache (go-common/fleetfetch), plain-HTML render mode, 4 MiB cap. Direct text= mode scans pasted HTML or plain content with no fetch. Per-failure notes pushed to a non-nil degraded[] (fetch_failed, no_extractable_text, no_license_found) instead of failing the response. ~30 unit tests (table-driven + httptest) cover MIT/Apache/GPL/BSD/MPL/ISC/Unlicense/CC text recognition, CC variants+versions, URL→SPDX mapping, link rel=license, JSON-LD string/object/@graph, copyright extraction + dedup, source attribution (link vs jsonld vs text), structured-wins merge precedence, confidence bounds, no-license degraded, missing-param 400, SSRF rejection, and text= mode (including raw-HTML payloads); reused extractor tests retained. /selftest exercises the pure-logic pipeline (MIT text→SPDX, CC-BY-4.0 link, Apache JSON-LD, copyright, extraction, SSRF guard) AND a live example.com fetch through the cache. TRL-4 ceiling: heuristic name + structured-signal matching, NOT full license-text fingerprinting like an SPDX text-match engine; English-centric license names; may miss obfuscated, custom, or dual-licensed declarations and bare ambiguous tokens.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"list-extractor","domain":"list-extractor.0crawl.com","mesh":"0crawl","host_port":18249,"category":"content","title":"List Extractor","summary":"Extracts HTML lists from a web page or raw HTML: ordered (ol), unordered (ul), and description (dl) lists, with item text, term/definition pairs, nesting depth, and per-list/total counts.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://list-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_list_extractor","url":"https://list-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Real DOM walk over golang.org/x/net/html (no regex over HTML structure): parses the document, prefers the first \u003carticle\u003e/\u003cmain\u003e content root then falls back to \u003cbody\u003e, and recursively collects top-level lists. A list is treated as top-level only when no ancestor element is itself a ul/ol/dl, so a nested list is never emitted as a separate top-level entry — it only bumps the enclosing list's depth (computed as the max list-nesting level under the node). \u003cul\u003e -\u003e type ul/ordered false, \u003col\u003e -\u003e type ol/ordered true with direct \u003cli\u003e item text, \u003cdl\u003e -\u003e type dl with term/definition pairs walked in document order from \u003cdt\u003e/\u003cdd\u003e (bare \u003cdt\u003e yields empty definition, orphan \u003cdd\u003e yields empty term). Each \u003cli\u003e/\u003cdt\u003e/\u003cdd\u003e text is the text of its direct, non-list descendants — a nested list inside an item does NOT fold its items into the parent's text, keeping item text crisp and avoiding up-tree duplication. script/style/noscript/svg/template/head/iframe subtrees are pruned via the shared skipTags map so code/CSS never leak into item text; whitespace is collapsed via the shared normalizeWhitespace helper and empty items are skipped. Response carries lists[] ({type, ordered, depth, item_count, items[] or pairs[]}) plus total_lists and total_items. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so many producers scanning the same URL trigger one upstream fetch; plain-HTML render mode. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode scans pasted HTML with no fetch. Per-failure notes pushed to degraded[] (fetch_failed, no_extractable_text, no_lists) instead of failing the response; degraded[] is always a non-nil slice. 23 unit tests cover ul/ol/dl extraction, ordered flag, term/definition pairing (including bare dt / orphan dd), nested-depth (flat=0 through 3 levels), top-level-only counting (nested ul and nested dl not double-counted, nested item text not leaked up), multiple-list ordering, total counts, empty-item skipping, whitespace normalisation, script/style stripping, article-preference, garbage-input safety, parse-input aliases, missing-param 400, and SSRF rejection. /selftest exercises the pure-logic pipeline (ul/ol/dl, ordered flag, pairs, depth, top-level-only, ordering, script/style pruning, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"loadbalancer-detect","domain":"loadbalancer-detect.0crawl.com","mesh":"0crawl","host_port":8107,"category":"infrastructure","title":"Loadbalancer Detect","summary":"Microservice for Loadbalancer Detect","tags":["go","infrastructure"],"health_url":"https://loadbalancer-detect.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_loadbalancer_detect","url":"https://loadbalancer-detect.0crawl.com","example":"/go_loadbalancer_detect?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"TRL-6 uplift 2026-05-16. Detection now stacks four orthogonal signal\nfamilies: (1) DNS multi-A / round-robin lookup, (2) parallel HEAD\nmulti-fetch with Server / ETag / Date-skew / cookie diversity scoring,\n(3) a vendor signature matrix covering F5 BIG-IP, AWS ALB/ELB,\nHAProxy, Citrix NetScaler, Barracuda, Pulse Secure, Nginx Plus, plus\nCDN families (Cloudflare, CloudFront, Fastly, Akamai), (4) a\nclassifier producing none|proxy|cdn|lb|cluster with an explicit\nadditive confidence formula. Evidence trail surfaced per vendor\nmatch. 19 unit + integration tests covering single-host, AWS ALB,\nF5 BIG-IP, multi-IP round-robin, plain-nginx no-LB, generic-fallback\nand vendor-suppression cases. Backward-compatible with v1.x callers\nvia the legacy `analysis` JSON sub-field. ADR: docs/adr/0001-trl-uplift-to-6.md.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"login-analyzer","domain":"login-analyzer.0crawl.com","mesh":"0crawl","host_port":8170,"category":"web_analysis","title":"Login Analyzer","summary":"Microservice for Login Analyzer","tags":["go","web-analysis"],"health_url":"https://login-analyzer.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_login_analyzer","url":"https://login-analyzer.0crawl.com","example":"/go_login_analyzer?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"2026-08-20 re-audit (clean-slate, fresh clone of origin/main @ 42cb246): confirmed the 2026-07-31 fetch-cache-masking fix (fleetfetch.WithoutCache on fetchClient) is still the sole live-fetch path in fetch()/Handler; the old httpClient (safehttp.NewClient) is dead code, unreferenced by any production path. TRL 6 holds; the trl_ceiling:4 contradiction from the stale 2026-05-16 assessment was already resolved on 2026-07-31 (PR #9) and remains resolved -- clearing trl_ceiling here to stop it re-surfacing as a false contradiction.\nFound and fixed a new, real correctness bug in oauth.go's matchProvider: the external-URL branch was already guarded (2026-07 fix) against classifying an OAuth/SSO provider from an attacker/redirect-controlled query string (only host+path may match); the relative-path branch (same-origin SAML/OIDC routes) had no equivalent guard and matched needles against the full href (path+query), so a same-origin link like \"/logout?return=/saml/consume\" was misreported as a real SSO provider -- inflating confidence (+0.15) and flipping auth_method from \"unknown\" to \"oauth-only\"/\"oauth+password\" on pages with zero actual SSO. Reproduced deterministically (matchProvider(\"/logout?return=/saml/consume\") returned \"saml\" pre-fix); fixed by matching only u.EscapedPath(), mirroring the external-URL branch. 2 new regression tests added (19 total: 17 pre-existing + 2 new); go build/vet/test clean. Version bumped 1.4.7 -\u003e 1.4.8. PR: https://github.com/baditaflorin/go_login_analyzer/pull/14 (open, not merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"menu-extractor","domain":"menu-extractor.0crawl.com","mesh":"0crawl","host_port":18266,"category":"content","title":"Menu Extractor","summary":"Extracts the navigation menu structure of a web page or raw HTML: nav / role=navigation / aria-labelled regions plus header and footer link lists, each as a tree of menu items (label, href, nested submenu children) with region classification and a region/link/depth summary.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://menu-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_menu_extractor","url":"https://menu-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Real DOM walk over golang.org/x/net/html (no regex over HTML structure): parses the document and discovers navigation regions by four signals in document order — explicit \u003cnav\u003e elements (source nav), any element with role=navigation (source role), any element whose aria-label mentions nav/menu (source aria), and \u003cul\u003e/\u003col\u003e link-lists that live directly inside a \u003cheader\u003e/\u003cfooter\u003e landmark and contain at least one link (source list). Once a region root is found its whole subtree is marked claimed so a nested nav inside a nav, or a header-nested list inside an explicit nav, is folded into the parent tree rather than re-emitted as a separate region. Each region builds a menu tree from its first descendant \u003cul\u003e/\u003col\u003e (one MenuItem per direct \u003cli\u003e: label+href from the first \u003ca\u003e that is NOT inside the li's nested submenu list, with the nested \u003cul\u003e/\u003col\u003e walked recursively into children[]; an \u003cli\u003e with no link falls back to its direct non-list text); regions with no list fall back to a flat list of their \u003ca\u003e descendants. Nesting depth is preserved (flat menu = depth 1, one submenu level = depth 2, ...). Regions are classified by nearest ancestor landmark: inside \u003cfooter\u003e -\u003e footer, inside \u003cheader\u003e -\u003e primary, else generic. script/style/noscript/svg/template/iframe/object/embed subtrees are pruned via the shared skipTags map so code/CSS never leak into labels; whitespace is collapsed via normalizeWhitespace. Response carries regions[] ({class, label, source, items[], link_count, max_depth}) plus a summary {region_count, link_count, max_depth}. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so many producers scanning the same URL trigger one upstream fetch; plain-HTML render mode. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode scans pasted HTML with no fetch. Per-failure notes pushed to a non-nil degraded[] (fetch_failed, no_navigation_found) instead of failing the response. 28 unit tests cover \u003cnav\u003e extraction, role=navigation, aria-label nav/menu detection, nested submenu tree, deep (3-level) nesting depth, header-vs-footer classification, generic standalone nav, header/footer bare-link-list detection, multiple regions, nested-nav not double-counted, label+href capture, label from inner markup, parent label not stolen by first child link, flat-link fallback, script/style not leaked, summary roll-up, empty/no-nav degraded, parse-input aliases, missing-param 400, SSRF rejection (input + handler), and text= mode. /selftest exercises the pure-logic pipeline (nav tree + nesting, role=navigation, header/footer classification, no-nav empty, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal. TRL-4 ceiling: static-DOM only — JS-rendered / hydrated menus (React/Vue nav built client-side) are invisible; region classification is heuristic (landmark-ancestor based, not semantic intent), so a mid-page \u003cnav\u003e with no header/footer ancestor is labelled generic; mega-menu structures that encode hierarchy via CSS rather than nested \u003cul\u003e collapse to a flat tree.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"merchant-profile","domain":"merchant-profile.0crawl.com","mesh":"0crawl","host_port":18302,"category":"domains","title":"Merchant Profile","summary":"E-commerce merchant profile: platform detection, payment methods, accepted currencies, price range, shipping regions, catalog SKU count — 6 analyzers in one structured record.","tags":["go","kind-container"],"health_url":"https://merchant-profile.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_merchant_profile","url":"https://merchant-profile.0crawl.com","example":"/?target=gymshark.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"This is a thin go_composite_runner recipe wrapper (RECIPE_LOCK=merchant, no service-specific Go source). Found and fixed a real fan-out client timeout bug (too short for the recipe's sibling calls) in the shared go_composite_runner, plus added checkout-flow-detection as a new capability, live-verified via a scratch process on the same live sibling ports the production container calls. See github.com/baditaflorin/go_merchant_profile PR #1 and github.com/baditaflorin/go_composite_runner PR #1.","trl_ceiling":7,"trl_ceiling_reason":"Reaches TRL 7 with checkout-flow detection.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"microformats2-extractor","domain":"microformats2-extractor.0crawl.com","mesh":"0crawl","host_port":18260,"category":"content","title":"Microformats2 Extractor","summary":"Parses microformats2 (mf2) markup from a web page or raw HTML into canonical mf2 JSON. Detects h-* root items (h-card, h-entry, h-event, h-feed, h-product, h-review, h-recipe, h-adr, h-geo and any other h-*), reads p-/u-/dt-/e- properties on descendants, applies the implied name/url/photo rules, nests h-* items inside properties (e.g. p-author h-card) and as children[], and collects rel values into rels{} and rel-urls{} — returning items[], rels, rel-urls, and a summary roll-up.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://microformats2-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_microformats2_extractor","url":"https://microformats2-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Real DOM walk over the golang.org/x/net/html tokenizer (no regex for HTML structure). Implements the COMMON microformats2 rules. Root detection of any h-* class (h-card, h-entry, h-event, h-feed, h-product, h-review, h-recipe, h-adr, h-geo and arbitrary h-* tokens), emitting the canonical type[] array sorted and de-duplicated. Property reading on descendants by class prefix. p-* takes the collapsed visible text with img alt / area alt / abbr title fallbacks. u-* takes href/src/data/poster (in that order) resolved ABSOLUTE against the final fetched URL via net/url ResolveReference, falling back to element text. dt-* takes the datetime/value/title attribute, falling back to element text. e-* yields the {value, html} embedded-HTML object (collapsed text plus serialized inner HTML). Implied properties per the spec subset. implied p-name from a sole img alt / area alt / abbr title / element text, suppressed when an explicit name exists or the root has nested item values; implied u-url from the root element when it is an a/area with href, else a sole a/area/link descendant; implied u-photo from the root when it is an img/object, else a sole img/object descendant. Nesting. an h-* element carrying a property class becomes that property's value as a nested item (e.g. p-author h-card resolves to an Item with its own properties), while a bare nested h-* is appended to the parent's children[]; a nested root is never double-counted as a top-level item. rel collection across the whole document. a/link/area rel tokens populate rels{} (token -\u003e deduped url list, absolute) and rel-urls{} (url -\u003e {rels, text, type}). All JSON collections are non-nil (items=[], rels={}, rel-urls={}, types_seen=[]) so the envelope is stable, and degraded[] carries non-fatal notes (fetch_failed, no_microformats) instead of failing the response so a page with zero mf2 markup still returns 200. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) in plain-HTML render mode; direct text= mode parses pasted HTML with no fetch (no base, so relative u-* stay relative). SSRF defense-in-depth. input-time block of literal loopback/private/link-local IPs (safehttp block list) plus localhost/.local names, with cache-side and safehttp-fallback dial-time guards catching DNS-resolved private IPs. 43 Go unit + handler tests cover explicit h-card properties, type[] arrays, implied name from text and from img alt, implied photo and url from sole elements and from the root element, implied-name suppression, dt-* from datetime/value/text, u-* text fallback, e-content value+html, nested author h-card, h-feed with child h-entry children[], multiple top-level roots, h-event properties, rels (me/author/webmention, multi-token, multi-url), absolute u-* resolution and relative-without-base, no-microformats empty, garbage/empty input, p-adr wrapper with nested props, summary sorting/dedup, abbr title fallback, and the handler text-mode + no_microformats + JSON-shape-stable paths. /selftest exercises the pure-logic pipeline (h-card name+url, implied name, absolute u-url, dt-published, e-content, nested author, rels, no-microformats, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real outbound-fetch signal. The documented TRL-4 ceiling. it implements the common-case rules, NOT the full mf2 algorithm. it deliberately SKIPS the value-class-pattern (vcp) for dt-* date/time assembly and for p-* (reads the attribute or element text directly, not multi-span value reconstruction), lang propagation onto property values, the mf1-to-mf2 backcompat upgrade path, and resolving u-* against an in-document base href (resolves against the fetched URL only).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mime-trap","domain":"mime-trap.0crawl.com","mesh":"0crawl","host_port":8145,"category":"security","title":"Mime Trap","summary":"Microservice for Mime Trap","tags":["go","security"],"health_url":"https://mime-trap.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_mime_trap","url":"https://mime-trap.0crawl.com","example":"/go_mime_trap?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Real RFC-style HTTP header parsing (Content-Type splitting, charset\nunquoting, X-Content-Type-Options exact-match), WHATWG MIME-sniffing\nvia stdlib net/http.DetectContentType, multi-axis classification\nrubric (declared vs sniffed vs URL-extension vs nosniff posture)\nemitting stable greppable codes (mime.mismatch.*, header.xcto.*,\nheader.charset.*, mime.svg.*, mime.pdf.*, mime.fallback.*).\n≥15 unit tests + ≥10 httptest integration cases covering SVG-with-\nscript, JSON-as-HTML, image-as-HTML, HTML-as-PNG, XSSI prefix,\nXCTO-missing-on-JS/HTML, charset-missing, octet-stream fallback for\nknown extensions, scope-guard, SSRF loopback, legacy ?target= alias,\nbody-bytes-hex cap, response-shape contract. Per-request 5s + total\n15s timeouts; 512 KiB body cap; SSRF guard via go-common/safehttp;\noptional ?probe_uploads=1 for upload-extension confusion fan-out.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mobile-friendly","domain":"mobile-friendly.0crawl.com","mesh":"0crawl","host_port":8294,"category":"domains","title":"Mobile Friendly","summary":"Microservice for Mobile Friendly","tags":["domains","go"],"health_url":"https://mobile-friendly.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_mobile_friendly","url":"https://mobile-friendly.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"500-domain live audit against the deployed production container. Fixed a real bug: responsive \u003cimg\u003e tags with srcset were falsely flagged for horizontal-scroll risk (37% of sample), same signal the service already credits as evidence of responsiveness. 59/118 false positives cleared post-fix, including verdict upgrades. Also found genuine viewport false negatives traced to the shared fetch-cache layer serving different bytes than a direct fetch (upstream issue, not this repo). See github.com/baditaflorin/go_mobile_friendly PR #10.","trl_ceiling":6,"trl_ceiling_reason":"Requires headless browser, DOM rendering","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"named-entity-recognizer","domain":"named-entity-recognizer.0crawl.com","mesh":"0crawl","host_port":18285,"category":"nlp","title":"Named Entity Recognizer","summary":"Named-entity recognizer (PERSON/ORG/LOCATION/PRODUCT/EVENT) — pure-Go prose statistical NER + curated gazetteer, rune-accurate offsets, SSRF-guarded url fetch","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://named-entity-recognizer.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_named_entity_recognizer","url":"https://named-entity-recognizer.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"First-pass audit (production runs a real ONNX transformer, dslim/bert-base-NER via hugot v0.7.4, with a prose+gazetteer fallback): found a major silent-degradation bug -- 62%% (135/217) of real production pages were silently falling back to the much weaker rule-based engine, with the response still claiming engine:hugot_bert_ner_onnx and degraded:[], completely invisible to any consumer. Root cause is an upstream hugot tokenizer byte-offset-drift bug on multi-byte UTF-8 text, not fixable from this repo -- made it observable instead with proper per-request degraded tags. Also fixed nationalities (French/German/American) mislabeled PRODUCT at \u003e99.9%% confidence (added a curated demonym stoplist) and corrupted/truncated entity text leaking through from the same upstream offset bug (added a word-boundary check that drops misaligned spans, confirmed on real pages like 'porary Music' instead of 'Contemporary Music'). Confirmed fetch-cache masking does not apply. trl held at 7 (this fix itself is the evidence-trail upgrade); trl_ceiling=7 added -- capped by the unresolved upstream tokenizer bug plus structural English-centricity of both engines. See PR #2 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"office-locations","domain":"office-locations.0crawl.com","mesh":"0crawl","host_port":8295,"category":"domains","title":"Office Locations","summary":"Microservice for Office Locations","tags":["domains","go"],"health_url":"https://office-locations.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_office_locations","url":"https://office-locations.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"The prior ceiling_reason cited two blockers that were actually closed within days back in May 2026 and never re-assessed -- a documentation-honesty gap, not a trl\u003eceiling contradiction. This pass found and fixed 2 real precision bugs on a 500-domain live sample (alpha-3 country codes leaking unnormalized; legal-suffix footers/suite numbers stamped into the city field). See github.com/baditaflorin/go_office_locations PR #15.","trl_ceiling":7,"trl_ceiling_reason":"Live re-probe surfaced an un-guarded country-resolution edge (embedded-postal recovery); SLA-grade band-8 needs that hardened plus a labelled multi-country precision eval.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"open-redirect","domain":"open-redirect.0crawl.com","mesh":"0crawl","host_port":8149,"category":"security","title":"Open Redirect","summary":"Microservice for Open Redirect","tags":["go","security"],"health_url":"https://open-redirect.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_open_redirect","url":"https://open-redirect.0crawl.com","example":"/go_open_redirect?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Canonical 26-payload bypass set with class taxonomy\n(absolute / protocol-relative / userinfo / scheme-abuse / encoding /\nsuffix / unicode / CRLF). 17-name redirect-param matrix. eTLD+1\nescape detection via golang.org/x/net/publicsuffix (Mozilla PSL).\nMulti-hop chain tracing up to 5 hops with javascript:/data: refusal\nand unfollowed-Location-on-cap evaluation. Per-request 4s, total 30s,\nworker pool 4. handler_test.go + chain_test.go cover vulnerable\necho server, safe server, same-host ignore, dangerous-scheme labeling,\nhop cap, eTLD+1 comparison (incl. multi-label TLDs), back-compat\n?url= alias, SSRF guard. See docs/adr/0001-trl-uplift-to-6.md.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"outlink-graph","domain":"outlink-graph.0crawl.com","mesh":"0crawl","host_port":8296,"category":"domains","title":"Outlink Graph","summary":"Microservice for Outlink Graph","tags":["domains","go"],"health_url":"https://outlink-graph.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_outlink_graph","url":"https://outlink-graph.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"400-domain live production diff against domain_outlinks (tool_version 2.4.3): found and fixed a www/non-www internal-vs-subdomain classification flip (7/400 = 1.75%) and 3 dead-gazetteer false-categorization bugs (aws.amazon.com tagged 'affiliate' instead of 'cloud', cloud.google.com falling through to blank, fonts.gstatic.com mistagged 'cloud' instead of 'fonts'). See github.com/baditaflorin/go_outlink_graph PR #12.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"page-load-metrics","domain":"page-load-metrics.0crawl.com","mesh":"0crawl","host_port":8297,"category":"domains","title":"Page Load Metrics","summary":"Microservice for Page Load Metrics","tags":["domains","go"],"health_url":"https://page-load-metrics.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_page_load_metrics","url":"https://page-load-metrics.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Re-validated against real production data after the 2026-07-01 conservative reset (never followed up with real validation): pulled 800 random real rows plus a targeted 100-domain sample of every non-br/gzip/identity content_encoding value from domain_page_load (3.3M rows), ran the service live against all of them with same-time before/after A-B runs. Found and fixed 3 real bugs within the HTTP-level ceiling: (1) decodeBody() had no case for deflate/x-gzip, so it silently reported still-compressed wire bytes as decoded HTML and fed undecoded bytes into the HTML parser, blinding all downstream structural signals -- confirmed live, one domain's html_bytes was undercounted by 83%, another's score swung 92(A)-\u003e48(F) once real structural findings surfaced. (2) scoreTransfer() treated any non-empty/identity content_encoding as real compression, so mislabeled headers (utf-8) and AWS's non-compressing aws-chunked framing dodged the uncompressed-HTML penalty -- fixed by gating on measured byte savings, not the label. (3) a bare EOF was misclassified as HTTP 502 instead of the honest unreachable taxonomy. Same-time control A/B confirmed near-identical grade distributions on the general population (zero regression) with real targeted improvement only on the ~25 domains carrying the buggy encodings. Full go build/test passes (69 tests). See github.com/baditaflorin/go_page_load_metrics PR #15 for full writeup.","trl_ceiling":6,"trl_ceiling_reason":"Requires a headless browser / DOM rendering to measure real paint/layout metrics; this service is an HTTP-level probe.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"passive-voice-detector","domain":"passive-voice-detector.0crawl.com","mesh":"0crawl","host_port":18264,"category":"content","title":"Passive Voice Detector","summary":"Passive-voice detection for a web page or raw text — flags sentences using a be/get auxiliary plus a past participle, reports the matched trigger per sentence, total/passive sentence counts, and the passive-sentence ratio.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://passive-voice-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_passive_voice_detector","url":"https://passive-voice-detector.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Heuristic passive-voice detector over a real HTML text extractor (golang.org/x/net/html tokenizer, no regex): prunes script/style/noscript/svg/template/head/iframe subtrees, prefers the first \u003carticle\u003e/\u003cmain\u003e region then falls back to \u003cbody\u003e, collapses whitespace and inserts block-element boundaries so words aren't glued. Splits prose into sentences on terminal punctuation (collapsing punctuation runs, trailing-fragment aware) and flags each sentence as passive when a form of to-be (am/is/are/was/were/be/been/being) or a get-passive (get/gets/getting/got/gotten) is followed — within a small window that skips up to three intervening adverbs/negators so 'has been carefully reviewed' still matches — by a past participle. Participles are identified heuristically: regular -ed forms (with a curated exclusion list for short non-verbal -ed words like red/bed/embed) plus a curated list of ~110 common irregular past participles (done/made/seen/taken/given/written/known/shown/held/thrown/etc.). Reports the flagged sentences with their matched trigger (auxiliary + participle), total sentence count, passive sentence count, and the passive ratio as a percentage. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so 20 producers analysing the same URL trigger one upstream fetch; plain-HTML render mode. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode scores pasted content with no fetch. Per-failure notes pushed to a non-nil degraded[] (fetch_failed, no_extractable_text, low_sample:\u003cn\u003e_sentences) instead of failing the response; inputs below five sentences flagged as statistically noisy. ~30 unit tests cover sentence splitting, classic be-passives (was thrown, is being reviewed, has been done), get-passives (got hit, gets done), active sentences NOT flagged, irregular participles, adverb-interrupted passives, the adverb window not overreaching into unrelated clauses, passive-ratio math, the participle classifier, tokenisation, low-sample handling, missing-param 400, SSRF rejection, text= mode, plus the reused HTML-extraction cases (script/style stripping, article preference, whitespace collapse, block boundaries). /selftest exercises the pure-logic pipeline (a known passive flags, a known active does not, ratio math, extraction, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal. TRL-4 ceiling: heuristic participle detection without a POS tagger or dependency parser, English-only — it will miss participles outside the curated list and false-positive on adjectival participles ('the painted wall'), copular complements, and get as a main verb, where a full NLP parser would not.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"payment-detector","domain":"payment-detector.0crawl.com","mesh":"0crawl","host_port":8298,"category":"domains","title":"Payment Detector","summary":"Microservice for Payment Detector","tags":["domains","go"],"health_url":"https://payment-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_payment_detector","url":"https://payment-detector.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh 25-domain sample): found and fixed 2 evidence-inflation bugs -- 404/error pages were still scanned for payment-icon evidence (live-confirmed: a dead Shopify error template kept surfacing sitewide footer badges as 'detected' 4x over on codycallco.com; a stale Stripe.js reference on a 404 page produced a false detection on nybooks.com), and a URL-string dedup bug caused duplicate double-fetches on bare domains. Verdicts unchanged, only duplicate/stale evidence removed. See PR #14 (merged).","trl_ceiling":8,"trl_ceiling_reason":"Production-grade live detection-rate is bounded by the upstream fleetfetch RenderJS cache (502 context-deadline on every probe) — when it times out the detector never sees a page body, so live correctness can't be proven without a faster/warmer fetch tier or a stored-output table. Detector logic itself is sound and fully unit-tested.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-bounty-pilot","domain":"pentest-bounty-pilot.0crawl.com","mesh":"0crawl","host_port":18179,"category":"security","title":"Pentest Bounty Pilot","summary":"Bounty-hunt orchestrator: POST /hunt drives waf-detect → cookie-pwn → js-bundle-scanner → wayback-urls → reflection-hunter against given targets, returns consolidated triage JSON.","tags":["go","kind-container","language-go","runtime-compose","security"],"health_url":"https://pentest-bounty-pilot.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go-pentest-bounty-pilot","url":"https://pentest-bounty-pilot.0crawl.com","example":"/?api_key=default_token","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":4,"trl_evidence":"Wraps 6 fleet primitives. Per-host worker pool, WAF pre-filter, triage rollup. 5 integration tests with fixture upstreams.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-cookie-pwn","domain":"pentest-cookie-pwn.0crawl.com","mesh":"0crawl","host_port":18174,"category":"security","title":"Pentest Cookie Pwn","summary":"Parse Set-Cookie, classify cookies (session/Keycloak/F5/CSRF/tracker), flag missing flags, probe session-bearing endpoints, emit runnable PoC tar.gz.","tags":["go","kind-container","language-go","runtime-compose","security"],"health_url":"https://pentest-cookie-pwn.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go-pentest-cookie-pwn","url":"https://pentest-cookie-pwn.0crawl.com","example":"/?url=https://example.com\u0026test_session=1\u0026api_key=default_token","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"5 cookie classes + 2 fallbacks, 9 severity-coded issue codes, 9 session-probe endpoints, PoC bundle generator with 4 embedded templates. 7 unit tests with real CyberGhost/Thuringer fixtures.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-js-bundle-scanner","domain":"pentest-js-bundle-scanner.0crawl.com","mesh":"0crawl","host_port":18178,"category":"security","title":"Pentest Js Bundle Scanner","summary":"Fetch URL, recurse script src tags, scan 21 secret-pattern classes (AWS/Stripe/GitHub/Google/Anthropic/RSA-PEM/etc.), extract endpoints, classify sourcemaps as first vs third party (eTLD+1).","tags":["go","kind-container","language-go","runtime-compose","security"],"health_url":"https://pentest-js-bundle-scanner.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go-pentest-js-bundle-scanner","url":"https://pentest-js-bundle-scanner.0crawl.com","example":"/?target=https://example.com\u0026api_key=default_token","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"21 secret-pattern classes (private RSA requires full PEM block to avoid jsencrypt FP). Static-asset filtering. First-vs-third-party sourcemap classifier. 7 unit tests with realistic SPA fixture.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-reflection-hunter","domain":"pentest-reflection-hunter.0crawl.com","mesh":"0crawl","host_port":18175,"category":"security","title":"Pentest Reflection Hunter","summary":"Brute-fuzz ~40 standard params, classify reflection context (js-string/html-attr/json/url), escalate with composite breakout payloads. Filters WAF-challenge interstitials before classification.","tags":["go","kind-container","language-go","runtime-compose","security"],"health_url":"https://pentest-reflection-hunter.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go-pentest-reflection-hunter","url":"https://pentest-reflection-hunter.0crawl.com","example":"/?url=https://example.com\u0026params=q,promo\u0026escalate=1\u0026api_key=default_token","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"6 reflection contexts + per-context escalation, 11 inline WAF signatures (vendored from go-pentest-waf-detect), 6 integration tests covering vulnerable/safe/WAF-masked/no-reflection/skip-WAF.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-waf-detect","domain":"pentest-waf-detect.0crawl.com","mesh":"0crawl","host_port":18295,"category":"security","title":"Pentest Waf Detect","summary":"Fingerprint WAF/CDN challenge interstitials (14 vendors, 18 signatures). Used by reflection-hunter and bounty pipeline to drop interstitial false positives.","tags":["go","kind-container","language-go","runtime-compose","security"],"health_url":"https://pentest-waf-detect.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go-pentest-waf-detect","url":"https://pentest-waf-detect.0crawl.com","example":"/?url=https://example.com\u0026api_key=default_token","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"14 vendor signatures, 10 unit tests covering CF managed-challenge / Akamai / F5 / Imperva / PerimeterX / DataDome / ModSecurity / no-WAF baseline.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-ywh-sync","domain":"pentest-ywh-sync.0crawl.com","mesh":"0crawl","host_port":18176,"category":"security","title":"Pentest Ywh Sync","summary":"Pull YWH public program list + scopes from api.yeswehack.com, filter by min-bounty / max-reports / verified, emit bounty-scope-checker seed entries.","tags":["go","kind-container","language-go","runtime-compose","security"],"health_url":"https://pentest-ywh-sync.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go-pentest-ywh-sync","url":"https://pentest-ywh-sync.0crawl.com","example":"/programs?api_key=default_token","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":4,"trl_evidence":"YWH API client with pagination, 1h in-memory cache, criteria-based filter, /programs/seed for direct ingestion into bounty-scope-checker. 5 unit tests with real DataDome fixture.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"phone-extractor","domain":"phone-extractor.0crawl.com","mesh":"0crawl","host_port":8139,"category":"recon","title":"Phone Extractor","summary":"Microservice for Phone Extractor","tags":["go","recon"],"health_url":"https://phone-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_phone_extractor","url":"https://phone-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"libphonenumber-grade extraction, region detection, context windows. ~50KB of focused logic. TRL re-audit (2026-08-08, first since the initial 2026-05-13 batch) targeted the fleet-wide bare-safehttp.NewClient() fetch-cache bug. Found: handler.go's httpClient var is built via bare safehttp.NewClient() (no WithoutFetchCache/WithForceHTTP2), but tracing every call site shows it is dead code -- since commit eb7135f (v1.3.1, \"route HTML fetch through fleetfetch cache\") no code path calls httpClient.Do/.Get; the live page-fetch path is fetchClient (fleetfetch), a separate client with its own intentional, already-surfaced cache (FetchProvenance / X-FetchCache-* fields on every response). So the \"silently serves stale/cached responses\" bug does NOT currently affect production traffic through this service -- unlike sibling services (go_oauth_mapper, asn-lookup, sourcemap-finder) where the equivalent client was live and exploitable. Still hardened httpClient with WithoutFetchCache()+WithForceHTTP2() as defense-in-depth against a future revival silently reinheriting the fleet cache (main.go's server.New installs a process-wide DefaultFetchDelegate resolved at call time, not construction time). Added TestHTTPClient_BypassesProcessWideFetchCache, verified to fail pre-fix / pass post-fix. Also ran a quick extraction sanity pass (international +44/+33/+49, extensions, tel_href, vanity numbers, JS-DOM-split-span obfuscation) -- all extracted correctly, no new false positives. One real false-negative class found (not fixed, flagged for a follow-up pass): phone separators rendered as Unicode typographic dashes (en dash U+2013, hyphen U+2010, non-breaking hyphen U+2011 -- e.g. from HTML entities or CMS \"smart typography\" like WordPress wptexturize) are silently dropped by candidateRegex, which only accepts ASCII hyphen. Bumped to v1.4.7. See github.com/baditaflorin/go_phone_extractor PR #18 (open, not merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"policy-clause-extractor","domain":"policy-clause-extractor.0crawl.com","mesh":"0crawl","host_port":18271,"category":"content","title":"Policy Clause Extractor","summary":"Segment a legal/policy web page or raw HTML (privacy policy, terms of service, cookie policy, EULA, refund/return, acceptable-use) into clauses keyed by heading and classify each by policy type (data-collection, data-sharing, cookies, retention, user-rights/GDPR, liability, governing-law, termination, refund-return, acceptable-use, contact/DPO), plus a summary roll-up.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://policy-clause-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_policy_clause_extractor","url":"https://policy-clause-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Real DOM-driven policy segmenter over a golang.org/x/net/html tokenizer (no regex over HTML structure): prunes script/style/noscript/svg/template/head/iframe subtrees, prefers the first \u003carticle\u003e/\u003cmain\u003e region then falls back to \u003cbody\u003e, walks the tree in document order and opens a new clause at every h1-h6 heading (text before the first heading becomes a synthetic preamble clause so nothing is dropped); \u003csection\u003e/\u003carticle\u003e wrappers contribute naturally because their own headings drive the boundary. Each clause carries heading, level, body word-count, and a 200-char snippet. Classification is a curated keyword/phrase lexicon (substring, case-insensitive, heading double-weighted) across eleven policy types: data-collection, data-sharing/third-parties, cookies, retention, user-rights/GDPR, liability/warranty, governing-law/jurisdiction, termination, refund/return, acceptable-use, contact/DPO. The summary rolls up clause_count, a by_type histogram, a detected_policy_kind guess (privacy-policy / terms-of-service / cookie-policy / eula / refund-policy / acceptable-use-policy via phrase tally, else unknown), has_gdpr_signals, has_contact, and an uncategorized_rate. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so many producers analysing the same policy URL trigger one upstream fetch; plain-HTML render mode. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode extracts pasted raw HTML with no fetch. Per-failure notes pushed to degraded[] (fetch_failed, no_clauses_segmented) instead of failing the response. 30+ unit tests cover each of the eleven policy-type classifications, heading-based segmentation, preamble capture, section boundaries, multi-type clauses, uncategorized clauses, GDPR/user-rights and contact/DPO signal detection, policy-kind detection, the summary roll-up + histogram + uncategorized_rate, script/style not leaking into clause text, snippet truncation, article-root preference, parse-input aliases (url/target/q), missing-param 400, SSRF rejection (input + handler), and text= raw-HTML mode. /selftest exercises the pure-logic pipeline (segmentation, classification, signal + kind detection, script/style stripping, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal. CEILING (honest TRL-4, not higher): static-DOM only — JS-rendered/accordion-collapsed policy pages are invisible to the tokenizer; classification is a heuristic lexicon, not semantic legal understanding, so it cannot disambiguate context, negation (e.g. 'we do NOT sell your data' still hits data-sharing), or paraphrase outside the curated phrases; English-centric — non-English policies will largely fall through to uncategorized; segmentation assumes heading-structured markup, so wall-of-text policies with no h-tags collapse into a single preamble clause.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"press-mentions","domain":"press-mentions.0crawl.com","mesh":"0crawl","host_port":8300,"category":"domains","title":"Press Mentions","summary":"Microservice for Press Mentions","tags":["domains","go"],"health_url":"https://press-mentions.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_press_mentions","url":"https://press-mentions.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"600-domain live audit. Fixed a real bug present since the tool's first commit: a bare 'bottom' string in the footer-hint matcher collided with common CSS classes, live-confirmed on stripe.com itself (a scroll-progress indicator opened a fake footer window crediting an unrelated customer case study as press coverage). False positives dropped 30-\u003e7 across the sample; some verdicts flipped (e.g. high_visibility-\u003emoderate). See github.com/baditaflorin/go_press_mentions PR #16.","trl_ceiling":7,"trl_ceiling_reason":"full coverage needs JS-render/browser for SPA-rendered press strips + paid media-monitoring feeds; static-HTML CPU parsing is at its ceiling","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"price-range","domain":"price-range.0crawl.com","mesh":"0crawl","host_port":8301,"category":"domains","title":"Price Range","summary":"Microservice for Price Range","tags":["domains","go"],"health_url":"https://price-range.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_price_range","url":"https://price-range.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Confirmed and independently verified a fetch-cache-masking timeout bug (35/200 = 17.5% of live domains failing at the 6s timeout despite curl succeeding in under 1s) already fixed via go-common's WithoutFetchCache in a concurrently-merged PR. This pass added a second, independent fix: parseAmount misread dot-decimal EUR/BRL/TRY/DKK prices as comma-decimal by trusting currency defaults instead of actual page formatting, inflating prices ~100x (e.g. EUR 49.00 -\u003e 4900); fixed via digit-count-based disambiguation, verified live (4/4 EUR prices corrected on a real site). See github.com/baditaflorin/go_price_range PR #9.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pricing-tier-parser","domain":"pricing-tier-parser.0crawl.com","mesh":"0crawl","host_port":18268,"category":"content","title":"Pricing Tier Parser","summary":"Extract pricing tiers / plan cards from a web page or raw HTML — per-tier plan name, parsed price (currency + amount + billing period), most-popular flag, and feature list, plus a summary (tier count, currency, price range, billing-toggle detection).","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://pricing-tier-parser.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_pricing_tier_parser","url":"https://pricing-tier-parser.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Real DOM walk over the parsed HTML tree (golang.org/x/net/html tokenizer — NO regex over HTML structure; regex is confined to parsing the flat price string). Card detection is two-tier: first matches containers whose class/id carries a pricing keyword (pricing/plan/tier/package/subscription) and that hold a price-looking text node, then falls back to repeated price-bearing sibling cards for unlabelled grids. Per tier it extracts the plan name (first heading h1-h6, else a name/title-classed element), the price (currency symbol $/£/€/¥/₹ or ISO code, decimal amount with thousands separators, normalised billing period from /mo //year /per-user /week /day /once, plus Free and Contact-us/Custom flags), a most-popular/highlighted flag (class markers popular/highlight/featured/recommended/active or a badge text node), and the full \u003cli\u003e feature list. A summary rolls up tier count, the majority currency, price range, has-free/has-custom, and monthly/annual billing-toggle detection. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so N producers parsing the same URL trigger one upstream fetch; plain-HTML render mode. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode parses pasted markup with no fetch. Per-failure notes pushed to a non-nil degraded[] (no_pricing_found, fetch_failed) instead of failing the response. ~30 unit tests cover currency/decimal/period price parsing, Free/Contact-us, plan-name + feature extraction, popular flag, multi-tier and keyword-vs-sibling detection, price-range summary, billing-toggle, no-pricing degraded, missing-param 400, SSRF rejection, and text= mode. /selftest exercises the pure-logic pipeline (price parsing, card→tier, popular flag, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal. TRL-4 ceiling: card detection is heuristic (class/id keywords + price-bearing siblings) over the STATIC server-rendered DOM only — JS-rendered or tabbed/accordion pricing, per-toggle price swaps, and non-card layouts (comparison tables, sliders) are out of scope; currency and billing-period recognition are heuristic substring/regex matches, not a locale-aware money parser, so exotic separators (1.299,00) and uncommon currencies are not handled.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"promo-code-detector","domain":"promo-code-detector.0crawl.com","mesh":"0crawl","host_port":18267,"category":"content","title":"Promo Code Detector","summary":"Detect promotional offers and discount/coupon codes on a web page or in raw text — coupon codes near trigger words (use code, promo, voucher), percentage-off and amount-off offers across currencies, BOGO, free shipping, free trial, plus urgency/expiry hints.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://promo-code-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_promo_code_detector","url":"https://promo-code-detector.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Heuristic promo/coupon detector over a real HTML text extractor (golang.org/x/net/html tokenizer, no regex over HTML structure): prunes script/style/noscript/svg/template/head/iframe subtrees, prefers the first \u003carticle\u003e/\u003cmain\u003e region then falls back to \u003cbody\u003e, collapses whitespace and inserts block-element boundaries. Over the extracted visible TEXT it runs three regex/heuristic detector families: (1) coupon CODES — uppercase-alphanumeric tokens gated by a trigger-word proximity check (use code / promo / coupon / voucher / code:) so bare acronyms (NASA, HTML, even digit-bearing COVID19) without a nearby trigger are not reported; each hit carries its trigger word, a surrounding context snippet, and a parsed trailing value (SAVE20 -\u003e 20); (2) OFFERS — percentage-off (20% off, save 15%, up to 50%), amount-off across $/£/€/¥ and word currencies (USD/EUR/GBP), BOGO/buy-one-get-one/B1G1, free shipping/delivery, free trial — each with the raw matched span and parsed value where applicable; (3) urgency/expiry hints (ends today/tonight, limited time, expires \u003cdate\u003e, hurry/last chance, while supplies last). Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so many producers scanning the same URL trigger one upstream fetch; plain-HTML render mode. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, OUTBOUND-only, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode scans pasted text or raw HTML with no fetch. Per-failure notes pushed to a non-nil degraded[] (fetch_failed, no_extractable_text, no_promotions_found) instead of failing the response. ~30 unit + handler tests cover code detection with trigger proximity, no-false-positive on bare/digit acronyms, percentage and multi-currency amount parsing, BOGO/free-shipping/free-trial, urgency/expiry hints, value extraction, dedup, no-promo and no-text degraded paths, missing-param 400, SSRF rejection, and text= (plain + HTML) mode, plus the reused extractor cases. /selftest exercises the pure-logic pipeline (code+offer detection, plain-text yields nothing, acronym false-positive guard, HTML extraction, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal. TRL-4 ceiling: heuristic and English-centric, may miss image-embedded offers and JS-injected codes, and the trigger-proximity heuristic has documented false-positive/negative edges (an unusual code shape far from any trigger word is dropped; a true acronym sitting next to the word 'code' could be over-reported).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"proxy-fingerprint","domain":"proxy-fingerprint.0crawl.com","mesh":"0crawl","host_port":8331,"category":"infrastructure","title":"Proxy Fingerprint","summary":"Microservice for Proxy Fingerprint","tags":["go","infrastructure"],"health_url":"https://proxy-fingerprint.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_proxy_fingerprint","url":"https://proxy-fingerprint.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"RFC 7230 Via header parser (multi-header, comment-aware) + RFC 7239 Forwarded.\n17-vendor signature table (Cloudflare, Akamai, CloudFront, Fastly, Vercel,\nNetlify, BunnyCDN, KeyCDN, CDN77, StackPath, Sucuri, Incapsula, Azure\nFront Door, Google, Varnish, GitHub Pages, generic CDN). Topology\nclassification (direct / reverse_proxy / forward_proxy / cdn / multi_layer).\nChain-depth inference from max(via_hops, distinct_vendors, generic_floor).\nActive X-Forwarded-For probe to detect transparent forwarding (echo,\ncache-key flip, Vary advertisement). 28 unit tests + 6 httptest end-to-end\nscenarios across canned vendor headers. SSRF-safe via go-common/safehttp.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pwa-manifest","domain":"pwa-manifest.0crawl.com","mesh":"0crawl","host_port":8168,"category":"web_analysis","title":"Pwa Manifest","summary":"Microservice for Pwa Manifest","tags":["go","web-analysis"],"health_url":"https://pwa-manifest.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_pwa_manifest","url":"https://pwa-manifest.0crawl.com","example":"/go_pwa_manifest?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"900-domain live audit found the fetch-cache-masking bug proven via timing (3 back-to-back requests: 2.34s/0.85s/0.92s, a ~2.5x cache-hit signature) -- especially severe here since the analyzer makes two live fetches per request (homepage + manifest). Fixed. Also fixed an empty-manifest false positive (Duda's default {}, Webflow's unrelated routing JSON accepted as valid manifests -- 17% of 'manifest found' hits) and a 406 icon-probe false negative from a missing Accept header. See github.com/baditaflorin/go_pwa_manifest PR #7.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"quote-extractor","domain":"quote-extractor.0crawl.com","mesh":"0crawl","host_port":18248,"category":"content","title":"Quote Extractor","summary":"Extracts quotations from a web page or raw HTML — \u003cblockquote\u003e (kind block) and inline \u003cq\u003e elements — capturing each quote's text, its cite= source URL, and any nested \u003ccite\u003e attribution, with block/inline counts.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://quote-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_quote_extractor","url":"https://quote-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Real DOM walk over a fetched HTML page (golang.org/x/net/html tokenizer, zero regex for structure): parses the document, prunes script/style/noscript/svg/template/head/iframe subtrees, prefers the first \u003carticle\u003e/\u003cmain\u003e region then falls back to \u003cbody\u003e, and walks for \u003cblockquote\u003e (kind block) and inline \u003cq\u003e (kind inline) in document order. Per quote it captures the normalised text, the cite= attribute (source URL), and the first nested \u003ccite\u003e child's text as the human-readable attribution. Quotation text is collected with the nested \u003ccite\u003e subtree pruned so the attribution never glues onto the quote body; the quote text and the source attribution are returned as distinct fields. Whitespace is collapsed via the shared normalizeWhitespace; quotes empty after normalisation are skipped; a \u003cq\u003e nested inside a \u003cblockquote\u003e is folded into the block's text rather than double-counted. Returns quotes[] (text/kind/cite/source, cite/source omitempty), count, block_count, inline_count. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so many producers scanning the same URL trigger one upstream fetch; plain-HTML render mode (the static DOM is sufficient — no JS rendering needed). SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) plus localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode scans pasted HTML with no fetch. Non-fatal conditions pushed to degraded[] (fetch_failed:\u003cerr\u003e, no_extractable_text, no_quotes) instead of failing the response; a page with text but no quotes still returns 200. ~25 unit tests cover block/inline extraction, cite-attribute capture on both element types, nested \u003ccite\u003e source capture and its removal from the quote body, multi-quote document ordering, script/style isolation, empty/quoteless input, empty-quote skipping, whitespace normalisation, omitempty JSON shape, nested-q non-double-counting, parse-input aliases, missing-param 400, SSRF rejection, and the text-mode/no_quotes handler paths. /selftest exercises the full pure-logic pipeline AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal. TRL-4 ceiling vs higher: it extracts only the explicit semantic quote elements (\u003cblockquote\u003e/\u003cq\u003e) — it does not infer quotations from typographic quotation marks in running prose, which would need NLP-grade sentence boundary detection.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"ratelimit-tester","domain":"ratelimit-tester.0crawl.com","mesh":"0crawl","host_port":8156,"category":"security","title":"Ratelimit Tester","summary":"Microservice for Ratelimit Tester","tags":["go","security"],"health_url":"https://ratelimit-tester.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_ratelimit_tester","url":"https://ratelimit-tester.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"classifier matrix (none/fixed-window/token-bucket/sliding/indeterminate), 7 bypass vectors with rate-normalized decision, hard caps (100 req / 50 RPS), /selftest with strict+weak httptest fixtures","trl_ceiling":7,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"readability-index","domain":"readability-index.0crawl.com","mesh":"0crawl","host_port":18245,"category":"content","title":"Readability Index","summary":"Readability scoring for a web page or raw text — Flesch Reading Ease, Flesch-Kincaid Grade, Gunning Fog, SMOG, Coleman-Liau, and ARI, plus a consensus US-grade estimate.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://readability-index.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_readability_index","url":"https://readability-index.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Pure-math readability engine over a real HTML text extractor (golang.org/x/net/html tokenizer, no regex): prunes script/style/noscript/svg/template/head/iframe subtrees, prefers the first \u003carticle\u003e/\u003cmain\u003e region then falls back to \u003cbody\u003e, collapses whitespace and inserts block-element boundaries so words aren't glued. Computes six standard indices from raw counts (sentences/words/syllables/letters/complex-words) — Flesch Reading Ease, Flesch-Kincaid Grade, Gunning Fog, SMOG, Coleman-Liau, ARI — plus a consensus grade (mean of the five grade-level scales). Syllable counter is the standard vowel-group heuristic with silent-e and consonant+le corrections (documented off-by-one on proper nouns/loanwords, the TRL-4 ceiling vs a CMU-dict lookup). Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so 20 producers analysing the same URL trigger one upstream fetch; plain-HTML render mode. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode scores pasted content with no fetch. Per-failure notes pushed to degraded[] (fetch_failed, no_extractable_text, low_sample:\u003cn\u003e_words) instead of failing the response; \u003c100-word inputs flagged as statistically noisy. ~25 unit tests cover syllable counts, sentence/word/letter tokenisation, contraction handling, the six indices' easy-vs-hard ordering, the pangram's reading-ease band, consensus mean, HTML script/style stripping, article-preference, whitespace collapse, block boundaries, parse-input aliases, missing-param 400, and SSRF rejection. /selftest exercises the pure-logic pipeline (syllables, easy/hard scoring, extraction, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"reading-time-estimator","domain":"reading-time-estimator.0crawl.com","mesh":"0crawl","host_port":18246,"category":"content","title":"Reading Time Estimator","summary":"Estimates reading time for a web page or raw text across slow/average/fast WPM bands, plus a Medium-style per-image viewing allowance — returns words, image count, per-band minutes/seconds, and a humanized 'about N min read' label.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://reading-time-estimator.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_reading_time_estimator","url":"https://reading-time-estimator.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Reading-time estimator over a real HTML text extractor (golang.org/x/net/html tokenizer, no regex): the shared extractor prunes script/style/noscript/svg/template/head/iframe subtrees, prefers the first \u003carticle\u003e/\u003cmain\u003e region then falls back to \u003cbody\u003e, collapses whitespace and inserts block-element boundaries so words aren't glued. Word count reuses the readability tokenizer's rule (runs of letters with apostrophes kept, so 'don't' counts once; digit-only/punctuation tokens excluded). Reading time is computed at three documented WPM bands — slow 150, average 238 (Brysbaert 2019 adult-silent-reading mean), fast 300 — each returning minutes (2dp), whole seconds_total, and a humanized label ('less than a minute' under 60s, else 'about N min read' rounded to the nearest minute, singular at 1). The average band is surfaced at top level as primary; its WPM is overridable via the wpm query param (clamped 50-1000, out-of-range flagged in degraded[]). Image count is the number of \u003cimg\u003e elements parsed over the whole document via the same html tokenizer; each image adds a Medium-style viewing allowance (12s for the first, -1s per subsequent image, 3s floor) — a documented simplification that does not count \u003cpicture\u003e/\u003cfigure\u003e/\u003csvg\u003e or CSS backgrounds. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so many producers analysing the same URL trigger one upstream fetch; plain-HTML render mode. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode estimates pasted content with no fetch (images=0). Per-failure notes pushed to degraded[] (empty_text, fetch_failed:\u003cerr\u003e, no_extractable_text, low_sample:\u003cn\u003e_words_below_20, invalid_wpm/wpm_out_of_range) instead of failing the response. ~20 unit tests cover word tokenisation + contractions, \u003cimg\u003e counting (and the deliberate non-counting of picture/figure/svg), the per-image allowance + floor, band words-only math (238 words @ 238 wpm == 60s), image-allowance addition, WPM monotonicity (fewer minutes at higher WPM), wpm override re-anchoring only the average band, 2dp minute rounding, humanize banding, empty-text handling, plus handler-level text mode, wpm parse/validation, low-sample degraded, missing-param 400, and SSRF rejection; the copied extraction suite adds 6 more. /selftest exercises the pure-logic pipeline (word count, WPM monotonicity, humanize bands, image counting, extraction strip, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal. TRL-4 ceiling: WPM constants are population averages not per-reader calibration, and the image allowance is a heuristic not a measured dwell time.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"redirect-tracer","domain":"redirect-tracer.0crawl.com","mesh":"0crawl","host_port":8332,"category":"infrastructure","title":"Redirect Tracer","summary":"Microservice for Redirect Tracer","tags":["go","infrastructure"],"health_url":"https://redirect-tracer.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_redirect_tracer","url":"https://redirect-tracer.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"TRL LOWERED 7-\u003e5 (2026-08-20): the prior TRL-7 claim ('redirect-chain tracing with loop detection, header validation') did not hold in production. go_redirect_tracer's newClient() (tracer.go) built its HTTP client with a bare safehttp.NewClient(), which carries go-common's DEFAULT CheckRedirect policy (safehttp_helpers.go, NewClient, go-common v0.88.0): it auto-follows up to 5 redirects INSIDE client.Do() before any response reaches caller code. Since trace()'s entire job is to walk and report each hop, that default silently defeated it end-to-end: the manual hop loop only ever saw the already-resolved final response, so hop_count/per-hop cookies/Location headers/host-change flags collapsed to a single terminal hop for any chain with real intermediate redirects. Confirmed live 2026-08-20 with the actual go-common v0.88.0 client against a local 3-hop (302-\u003e302-\u003e200) server: client.Do() returned status 200 on the very first call, with neither intermediate Location header ever surfaced; independently confirmed with curl --max-time against the same server (curl without -L shows the two distinct 302s; curl -L collapses them exactly like the buggy client did). Notably the repo's OWN pre-existing test (TestTrace_FollowsChain, handler_test.go) already worked around this by building a separate throwaway http.Client with CheckRedirect-\u003eErrUseLastResponse instead of exercising the real newClient() ('Use a plain client without guarded dialer just for this test') -- so the bug had zero test coverage and the passing test suite gave false confidence. Fix opened as baditaflorin/go_redirect_tracer PR #12 (branch fix/redirect-checkredirect-auto-follow, commit 94c6d30; NOT merged, NOT deployed): newClient() now overrides CheckRedirect to return http.ErrUseLastResponse so every hop is actually surfaced to trace()'s loop, plus adds safehttp.WithoutFetchCache() (separate, second-order fix: a bare safehttp.NewClient() would otherwise route every hop's GET through the process-wide fleet fetch-cache delegate when FLEET_FETCH_CACHE_URL is set fleet-wide, serving stale cached bytes/timing instead of the live per-hop signal this tool exists to produce). Added TestTrace_ObservesEachIntermediateHop, verified to fail pre-fix (hop_count=1) and pass post-fix (hop_count=3). Service Version bumped 1.5.6-\u003e1.6.0 in the PR. TRL 5 (developing: multi-step logic present, partial/newly-added test coverage of the core claim, fix not yet merged/deployed) reflects the CURRENT production state, which is still running the pre-fix binary. Re-assess toward 6-7 once PR #12 is merged, deployed, and the hop-by-hop behavior is reverified live against the running service.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"remote-detector","domain":"remote-detector.0crawl.com","mesh":"0crawl","host_port":8302,"category":"domains","title":"Remote Detector","summary":"Microservice for Remote Detector","tags":["domains","go"],"health_url":"https://remote-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_remote_detector","url":"https://remote-detector.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"v3.1.0 de-biases the English-only lexicon + probe paths: ~120 multilingual remote-work phrases across FR/DE/ES/IT/PT/NL/RU/JA/KO/ZH+SE/NO/DA/FI/PL/TR plus non-English anti-signals and localized careers paths (/karriere,/emploi,/empleo,/lavora-con-noi,/recruit,/採用). Real-data fixtures: 0/12 locales yielded a remote verdict before -\u003e 12/12 classify remote-first after. 42 test funcs incl. 30-case multilingual table; build/vet/gofmt/test green; deployed live (smoke gate green).","trl_ceiling":7,"trl_ceiling_reason":"CPU-only static-HTML probe; TRL 8-9 would need a JS-rendering browser tier (careers SPAs that lazy-load job copy still read unknown) plus persistent historical tracking, both outside the CPU-only mandate.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"revenue-model","domain":"revenue-model.0crawl.com","mesh":"0crawl","host_port":8303,"category":"domains","title":"Revenue Model","summary":"Microservice for Revenue Model","tags":["domains","go"],"health_url":"https://revenue-model.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_revenue_model","url":"https://revenue-model.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh 82-domain sample): explicitly ruled out fetch-cache as a bug (confirmed this is the documented-correct pattern for bulk HTML classifiers per go-common's own fleetfetch docs). Found and fixed a real verdict-consistency bug: the primary-model/verdict arbitration hadn't learned a demotion gate added in the prior pass, producing self-contradictory responses (e.g. primary_model:'api_usage' + verdict:'ambiguous' on together.ai). See PR #16 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"reverse-dns","domain":"reverse-dns.0crawl.com","mesh":"0crawl","host_port":8333,"category":"infrastructure","title":"Reverse Dns","summary":"Microservice for Reverse Dns","tags":["go","infrastructure"],"health_url":"https://reverse-dns.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_reverse_dns","url":"https://reverse-dns.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"TRL 6 capability: multi-resolver PTR fanout (1.1.1.1, 8.8.8.8, 9.9.9.9)\nfor IPv4 + IPv6, real FCrDNS forward-confirm via miekg/dns (not the OS\nresolver — so an in-process test server can drive the suite hermetically),\nbulk mode with 10-worker pool over ?ips= (≤50) and ?cidr= (≤/24, 256\nhosts), per-lookup 2s + total 30s timeout, refusal of private/loopback\nunless ALLOW_PRIVATE=1, optional ?include_asn=1 composing the sibling\nasn-lookup service (env ASN_LOOKUP_URL), zone cohesion summary on CIDR\nprobes. Backward-compat: ?host= and ?target=. 13 hermetic tests cover\nFCrDNS pass/fail, NXDOMAIN, IPv6, bulk, CIDR expand limits, and private-IP\nrefusal. Pure Go, CGO-free.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"review-presence","domain":"review-presence.0crawl.com","mesh":"0crawl","host_port":18292,"category":"domains","title":"Review Presence","summary":"Fetch Trustpilot/G2/Capterra/Glassdoor star rating + review count for a brand by parsing each public profile's JSON-LD AggregateRating","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://review-presence.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_review_presence","url":"https://review-presence.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Real production-data audit: queried domain_review_presence (1,255,981 rows) and domains (11.9M rows), built and ran the live binary against ~1,550 real domains. Fixed non-5-scale schema.org star rating handling and added junip widget detection. See github.com/baditaflorin/go_review_presence PR #9.","trl_ceiling":7,"trl_ceiling_reason":"Authoritative third-party rating and review counts require a headless browser or paid platform APIs because major profile pages hard-block server-side fetches.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"robots-analyzer","domain":"robots-analyzer.0crawl.com","mesh":"0crawl","host_port":8184,"category":"web_analysis","title":"Robots Analyzer","summary":"Microservice for Robots Analyzer","tags":["go","web-analysis"],"health_url":"https://robots-analyzer.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_robots_analyzer","url":"https://robots-analyzer.0crawl.com","example":"/go_robots_analyzer?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"1.3.1: RFC 9309 §2.2.2 path matching with $ end-anchor and * wildcards; §2.3 precedence (specific UA \u003e wildcard, longest-match wins, Allow beats Disallow on ties); Request-rate + Visit-time directive parsing; CrawlabilityMatrix evaluates 7 probe paths × {*, Googlebot, top-3 site UAs}. 10/10 corpus PASS; verified evidence: HN matrix shows /login disallowed for both * and Googlebot.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"robots-parser","domain":"robots-parser.0crawl.com","mesh":"0crawl","host_port":8304,"category":"domains","title":"Robots Parser","summary":"Microservice for Robots Parser","tags":["domains","go"],"health_url":"https://robots-parser.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_robots_parser","url":"https://robots-parser.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh 25-domain sample): found and fixed 2 real bugs -- (1) fetch-cache masking, confirmed live via cache-hit timing signature (1.3s-\u003e0.25s repeat-request pattern); (2) a UA-group flush bug where parseRobots never flushed a pending User-agent block before a global directive or at EOF, live-reproduced on anythinggos.com and capable of silently merging two UA blocks' Disallow rules. See PR #8 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"scan-port","domain":"scan-port.0crawl.com","mesh":"0crawl","host_port":8222,"category":"recon","title":"Scan Port","summary":"Microservice for Scan Port","tags":["go","recon"],"health_url":"https://scan-port.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_scan_port","url":"https://scan-port.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"First-pass audit (125-domain sample, 1220 live port probes): confirmed timeout-vs-closed classification is already correct (timing analysis shows clean separation between filtered/timeout and open/closed) and independently re-verified (out-of-band Python socket connects) a structural connect-scan false-positive class (a host that TCP-accepts on every port). Found and fixed a real bug -- proto=both ran TCP then UDP scans sequentially against one shared context deadline, so a slow TCP pass could silently starve UDP of its entire time budget (0 ports ever dialed); fixed by running both concurrently. trl bumped 6-\u003e7; trl_ceiling=7 added -- bare TCP-connect scanning structurally cannot distinguish a real service from a catch-all edge, UDP's open|filtered ambiguity is protocol-inherent, and there's no service-owned persistent rate limiting. See PR #4 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"scan-port-banner","domain":"scan-port-banner.0crawl.com","mesh":"0crawl","host_port":8089,"category":"recon","title":"Scan Port Banner","summary":"Microservice for Scan Port Banner","tags":["go","recon"],"health_url":"https://scan-port-banner.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_scan_port_banner","url":"https://scan-port-banner.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Per-port probe table covers SSH/FTP/SMTP(EHLO)/POP3/IMAP/HTTP/HTTPS-via-TLS/Redis/memcached/MySQL/Postgres/Mongo/Elasticsearch/Telnet (composes with telnet-banner for IAC handling). Structured fingerprints (product/version/os_hint) for OpenSSH, Dropbear, nginx, Apache, lighttpd, IIS, Caddy, Postfix, Exim, Sendmail, vsftpd, ProFTPD, Pure-FTPd, Redis, memcached, MariaDB, MySQL, Dovecot, Cyrus. Pure-Go (CGO-free), no shell-out to nmap/curl. Per-port 5s + total 12s timeouts. ALLOW_PRIVATE guard against RFC1918. ≥30 unit tests with canned-banner net.Listen fixtures (HTTP/SSH/SMTP/Redis/FTP/IMAP/MySQL).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"scan-port-ssh","domain":"scan-port-ssh.0crawl.com","mesh":"0crawl","host_port":8090,"category":"recon","title":"Scan Port Ssh","summary":"Microservice for Scan Port Ssh","tags":["go","recon"],"health_url":"https://scan-port-ssh.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_scan_port_ssh","url":"https://scan-port-ssh.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"x/crypto/ssh full algo capture, weak-algo detection (KEX/cipher/MAC/host_key), findings-store wire with sha256-of-algos dedup, /selftest against in-process ssh.NewServerConn with planted weak algos (12 invariants)","trl_ceiling":7,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"scc","domain":"scc.0crawl.com","mesh":"0crawl","host_port":8305,"category":"domains","title":"Scc","summary":"Microservice for Scc","tags":["domains","go"],"health_url":"https://scc.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_scc","url":"https://scc.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Second-pass re-audit (fresh 250-domain sample): explicitly ruled out fetch-cache as a bug (uses fleetfetch, the correct shared-cache client). Found and fixed a real SPA-shell-detection bug: contentElementCount excluded decorative \u003csvg\u003e bulk but not \u003chead\u003e/\u003cscript\u003e/\u003ctemplate\u003e boilerplate, causing near-text-free SPA shells (x.com, Instagram) to blow the content budget purely on head tags. Also patched a Dependabot HTML-parser DoS CVE (golang.org/x/net). See PR #8 (merged).","trl_ceiling":6,"trl_ceiling_reason":"full structural complexity for SPAs needs post-JS DOM rendering, which a CPU-only static fetch cannot do","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"schema-extractor","domain":"schema-extractor.0crawl.com","mesh":"0crawl","host_port":8165,"category":"web_analysis","title":"Schema Extractor","summary":"Microservice for Schema Extractor","tags":["go","web-analysis"],"health_url":"https://schema-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_schema_extractor","url":"https://schema-extractor.0crawl.com","example":"/go_schema_extractor?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"2.3.0 transcodes the fetched body to UTF-8 honouring the declared charset (BOM/Content-Type/\u003cmeta\u003e/statistical via x/net/html/charset) BEFORE html.Parse, and normalizes Unicode-form IDN hosts to punycode (IDNA2008 via x/net/idna) before the SSRF guard+fetch. Before, raw-byte parsing mojibake'd then U+FFFD'd every non-ASCII JSON-LD/microdata/RDFa value on legacy-charset pages while ASCII type names survived. 17 new table-driven tests across 9 real legacy encodings (Shift_JIS/EUC-JP/EUC-KR/ISO-8859-1/ISO-8859-2/windows-1251/GBK/Big5/windows-1252) + 8 IDN cases, each with regression guards proving the old path was wrong; build/vet/gofmt green. Live: bücher.de-\u003exn--bcher-kva.de returns 200 (was unresolvable). Detection rate gap motivating the fix: legacy-charset ccTLDs .fr 11% / .jp 12% / .kr 14% vs UTF-8 ccTLDs .de 46% / .au 56%.","trl_ceiling":7,"trl_ceiling_reason":"True 8-9 needs a JS-rendering browser engine to see client-injected schema (service already emits an honest JS-rendered note) plus cross-source corroboration; out of scope for a CPU-only static fetcher.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"search-bing-go","domain":"search-bing-go.0crawl.com","mesh":"0crawl","host_port":3413,"category":"search","title":"Search Bing Go","summary":"Microservice for Search Bing Go","tags":["go","search"],"health_url":"https://search-bing-go.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go-search-bing-go","url":"https://search-bing-go.0crawl.com","example":"/?query=anthropic+claude","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"TRL 5 uplift on 2026-05-16 (see docs/adr/0001-trl-uplift-to-5.md).\n- Direct Bing scrape (no proxy dep), parsed with golang.org/x/net/html.\n- /ck/a redirect decoder: strip 2-char prefix, try Std/URL/RawStd/RawURL base64 with padding fallback.\n- Pagination 1-5 (?page=, mapped to first=1/11/21/...); cc (?cc=, default us); safesearch off|moderate|strict (-\u003e adlt=).\n- 5-UA rotating pool (Chrome/Firefox/Safari/Edge), stable per cache key; Referer https://www.bing.com/.\n- In-process TTL cache (1h), key = sha256(q|page|cc|safesearch).\n- Stable JSON envelope: {q, page, cc, safesearch, results[{title,url,snippet,position}], count, duration_ms, cached}.\n- Per-request 8s, total handler 12s budget.\n- 14 test cases across pkg/bing (parser fixtures + httptest.Server-driven handler + UA pool).","trl_ceiling":5,"trl_ceiling_reason":"depends on paid API or browser crawling","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"search-duck-go","domain":"search-duck-go.0crawl.com","mesh":"0crawl","host_port":3401,"category":"search","title":"Search Duck Go","summary":"Microservice for Search Duck Go","tags":["go","search"],"health_url":"https://search-duck-go.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go-search-duck-go","url":"https://search-duck-go.0crawl.com","example":"/?query=anthropic+claude","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"First-pass audit (confirmed genuinely distinct from sibling go-search-duck -- different mesh, different upstream endpoint, different API contract, no shared code). Found and fixed 2 real bugs: (1) the recurring fetch-cache-masking bug, which would defeat this service's retry-through-fresh-proxy-IP logic and leak cached DDG responses across unrelated services. (2) A bot-challenge page misreported as 'zero results' then CACHED as a false-empty result for the full 1h TTL -- exactly the risk this service's own ADR warned about but never guarded against; fixed with DOM-based bot-challenge detection (stable anomaly-modal/challenge-form markers) that skips the cache entirely. Live DDG testing (kept conservative, ~5 requests) confirmed correct behavior for a coherent browser persona vs. a bare request. trl held at 5; trl_ceiling=6 added -- DDG's HTML-Lite endpoint has no official API/SLA and actively detects/blocks this exact traffic pattern, a structural adversarial limit no further engineering removes. See PR #4 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"seasonal-detector","domain":"seasonal-detector.0crawl.com","mesh":"0crawl","host_port":8306,"category":"domains","title":"Seasonal Detector","summary":"Microservice for Seasonal Detector","tags":["domains","go"],"health_url":"https://seasonal-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_seasonal_detector","url":"https://seasonal-detector.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh, disjoint 500-domain sample): explicitly ruled out fetch-cache as a bug (uses the correct fleetfetch client; deployed cache TTL of 10 minutes is too short to plausibly mask a wrong season). Found and fixed a real self-contradiction bug: the top-level 'seasonal' boolean never inherited the off-season ceiling already applied per-detection, so an out-of-season detection could report seasonal:true while the rest of the response said otherwise. Live-confirmed on 2 real domains. See PR #13 (merged).","trl_ceiling":7,"trl_ceiling_reason":"TRL 7 needs proof on live production traffic with cross-checks; deterministic + multi-script unit proof landed, but sparse live seasonal copy in late May blocked a production detection-rate before/after.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"secrets-scanner","domain":"secrets-scanner.0crawl.com","mesh":"0crawl","host_port":8229,"category":"security","title":"Secrets Scanner","summary":"Microservice for Secrets Scanner","tags":["go","security"],"health_url":"https://secrets-scanner.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_secrets_scanner","url":"https://secrets-scanner.0crawl.com","example":"/go_secrets_scanner?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (fresh 250-domain sample): found and fixed a real false-positive class -- GCP API keys (AIza-prefixed) matched on 11/226 domains, 100% benign Google-documented public browser keys (Maps/YouTube/Sign-In), all reported at severity=high/confidence=high indistinguishable from a real leak; downgraded to severity=info with context-aware detection. Also fixed the recurring fetch-cache-masking bug, notably relevant since this scanner's entire job is live-freshness detection. Self-scan of the repo's own source/history for accidentally-committed secrets came back clean (only the documented default_token placeholder). trl/trl_ceiling held at 6/7 for one more production cycle to confirm the false-positive drop holds at scale. See PR #4 (merged).","trl_ceiling":7,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"security-header-analyzer","domain":"security-header-analyzer.0crawl.com","mesh":"0crawl","host_port":8091,"category":"security","title":"Security Header Analyzer","summary":"Microservice for Security Header Analyzer","tags":["go","security"],"health_url":"https://security-header-analyzer.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_security_header_analyzer","url":"https://security-header-analyzer.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Differentiated diff-engine over five named compliance baselines\n(owasp-a-grade, mozilla-observatory-100, pci-dss, hipaa, fedramp-moderate).\nPer-header conformance verdict (pass|warn|fail) with exact suggested fix\nvalues, weighted scoring, http-vs-https comparison, multi-page averaging.\nBuilt on go-common/safehttp (SSRF-gated) and go-common/server. Test\ncoverage: handler + diff + profiles, ≥17 cases, all green via httptest.\nCPU-only, CGO-free, single binary.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"security-headers","domain":"security-headers.0crawl.com","mesh":"0crawl","host_port":8307,"category":"domains","title":"Security Headers","summary":"Microservice for Security Headers","tags":["domains","go"],"health_url":"https://security-headers.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_security_headers","url":"https://security-headers.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Production-DB anomaly (174 domains with all 4 key headers present still graded F; google.com/microsoft.com graded D/F despite serving real headers) investigated live end-to-end and found to be a correct-behavior semantic gap, not a bug: the tool grades header *quality* across 12 weighted signals (e.g. HSTS present but max-age=0 scores F), not just presence -- reproduced byte-for-byte the same scores the DB already stores. A separate, real bug was found and fixed instead: newClient() built its safehttp.Client without .WithoutFetchCache(), meaning production grading requests could be served stale/shared cached responses instead of live origin fetches. Fixed (v2.2.7) with a regression test proving the fetch-cache delegate is never invoked. See github.com/baditaflorin/go_security_headers PR #14 (merged). Rows with tool_version\u003c2.2.7 are re-crawl candidates.","trl_ceiling":7,"trl_ceiling_reason":"8-9 needs a real browser engine for post-JS-render header capture plus a persistent cross-check/SLA tier; structurally above a CPU-only RFC header-parser","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"security-txt","domain":"security-txt.0crawl.com","mesh":"0crawl","host_port":8167,"category":"web_analysis","title":"Security Txt","summary":"Microservice for Security Txt","tags":["go","web-analysis"],"health_url":"https://security-txt.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_security_txt","url":"https://security-txt.0crawl.com","example":"/go_security_txt?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"RFC 9116 fetch+validate with per-field evidence trail, soft-404 masquerade detection, misnamed-field + host-mismatch warnings. Pass-3 adds IDN host normalization via golang.org/x/net/idna (IDNA2008 lookup) before the SSRF-guard resolver: Unicode-form IDN domains (valenca.dev, baslat.net, Cyrillic/CJK/Arabic/Devanagari) reached 0/10 -\u003e 10/10 live, confirmed before=400 'no such host' / after=200. Soft-404 FP class (293/1000 present-but-no-Contact rows) found already-fixed by deployed code and discarded. 30+ multi-script table tests added.","trl_ceiling":7,"trl_ceiling_reason":"PGP cleartext signatures are detected but not cryptographically verified (no key fetch/validation); true 8-9 needs signature verification + a persistent cross-run history feed, structurally beyond a stateless CPU-only fetcher","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"seo-audit","domain":"seo-audit.0crawl.com","mesh":"0crawl","host_port":18298,"category":"web_analysis","title":"Seo Audit","summary":"Full SEO site audit: on-page basics, keyword density, heading structure, structured data, sitemap, robots.txt, broken links, mobile-friendliness — 9 analyzers in one call.","tags":["go","kind-container"],"health_url":"https://seo-audit.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_seo_audit","url":"https://seo-audit.0crawl.com","example":"/?target=stripe.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Re-audit (fresh start after a prior attempt was killed by an external session-limit cutoff, fresh 200-domain sample): confirmed this is a thin go_composite_runner recipe wrapper with no service-specific Go source. Confirmed the composite-runner fan-out client timeout bug (18s-\u003e32s fix, merged 2026-07-30 upstream) directly affects this recipe: with the deployed image over a month stale (pre-dating the fix), 38%% of domains (76/200) recover a result once the fix is applied -- the sitemap-finder sub-check alone jumps from 74.5%% to 99.5%% success. Opened a regression test on go_composite_runner (PR #4, merged) and a docs-only evidence update on go_seo_audit (PR #1, merged). trl/ceiling held at 6/8 pending redeploy against the fixed composite-runner image and re-assessment.","trl_ceiling":8,"trl_ceiling_reason":"Reaches TRL 8 with issue prioritisation and fix recommendations.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"seo-basics","domain":"seo-basics.0crawl.com","mesh":"0crawl","host_port":8308,"category":"domains","title":"Seo Basics","summary":"Microservice for Seo Basics","tags":["domains","go"],"health_url":"https://seo-basics.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_seo_basics","url":"https://seo-basics.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"1.3.1: multi-sitemap parsing (RFC 9309 §2.2.4 allows multiple Sitemap: directives) with per-sitemap reachability/Content-Type probe; canonical reachability probe (status + same-host + self-reference); pathsEqualish handles trailing-slash equivalence. 9/10 corpus PASS.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"service-worker-detector","domain":"service-worker-detector.0crawl.com","mesh":"0crawl","host_port":18259,"category":"content","title":"Service Worker Detector","summary":"Detects Progressive-Web-App / service-worker signals from the STATIC markup of a web page (or raw HTML): inline navigator.serviceWorker.register() calls with the resolved script URL and scope option, the \u003clink rel=manifest\u003e URL, and PWA meta/link tags (theme-color, apple-mobile-web-app-capable, apple-touch-icon, mobile-web-app-capable, viewport). Returns a flat report with has_service_worker, sw_registrations[], manifest_url, pwa_signals, a pwa_score count, and an evidence[] trail.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://service-worker-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_service_worker_detector","url":"https://service-worker-detector.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Real DOM walk over golang.org/x/net/html (no regex over HTML structure): the whole document is parsed once, inline \u003cscript\u003e text is accumulated (scripts with a src= attribute are skipped — an external bundle is not readable statically), and every \u003clink\u003e/\u003cmeta\u003e is inspected for PWA signals. Inline service-worker registration is detected by locating navigator.serviceWorker.register( / bare serviceWorker.register( / workbox.register( / wb.register( call sites, then hand-walking the argument list to the matching close paren (string-literal-aware so a close paren inside a quoted string does not terminate the span early) and pulling the first single/double/back-tick-quoted string as the script URL plus an optional scope: option; a computed/variable first argument is honestly skipped rather than guessed. Script URL, scope, manifest href (from \u003clink rel=manifest\u003e, rel parsed as a space-separated token set), and apple-touch-icon href are resolved to absolute URLs against the page's final post-redirect fetched URL via net/url ResolveReference (text= mode has no base, so relative URLs stay as authored). PWA meta detection covers theme-color, apple-mobile-web-app-capable, apple-mobile-web-app-status-bar-style, mobile-web-app-capable, and viewport, with case-insensitive name matching. pwa_score counts the positive signals (manifest, theme-color, apple-mobile-web-app-capable, mobile-web-app-capable, apple-touch-icon, viewport, and an inline registration). has_service_worker is true when EITHER an inline register() call was parsed (the strongest static tell) OR a manifest link co-occurs with at least one PWA meta/icon signal — a strong-but-not-certain combo. Honest TRL-4 ceiling: static markup only — a worker registered from an external/minified bundle is invisible (no JS execution), and this service does not fetch the manifest or sw.js to confirm. That ceiling is surfaced on every response lacking an inline registration via the degraded[] note sw_in_external_bundle_possible; a page with zero signals gets no_pwa_signals, and fetch errors get fetch_failed:\u003cerr\u003e. degraded[] is always a non-nil slice. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) in plain-HTML render mode so many producers scanning the same URL trigger one upstream fetch. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) plus localhost/.local names, with cache-side and safehttp-fallback dial-time guards catching DNS-resolved private IPs; the input guard is OUTBOUND-only and never inspects relative script/manifest URLs. 33 unit tests cover inline register (single/double/back-tick quotes), scope option parsing with whitespace, bare serviceWorker and workbox variants, external-bundle invisibility, computed-arg skip, paren-in-string arg slicing, multiple registrations, unterminated-call safety, manifest + apple-touch-icon resolution, every PWA meta family, pwa_score counting, the has_service_worker true/false logic across inline / manifest+meta / manifest-only / meta-only cases, no-signals and garbage input, evidence collection, multi-token rel, case-insensitive meta names, plus handler text-mode, no-signals degraded, external-bundle ceiling note, parse-input aliases, missing-param 400, and SSRF rejection. /selftest exercises the pure-logic pipeline (inline register + manifest, scope option, relative resolution, PWA meta, no-signals false, manifest+meta combo true, external-bundle ceiling, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"services-dashboard","domain":"services-dashboard.0crawl.com","mesh":"0crawl","host_port":18173,"category":"domains","title":"Services Dashboard","tags":["domains","go"],"health_url":"https://services-dashboard.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_services_dashboard","url":"https://services-dashboard.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"First-pass audit: found and fixed a real data race between the background poll loop and on-demand API-triggered tests, both operating on the same shared *Service struct without holding the registry lock across blocking network calls (3 distinct races confirmed via go test -race, fixed by snapshotting fields under lock). Added the repo's first-ever test suite. Also surfaced an urgent ops finding: the dashboard's own canonical URL is currently serving a completely different service (a port-collision routing issue on the fleet host, not a code bug) -- flagged for the deploy/routing team. trl held at 5 pending broader test coverage; trl_ceiling=7 added. See PR #2 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"session-management","domain":"session-management.0crawl.com","mesh":"0crawl","host_port":8095,"category":"security","title":"Session Management","summary":"Microservice for Session Management","tags":["go","security"],"health_url":"https://session-management.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_session_management","url":"https://session-management.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"RFC6265bis prefix validation (__Secure-/__Host-), curated session-cookie list (~25 platforms), Shannon-entropy weak-token detector, two-pass fixation probe behind ?probe_fixation=1, ≥18 unit + httptest cases (entropy_test.go + validate_test.go + handler_test.go) all green; safehttp client with no auto-jar so cookies aren't replayed across analyses.","trl_ceiling":5,"trl_ceiling_reason":"needs authenticated session state for full testing","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"shipping-regions","domain":"shipping-regions.0crawl.com","mesh":"0crawl","host_port":8310,"category":"domains","title":"Shipping Regions","summary":"Microservice for Shipping Regions","tags":["domains","go"],"health_url":"https://shipping-regions.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_shipping_regions","url":"https://shipping-regions.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Standalone service (not a go_composite_runner recipe). Tested against domain_shipping_regions/domain_shipping_region_items (~2.8M rows) plus a fresh 1,400-domain sample. Fixed a carrier-brand country-name false positive ('Canada Post', 'Australia Post' read as shipping destinations, 3.1% of tested domains, confirmed on the repo's own etsy.com smoke-test URL) and a negation/exclusion polarity inversion ('we do not ship to X', 'ship worldwide except X' registered as positive destinations, 3% prevalence, confirmed on dancesafe.org where 8 explicitly-embargoed countries showed as shippable). See github.com/baditaflorin/go_shipping_regions PR #13.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"simulate-ddos","domain":"simulate-ddos.0crawl.com","mesh":"0crawl","host_port":8092,"category":"security","title":"Simulate Ddos","summary":"Microservice for Simulate Ddos","tags":["go","security"],"health_url":"https://simulate-ddos.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_simulate_ddos","url":"https://simulate-ddos.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":4,"trl_evidence":"Safety-first re-audit (no live network traffic generated -- static analysis + non-networked unit tests only): confirmed the target-allowlist and hard request/concurrency caps (MaxRequests=50, MaxConcurrentWorkers=5, hardcoded Go constants never read from env/request params) are real, fail-closed, and non-bypassable -- already fixed 5 days prior in a merged PR that replaced a genuinely dangerous unbounded earlier version. Wrote new tests positively proving each control (credential-URL rejection, redirect revalidation, cap enforcement against a huge requested volume). Fixed a stale smoke-test config that always 404'd. Flagged, NOT fixed (needs human judgment): the repo ships a committed .env with AUTH_TOKEN=default_token and README examples use the same token -- currently inert since the allowlist is empty, but a latent risk if ops ever configures a real allowlist without rotating this token. trl bumped 2-\u003e4 (catching up to the already-shipped safety fix); trl_ceiling stays 4 -- this tool deliberately never produces the evidence trail the 6-7 'real' band requires. See PR #4 (merged).","trl_ceiling":4,"trl_ceiling_reason":"policy-blocked from public deployment","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"sitemap-finder","domain":"sitemap-finder.0crawl.com","mesh":"0crawl","host_port":8311,"category":"domains","title":"Sitemap Finder","summary":"Discovers a site's sitemaps via robots.txt + common-path probes, follows sitemapindex chains, decompresses .gz, returns URL inventory sorted by lastmod with an evidence trail.","tags":["domains","go"],"health_url":"https://sitemap-finder.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_sitemap_finder","url":"https://sitemap-finder.0crawl.com","example":"/?target=https://stripe.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh 30-domain sample): found and fixed a real fetch-cache-masking bug, live-proved with real timing (21.7s vs ~1s on a cold cache miss, nearly exhausting the 25s budget) and corrupted evidence fields (wrong byte counts, missed gzip detection from the cache silently decompressing responses). Also flagged (not fixed, ops scope) that production is running a 4-week-stale image missing PR #5's relative-sitemap-index-child fix while sibling services redeployed ~20h prior. trl_ceiling was previously unset; added ceiling=8. See PR #7 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"smuggling-probe","domain":"smuggling-probe.0crawl.com","mesh":"0crawl","host_port":8154,"category":"security","title":"Smuggling Probe","summary":"Microservice for Smuggling Probe","tags":["go","security"],"health_url":"https://smuggling-probe.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_smuggling_probe","url":"https://smuggling-probe.0crawl.com","example":"/go_smuggling_probe?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Raw TCP/TLS request-boundary probes cover CL.TE, TE.CL, TE.TE, duplicate CL, SSRF-sticky resolution, deltas, and tests.","trl_ceiling":6,"trl_ceiling_reason":"Timing-only request smuggling signals require manual confirmation to avoid false positives.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"social-graph","domain":"social-graph.0crawl.com","mesh":"0crawl","host_port":8312,"category":"domains","title":"Social Graph","summary":"Microservice for Social Graph","tags":["domains","go"],"health_url":"https://social-graph.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_social_graph","url":"https://social-graph.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"No audit-reset commit found -- genuine incremental hardening across 10+ rounds. Confirmed real table domain_social_profiles (~1.29M rows, tool_name='social-graph'). Tested against 600 real domains. Fixed: Weibo URL-routing prefixes (u/p/n) were being stored as the actual handle -- confirmed live in production, 144 rows literally have handle=\"u\", and CJK nicknames under /n/ were replaced with the literal string \"n\"; also fixed hyphenated-domain brand matching and wired Facebook's fb-page widget as a genuine owned-profile signal while correctly leaving fb-like alone (its link is often self-referential, not an identity claim). On a 517-domain corpus: domains with \u003e=1 owned profile 169-\u003e179, zero regressions, no new false positives in a 25-profile precision spot-check. See github.com/baditaflorin/go_social_graph PR #18.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"social-proof-extractor","domain":"social-proof-extractor.0crawl.com","mesh":"0crawl","host_port":18269,"category":"content","title":"Social Proof Extractor","summary":"Extract social-proof signals from a web page or raw HTML — schema.org AggregateRating (JSON-LD + microdata), visible star ratings, review counts, customer/usage counts, testimonial blocks, press mentions, and trust-badge logo counts, plus a one-line summary.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://social-proof-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_social_proof_extractor","url":"https://social-proof-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Real DOM walk over a fetched page (golang.org/x/net/html tokenizer, no regex over HTML structure — regex used only over already-extracted text spans): parses schema.org AggregateRating from both JSON-LD (recursively searching @graph / nested Product nodes for ratingValue + reviewCount/ratingCount, coercing numeric strings, defaulting scale to bestRating or 5) and microdata (itemprop=ratingValue/bestRating/reviewCount, preferring the machine-readable content attribute). Heuristic text patterns over the visible prose detect visible star ratings (4.8 out of 5, 4.8/5), review counts with thousands separators (1,234 reviews), and customer/usage headline counts with k/m/b magnitude + optional plus (trusted by 10,000+ customers, 1M+ downloads), filtering out sub-100 noise. DOM-class/blockquote heuristics count testimonial blocks; a known-outlet list gated on an as-seen-in/press region or phrase yields press mentions; the largest img/svg cluster inside a logos/clients/partners/brands region gives a trust-badge logo count. Structured ratings win over visible-text ratings; results roll up into a structured social_proof object plus a human summary. Input fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so N producers scanning the same URL trigger one upstream fetch; plain-HTML render mode; 4 MiB body cap. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode scans pasted HTML with no fetch. Per-failure notes pushed to degraded[] (no_social_proof_found, fetch_failed:\u003cerr\u003e) instead of failing the response. ~30 table-driven + httptest unit tests cover JSON-LD/microdata/@graph rating parse, scale defaulting, visible X-out-of-5 and X/5 parse, review-count thousands separators, k/m/b usage counts and the +-flag, sub-100 noise rejection, testimonial counting, press-mention detection (region- and phrase-gated), logo-region img counting, no-proof→degraded, missing-param 400, SSRF rejection, and text= mode. /selftest exercises the pure-logic pipeline (JSON-LD rating, usage-count heuristic, visible-rating, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal. TRL-4 ceiling: signal counts are heuristic (text phrasing is English-centric; logo/testimonial counts key on conventional class names), static-DOM only (no JS-rendered review widgets like Trustpilot/Yotpo embeds), and outlet detection is a curated English-language press list rather than an exhaustive registry — a headless-render + entity-recognition pass would lift accuracy and TRL but isn't required for aggregate page-level social-proof scoring.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"sourcemap-finder","domain":"sourcemap-finder.0crawl.com","mesh":"0crawl","host_port":8347,"category":"recon","title":"Sourcemap Finder","summary":"Microservice for Sourcemap Finder","tags":["go","recon"],"health_url":"https://sourcemap-finder.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_sourcemap_finder","url":"https://sourcemap-finder.0crawl.com","example":"/go_sourcemap_finder?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"2026-08-08 re-audit (prior evidence from 2026-05-13 was stale, never re-audited): confirmed and fixed the fleet-wide safehttp bare-constructor bug in this service. handler.go:37 built its shared httpClient (used for every live probe -- target-page fetch in handler_helpers.go, .map convention-guess probing in handler_probe.go, and map-body fetch in handler_fetch.go) via a bare safehttp.NewClient() with no WithoutFetchCache()/WithForceHTTP2(). Verified against go-common v0.80.0 source (safehttp/fetchcache.go, safehttp/safehttp_with.go): NewClient() with no fetch-cache opt-out silently resolves the process-wide DefaultFetchDelegate at call time, so on any host with FLEET_FETCH_CACHE_URL set, live origin probes were transparently routed through the fleet fetch cache -- a stale cached 200 could report a source map as present long after it was removed from the origin, and a stale cached 404/miss could hide a newly deployed one, corrupting the tool's core recon signal. The missing WithForceHTTP2() also meant HTTP/2-only origins silently fell back to HTTP/1.1 under the custom SSRF-guard DialContext (net/http conservatively disables H2 with a custom dialer unless ForceAttemptHTTP2 is set). Fix (PR https://github.com/baditaflorin/go_sourcemap_finder/pull/8, unmerged): added safehttp.WithoutFetchCache() + safehttp.WithForceHTTP2() to the httpClient constructor. Added TestHTTPClientBypassesFetchCache, a regression test that installs a stub safehttp.FetchDelegate returning a stale cached 200+map-body, points the real httpClient at a live loopback server returning 404, and asserts the live 404 wins and the delegate is never consulted -- confirmed this test fails against the pre-fix bare constructor and passes with the fix. Live-verified (ad-hoc, uncommitted) against reactjs.org, www.cloudflare.com (HTTP/2 origins), and code.jquery.com: normal crawl/discovery behavior unchanged, all 200s, no regressions. Version bumped 1.3.4 -\u003e 1.3.5 (CHANGELOG.md added). Core map-parsing/source-path-extraction capability (the basis for the prior TRL-6 rating) is unchanged by this fix, so trl/trl_ceiling are left as-is; this was a live-probe reliability/correctness fix, not a capability change.","trl_ceiling":8,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"structured-data-validator","domain":"structured-data-validator.0crawl.com","mesh":"0crawl","host_port":18254,"category":"content","title":"Structured Data Validator","summary":"Finds and validates a web page's structured data from three sources — JSON-LD (\u003cscript type=application/ld+json\u003e), Microdata (itemscope/itemtype/itemprop), and RDFa (vocab/typeof/property) — reporting per block its format, the @type/itemtype/typeof values, whether it parsed, any parse errors, and recommended-field warnings for common schema.org types, plus a summary with total/valid/invalid counts, types_seen, and a by_format histogram.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://structured-data-validator.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_structured_data_validator","url":"https://structured-data-validator.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Finds and validates structured data from three sources on a fetched (or pasted) HTML page, walking the WHOLE parsed document (golang.org/x/net/html tokenizer, zero regex for structure) — JSON-LD scripts routinely live in \u003chead\u003e, so it deliberately does not restrict to a content root. (1) JSON-LD validation is rigorous: each \u003cscript type=application/ld+json\u003e body is parsed with the stdlib encoding/json; malformed JSON yields valid=false plus a precise error message including the byte offset reported by the decoder (json.SyntaxError/UnmarshalTypeError Offset). @type is extracted from a lone object, every object of a JSON array, and the @graph wrapper array; @type accepts both the string and array forms. (2) Microdata extraction reads itemscope elements (top-level and nested), pulling type(s) from itemtype and the itemprop names from descendants without leaking a nested item's props up to its parent. (3) RDFa extraction reads typeof elements, pulling type(s) from typeof and property names from descendants scoped to the nearest typeof ancestor, matching CURIE properties (schema:headline) by bare name. For a curated, intentionally-small checklist of common schema.org types it emits recommended-but-missing-field warnings — Article/NewsArticle/BlogPosting need headline; Product/Organization/Person need name; BreadcrumbList needs itemListElement — keyed on the bare type name so full-URL, CURIE, and bare forms all match. Returns blocks[] (format, types, valid, errors[], warnings[]; errors/warnings always non-nil) plus summary { total_blocks, valid_blocks, invalid_blocks, types_seen[] deduped+sorted, by_format map }. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) in plain-HTML render mode — the static markup already carries the ld+json scripts and itemscope/typeof attributes, so no JS rendering is needed. SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) plus localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode scans pasted HTML with no fetch. Non-fatal conditions go to degraded[] (fetch_failed:\u003cerr\u003e, no_structured_data, invalid_blocks) instead of failing the response; a page with no structured data still returns 200. ~36 unit tests cover valid single-object/array/@graph JSON-LD, malformed JSON-LD with offset, string and array @type, the per-type recommended-field warnings, full-URL type matching, ld+json charset param, microdata itemtype/itemprop and nested-scope isolation, RDFa typeof/property and CURIE matching, summary counts + by_format + types_seen dedupe/sort, no-data and garbage input, non-nil slices, parseInput aliases, missing-param 400, SSRF rejection, and the finishAnalysis degraded[] tagging. /selftest exercises the pure-logic pipeline (1 valid + 1 invalid JSON-LD, the missing-headline warning, microdata/RDFa extraction, summary, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal. TRL-4 ceiling vs higher: it validates parse correctness plus a curated required/recommended-field checklist for a handful of common schema.org types — it does NOT validate against the full schema.org vocabulary graph (property domains/ranges, enumerations, cardinality), which is what a full validator like Google's Rich Results Test does and would require carrying the entire vocabulary. Microdata/RDFa are structural extraction with lighter checks than the rigorous JSON-LD JSON parse.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"subdomain-finder","domain":"subdomain-finder.0crawl.com","mesh":"0crawl","host_port":8348,"category":"recon","title":"Subdomain Finder","summary":"Microservice for Subdomain Finder","tags":["go","recon"],"health_url":"https://subdomain-finder.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_subdomain_finder","url":"https://subdomain-finder.0crawl.com","example":"/go_subdomain_finder?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"v1.6.0 adds wildcard-DNS suppression to the passive-source liveness pass (probe a random nonce label; under a catch-all *.apex record count a candidate active only when its A/AAAA answer introduces an IP the wildcard set does not; apex never suppressed) plus golang.org/x/net/idna (IDNA2008 lookup) so Unicode hosts/subdomains normalize to punycode instead of being dropped by the ASCII-only validator. domainscope showed 16,831 stored rows with active_count==total_count\u003e=10 (407,922 claimed-active) - the dominant FP class; 5/5 worst offenders (domainloud.com, alyssalow.com...) confirmed wildcarded via nonce-label dig. Fixture reproducing domainloud.com's 369/369 row: OLD counted all 369 active, NEW keeps 2 (apex + 1 distinct host) = 367 FP removed. Live-confirmed IDN: probe muenchen.de returns domain xn--mnchen-3ya.de and resolves. 19 new table-driven tests; build/test/vet/gofmt green.","trl_ceiling":7,"trl_ceiling_reason":"TRL 8+ needs paid resolver/threat-intel feeds and an exhaustive 10k-100k brute dictionary beyond the polite CPU-only resolver budget; passive feeds (crt.sh/hackertarget) are also intermittently rate-limited/502 in production.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"subdomain-takeover","domain":"subdomain-takeover.0crawl.com","mesh":"0crawl","host_port":8223,"category":"security","title":"Subdomain Takeover","summary":"Microservice for Subdomain Takeover","tags":["go","security"],"health_url":"https://subdomain-takeover.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_subdomain_takeover","url":"https://subdomain-takeover.0crawl.com","example":"/go_subdomain_takeover?domain=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"1.6.0 adds a NotClaimable flag for can-i-take-over-xyz 'Edge case / Not vulnerable' platforms (Fastly); both the claimability and legacy severity ladders now cap such matches at dangling_review/possible. On 400 live re-probes of stored findings, Fastly false-'vulnerable' verdicts dropped 17 to 0 (22% of all 'vulnerable' were Ghost(Pro)/RebelMouse-over-Fastly HTTP-500 'unknown domain' pages on shared service maps an attacker cannot register), while genuine GitHub Pages/Azure orphans stayed vulnerable. Also adds IDNA2008 Unicode-\u003epunycode normalization (golang.org/x/net/idna, CGO-free) so native-script IDNs (bucher.de, rossiya.rf, example.jp) are scanned instead of rejected by the RFC-1035 ASCII validator (451 stored IDN domains affected). +18 table-driven tests; build/test/vet/gofmt green.","trl_ceiling":7,"trl_ceiling_reason":"TRL 8 would need battle-tested cross-checks / paid threat-intel feeds / stateful re-verification; the detector is CPU-only DNS+HTTP with a curated gazetteer and reaches its real ceiling at principled, evidence-trailed, false-positive-hardened detection.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"substack-scraper","domain":"substack-scraper.0crawl.com","mesh":"0crawl","host_port":8236,"category":"content","title":"Substack Scraper","summary":"Public-metadata scraper for Substack publications: posts, cadence, recommendations, authors.","tags":["go","substack"],"health_url":"https://substack-scraper.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_substack_scraper","url":"https://substack-scraper.0crawl.com","example":"/?url=https://example.substack.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Re-audited 2026-08-20 on a fresh clone at go_substack_scraper@1ab2e9f (go-common@v0.88.0 tip). Confirmed the fleet-wide bare-safehttp.NewClient()/DefaultFetchDelegate stale-cache footgun does NOT apply here: the package-level httpClient var built via safehttp.NewClient() (handler.go) was never called anywhere (no .Get/.Do reference in the repo) -- genuinely dead code, removed in the fix PR. The real fetch path (fetchClient = fleetfetch.NewClient(...)) intentionally routes through the shared fleet fetch cache by design (fleetfetch's documented purpose for HTML scrapers per go-common/fleetfetch/doc.go) with a 60s default max-age, not the multi-hour-stale pattern this bug class usually describes elsewhere in the fleet. Found and fixed a real, previously-undetected correctness bug instead: the /api/v1/archive fetch was hardcoded to limit=12 while maxPosts=24 governs resp.Truncated/resp.TotalPosts and is what the HTML-fallback path (extractPostsFromHTML) can return -- so the primary (preferred) API path silently delivered at most half the recent posts the response's own truncation semantics promised. Verified live against astralcodexten.com/api/v1/archive on 2026-08-20: limit=12 returns exactly 12 posts, limit=24 returns up to 24 -- Substack honors the param directly, so this directly capped what every caller of the deployed service saw. Also live-verified isSubstack marker detection, the audience field values (everyone/only_paid) driving is_subscriber_only, and redirect-following (noahpinion.substack.com -\u003e www.noahpinion.blog, a common real-world case for bare .substack.com URLs) against several real current Substack publications (astralcodexten.com, slowboring.com, thefp.com) -- all correct. Fix + regression test (TestArchiveEndpointRequestsMaxPosts, fails against the old limit=12 value) in PR https://github.com/baditaflorin/go_substack_scraper/pull/8 (v1.1.2 -\u003e v1.1.3), not merged. TRL lowered 7 -\u003e 6 pending merge: the as-deployed main branch still ships the posts-undercounting bug and had no handler-level regression coverage before this audit.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"svg-icon-inventory","domain":"svg-icon-inventory.0crawl.com","mesh":"0crawl","host_port":18256,"category":"content","title":"Svg Icon Inventory","summary":"Inventories every SVG / icon usage on a web page or raw HTML and classifies by mechanism: inline \u003csvg\u003e elements (with their \u003csymbol\u003e defs and viewBox), sprite references via \u003cuse href='#id'\u003e / \u003cuse xlink:href='sprite.svg#id'\u003e, \u003cimg src='*.svg'\u003e, external SVG via \u003cobject data='*.svg'\u003e / \u003cembed src='*.svg'\u003e, and icon-font usage (fa-/material-icons/glyphicon/bi-/icon- class heuristics). Returns icons[] (mechanism, resolved-absolute ref/src, symbol_id, viewBox), a per-mechanism summary, plus deduped unique_symbol_ids[] and external_sprite_urls[].","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://svg-icon-inventory.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_svg_icon_inventory","url":"https://svg-icon-inventory.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Real DOM walk over golang.org/x/net/html (no regex over HTML structure): parses the whole document and recursively collects every SVG/icon usage in document order, classifying each into one of five mechanisms. Inline \u003csvg\u003e elements are counted with their viewBox (attribute case is preserved inside SVG foreign content, so the camelCase viewBox is read correctly), and every nested \u003csymbol id\u003e def is surfaced as its own inline_svg row with id + viewBox so a caller can rebuild the sprite map. Sprite instances via \u003cuse\u003e are detected by element name (the parser assigns no atom to \u003cuse\u003e/\u003csymbol\u003e) reading href first then the legacy xlink:href: a same-document #id reference records the fragment as symbol_id and leaves the ref unresolved, while an external \u003cuse xlink:href='sprite.svg#id'\u003e splits file from fragment, resolves the file part to an absolute URL against the page's final post-redirect fetched URL via net/url ResolveReference (protocol-relative //host and path-relative forms both handled), re-attaches the fragment for the ref, and records the deduped sprite-file URL in external_sprite_urls. \u003cimg src='*.svg'\u003e, \u003cobject data='*.svg'\u003e, and \u003cembed src='*.svg'\u003e are matched by a conservative SVG-ref test (path ends in .svg case-insensitively after stripping query/fragment, or a data:image/svg+xml URI) so non-SVG images and a generic .php endpoint with a .svg query param are not mis-counted; embed is folded into the object_svg bucket. Icon-font usage is a class-name heuristic over a finite curated token set (fa-, material-icons, glyphicon, bi-, icon-): prefix tokens ending in '-' match the glyph form (fa-home, bi-house, icon-cart) while base-class tokens match exactly or as a hyphenated family (material-icons, glyphicon/glyphicon-star), and a bare base class with no glyph modifier (a lone 'fa') is intentionally not counted to avoid false positives. This is the honest TRL-4 ceiling: it counts references by class name and does not render, rasterize, or fetch the glyph, and a novel icon-font convention not on the curated list is not detected (the TRL-5+ ceiling would require rendering or an external dataset). symbol ids and external sprite URLs are deduped in insertion order so the JSON output is deterministic. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) so many producers scanning the same URL trigger one upstream fetch; plain-HTML render mode (static DOM, no JS). SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) + localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs; the input guard is OUTBOUND-only and never inspects relative icon refs. Direct text= mode scans pasted HTML with no fetch (empty base, so relative refs stay as-is). Per-failure notes pushed to degraded[] (fetch_failed:\u003cerr\u003e, no_icons) instead of failing the response; degraded[] is always a non-nil slice and icons/unique_symbol_ids/external_sprite_urls are always non-nil. 36 unit tests cover inline svg + viewBox case-preservation, symbol def collection and id-less skip, multi-symbol order, same-doc and external \u003cuse\u003e, href-beats-xlink:href, img svg incl. uppercase/query/data-URI, non-svg img rejection, object + embed svg incl. non-svg rejection, every icon-font family + prefix-false-positive + bare-base rejection, relative + protocol-relative sprite resolution, unresolved-without-base, unique-symbol-id and external-sprite-url dedupe, full summary counts, no-icons, garbage input safety, document-order preservation, icons-anywhere, href-less use skip, plus the isSVGRef/splitFragment/matchIconFontClass helper tables, and handler text-mode, parse-input aliases, missing-param 400, and SSRF rejection. /selftest exercises the pure-logic pipeline (inline+use+img mix, external sprite resolution, symbol defs + unique ids, object+embed, icon-font heuristic incl. bare-base rejection, no-icons summary, SSRF guard) AND a live example.com fetch through the cache so the deploy smoke-gate has a real signal.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"svi","domain":"svi.0crawl.com","mesh":"0crawl","host_port":8313,"category":"domains","title":"Svi","summary":"Microservice for Svi","tags":["domains","go"],"health_url":"https://svi.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_svi","url":"https://svi.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Corrected DOWNWARD from trl:7. The maintainer's own commit skipped a real TRL-6 assessment, bumping 5-\u003e7 in one shot while silently rewriting trl_ceiling_reason to imply a higher bar had been reached with no new capability (no Chromium/Playwright dependency before or after). The repo's own README and ADR still say TRL 5/6, contradicting service.yaml's TRL 7. Also fixed a real bug: non-web URI schemes (whatsapp:, tg:) were miscounted as broken internal links on a 600-domain live sample (13/600 affected). No dedicated production output table found for this service. See github.com/baditaflorin/go_svi PR #7.","trl_ceiling":7,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"swagger-finder","domain":"swagger-finder.0crawl.com","mesh":"0crawl","host_port":8349,"category":"recon","title":"Swagger Finder","summary":"Microservice for Swagger Finder","tags":["go","recon"],"health_url":"https://swagger-finder.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_swagger_finder","url":"https://swagger-finder.0crawl.com","example":"/go_swagger_finder?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Probes 28 well-known OpenAPI/Swagger/GraphQL paths concurrently (worker pool of 8, 5s per-request, 60s total cap) via go-common/safehttp (SSRF-safe). Parses responses with kin-openapi v0.135.0 — OpenAPI 3.x natively, Swagger 2.0 upgraded via openapi2conv. Extracts {method,path,summary,parameters,security_schemes} inventory (capped at 2k endpoints). 1h sha256-keyed in-memory cache. Tested with httptest fixtures covering openapi3, swagger2, graphql, html, junk, and 404 cases.","trl_ceiling":4,"trl_ceiling_reason":"Functionally superseded by api-extractor. Deprecate.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"table-extractor","domain":"table-extractor.0crawl.com","mesh":"0crawl","host_port":18289,"category":"content","title":"Table Extractor","summary":"Parse every HTML table into a dense matrix with full colspan/rowspan expansion and header detection (no regex)","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://table-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_table_extractor","url":"https://table-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"First-pass audit (fresh 260-domain sample): found and fixed 2 real bugs -- mojibake on non-UTF-8 pages (confirmed live on a real EUC-JP Japanese site, same charset-transcoding fix already shipped in sibling go_schema_extractor), and a header-rowspan carry bug that silently shifted real table data one column left. Explicitly verified fetch-cache masking does not apply (uses fleetfetch, the correct shared-cache client). trl held at 7; trl_ceiling=7 added -- CPU-only parser with no headless browser, so JS-rendered tables and ARIA grids are structurally invisible. See PR #2 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"team-member-extractor","domain":"team-member-extractor.0crawl.com","mesh":"0crawl","host_port":18251,"category":"content","title":"Team Member Extractor","summary":"Extracts a roster of team / staff members from an about-us or team page (or raw HTML) — each member's name, role (job title), short bio, photo_url (resolved absolute), and social/profile links — preferring schema.org Person (JSON-LD then microdata) and falling back to a conservative repeated-card heuristic. Returns members[] plus count and the detection method.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://team-member-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_team_member_extractor","url":"https://team-member-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Real DOM walk over a fetched HTML page (golang.org/x/net/html tokenizer, no regex over HTML structure) plus stdlib encoding/json for embedded structured data. Detection runs three strategies in strict priority order. (1) schema.org Person via JSON-LD: every \u003cscript type=\"application/ld+json\"\u003e block is parsed and walked recursively — top-level Person, Person inside an @graph or array, and Person under an Organization's member/employee/founder/alumni properties are all harvested, with namespaced @type forms (https://schema.org/Person, schema:Person) recognised; jobTitle, description, image (string / array / ImageObject.url), sameAs and url become role/bio/photo_url/links; results are de-duplicated by name. (2) schema.org microdata: elements whose itemtype ends in /Person are read via their itemprop children (name/jobTitle/description/image/sameAs/url), without descending into nested itemscope entities. (3) Conservative repeated-card heuristic: under a common parent it finds the dominant run (\u003e=2) of same-tag card containers (li/article/div/section), extracts a name from the first heading or strong/b that passes a strict person-name gate (2-4 tokens, each capitalised or an allowed name connective, no digits/role-words, length-capped), a role from a class/itemprop hint (role/title/position/jobTitle) or a nearby short line carrying a known role keyword, the longest paragraph as bio, the first img as photo, and the card's anchor hrefs as links. The heuristic is deliberately conservative: a group must yield \u003e=2 qualifying members AND at least one must carry a role line, otherwise it is dropped — so navigation bars, footers, and link lists are not emitted as people. Photo and link hrefs are resolved against the fetched final URL via net/url ResolveReference; javascript:/fragment-only hrefs are dropped. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch) in plain-HTML render mode (the static DOM is sufficient — no JS rendering needed). SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) plus localhost/.local names, with cache-side + safehttp-fallback dial-time guards catching DNS-resolved private IPs. Direct text= mode scans pasted HTML with no fetch. Non-fatal conditions are pushed to degraded[] (fetch_failed:\u003cerr\u003e, no_extractable_text, jsonld_parse_error, heuristic_fallback, no_members) instead of failing; a page with text but no detectable roster still returns 200, and the response reports which method (jsonld/microdata/heuristic/none) was used. ~35 unit tests cover JSON-LD single/array/@graph/org-employee/namespaced-type/ImageObject/given-family-name/malformed/dedup/precedence, microdata single/multiple/content-attr, the heuristic across div/li/article cards with role-evidence gating, single-card rejection, nav rejection, mixed-role majority, bio capture, relative-link resolution, the name gate's accept/reject sets, omitempty JSON shape, non-nil slice stability, script isolation, and SSRF rejection. /selftest exercises all three pure-logic strategies plus a live example.com fetch through the cache so the deploy smoke-gate has a real signal. TRL-4 ceiling: JSON-LD and microdata paths are exact, but the heuristic card detection is structurally fragile against unmarked, bespoke, or visually-driven layouts — distinguishing a true team card from a generic content card without semantic markup is a judgement a trained model would make far better than these hand-tuned rules, and the conservative gate trades recall (missing people) for precision (not emitting non-people).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"team-size","domain":"team-size.0crawl.com","mesh":"0crawl","host_port":8314,"category":"domains","title":"Team Size","summary":"Microservice for Team Size","tags":["domains","go"],"health_url":"https://team-size.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_team_size","url":"https://team-size.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Second-pass re-audit (fresh 40-domain sample): found and fixed 2 real false-positive bugs -- schema.org Review-block author names (customer reviewers) counted as team members, and unfiltered schema.org Person names (CMS/theme boilerplate accounts) counted as employees. Also definitively resolved the cross-service field-contract question for go_company_size's integration: estimate.value/range_low/range_high/confidence/method, wrapped in the standard envelope -- that integration bug is now independently fixed on the go_company_size side (PR #20, merged same day). See PR #9 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"tech-stack","domain":"tech-stack.0crawl.com","mesh":"0crawl","host_port":8162,"category":"web_analysis","title":"Tech Stack","summary":"Microservice for Tech Stack","tags":["go","web-analysis"],"health_url":"https://tech-stack.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_tech_stack","url":"https://tech-stack.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Frontend/backend technology fingerprints across frameworks, CSS, CMS, analytics, CDN, server headers, versions, JSON API shape, and tests.","trl_ceiling":7,"trl_ceiling_reason":"Dynamic-only framework evidence requires JS rendering for full coverage.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"technology-stack","domain":"technology-stack.0crawl.com","mesh":"0crawl","host_port":8315,"category":"domains","title":"Technology Stack","summary":"Microservice for Technology Stack","tags":["domains","go"],"health_url":"https://technology-stack.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_technology_stack","url":"https://technology-stack.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Live production-DB audit found tech_count=0 on 51.2% of successful rows; investigated and found 71.9% of the zero rows carry a tool_version whose fetch path routed through a since-fixed contended cache bug (backlog awaiting reprocessing) -- current-version zero rate is a plausible ~17%, mostly genuine parked/static/bot-challenge pages, confirmed via 40+ live spot-checks. A real bug was found separately: techFromAssetURL used an unqualified substring match for 'bootstrap', misattributing Bootstrap Icons CDN URLs (an independently-versioned sibling project) as the Bootstrap CSS framework and bleeding its version onto it, poisoning the CPE/CVE bridge with a nonexistent version. Fixed (v1.9.6) by detecting bootstrap-icons as its own technology before the generic Bootstrap match. See github.com/baditaflorin/go_technology_stack PR #22 (merged). Rows with tool_version\u003c1.9.6 are re-crawl candidates.","trl_ceiling":7,"trl_ceiling_reason":"Static (no-JS) HTTP+markup fingerprinting. Detecting JS-injected platforms (client-rendered SPAs that only emit their analytics/CMS markers after hydration) requires a real browser engine (chromedp/playwright), which is out of scope for a CPU-only single-fetch service. TRL 8-9 would need a headless-render feed.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"telnet-banner","domain":"telnet-banner.0crawl.com","mesh":"0crawl","host_port":8086,"category":"security","title":"Telnet Banner","summary":"Microservice for Telnet Banner","tags":["go","security"],"health_url":"https://telnet-banner.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_telnet_banner","url":"https://telnet-banner.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"30-row fingerprint table (Mikrotik/Cisco/Juniper/OpenBSD/Solaris-CVE-2007-0882/IoT cameras/BusyBox-Mirai/etc.), IAC-WONT negotiation, in-process TCP listener for /selftest, hex-safe banner storage","trl_ceiling":7,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"testimonial-extractor","domain":"testimonial-extractor.0crawl.com","mesh":"0crawl","host_port":18253,"category":"content","title":"Testimonial Extractor","summary":"Extracts testimonials / customer reviews / endorsements from a web page or raw HTML — schema.org Review JSON-LD first, then \u003cblockquote\u003e with \u003ccite\u003e/\u003cfigcaption\u003e attribution, then heuristic testimonial cards — capturing each testimonial's text, author, author_title, numeric rating (when present), and source_url, plus count and a has_ratings flag.","tags":["kind-container","language-go","runtime-compose"],"health_url":"https://testimonial-extractor.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_testimonial_extractor","url":"https://testimonial-extractor.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Real DOM walk over a fetched HTML page (golang.org/x/net/html tokenizer; zero regex for structure) with a confidence-ordered three-strategy extractor. Strategy 1 (authoritative): parses every \u003cscript type=application/ld+json\u003e block with the stdlib JSON decoder and harvests schema.org Review / Testimonial nodes — recursing through @graph, arrays, and the review/reviews/itemListElement properties of a parent Product/Organization — mapping reviewBody/description/text to the body, a string-or-Person/Organization author to name + jobTitle/affiliation/worksFor, reviewRating.ratingValue (or a bare ratingValue, numeric or string) to the rating, and url/sameAs to a source link. Strategy 2: \u003cblockquote\u003e testimonials attributed by a nested \u003ccite\u003e, an enclosing \u003cfigure\u003e's \u003cfigcaption\u003e, or an immediately-following \u003ccite\u003e; a bare unattributed pull-quote is conservatively rejected UNLESS it sits inside a testimonial-flavoured container, to avoid emitting marketing/nav copy. Strategy 3 (best-effort, flagged heuristic_fallback): block-container cards (div/section/article/li/figure) whose class/id mentions testimonial/review/endorsement/quote/feedback, taking the longest quote element/paragraph as the body and a cite/footer/author-class/shortest-paragraph line as the attribution; an outer wrapper that contains inner card containers descends to those rather than emitting one blob. Ratings are best-effort and conservative: schema.org microdata itemprop=ratingValue (content= or text) first, then aria-label/title phrases like '5 out of 5' / 'Rated 4.5' / '4.5/5', then a filled-star glyph count — surfaced per-testimonial as an omitempty numeric rating plus a top-level has_ratings flag. JSON-LD short-circuits the DOM heuristics so the same visible card is never double-counted. Author lines are split into author + author_title on a leading dash/em-dash and the first comma or ' - '/' – ' separator. Relative source/author URLs are resolved against the final fetched URL. Input is fetched through the fleet HTTP fetch cache (go-common/fleetfetch, plain-HTML render mode) with SSRF defense-in-depth: input-time block of literal loopback/private/link-local IPs (safehttp block list) plus localhost/.local names, and cache-side + safehttp-fallback dial-time guards for DNS-resolved private IPs. Direct text= mode scans pasted HTML with no fetch. Non-fatal conditions go to a non-nil degraded[] (fetch_failed:\u003cerr\u003e, no_extractable_text, jsonld_parse_error, heuristic_fallback, no_testimonials) instead of failing; a page with text but no testimonials still returns 200. ~40 unit tests plus /selftest cover the JSON-LD review/rating/author paths, blockquote+cite/figcaption/following-cite attribution, the conservative bare-quote rejection, heuristic card extraction and wrapper de-duplication, all three rating heuristics and has_ratings, author-line splitting, empty/garbage/no-testimonial input, parse-input aliases, missing-param 400, SSRF rejection, and the text-mode handler paths; /selftest also runs a live example.com fetch through the cache so the deploy smoke-gate has a real signal. TRL-4 ceiling vs higher: Strategy 1 is exact, but the heuristic-card path and star-glyph/aria rating detection are structurally fragile — they pattern-match on author-supplied class names and rating glyphs, so an unconventional widget will be missed or mis-rated; lifting that ceiling would need site-specific templates or NLP-grade layout inference, not more heuristics.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"tos-finder","domain":"tos-finder.0crawl.com","mesh":"0crawl","host_port":8316,"category":"domains","title":"Tos Finder","summary":"Microservice for Tos Finder","tags":["domains","go"],"health_url":"https://tos-finder.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_tos_finder","url":"https://tos-finder.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Second-pass re-audit (fresh 60-domain sample): found and fixed a real bug -- the fleetfetch fallback client (used when the shared fetch cache degrades) silently stripped the User-Agent, causing real production sites to 403-block the bare Go-http-client UA. Live-confirmed 2 domains flipping from blocked/unreachable to correct results after fix. See PR #14 (merged).","trl_ceiling":7,"trl_ceiling_reason":"No JS render engine: JS-rendered SPA footers (e.g. naver.com) carry no static legal anchors and stay unreachable for a CPU-only pure-Go fetcher; plus no persistence / cross-source corroboration. Closing either needs a headless browser or a stored evidence store, out of scope for this service shape.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"trust-decay","domain":"trust-decay.0crawl.com","mesh":"0crawl","host_port":8317,"category":"domains","title":"Trust Decay","summary":"Microservice for Trust Decay","tags":["domains","go"],"health_url":"https://trust-decay.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_trust_decay","url":"https://trust-decay.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":8,"trl_evidence":"Second-pass re-audit (fresh, disjoint 600-domain sample, zero commits since prior fix): genuinely clean -- confirmed the prior TLS chain-trust/hostname-coverage fix holds up on an independent sample with consistent residual-failure rates, and explicitly ruled out fetch-cache (never calls the vulnerable client constructor). No PR opened; trl/ceiling held at 8/8, evidence base strengthened.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"typosquat-finder","domain":"typosquat-finder.0crawl.com","mesh":"0crawl","host_port":8350,"category":"recon","title":"Typosquat Finder","summary":"Microservice for Typosquat Finder","tags":["go","recon"],"health_url":"https://typosquat-finder.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_typosquat_finder","url":"https://typosquat-finder.0crawl.com","example":"/go_typosquat_finder?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"PSL adoption via publicsuffix.EffectiveTLDPlusOne (fixes multi-label TLD bug); 32-row offline corpus at 100% hit-rate; parked-SSL-CN heuristic against 7 provider markers; /selftest; psl_version in /version. TRL-uplift audit (2026-08-08) found probeClient (resolve.go) built via bare safehttp.NewClient() -- no WithoutFetchCache/WithForceHTTP2 -- so whenever the process-wide fleet fetch-cache delegate is installed, every DNS-active candidate's HTTP probe (status, Server header, redirect target, body simhash) could silently be served from cache instead of the live origin. This is a correctness bug specific to this service's purpose: body-hash similar-content classification (grouping variations that serve the same parking page) depends on the probe reflecting what the candidate serves right now, so a stale hit would make repeat scans of a live-but-changed domain report identical fingerprints forever and mask newly-live phishing pages as still-dormant. Fixed by adding safehttp.WithoutFetchCache() and safehttp.WithForceHTTP2() to the probeClient constructor, preserving the existing manual Timeout/CheckRedirect. New regression test safehttp_client_test.go:TestProbeClient_BypassesFetchCache installs a fake stale fetch delegate and proves the fix: fails pre-fix (delegate consulted, stale body returned), passes post-fix (live httptest origin reached, delegate never consulted); a second test confirms the pre-existing Timeout/one-hop CheckRedirect policy survived unchanged. Bumped Version 1.4.1 -\u003e 1.4.2. Live-verified end-to-end post-fix against real domains via the built binary: github.com (117 variations generated, 71 active), paypal.com (110 generated, 80 active), apple.com (92 generated, 55 active) -- DNS fan-out, HTTP probing, body-hash, and classification all functioning correctly. See github.com/baditaflorin/go_typosquat_finder PR #5 (open, not yet merged as of 2026-08-08).","trl_ceiling":6,"trl_ceiling_reason":"Bounded by seed-brand dictionary you ship. Real upgrade needs malicious-domain corpus from threat intel.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"ugc-detector","domain":"ugc-detector.0crawl.com","mesh":"0crawl","host_port":8318,"category":"domains","title":"Ugc Detector","summary":"Microservice for Ugc Detector","tags":["domains","go"],"health_url":"https://ugc-detector.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_ugc_detector","url":"https://ugc-detector.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"2026-08-08 re-audit (PR go_ugc_detector#8, v2.1.3-\u003e2.1.4): (1) handler.go's httpClient used bare safehttp.NewClient(), the fleet-wide anti-pattern that silently opts into the process-wide fetch-cache delegate (go-common/safehttp@v0.80.0 NewClient defaults useDefaultFetchCache=true unless WithoutFetchCache/WithForceHTTP2/WithoutProxy set) -\u003e stale cache-replayed bytes with no live TLS/redirect chain behind SSRF re-validation. Confirmed httpClient is currently DEAD CODE for the real fetch path (analyze()/fetchPage() use fleetfetch.NewClient()'s fetchClient, a distinct intentional fleet-cache-aware fetcher), so no live prod impact today, but fixed (.WithoutFetchCache()+.WithForceHTTP2()) plus a regression test (TestHTTPClientBypassesFetchCache, verified fails pre-fix/passes post-fix) so a future reuse of httpClient does not silently reinherit it. (2) Ran the built detector against 10 live pages to sanity-check the prior no-live-sample TRL 7 self-report: correct on news.ycombinator.com and old.reddit.com/r/programming (forum sigs), en.wikipedia.org (wiki=true), example.com/anthropic.com (correctly verdict=none). CONFIRMED FALSE POSITIVE: https://go.dev/ref/spec (static docs page, zero UGC) returned verdict=moderate, forum_platform=reddit, confidence=4.0 -- caused by signatures.go's reddit signature matching the bare substring reddit.com/r/ anywhere in the HTML body, which fires on an ordinary follow-us-on-Reddit social-icon link in the site header, not any forum embed. Since outbound social-follow links to reddit.com/r/\u003cname\u003e are extremely common across ordinary marketing/docs sites, this false-positive class is plausibly widespread, not a one-off, and was not caught by the existing table-driven test suite (all synthetic HTML, no live-page validation). Also observed coverage gaps: github.com issue pages returned verdict=none (JS-rendered, no UGC markup in server HTML -- consistent with the documented no-headless-browser ceiling) and stackoverflow.com returned HTTP 403 (bot-blocked, could not be assessed at all).","trl_ceiling":7,"trl_ceiling_reason":"Reaches TRL 7 with schema.org Review parsing + moderation-system fingerprints.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"update-frequency","domain":"update-frequency.0crawl.com","mesh":"0crawl","host_port":8319,"category":"domains","title":"Update Frequency","summary":"Microservice for Update Frequency","tags":["domains","go"],"health_url":"https://update-frequency.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_update_frequency","url":"https://update-frequency.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit: found and fixed a severe fetch-cache-masking bug -- every outbound fetch (homepage, robots.txt, feeds, sitemap, Wayback CDX) was eligible for silent cache replay instead of live fetch, undermining this service's core cadence-measurement purpose. Proved live with a stub cache server: 14/14 requests served stale before fix, 0/14 after; live production ground-truth reproduced exactly post-fix. See PR #11 (merged).","trl_ceiling":8,"trl_ceiling_reason":"TRL 8 requires distributed-trace deduplication of multi-feed sites, language-aware date scraping for non-English homepages, and a paid historical-content feed to disambiguate cosmetic re-crawls from genuine content edits at scale.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"url-shortener","domain":"url-shortener.0crawl.com","mesh":"0crawl","host_port":8320,"category":"domains","title":"Url Shortener","summary":"Microservice for Url Shortener","tags":["domains","go"],"health_url":"https://url-shortener.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_url_shortener","url":"https://url-shortener.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Confirmed honest: real, isolated bad brand-table entry found and fixed (trib.com, a real news site, misclassified as the SocialFlow shortener trib.al) -- checked the whole 100-entry brand table against 235,953 real production domains, only 2 legitimate hits remain. Also fixed a broken self-test that had silently exercised a stale auth path for 2.5 months across two prior TRL sign-offs. See github.com/baditaflorin/go_url_shortener PR #3.","trl_ceiling":5,"trl_ceiling_reason":"needs real browser DOM for URL preview","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"user-demographics","domain":"user-demographics.0crawl.com","mesh":"0crawl","host_port":8321,"category":"domains","title":"User Demographics","summary":"Microservice for User Demographics","tags":["domains","go"],"health_url":"https://user-demographics.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_user_demographics","url":"https://user-demographics.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":8,"trl_evidence":"TRL 7-\u003e8: found and fixed 3 confirmed geographic false-positive classes via live production re-testing on 114 real domains from the prod domains/domain_demographics tables (e.g. \\blei\\b colliding with Portuguese 'law' and Italian 'she'/'you'). See github.com/baditaflorin/go_user_demographics PR #21.","trl_ceiling":8,"trl_ceiling_reason":"Single-fetch homepage inference cannot reach production-grade (TRL 8+) audience certainty without persistence/cross-checks; also gated by the shared fleetfetch tier (RenderJS 502 fleet-wide).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"vendor-security-scorecard","domain":"vendor-security-scorecard.0crawl.com","mesh":"0crawl","host_port":18299,"category":"security","title":"Vendor Security Scorecard","summary":"Third-party / vendor risk scorecard: HTTP security headers, HSTS, cookie flags, DNSSEC, CORS posture, end-of-life tech — 6 security analyzers merged into one graded report.","tags":["go","kind-container"],"health_url":"https://vendor-security-scorecard.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_vendor_security_scorecard","url":"https://vendor-security-scorecard.0crawl.com","example":"/?target=stripe.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":4,"trl_evidence":"First-pass audit of this go_composite_runner recipe (fans out to 6 siblings: security-headers, hsts-checker, cookie-checker, domain-dnssec-validator, cors-scanner, domain-tech-eol-flagger): live 250-domain sample found cookie-checker and cors-scanner failing 250/250 (100%) with connection-refused -- confirmed via docker ps that neither sibling has ever had a deployable image built/pushed, an infra gap flagged as a separate task, not a code bug in this service. Found and fixed a real cross-service field-name mismatch: those same 2 siblings emit their verdict as overall_risk, but go_composite_runner's auto-lift key list never included it, so even a successful response's risk verdict silently never reached the summary. Confirmed fetch-cache masking does not apply (LAN fan-out via plain http.Client is the correct convention here, not a bug). Real trl DOWNGRADE recommended: trl 6-\u003e4, trl_ceiling 8-\u003e7 -- a 'vendor security scorecard' permanently missing 2 of 6 advertised signals since inception isn't a demonstrated full-scope subsystem, and the service computes no actual weighted/aggregate score (a legitimate scope choice, not itself a bug, hence ceiling 7 not 8). See PR #5 on go_composite_runner (merged).","trl_ceiling":8,"trl_ceiling_reason":"Reaches TRL 8 with CVSS-weighted aggregate score and remediation guidance.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"video-content","domain":"video-content.0crawl.com","mesh":"0crawl","host_port":8322,"category":"domains","title":"Video Content","summary":"Video-content detector: schema.org VideoObject parsing, platform detection (YouTube/Vimeo/Wistia), autoplay + accessibility scoring.","tags":["go","video"],"health_url":"https://video-content.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_video_content","url":"https://video-content.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"v2.3.0 requires playable HTML5 sources or playable VideoObject content/embed URLs; thumbnail-only schema, empty video tags, tracking/generic text are excluded. Existing hosted embed/facade detection and accessibility evidence retained.","trl_ceiling":5,"trl_ceiling_reason":"needs ML model for codec and bitrate inference","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"voice-search","domain":"voice-search.0crawl.com","mesh":"0crawl","host_port":8323,"category":"seo","title":"Voice Search","tags":["go"],"health_url":"https://voice-search.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_voice_search","url":"https://voice-search.0crawl.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (250-domain live sample, live before/after): found and fixed 2 real bugs. (1) The recurring fetch-cache-masking bug -- for a service whose entire job is auditing live page state and measuring real TTFB, silently serving cached bytes is a correctness bug, not just a performance nuance; the same root cause already caused a 79.9% production-fetch failure in sibling go_technology_stack. Fixed with WithoutFetchCache + WithForceHTTP2 (the SSRF-guarded dialer otherwise silently forces HTTP/1.1). (2) A question-heading false positive -- a real 19-word marketing tagline starting with 'Where' was scored as a conversational question heading because the bare-prefix match had no length bound; capped at 14 words, verified genuine short question headings still match. Confirmed genuinely differentiated from sibling go_domain_faq_schema (a narrow single-signal detector vs. this service's broad 8-signal composite auditor). trl bumped 5-\u003e6; trl_ceiling=7 added -- the score is an unvalidatable heuristic (no ground truth for 'voice-search readiness' exists) and body-text signals get polluted by nav/footer boilerplate on real pages, a structural limit not a patchable bug. See PR #3 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"wayback-checker","domain":"wayback-checker.0crawl.com","mesh":"0crawl","host_port":8351,"category":"recon","title":"Wayback Checker","summary":"Microservice for Wayback Checker","tags":["go","recon"],"health_url":"https://wayback-checker.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_wayback_checker","url":"https://wayback-checker.0crawl.com","example":"/go_wayback_checker?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"First-pass audit (470-domain sample across 3 sampling strategies, live before/after twice): found and fixed 3 real bugs -- a DNS-liveness requirement (inherited from a generic SSRF guard meant for direct-fetch services) wrongly blocked archive lookups for domains that don't currently resolve but have real historical archive.org data (confirmed on 4 domains with history back to 2008-2016, hitting 4.7% of the sample); a CDX-timeout-masking bug that would produce a wrong verdict on 55% of a 320-domain sample; and a too-tight timeout budget given archive.org's real observed latency (up to 16.4s). Explicitly confirmed fetch-cache masking does not apply (plain http.Client, no safehttp usage). trl held at 7 (honestly earned); trl_ceiling=7 added -- structurally capped below production/SLA-grade because its sole data source is a free, unauthenticated, SLA-less third-party API observed at a 50-69% 'unknown' rate across two sampling windows, which no client-side tuning can fully fix. See PR #4 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"web-vitals-report","domain":"web-vitals-report.0crawl.com","mesh":"0crawl","host_port":18300,"category":"web_analysis","title":"Web Vitals Report","summary":"Core Web Vitals and performance report: page-load metrics, CrUX field vitals (p75 LCP/CLS/INP/TTFB), DOM complexity, compression, cache policy, website carbon footprint.","tags":["go","kind-container"],"health_url":"https://web-vitals-report.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_web_vitals_report","url":"https://web-vitals-report.0crawl.com","example":"/?target=stripe.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"6/6 OK on stripe.com; page_load slow + carbon C. Public at web-vitals-report.0crawl.com.","trl_ceiling":7,"trl_ceiling_reason":"Reaches TRL 7 with weighted performance grade.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"website-carbon","domain":"website-carbon.0crawl.com","mesh":"0crawl","host_port":8324,"category":"domains","title":"Website Carbon","summary":"Microservice for Website Carbon","tags":["domains","go"],"health_url":"https://website-carbon.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_website_carbon","url":"https://website-carbon.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":8,"trl_evidence":"Second-pass re-audit (fresh, disjoint 350-domain sample): found and fixed a real fetch-cache-masking bug in the green-hosting (GWF) check specifically -- since a 'green' verdict zeroes ~40% of the per-visit energy estimate, a masked/stale verdict directly skews the headline co2_grams_per_visit output. Live-proved with a stub cache: a genuinely non-green domain (si-studia.ru) got a fabricated green/Grade-A/0.149g verdict before the fix vs correct non-green/Grade-B/0.25g (+68%) after. Byte-probing paths (HEAD/Range-GET) confirmed unaffected. See PR #11 (merged).","trl_ceiling":5,"trl_ceiling_reason":"needs authenticated session for extended carbon source data","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"websocket-analyzer","domain":"websocket-analyzer.0crawl.com","mesh":"0crawl","host_port":8334,"category":"infrastructure","title":"Websocket Analyzer","summary":"Microservice for Websocket Analyzer","tags":["go","infrastructure"],"health_url":"https://websocket-analyzer.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_websocket_analyzer","url":"https://websocket-analyzer.0crawl.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"4 probes (origin/auth/subprotocol/framesize) with hard 1MiB cap, in-process WS fixtures for /selftest, safehttpAllowLoopback() toggle for test-time SSRF guard\n\n2026-08-20 audit (claude-sonnet-5-trl-audit-2026-08-20): fresh clone of origin/main (68f7ee9) reviewed end-to-end against its stated purpose (WS endpoint discovery + CSWSH/auth/subprotocol/frame-size probing via nhooyr.io/websocket). Confirmed a real, live-verified correctness bug: dial.go's dialWS, probes.go's dialProbe, and discover.go's httpClient all built safehttp.NewClient() bare. A WebSocket handshake is a plain GET with Upgrade headers and no body -- eligible for the fleet-wide fetch-cache delegate the same as any ordinary GET -- but the cache has no notion of a 101 Switching Protocols upgrade and can only hand back a synthetic HTTP response, so once FLEET_FETCH_CACHE_URL is set (fleet-wide since go-common@v0.88.0) every origin/auth/subprotocol probe would dial-error on a non-101 status and silently report 'no finding' against a genuinely vulnerable target -- defeating this tool's entire purpose under a normal fleet deploy. Fixed in PR https://github.com/baditaflorin/go_websocket_analyzer/pull/10 (open, not merged) by adding .WithoutFetchCache() to all three clients. Added TestDialProbe_BypassesFetchCache: installs a stub FetchDelegate as the process-wide default and asserts it is never consulted and the missing-origin-check finding still surfaces against the open fixture; verified this test fails on the pre-fix code (delegate called, finding suppressed) and passes after. Bumped 0.2.3-\u003e0.2.4. TRL 7 reaffirmed post-fix -- probe architecture and detection logic are sound once the cache bypass is in place; PR is pending merge.","trl_ceiling":7,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"wellknown-scanner","domain":"wellknown-scanner.0crawl.com","mesh":"0crawl","host_port":8352,"category":"recon","title":"Wellknown Scanner","summary":"Microservice for Wellknown Scanner","tags":["go","recon"],"health_url":"https://wellknown-scanner.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_wellknown_scanner","url":"https://wellknown-scanner.0crawl.com","example":"/go_wellknown_scanner?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Re-audit (fresh 250-domain sample): confirmed genuinely differentiated from sibling go_security_txt (broad shallow multi-path prober vs. narrow deep RFC 9116 validator, intentional/acknowledged overlap). Found and fixed a severe bug -- existence checks were purely HTTP-status-based with zero body inspection, so SPA/CMS sites answering 200 for any path fabricated findings like exposed OIDC/Matrix endpoints (94% of all 'found' results in the sample were this false positive; 11/250 domains got every single one of ~30 probed paths wrongly flagged). Generalized a soft-404 detector already fixed for go_security_txt's one path (569-\u003e32 real findings, 0 false positives after). Also fixed the recurring fetch-cache-masking bug. Separately flagged an ops-urgent finding: the service's public hostname currently resolves to a different IP than every other tested fleet service, and no running container was found for it on the expected dockerhost -- production traffic appears to be served by an orphaned host outside the managed deploy pipeline. trl held at 6 explicitly until this fix is deployed and the DNS/deploy drift is resolved (a 94% false-positive rate is disqualifying regardless of the code fix until it's live); trl_ceiling held at 8. See PR #2 (merged).","trl_ceiling":8,"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"wp-plugins","domain":"wp-plugins.0crawl.com","mesh":"0crawl","host_port":8353,"category":"recon","title":"Wp Plugins","summary":"Microservice for Wp Plugins","tags":["go","recon"],"health_url":"https://wp-plugins.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_wp_plugins","url":"https://wp-plugins.0crawl.com","example":"/go_wp_plugins?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"First-pass audit (fresh 250-domain WordPress sample, live before/after): found and fixed 2 real bugs. (1) fetch-cache masking -- proved via a stub-delegate test since this service's whole job is reporting a target's CURRENT plugin/version state. (2) Cache-bust timestamps reported as plugin versions -- sites using WP Rocket/Autoptimize/W3TC-style asset combiners rewrite ?ver= to a raw Unix timestamp, which the tool reported verbatim as the plugin's 'version'; confirmed on 34/250 (13.6%) domains, 62 fields, now correctly falls back to find a real version elsewhere on the page when available, dropping to 0/250 with zero detection-rate regression. Remaining ~24% false-negative rate traced to JS-challenge/anti-bot interstitials, a genuine structural limit, not a bug. trl bumped 6-\u003e7 (now matching the existing ceiling); trl_ceiling held at 7 -- still blocked on a maintained CVE/WPScan dataset for vuln enrichment, plus the anti-bot-interstitial limitation. See PR #3 (merged).","trl_ceiling":7,"trl_ceiling_reason":"Vulnerability enrichment needs a maintained plugin CVE/WPScan-style dataset.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"wps","domain":"wps.0crawl.com","mesh":"0crawl","host_port":8270,"category":"domains","title":"Wps","summary":"Microservice for Wps","tags":["domains","go"],"health_url":"https://wps.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_wps","url":"https://wps.0crawl.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (fresh 140-domain sample): confirmed the source-level fetch-cache/HTTP2 fix (safehttp.WithForceHTTP2(), go-common v0.72.0) is already correctly merged and guarded by a regression test, but the DEPLOYED production container is running a stale pre-fix image (built before the 2026-07-30 go-common bump). Live-proved a 22-point score swing on wikipedia.org (Grade F vs Grade C) purely from this deploy lag. No PR needed -- redeploy from current main required to realize the fix in production. Also surfaced (separately) that the shared go_infrastructure_fetch_cache container was actively crash-looping (RestartCount 104) during this audit, a fleet-wide incident independent of this service.","trl_ceiling":7,"trl_ceiling_reason":"Lab-grade Core Web Vitals require real browser timings rather than static analysis.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"xss-payload","domain":"xss-payload.0crawl.com","mesh":"0crawl","host_port":8231,"category":"security","title":"Xss Payload","summary":"Microservice for Xss Payload","tags":["go","security"],"health_url":"https://xss-payload.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_xss_payload","url":"https://xss-payload.0crawl.com","example":"/go_xss_payload?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit: this is an active, SSRF-guarded XSS reflection prober (not a static payload catalog, despite stale README docs -- flagged for awareness). Found and fixed 2 real bugs: a false not_reflected result for numeric-entity-escaped quotes (Go's own html.EscapeString uses \u0026#34; not \u0026quot;, causing 4/15 payloads to be misreported as safe when actually reflected/escaped), and a snippet-truncation bug sizing off the wrong string length. Also fixed the recurring fetch-cache-masking bug. trl bumped 5-\u003e6; trl_ceiling=7 added -- fundamentally regex/substring heuristics, not a real browser engine, so it infers exploitability rather than confirming actual script execution. See PR #3 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"xss-scanner","domain":"xss-scanner.0crawl.com","mesh":"0crawl","host_port":8271,"category":"domains","title":"Xss Scanner","summary":"Microservice for Xss Scanner","tags":["domains","go"],"health_url":"https://xss-scanner.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_xss_scanner","url":"https://xss-scanner.0crawl.com","example":"/go_xss_scanner?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Corrected DOWNWARD from trl:6, which sat above this repo's own documented trl_ceiling of 5 (a pre-existing contradiction, not itself justified by real evidence). Real bug also found and fixed in the same pass: the FP-reduction classifier (context-safety/content-type/CSP refinements, benchmarked at 0.56-\u003e0.26-\u003e0.00 on /selftest) was never wired into the live scan path -- every live scan shipped the unrefined iter-1 severity. Confirmed live on a WordPress site: 7/8 reflections wrongly scored \"high\" before the fix, 2/8 after (both correctly retained as genuinely unresolved cases). See github.com/baditaflorin/go_xss_scanner PR #7.","trl_ceiling":5,"trl_ceiling_reason":"Real XSS confirmation requires DOM canary injection (headless browser). Reflection regex isn't real XSS.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"zone-transfer","domain":"zone-transfer.0crawl.com","mesh":"0crawl","host_port":8232,"category":"security","title":"Zone Transfer","summary":"Microservice for Zone Transfer","tags":["go","security"],"health_url":"https://zone-transfer.0crawl.com/health","repo_url":"https://github.com/baditaflorin/go_zone_transfer","url":"https://zone-transfer.0crawl.com","example":"/go_zone_transfer?domain=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass) of this DNS AXFR zone-transfer checker. Live-tested against zonetransfer.me (known-vulnerable), google.com, and a 150-domain live production sample. Found and fixed 4 real bugs: (1) leaked_records silently doubled/tripled per mirrored leaking nameserver (104 entries for 51 actually-distinct records on zonetransfer.me) -- fixed with proper dedup; (2) no bound on transfer duration/record count let a slow-drip server hold a connection open well past the request timeout -- fixed with a 20s/1000-record cap; (3) any mid-transfer error discarded already-captured evidence, turning a real leak interrupted by a network blip into a false negative -- fixed to preserve partial evidence; (4) three distinct real-world AXFR-refusal shapes (TCP reset/EOF, bare-SOA-close, NOERROR-empty-answer) were misclassified as generic errors instead of 'refused' -- confirmed on 89/91 pre-fix 'error' entries in the live sample, now down to 2 (98% drop) with zero regressions in true leak detection. trl bumped 5-\u003e7; trl_ceiling=7 (no glue/delegation-consistency check, no TSIG support, unverified IPv6 outbound in some environments). See github.com/baditaflorin/go_zone_transfer PR #5 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"kokoro-ovms-adapter","domain":"kokoro.voice.0docker.com","mesh":"0docker","host_port":18323,"category":"infrastructure","title":"Kokoro OpenVINO Adapter","summary":"Restricted compatibility adapter for the existing Octopus voice bridge. It validates requests, pins the approved OpenVINO Kokoro model and language, and streams WAV responses without retaining prompts or audio.","tags":["fleet-kokoro"],"health_url":"https://kokoro.voice.0docker.com/health","repo_url":"https://github.com/baditaflorin/go_kokoro_ovms_adapter","url":"https://kokoro.voice.0docker.com","example":"/health","auth":{"type":"none"},"auth_help":"no auth","trl":6,"trl_evidence":"Validated in a production-shaped Dockerhost canary using the existing bridge request shape: the pinned OpenVINO Model Server returned a valid WAV in under four seconds. Production promotion remains gated on the adapter image, model artifact, restricted gateway cutover, and end-to-end bridge smoke.","trl_ceiling":8,"trl_ceiling_reason":"Single Dockerhost and CPU-only inference sidecar; lift after a replicated model-serving deployment with automated canary rollback.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"agent-approval","domain":"agent-approval.0exec.com","mesh":"0exec","host_port":18310,"category":"infrastructure","title":"Agent Approval","summary":"Human-in-the-loop approval gate. POST /request to submit a risky action for human sign-off; GET /await to block until decided or timed out; POST /decide to record the human decision. Timeout resolves to a configurable default (deny by default). The safe-autonomy keystone.","openapi_url":"https://agent-approval.0exec.com/openapi.json","llms_url":"https://agent-approval.0exec.com/llms.txt","health_url":"https://agent-approval.0exec.com/health","version_url":"https://agent-approval.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-agent-approval","url":"https://agent-approval.0exec.com","example":"/pending","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit of this shared fleet-infra human-in-the-loop approval primitive: found and fixed a real bug -- Store.Decide only checked a 'decided' flag, not the request's own deadline, so a human could still POST /decide and have it succeed (overriding the documented fail-closed/fail-open default) after the timeout had already lapsed, if nobody had polled /await yet. Live-reproduced and fixed by consolidating expiry-checking into one shared path; concurrency (20 simultaneous /decide calls) was already correctly single-shot under go test -race. trl bumped 5-\u003e6; trl_ceiling=7 added -- deliberately in-RAM/ephemeral by design (no durability/audit trail of past decisions), a scope choice rather than a hard structural limit. See PR #3 (merged).","version":{"deployed_at":"2026-08-27T15:47:27Z","sha":"881c321","version":"0.1.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"agent-mailbox","domain":"agent-mailbox.0exec.com","mesh":"0exec","host_port":18304,"category":"infrastructure","title":"Agent Mailbox","summary":"Addressed request/reply bus for agents: POST /send to enqueue a message for a named agent, GET /inbox to drain it, POST /reply to send a correlated reply, GET /await to block until a reply arrives. Closes the A→B→A gap that fleet-notify (broadcast) and fleet-q (anonymous pull) leave open.","openapi_url":"https://agent-mailbox.0exec.com/openapi.json","llms_url":"https://agent-mailbox.0exec.com/llms.txt","health_url":"https://agent-mailbox.0exec.com/health","version_url":"https://agent-mailbox.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-agent-mailbox","url":"https://agent-mailbox.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit of this shared fleet-infra request/reply message bus: found and fixed a real capacity-cap bypass -- Store.Reply only incremented the message counter for one of two data structures a reply gets stored in, so MAILBOX_MAX_MSGS silently drifted under sustained normal traffic (reverting the fix, a 500-cycle test drove the counter to -500, an unbounded-growth exploit). Confirmed 0 message loss/duplication under 5000 concurrent send/drain operations with go test -race. trl bumped 5-\u003e6; trl_ceiling=7 added -- deliberately in-RAM/single-process/ephemeral with a process-wide (not per-recipient) capacity budget. See PR #3 (merged).","version":{"deployed_at":"2026-08-27T15:50:39Z","sha":"a766d09","version":"0.1.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"agent-quorum","domain":"agent-quorum.0exec.com","mesh":"0exec","host_port":18306,"category":"infrastructure","title":"Agent Quorum","summary":"k-of-n answer aggregation and voting for redundant agents. Create a round, cast votes, GET /result for the aggregated decision (majority/weighted/unanimous). Productizes the adversarial-verify loop as a fleet primitive.","openapi_url":"https://agent-quorum.0exec.com/openapi.json","llms_url":"https://agent-quorum.0exec.com/llms.txt","health_url":"https://agent-quorum.0exec.com/health","version_url":"https://agent-quorum.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-agent-quorum","url":"https://agent-quorum.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit of this shared fleet-infra k-of-n voting/consensus primitive: found and fixed a real bug -- decisions were never frozen once quorum was reached, so a straggler vote arriving after a caller was already told decided:true could silently flip or undo the outcome for the same round (live-reproduced: a 2-of-5 majority 'yes' decision flipped back to undecided by 2 more votes). Fixed with a freeze-on-decide pattern; confirmed no double-decide race exists under go test -race (single mutex covers record+aggregate+freeze atomically). trl bumped 5-\u003e6; trl_ceiling=7 added -- intentionally ephemeral/single-process, and voter identity isn't cryptographically bound to the caller (documented trust model, not changed). See PR #3 (merged).","version":{"deployed_at":"2026-08-27T15:54:55Z","sha":"8f3288d","version":"0.1.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"agent-tools","domain":"agent-tools.0exec.com","mesh":"0exec","host_port":18307,"category":"infrastructure","title":"Agent Tools","summary":"Turns the fleet catalog into an LLM function-calling manifest. GET /manifest returns a callable tool spec per service (name, description, base_url, auth, example_path). POST /refresh re-fetches the live catalog. Used by agents to discover how to call any fleet service.","openapi_url":"https://agent-tools.0exec.com/openapi.json","llms_url":"https://agent-tools.0exec.com/llms.txt","health_url":"https://agent-tools.0exec.com/health","version_url":"https://agent-tools.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-agent-tools","url":"https://agent-tools.0exec.com","example":"/manifest","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit: corrected the task's framing -- this is a read-only tool-manifest-serving service (fetches an operator-configured catalog URL, never parses a request body, no os/exec), not a command-execution surface, confirmed via source review and adversarial testing (path traversal, oversized/null-byte inputs all handled cleanly with no filesystem access). Found and fixed a real concurrency bug -- a cold-cache stampede (30 concurrent cold requests triggered 22 redundant upstream fetches), then caught a bug in the first-draft fix itself where the shared 'leader' request's context cancellation could abort the fetch for every other waiting caller too. No data races found under go test -race. trl bumped 5-\u003e6; trl_ceiling=7 added -- correctness is inherently capped by fidelity to its upstream catalog, can't meaningfully reach SLA-grade given its scope. See PR #3 (merged).","version":{"deployed_at":"2026-08-27T15:44:07Z","sha":"bd4bb07","version":"0.1.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"apikey-service","domain":"apikey-service.0exec.com","mesh":"0exec","host_port":18021,"category":"infrastructure","title":"Apikey Service","summary":"API key keystore for the 0exec mesh: issue/verify/revoke/list/purge. SQLite-backed, admin-token-gated. THE FLEET'S SINGLE POINT OF COMPROMISE — see fleet-state/OPS.md for hardening + rotation. NOT internet-exposed.","tags":["apikey","go","keystore"],"openapi_url":"https://apikey-service.0exec.com/openapi.json","llms_url":"https://apikey-service.0exec.com/llms.txt","health_url":"https://apikey-service.0exec.com/health","version_url":"https://apikey-service.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_apikey_service","url":"https://apikey-service.0exec.com","example":"/health","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"20 -race test funcs, audit_log table with prefix-only redaction, /audit admin-gated, /selftest","trl_ceiling":8,"trl_ceiling_reason":"Reaches TRL 8 with: hash keys at rest (SHA-256), per-IP rate limit on /verify, audit log table for /issue+/revoke, full test coverage, automated SQLite backup. None require external paid services.","version":{"deployed_at":"2026-09-02T17:18:36Z","sha":"fc7148e","version":"0.4.4"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"c-proxy","domain":"c-proxy.0exec.com","mesh":"0exec","host_port":18003,"category":"proxy","title":"C HTTP Proxy","summary":"Minimal libcurl-based forward proxy (single binary, low memory).","tags":["c","proxy","proxy","http","scraping"],"openapi_url":"https://c-proxy.0exec.com/openapi.json","llms_url":"https://c-proxy.0exec.com/llms.txt","health_url":"https://c-proxy.0exec.com/health","version_url":"https://c-proxy.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/c-proxy","url":"https://c-proxy.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"First-pass audit (confirmed genuinely written in C, a minimal libcurl-based forward proxy): found and fixed a real local-file-read vulnerability -- GET /?url=file:///etc/passwd let libcurl read arbitrary local files into memory since the protocol scheme was never restricted (live-proved with real /etc/passwd content); only invisible externally by an unrelated accident, not a real control. Fixed by allowlisting http/https schemes on both direct requests and redirects. Also fixed 2 real thread-safety bugs: curl_global_init() was never called before spawning per-connection threads (a documented libcurl requirement, dead TODO comment acknowledging it), and rand()/srand() were reseeded per-request across concurrent threads (data race, also defeating UA rotation). All verified clean under ASan/UBSan/TSan after the fix. Flagged (not fixed): a hardcoded proxy credential literal in source. trl bumped 4-\u003e5; trl_ceiling=7 added -- core path confirmed correct, but ad hoc HTTP parsing, a hardcoded credential, and no CI wiring are real non-structural gaps. See PR #1 (merged).","version":{"build_date":"2026-04-28T10:21:08Z","commit":"8d97895","service":"c-proxy","version":"8d97895"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"catalog-service","domain":"catalog-service.0exec.com","mesh":"0exec","host_port":18022,"category":"visualization","title":"Catalog Service","summary":"Renders services.json into the public catalog at catalog.0exec.com. Reads the registry's JSON slices and presents browsable tables of all fleet services with auth-help, TRL, mesh, and links.","openapi_url":"https://catalog-service.0exec.com/openapi.json","llms_url":"https://catalog-service.0exec.com/llms.txt","health_url":"https://catalog-service.0exec.com/health","version_url":"https://catalog-service.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-catalog-service","url":"https://catalog-service.0exec.com","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":6,"trl_evidence":"Live for months, serves catalog.0exec.com production traffic","version":{"deployed_at":"2026-08-27T14:43:12Z","sha":"b9aa7b7","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"claudia","domain":"dockerhost:18312","mesh":"0exec","host_port":18312,"category":"content","title":"Claudia","summary":"Personal pilot project (not a fleet repo) — a hand-built Python/Flask app serving FTS5 search + browse over a private set of Romanian-language grammar textbooks, with stemming and fuzzy-match query expansion. Lives at /opt/services/claudia/ with its own docker-compose.yml but has no git remote and no service.yaml — built locally from a Dockerfile, not via GHCR/fleet-runner. Registered here so allocate-port and audit registry-host-port-set know host_port 18312 is claimed.","tags":["external","non-fleet","personal-project"],"openapi_url":"http://dockerhost:18312/openapi.json","llms_url":"http://dockerhost:18312/llms.txt","health_url":"http://dockerhost:18312/","version_url":"http://dockerhost:18312/.deploy/version.json","repo_url":"file:///opt/services/claudia","url":"http://dockerhost:18312","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"HTTP 400"},{"slug":"composite-runner","domain":"composite-runner.0exec.com","mesh":"0exec","host_port":18296,"category":"infrastructure","title":"Composite Runner","summary":"Generic composite fan-out engine. GET /?recipe=\u003cname\u003e\u0026target=\u003cdomain\u003e runs any named recipe concurrently across N fleet analyzers; returns a merged envelope with summary + per-source fields. Add a recipe row in recipes.go — no new code.","tags":["go","kind-container"],"openapi_url":"https://composite-runner.0exec.com/openapi.json","llms_url":"https://composite-runner.0exec.com/llms.txt","health_url":"https://composite-runner.0exec.com/health","version_url":"https://composite-runner.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_composite_runner","url":"https://composite-runner.0exec.com","example":"/?recipe=firmographic\u0026target=stripe.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Live on dockerhost 18296; 6 recipes tested end-to-end (firmographic 8/8, seo-audit 8-9/9, vendor-security 6/6, web-vitals 6/6, accessibility 5/5, merchant 6/6) across stripe/shopify/notion/gymshark.","trl_ceiling":8,"trl_ceiling_reason":"Reaches TRL 8 with catalog-driven recipe discovery and schema validation on output.","version":{"deployed_at":"2026-09-11T16:39:22Z","sha":"a2b9124","version":"1.1.4"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"country-iso-matcher","domain":"country-iso-matcher.0exec.com","mesh":"0exec","host_port":18315,"category":"geo","title":"Country Iso Matcher","summary":"Resolves a country name, native name, or common alias to its ISO 3166-1 alpha-2 code. Unicode-normalizing, accent- and case-insensitive matcher over a curated corpus of 183 countries plus their multilingual aliases, served entirely from memory. NOTE: iso3Code currently mirrors iso2Code -- the default CSV corpus carries no alpha-3 column.","tags":["geo","iso3166","kind-container","runtime-compose"],"openapi_url":"https://country-iso-matcher.0exec.com/openapi.json","llms_url":"https://country-iso-matcher.0exec.com/llms.txt","health_url":"https://country-iso-matcher.0exec.com/health","version_url":"https://country-iso-matcher.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/country-iso-matcher","url":"https://country-iso-matcher.0exec.com","example":"/api/convert?country=Germany","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":4,"trl_evidence":"First fleet-registered release (0.1.0, 2026-08-29). Verified live against the built amd64 image: /health, /version, /metrics (154 series) and /api/convert all 200; \"Germany\" -\u003e DE, \"Deutschland\" -\u003e DE (alias hit), \"United States\" -\u003e US, unknown input -\u003e 404 with a structured error. Real logic beyond a regex (Unicode NFD normalization, case/accent folding, alias table) and unit tests exist, but two known gaps hold it at 4: iso3Code is a documented fallback to iso2 under the default CSV source (csv_loader.go:72), and coverage is 183 of 249 assigned alpha-2 codes. Two of the repo's three test files had not compiled since the src/ restructure and were repaired as part of this onboarding.","trl_ceiling":6,"trl_ceiling_reason":"Ceiling is set by corpus quality, not by architecture. Reaching 6 needs a real ISO 3166-1 source of truth (alpha-3 backfilled, subdivisions, official/short/UN names, withdrawn-code history) rather than a 183-row hand-curated CSV with 59 alias rows.","version":{"deployed_at":"2026-09-01T03:25:17Z","sha":"6c2540e","version":"0.1.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"d3-graph","domain":"d3-graph.0exec.com","mesh":"0exec","host_port":18020,"category":"visualization","title":"D3 Graph Renderer","summary":"Fetches CSV/JSON and converts it to d3-rendered SVG/PNG visualisations.","tags":["go","visualization","visualisation","d3"],"openapi_url":"https://d3-graph.0exec.com/openapi.json","llms_url":"https://d3-graph.0exec.com/llms.txt","health_url":"https://d3-graph.0exec.com/health","version_url":"https://d3-graph.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/d3-graph","url":"https://d3-graph.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":3,"trl_evidence":"First-pass audit (Node/Express static-file server + client-side D3 v7/dagre-d3 force-graph viewer; no server-side rendering exists despite README claims, and the d3-node dependency is unused dead weight). Found 2 severe bugs. (1) The service is CURRENTLY COMPLETELY BROKEN in production: express.static('public') resolves relative to process.cwd(), not the source file, so under Docker's WORKDIR every static asset (/, /script.js, the actual graph CSV) 404s right now -- live-confirmed, and the deploy script has a resigned comment tolerating it rather than fixing it. (2) A real XSS: the hover-tooltip interpolates raw CSV source/target/label fields unescaped into HTML, and those labels can be populated from an attacker-chosen URL via the /fetch-and-convert NLP pipeline with zero sanitization anywhere -- any HTML/script in a label executes on hover. Both fixed. Also fixed a hang-forever bug on malformed upstream NLP-service data (resource-exhaustion risk under adversarial/concurrent load). Added the repo's first real test suite (previously a stub that always failed). Real trl DOWNGRADE: 6-\u003e3 -- the service could not serve its core function in production at all; trl_ceiling=5 -- single-purpose internal tool, no app-level auth, an untrusted-data pipeline with no sanitization boundary of its own. See PR #1 (merged).","version":{"build_date":"2026-04-28T10:15:02Z","commit":"1b98d09","service":"d3-graph","version":"1b98d09"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"db-geo-geocode","domain":"db-geo-geocode.0exec.com","mesh":"0exec","host_port":18009,"category":"geo","title":"Geocode Cache (Postgres-backed)","summary":"Same shape as geo-geocode, with a Postgres cache layer in front.","tags":["geo","geo","geocoding","cache"],"openapi_url":"https://db-geo-geocode.0exec.com/openapi.json","llms_url":"https://db-geo-geocode.0exec.com/llms.txt","health_url":"https://db-geo-geocode.0exec.com/health","version_url":"https://db-geo-geocode.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/db-geo-geocode","url":"https://db-geo-geocode.0exec.com","example":"/?text=Bucharest","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (Go+Postgres cache layer in front of sibling geo-geocode's API aggregation, confirmed not a duplicate): found and fixed a real bug -- the upstream aggregator sometimes returns a literal null array element, and unmarshaling null into a non-pointer struct silently zeroed it with no error, so a genuine 'no result' response got served as a fake 200 with lat/lng 0,0 and PERMANENTLY CACHED in Postgres. Live-confirmed the same upstream flapping between real results and null for identical consecutive queries. Fixed to detect and reject empty/null decoded addresses before caching/serving. Confirmed parameterized SQL is injection-safe. trl held at 6; trl_ceiling=7 added -- accuracy is bounded by whichever free-tier provider the upstream happens to answer with (~500m-1km drift observed across providers), the Postgres cache has no TTL/refresh mechanism, and availability depends entirely on a single upstream with no fallback ordering (an outage was observed live during this audit). See PR #1 (merged).","version":{"build_date":"2026-04-28T10:46:42Z","commit":"4fa789f","service":"db-geo-geocode","version":"4fa789f"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-abuse-contact-rollup","domain":"domain-abuse-contact-rollup.0exec.com","mesh":"0exec","host_port":18189,"category":"recon","title":"Domain Abuse Contact Rollup","summary":"Unified abuse contact rollup (RDAP+security.txt+convention+scrape) for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-abuse-contact-rollup.0exec.com/openapi.json","llms_url":"https://domain-abuse-contact-rollup.0exec.com/llms.txt","health_url":"https://domain-abuse-contact-rollup.0exec.com/health","version_url":"https://domain-abuse-contact-rollup.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_abuse_contact_rollup","url":"https://domain-abuse-contact-rollup.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (fresh 250-domain sample): corrected a stale premise -- this is a real, complete, working service (not a stub/never-assessed; the repo's own service.yaml already had trl=4 from a pre-fix 2026-07-01 placeholder assessment). Found and fixed 2 real bugs -- a nondeterministic preferred_email selection driven by Go's randomized map iteration order with no tiebreak (28/250, 11%, disagreed across repeat runs of the identical binary); and RDAP 429/5xx responses silently indistinguishable from a genuine 404. Confirmed fetch-cache masking doesn't apply (uses fleetfetch by design) and confirmed rdap.org rate-limiting live (8/20 sequential lookups 429'd). trl bumped 4-\u003e6; trl_ceiling=7 added -- capped by dependence on the free, rate-limited, unauthenticated rdap.org redirector and ICANN's 2018 privacy redaction making genuine site-specific RDAP contacts industry-wide rare. See PR #6 (merged).","version":{"deployed_at":"2026-08-27T09:44:16Z","sha":"a8ceb66","version":"0.1.8"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-ai-bot-policy-scanner","domain":"domain-ai-bot-policy-scanner.0exec.com","mesh":"0exec","host_port":18195,"category":"security","title":"Domain Ai Bot Policy Scanner","summary":"AI-training opt-out posture scanner for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-ai-bot-policy-scanner.0exec.com/openapi.json","llms_url":"https://domain-ai-bot-policy-scanner.0exec.com/llms.txt","health_url":"https://domain-ai-bot-policy-scanner.0exec.com/health","version_url":"https://domain-ai-bot-policy-scanner.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_ai_bot_policy_scanner","url":"https://domain-ai-bot-policy-scanner.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Fresh source-level audit (DB pass found no anomaly) found and fixed a real cross-contamination bug: groupForAgent matched a robots.txt User-agent token against a gazetteer bot's canonical token in both prefix directions, silently cross-matching distinct gazetteer bots whenever one canonical token is a prefix of a sibling (Omgili/Omgilibot, AI2Bot/Ai2Bot-Dolma) -- confirmed live against Cloudflare's managed AI-bot blocklist format and cross-checked against production rows showing the contamination pattern. Fixed (v0.3.7) by dropping the RFC-9309-noncompliant reverse direction; a live 180-domain probe through the real parsing pipeline showed zero panics/contradictions post-fix. See github.com/baditaflorin/go_domain_ai_bot_policy_scanner PR #15 (merged). Rows with tool_version\u003c0.3.7 are re-crawl candidates.","version":{"deployed_at":"2026-08-27T09:45:14Z","sha":"6f41db2","version":"0.3.9"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-compliance-claim-scanner","domain":"domain-compliance-claim-scanner.0exec.com","mesh":"0exec","host_port":18198,"category":"security","title":"Domain Compliance Claim Scanner","summary":"Compliance claim scanner for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-compliance-claim-scanner.0exec.com/openapi.json","llms_url":"https://domain-compliance-claim-scanner.0exec.com/llms.txt","health_url":"https://domain-compliance-claim-scanner.0exec.com/health","version_url":"https://domain-compliance-claim-scanner.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_compliance_claim_scanner","url":"https://domain-compliance-claim-scanner.0exec.com","example":"/?target=stripe.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Live production-DB audit (~3.5M rows) found a sharp spike at pages_scanned_count=6 (233,741 rows, ~25% of all non-zero counts) across every shipped version. Root-caused, confirmed live via direct curl/md5: parked-domain and soft-404/SPA-catch-all sites return byte-identical HTTP 200 bodies at every one of the scanner's 6 candidate paths, so one page fetched under 6 URLs was counted as 6 distinct pages scanned -- and, more materially, caused claim extraction to rerun on the same content once per duplicate URL, multiplying recorded claims. Fixed (v0.4.6) with content-based de-duplication, reproduced before/after against live domains. See github.com/baditaflorin/go_domain_compliance_claim_scanner PR #15 (merged). Rows with tool_version\u003c0.4.6 are re-crawl candidates.","trl_ceiling":7,"trl_ceiling_reason":"Reaching 7 needs cross-checks against an external trust-registry / attestation feed (e.g. confirming a claimed SOC 2 against an auditor registry) — that requires a paid/external source, outside the CPU-only no-new-outbound-calls constraint.","version":{"deployed_at":"2026-08-23T21:57:47Z","sha":"6686cca","version":"0.4.8"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-ct-log-watcher","domain":"domain-ct-log-watcher.0exec.com","mesh":"0exec","host_port":18184,"category":"security","title":"Domain Ct Log Watcher","summary":"Certificate Transparency log inventory (crt.sh) for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-ct-log-watcher.0exec.com/openapi.json","llms_url":"https://domain-ct-log-watcher.0exec.com/llms.txt","health_url":"https://domain-ct-log-watcher.0exec.com/health","version_url":"https://domain-ct-log-watcher.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_ct_log_watcher","url":"https://domain-ct-log-watcher.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Live production-DB audit (~3.6M rows) found issuer_churn NULL/0.00 on 100% of rows, including domains with hundreds of certs and multiple issuers -- a dedicated partial index for churn\u003e0.5 could never return a row. Root-caused: handler.go wired the wire field to an unordered distinct-issuer-org list instead of any real computation, a type mismatch (array vs numeric column) guaranteeing null/zero on every write. Fixed (v0.3.7) by implementing a real time-ordered churn-rate algorithm with regression tests proving nonzero output for a genuinely churning history. See github.com/baditaflorin/go_domain_ct_log_watcher PR #12 (merged). Rows with tool_version\u003c0.3.7 are re-crawl candidates.","trl_ceiling":7,"trl_ceiling_reason":"single free heavily rate-limited crt.sh upstream (429/502/504), no second CT source or paid feed, no persistence/cross-check","version":{"deployed_at":"2026-09-11T07:51:37Z","sha":"8802a77","version":"0.3.13"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-dnssec-validator","domain":"domain-dnssec-validator.0exec.com","mesh":"0exec","host_port":18180,"category":"infrastructure","title":"Domain Dnssec Validator","summary":"DNSSEC validator (DS/DNSKEY/AD-bit) for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-dnssec-validator.0exec.com/openapi.json","llms_url":"https://domain-dnssec-validator.0exec.com/llms.txt","health_url":"https://domain-dnssec-validator.0exec.com/health","version_url":"https://domain-dnssec-validator.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_dnssec_validator","url":"https://domain-dnssec-validator.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Live production-DB audit (~3.7M rows) found grade B statistically unreachable (17/3.7M rows, 0.00046%) versus A=117K and C=40K. Root-caused to dead code in chainVerdict: the AD-bit corroboration downgrade to grade B lived in a switch branch that could never be reached given how rrsigStatus is always populated, so the common rrsigValid outcome always graded A regardless of AD-bit corroboration -- confirmed 68 production rows graded A with authentic=false. Fixed (v0.4.3) by moving the downgrade check into the reachable case, with regression tests pinning the B-grade path. See github.com/baditaflorin/go_domain_dnssec_validator PR #12 (merged). Rows with tool_version\u003c0.4.3 are re-crawl candidates.","trl_ceiling":7,"trl_ceiling_reason":"Single public validating resolver. Lifting to 8 needs multi-resolver quorum (a second independent validating resolver) and a full root-anchored walk (.-\u003eTLD-\u003ezone verifying RRSIGs at every cut). That is breadth, not the core crypto check, which is already real.","version":{"deployed_at":"2026-08-27T14:38:22Z","sha":"0c7930a","version":"0.4.5"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-documentation-platform-detector","domain":"domain-documentation-platform-detector.0exec.com","mesh":"0exec","host_port":18197,"category":"content","title":"Domain Documentation Platform Detector","summary":"Docs platform detector for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-documentation-platform-detector.0exec.com/openapi.json","llms_url":"https://domain-documentation-platform-detector.0exec.com/llms.txt","health_url":"https://domain-documentation-platform-detector.0exec.com/health","version_url":"https://domain-documentation-platform-detector.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_documentation_platform_detector","url":"https://domain-documentation-platform-detector.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Fresh audit (DB pass found no anomaly) found and fixed a real, production-confirmed false positive: classify() pinned primary_platform=swagger_ui from swagger-ui-dist's bundled JS filenames alone, with no check the page was ever wired to a real API spec -- a cluster of unrelated small-business sites (several real-estate-agent pages) all serve the byte-identical, never-configured stock demo page pointed at Swagger's own public petstore.swagger.io sample spec. swagger_ui was the #2 most common detected platform (575 domains) fleet-wide. Fixed (v0.4.9) by skipping a swagger_ui match when the body still carries the literal default demo URL; verified live all 7 sampled false positives flip to no_data while genuine installs remain detected. See github.com/baditaflorin/go_domain_documentation_platform_detector PR #14 (merged). Rows with tool_version\u003c0.4.9 are re-crawl candidates.","version":{"deployed_at":"2026-08-27T22:34:34Z","sha":"5f87841","version":"0.4.15"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-email-deliverability-score","domain":"domain-email-deliverability-score.0exec.com","mesh":"0exec","host_port":18181,"category":"security","title":"Domain Email Deliverability Score","summary":"Composite email-deliverability grader for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-email-deliverability-score.0exec.com/openapi.json","llms_url":"https://domain-email-deliverability-score.0exec.com/llms.txt","health_url":"https://domain-email-deliverability-score.0exec.com/health","version_url":"https://domain-email-deliverability-score.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_email_deliverability_score","url":"https://domain-email-deliverability-score.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Rigorous fresh audit: live 364-domain production sample plus ~3.5M-execution coverage-guided fuzz testing of every record parser (SPF/DMARC/DKIM/BIMI) found zero panics and zero misclassifications. The two anomalies flagged during testing (dual-SPF-record domains) were confirmed to be correct RFC 7208 PermError detections of genuine real-world misconfigurations, not tool bugs. No code change needed -- this service held up cleanly under an independent, adversarial re-verification after 7+ prior audit passes.","trl_ceiling":7,"trl_ceiling_reason":"No live SMTP-delivery / inbox-placement / sending-reputation feed; DKIM selector discovery is gazetteer-bounded, not exhaustive — the production-grade deliverability signals require paid feeds.","version":{"deployed_at":"2026-09-11T05:29:52Z","sha":"a73fabc","version":"0.3.10"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-http3-quic-detector","domain":"domain-http3-quic-detector.0exec.com","mesh":"0exec","host_port":18190,"category":"infrastructure","title":"Domain Http3 Quic Detector","summary":"HTTP/3 + QUIC handshake probe for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-http3-quic-detector.0exec.com/openapi.json","llms_url":"https://domain-http3-quic-detector.0exec.com/llms.txt","health_url":"https://domain-http3-quic-detector.0exec.com/health","version_url":"https://domain-http3-quic-detector.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_http3_quic_detector","url":"https://domain-http3-quic-detector.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Live production-DB audit found apple.com/amazon.com/microsoft.com/facebook.com/wikipedia.org all falsely graded F (https_available=false) in the same batch google.com/cloudflare.com/github.com correctly passed. Cross-validated against an independent table (domain_tls) confirming no real outage. Root-caused: classifyProbeError checked the 'tls' substring before checking timeout-ness, so Go's literal error string 'net/http: TLS handshake timeout' got misfiled as a non-retryable TLS error instead of a retryable connect timeout -- major CDN/WAF-fronted domains with heavier handshakes got zero retries. Fixed (v0.4.5) by checking timeout-ness first; confirmed the fleet's safehttp fetch-cache bug does not apply here (this is a HEAD-only availability check, not GET). See github.com/baditaflorin/go_domain_http3_quic_detector PR #10 (merged). Rows with tool_version\u003c0.4.5 are re-crawl candidates.","trl_ceiling":7,"trl_ceiling_reason":"Single CPU-only probe; true TRL 8 needs independent QUIC cross-checks / IP-path diversity / persistence, out of scope for one detector.","version":{"deployed_at":"2026-08-31T21:13:46Z","sha":"af69546","version":"0.4.7"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-mobile-app-resolver","domain":"domain-mobile-app-resolver.0exec.com","mesh":"0exec","host_port":18187,"category":"infrastructure","title":"Domain Mobile App Resolver","summary":"iOS/Android mobile app linkage resolver for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-mobile-app-resolver.0exec.com/openapi.json","llms_url":"https://domain-mobile-app-resolver.0exec.com/llms.txt","health_url":"https://domain-mobile-app-resolver.0exec.com/health","version_url":"https://domain-mobile-app-resolver.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_mobile_app_resolver","url":"https://domain-mobile-app-resolver.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Live production-DB audit (~3.5M rows) found ios_present=true with ios_app_count=0 on 91.9% of such rows (apple.com, microsoft.com both affected). Investigated and found this was intentional: ios_present is legitimately asserted by domain-tied iTunes/HTML-App-Links/regional-store signals that never populate ios_apps (AASA-only) -- collapsing presence to require AASA would reintroduce a prior false-negative bug this service was hardened against. Fixed (v0.5.7) instead by adding authoritative ios_app_count/android_app_count fields deduped across every presence-asserting signal, guaranteeing presence==(count\u003e0) for every response; live-verified against apple.com and microsoft.com. See github.com/baditaflorin/go_domain_mobile_app_resolver PR #15 (merged). Rows with tool_version\u003c0.5.7 are re-crawl candidates.","trl_ceiling":7,"trl_ceiling_reason":"Reaching TRL 8 needs a paid/queryable cross-store feed (or JS-rendered fetch tier) to confirm an app truly exists in each regional store rather than parsing the advertised link; outside the CPU-only / no-paid-feed / no-new-outbound-call envelope.","version":{"deployed_at":"2026-08-26T00:30:44Z","sha":"015e765","version":"0.5.10"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-newsletter-platform-detector","domain":"domain-newsletter-platform-detector.0exec.com","mesh":"0exec","host_port":18193,"category":"web_analysis","title":"Domain Newsletter Platform Detector","summary":"Newsletter platform detector for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-newsletter-platform-detector.0exec.com/openapi.json","llms_url":"https://domain-newsletter-platform-detector.0exec.com/llms.txt","health_url":"https://domain-newsletter-platform-detector.0exec.com/health","version_url":"https://domain-newsletter-platform-detector.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_newsletter_platform_detector","url":"https://domain-newsletter-platform-detector.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Investigated the same 'false written on failed fetch' pattern (18.4% of rows, substack.com itself affected). Found this repo's own contract was already fixed in-repo back on 2026-06-09 (a prior, unrelated commit adopted go-common/meshresult and switched failure paths to omit the data field entirely rather than assert false) -- confirmed via git history. The corruption continues accruing daily regardless, proof the root cause lives entirely in the separate ingestion/orchestrator component, not this repo. No fix forced, no PR opened. Second of 4 sibling services confirming the same root cause -- see the fleet-wide note below.","trl_ceiling":7,"trl_ceiling_reason":"The shared JS-render upstream can degrade on cold or failed renders, limiting SLA-grade completeness.","version":{"deployed_at":"2026-08-27T23:19:11Z","sha":"ce21388","version":"0.4.6"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-open-source-presence","domain":"domain-open-source-presence.0exec.com","mesh":"0exec","host_port":18196,"category":"recon","title":"Domain Open Source Presence","summary":"Linked source orgs + OSS score for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-open-source-presence.0exec.com/openapi.json","llms_url":"https://domain-open-source-presence.0exec.com/llms.txt","health_url":"https://domain-open-source-presence.0exec.com/health","version_url":"https://domain-open-source-presence.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_open_source_presence","url":"https://domain-open-source-presence.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (fresh 250-domain sample + live spot-check of 30 known OSS companies, 27/30 correct): found and fixed 2 real bugs -- an inconsistent length threshold meant exactly-3-character brand tokens (e.g. 'n8n') could never match via containment, confirmed live losing a 200k+-star OSS company entirely (fixed with a careful prefix-anchored rule, not a naive blanket match which a stress test showed would introduce new false positives); and a GitHub API rate-limit quota-doubling bug on failed lookups. Confirmed fetch-cache masking doesn't apply (uses fleetfetch by design) and confirmed a real, live GitHub unauthenticated rate-limit exhaustion (60/hour shared fleet-wide). Flagged (not overridden) a catalog/repo discrepancy: this repo's own service.yaml had self-bumped to trl=7 without a fresh assessor stamp. trl held at 6 pending that reconciliation; trl_ceiling=8 added. See PR #12 (merged).","version":{"deployed_at":"2026-08-27T23:12:52Z","sha":"c3c1d61","version":"0.2.7"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-passive-dns-history","domain":"domain-passive-dns-history.0exec.com","mesh":"0exec","host_port":18183,"category":"infrastructure","title":"Domain Passive Dns History","summary":"Historical passive-DNS observations for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-passive-dns-history.0exec.com/openapi.json","llms_url":"https://domain-passive-dns-history.0exec.com/llms.txt","health_url":"https://domain-passive-dns-history.0exec.com/health","version_url":"https://domain-passive-dns-history.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_passive_dns_history","url":"https://domain-passive-dns-history.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Live production-DB audit found unique_ips=0 on 57.4% of status=ok rows, mostly explained (96.8% zero-rate) by legacy pre-tool_version bulk-seed rows; filtered to current versions the zero-rate was only ~0.2%. That residual traced to a real silent-data-loss bug: sub-host observations from the HackerTarget source are annotated as '\u003cip\u003e (host)', but the dedup validation gate ran IP parsing on the whole annotated string, which never parses, so the record was silently dropped -- discarding the majority of real historical address evidence while the domain still reported status=ok. Confirmed live against real affected production domains and a fresh HackerTarget call. Fixed (v0.3.5) to validate only the leading IP token while preserving the host-evidence suffix. See github.com/baditaflorin/go_domain_passive_dns_history PR #12 (merged). Rows with tool_version\u003c0.3.5 are re-crawl candidates.","trl_ceiling":8,"trl_ceiling_reason":"Comprehensive multi-year passive-DNS history requires a paid feed (Farsight DNSDB / SecurityTrails); the free public sources are sparse + rate-limited (HackerTarget hostsearch/dnslookup) and the formerly-primary Mnemonic public read API is decommissioned (CloudFront 502). Cannot break the ceiling CPU-only without a new paid outbound source, which the rules forbid.","version":{"deployed_at":"2026-09-11T02:33:56Z","sha":"4fd9f29","version":"0.3.8"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-rbl-reputation","domain":"domain-rbl-reputation.0exec.com","mesh":"0exec","host_port":18182,"category":"security","title":"Domain Rbl Reputation","summary":"RBL reputation check across 8 public blocklists for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-rbl-reputation.0exec.com/openapi.json","llms_url":"https://domain-rbl-reputation.0exec.com/llms.txt","health_url":"https://domain-rbl-reputation.0exec.com/health","version_url":"https://domain-rbl-reputation.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_rbl_reputation","url":"https://domain-rbl-reputation.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Live production-DB audit found grade F essentially never fires (0/10,757 current-version rows; only 40 F rows exist fleet-wide, all stale). Root-caused: 2 of 7 configured DNSBL zones (SORBS) have been completely dead since the provider was decommissioned on 2026-06-05 (over two years live-verified as NXDOMAIN against 3 independent resolvers) -- every lookup against them silently returns 'not listed' with no error signal, degrading real IP-reputation coverage. Fixed (v0.4.4) by removing the dead zones, matching a prior same-class fix for uribl.com. False-positive handling (RBL timeout/rate-limit misread as a hit) independently verified correct against a live 120-domain sample. See github.com/baditaflorin/go_domain_rbl_reputation PR #12 (merged). Rows with tool_version\u003c0.4.4 are re-crawl candidates.","trl_ceiling":7,"trl_ceiling_reason":"DNSBL verdicts are bounded by free public blocklist coverage and the shared resolver vantage point; SLA-grade reputation (TRL 8-9) needs paid/commercial threat feeds, multiple resolver vantage points, and historical listing persistence that this CPU-only DNS-query service cannot provide.","version":{"deployed_at":"2026-08-27T10:09:44Z","sha":"6568719","version":"0.4.5"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-saas-host-mapper","domain":"domain-saas-host-mapper.0exec.com","mesh":"0exec","host_port":18191,"category":"infrastructure","title":"Domain Saas Host Mapper","summary":"SaaS hosting platform detector for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-saas-host-mapper.0exec.com/openapi.json","llms_url":"https://domain-saas-host-mapper.0exec.com/llms.txt","health_url":"https://domain-saas-host-mapper.0exec.com/health","version_url":"https://domain-saas-host-mapper.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_saas_host_mapper","url":"https://domain-saas-host-mapper.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Live production-DB audit found 143,413 wordpress_com-classified rows, but only 0.07% have real wordpress.com CNAME evidence -- appearing to be a live false-positive bug. Investigated and found the opposite: a prior 'Pass 3' fix (merged 2026-05-31) that correctly reserves wordpress_com for real CNAME matches is genuinely deployed and correct -- live-verified against the currently-deployed v0.3.7 binary and confirmed 28/28 post-fix-tool_version rows are all genuine matches. Root cause of the bad aggregate: 99.98% of wordpress_com rows carry a blank tool_version, meaning they predate the fix and have never been reprocessed -- a pipeline backfill gap, not a code or deployment defect. No code change made. Priority re-crawl target: all domain_saas_host rows with blank/NULL tool_version (~2.88M rows fleet-wide).","trl_ceiling":7,"trl_ceiling_reason":"Fingerprint-only (DNS+HTTP-header) detection; an origin behind a generic CDN/anycast front (Cloudflare, AWS Global Accelerator) is structurally undeterminable without a browser engine or paid host-intel feed.","version":{"deployed_at":"2026-09-11T02:30:20Z","sha":"274dd02","version":"0.3.11"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-structured-data-rollup","domain":"domain-structured-data-rollup.0exec.com","mesh":"0exec","host_port":18188,"category":"content","title":"Domain Structured Data Rollup","summary":"JSON-LD/OG/Twitter/microdata rollup for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-structured-data-rollup.0exec.com/openapi.json","llms_url":"https://domain-structured-data-rollup.0exec.com/llms.txt","health_url":"https://domain-structured-data-rollup.0exec.com/health","version_url":"https://domain-structured-data-rollup.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_structured_data_rollup","url":"https://domain-structured-data-rollup.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Rigorous fresh audit: two independent live 200-domain production samples (~320 real JSON-LD blocks parsed total) found zero malformed-JSON-LD parse failures and correct handling of @graph/multi-type-array/embed-segregation on real pages. The one DB-level anomaly flagged (NULL og_title when has_open_graph=true, 1.5% of rows) was live-verified against 10 real affected domains -- all genuinely omit an og:title tag while shipping other OG tags; a duplicate-tag-overwrite theory was also tested and ruled out (0/8 sampled duplicates were empty). No code change needed.","trl_ceiling":7,"trl_ceiling_reason":"Structured data injected only after client-side JS rendering needs a headless DOM fetcher (same ceiling as sibling schema-extractor); offline parse path is identical to the live one.","version":{"deployed_at":"2026-08-26T00:36:21Z","sha":"5f7e27d","version":"0.3.10"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-support-stack-detector","domain":"domain-support-stack-detector.0exec.com","mesh":"0exec","host_port":18192,"category":"web_analysis","title":"Domain Support Stack Detector","summary":"Help desk / live-chat platform detector for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-support-stack-detector.0exec.com/openapi.json","llms_url":"https://domain-support-stack-detector.0exec.com/llms.txt","health_url":"https://domain-support-stack-detector.0exec.com/health","version_url":"https://domain-support-stack-detector.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_support_stack_detector","url":"https://domain-support-stack-detector.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":8,"trl_evidence":"Live production-DB audit found primary_vendor='reamaze' as the single largest detected vendor (1,191 rows), with 49.5% being spam/parked .info domains. Traced the residual (post-earlier-fix) cases via live browser reproduction to GoDaddy Website Builder unconditionally loading Reamaze's shared JS bundle via a GoDaddy-specific loader file, whose bundled CSS/DOM boilerplate satisfied the detector's 'activation' marker regardless of merchant intent -- verified against reamaze.com's own genuine install, which never carries that GoDaddy-specific loader filename. Fixed (v0.3.8) with a targeted confidence cap keyed to the GoDaddy loader marker, with regression tests for both the false-positive and true-positive cases. See github.com/baditaflorin/go_domain_support_stack_detector PR #14 (merged). Rows with tool_version\u003c0.3.8 are re-crawl candidates.","version":{"deployed_at":"2026-08-27T22:51:50Z","sha":"802aea3","version":"0.3.10"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-tech-eol-flagger","domain":"domain-tech-eol-flagger.0exec.com","mesh":"0exec","host_port":18186,"category":"security","title":"Domain Tech Eol Flagger","summary":"Tech-stack end-of-life flagger (endoflife.date) for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-tech-eol-flagger.0exec.com/openapi.json","llms_url":"https://domain-tech-eol-flagger.0exec.com/llms.txt","health_url":"https://domain-tech-eol-flagger.0exec.com/health","version_url":"https://domain-tech-eol-flagger.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_tech_eol_flagger","url":"https://domain-tech-eol-flagger.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Live production-DB audit found a plausible eol distribution (php-7.4.33, jquery-1.8.3, nginx-1.24.0 dominate, all genuinely EOL) -- the healthiest of a 30-service DB sweep. A source-level audit still found and fixed a real, systemic false negative: jQuery signatures required a version directly adjacent to 'jquery' in the filename, never matching WordPress's own bundled-jQuery shape (wp-includes/js/jquery/jquery.min.js?ver=X.Y.Z) -- live re-fetch of 12 real WordPress sites already flagged with an EOL WP core found 11/12 also carried this exact pattern with a genuinely EOL jQuery 1.x, none previously detected. Fixed (v0.4.3) with a signature scoped to WordPress's script-loader-pinned ver= filename shape, verified not to bleed into jQuery UI/Migrate/Validate. See github.com/baditaflorin/go_domain_tech_eol_flagger PR #13 (merged). Rows with tool_version\u003c0.4.3 are re-crawl candidates.","trl_ceiling":7,"trl_ceiling_reason":"Authoritative, continuously-fresh EOL dating needs a live lifecycle/CVE feed (endoflife.date); a CPU-only offline gazetteer is correct-at-curation-date but cannot guarantee freshness for TRL 7+.","version":{"deployed_at":"2026-08-27T10:11:23Z","sha":"cba4799","version":"0.4.5"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-third-party-fetch-map","domain":"domain-third-party-fetch-map.0exec.com","mesh":"0exec","host_port":18185,"category":"web_analysis","title":"Domain Third Party Fetch Map","summary":"Homepage third-party fetch bucketing for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-third-party-fetch-map.0exec.com/openapi.json","llms_url":"https://domain-third-party-fetch-map.0exec.com/llms.txt","health_url":"https://domain-third-party-fetch-map.0exec.com/health","version_url":"https://domain-third-party-fetch-map.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_third_party_fetch_map","url":"https://domain-third-party-fetch-map.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Live production-DB audit found no internal contradictions, but a fresh pass found and fixed a real bug: multi-tenant infrastructure CDN hosts (cloudfront.net, s3.amazonaws.com) are PSL 'private' suffixes, so each tenant subdomain was treated as its own registrable domain -- a page pulling assets from 2+ distinct CloudFront distributions (a common real pattern) was reported as referencing multiple distinct third-party vendors. Live query found 1,045 domains (14% of CloudFront users) affected, +1,727 phantom domain counts from CloudFront alone. Fixed (v0.4.6) by folding known multi-tenant infra-CDN hosts to one shared vendor identity for aggregation only, verified against a real 4-distribution production page. See github.com/baditaflorin/go_domain_third_party_fetch_map PR #15 (merged). Rows with tool_version\u003c0.4.6 are re-crawl candidates.","trl_ceiling":7,"trl_ceiling_reason":"Static HTML parse only sees markup-declared resources; capturing runtime XHR/fetch()/dynamically-injected third parties (TRL 8+) needs a real headless browser, which is structurally out of scope for a CPU-only Go service.","version":{"deployed_at":"2026-08-27T10:08:22Z","sha":"5e2b33f","version":"0.4.8"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-trust-composite-grader","domain":"domain-trust-composite-grader.0exec.com","mesh":"0exec","host_port":18199,"category":"security","title":"Domain Trust Composite Grader","summary":"Composite 0-100 trust score for the domainscope enricher pipeline","tags":["domainscope","go-domain"],"openapi_url":"https://domain-trust-composite-grader.0exec.com/openapi.json","llms_url":"https://domain-trust-composite-grader.0exec.com/llms.txt","health_url":"https://domain-trust-composite-grader.0exec.com/health","version_url":"https://domain-trust-composite-grader.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_trust_composite_grader","url":"https://domain-trust-composite-grader.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (never formally assessed before): confirmed this is a real, complete, fully self-contained service (does NOT call sibling services despite the catalog description implying aggregation) computing 6 signals itself (RDAP age, DNSSEC, SPF/DMARC, MTA-STS, TLS, security.txt). Does not use safehttp.NewClient() (uses fleetfetch exclusively), so fetch-cache masking does not apply. Found a real bug: the DEPLOYED production container (running since 2026-07-11) predates two already-merged main commits shipped without a version bump, missing a fix that makes checkTLS/checkSecurityTxt always score dial failures (including transient DNS timeouts) as measured negatives -- confirmed on ~17.6% of a 500-row production sample, the largest single scoring component. Backfilled CHANGELOG/version and recommended redeploy. See PR #8 (merged) + services-registry PR #31 (merged, added this service's first-ever registry entry).","trl_ceiling":7,"trl_ceiling_reason":"Self-contained protocol-hygiene heuristic (RDAP age via IANA bootstrap, DNSSEC, SPF/DMARC, MTA-STS, TLS, RFC 9116 security.txt) with real RFC-compliant parsing and a measured-vs-unmeasured evidence trail, but no external reputation/threat-intel signal, no historical-trend component, and no empirically-calibrated ground truth for its 90-point weighting scheme -- structurally cannot reach SLA-grade (8-9) as designed.","version":{"deployed_at":"2026-08-27T14:10:12Z","sha":"fb4c80e","version":"0.1.8"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"domain-well-known-catalog","domain":"domain-well-known-catalog.0exec.com","mesh":"0exec","host_port":18194,"category":"security","title":"Domain Well Known Catalog","summary":"Semantic /.well-known/ coverage scanner that rejects wildcard routes, soft 404s, malformed documents, and wrong redirects.","tags":["domainscope","go-domain"],"openapi_url":"https://domain-well-known-catalog.0exec.com/openapi.json","llms_url":"https://domain-well-known-catalog.0exec.com/llms.txt","health_url":"https://domain-well-known-catalog.0exec.com/health","version_url":"https://domain-well-known-catalog.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_domain_well_known_catalog","url":"https://domain-well-known-catalog.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (never synced to central registry before, though the repo's own service.yaml had a local trl=6 self-assessment from July 2026): confirmed genuinely complete and working, NOT a duplicate of sibling go_wellknown_scanner (different mesh, narrower 24-path catalog but materially deeper per-path semantic validation vs. the scanner's broader ~30-path/soft-404-only approach). Live endpoint healthy, no deploy/DNS drift. Found a real bug: change-password was the only catalogued path exempted from the generic 'reject an unexplained HTML body' check every other path gets -- the single largest source of all findings in a 250-domain sample, 51/250 (20.4%) false positives from CMS/parking/anti-bot catch-all pages. Fixed, dropping false positives to 3/250. Uses fleetfetch (not safehttp), so the literal fetch-cache bug pattern doesn't apply -- flagged fleetfetch's own documented 'live probe semantics should bypass cache' guidance as a follow-up, not changed here (no concrete evidence of a wrong result from it). See PR #4 (merged).","version":{"deployed_at":"2026-08-20T22:43:34Z","sha":"26cb273","version":"0.2.5"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-alertmanager","domain":"fleet-alertmanager.0exec.com","mesh":"0exec","host_port":18321,"category":"observability","title":"Fleet Alertmanager","summary":"Alertmanager routing the 18 rules in prometheus/rules/fleet-alerts.yml to fleet-notify. Runs in host network mode, --web.listen-address=:18321. No browser UI use case of its own -- reached only by Prometheus, locally.","openapi_url":"https://fleet-alertmanager.0exec.com/openapi.json","llms_url":"https://fleet-alertmanager.0exec.com/llms.txt","health_url":"https://fleet-alertmanager.0exec.com/health","version_url":"https://fleet-alertmanager.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-metrics-hub","url":"https://fleet-alertmanager.0exec.com","example":"/-/healthy","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Stock prom/alertmanager:v0.34.0 wired to route Prometheus-native alerts (previously had no delivery path at all -- see fleet-prometheus entry's note on fleet-alerts.yml) through fleet-notify's no-auth webhook. Config is a single static route + one webhook receiver, not independently tested beyond confirming delivery live post-deploy. trl set to match the fleet-grafana/fleet-prometheus siblings in this same repo (config-driven third-party binary, no CI); trl_ceiling held at 8 for the same reason.","trl_ceiling":8,"reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"HTTP 401"},{"slug":"fleet-backoff-coordinator","domain":"fleet-backoff-coordinator.0exec.com","mesh":"0exec","host_port":18163,"category":"fleet_infra","title":"Fleet Backoff Coordinator","summary":"response-driven backoff coordinator","tags":["kind-container"],"openapi_url":"https://fleet-backoff-coordinator.0exec.com/openapi.json","llms_url":"https://fleet-backoff-coordinator.0exec.com/llms.txt","health_url":"https://fleet-backoff-coordinator.0exec.com/health","version_url":"https://fleet-backoff-coordinator.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-backoff-coordinator","url":"https://fleet-backoff-coordinator.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). response-driven backoff coordinator. /selftest + INTEGRATIONS.md shipped. ADR-0013. See services-registry/docs/adr/0013-fleet-backoff-coordinator.md.","trl_ceiling":7,"version":{"deployed_at":"2026-08-27T14:44:40Z","sha":"6ba32df","version":"0.1.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-backup","domain":"fleet-backup.0exec.com","mesh":"0exec","host_port":18311,"category":"observability","title":"Fleet Backup","summary":"F6 fleet backup orchestrator. Every 6h snapshots configured sources (SQLite, git, files, directories), encrypts with age (multiple recipients for key rotation), pushes to URI-shaped destination (initial: local:///opt/backups; future: storage-box:// rsync over SSH). Verifies every write by decrypt+tar-diff round-trip; mismatch = FAILED run, retention prune skipped. Per-instance SQLite audit log enforces \"never delete what we didn't create\" invariant. 7-daily / 4-weekly / 12-monthly retention. POST /restore always dry-run; actual restore is operator-driven with offline age identity (daemon never holds the decrypting key).","openapi_url":"https://fleet-backup.0exec.com/openapi.json","llms_url":"https://fleet-backup.0exec.com/llms.txt","health_url":"https://fleet-backup.0exec.com/health","version_url":"https://fleet-backup.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-backup","url":"https://fleet-backup.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":4,"trl_evidence":"Initial scaffold (2026-05-19). 19 unit tests with injectable TarFn/EncryptFn/Destination + :memory: audit DB — tests never touch real disk or run heavy crypto on the hot path. Covered: AGE_RECIPIENTS empty/malformed/blank-only refuses to start (fail-CLOSED on missing crypto); malformed-key error redacts key body (no leak to logs); encrypt+decrypt + tar+untar round-trip; recipient fingerprint never contains raw pubkey; classify retention against 365 daily inputs / sparse inputs / multiple-same-day / zero-bands / non-RFC3339-rejected / deterministic-against-synthetic-clock; orchestrator successful snapshot writes audit row with recipient FP; destination-unreachable writes no blobs AND no audit rows; verify-mismatch marks run FAILED AND skips retention prune (safety invariant: failed run = no safe to delete history); retention-prune respects unowned-snapshot invariant (manually-placed blobs survive); /status JSON shape carries last_run/next_run/runs/audit/recipient_fingerprints/destination_ready; /restore defaults dry-run; /restore dry_run=false rejected without confirm_restore=YES; /run admin-gated (403 without token); /selftest 200 happy path + 503 on destination unreachable; parseSources rejects malformed (missing kind, unknown kind, missing path, duplicate names); LocalDest round-trip on real tmpdir; storage-box:// NotImplemented surfaces cleanly.","trl_ceiling":7,"trl_ceiling_reason":"Verify-after-write in production is byte-equality on the encrypted blob (daemon holds no decrypting identity, by design). Full encrypt+decrypt+tar-diff verify only runs in tests + when an operator opts a verifying identity into the daemon. Lift to 7+ would either issue the daemon a dedicated verify-only identity or require every restore retrieval to verify before exposing bytes.","version":{"deployed_at":"2026-08-27T14:43:51Z","sha":"65f1e16","version":"0.1.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-body-redactor","domain":"fleet-body-redactor.0exec.com","mesh":"0exec","host_port":18154,"category":"fleet_infra","title":"Fleet Body Redactor","summary":"canonical sensitive-data redactor","tags":["kind-container"],"openapi_url":"https://fleet-body-redactor.0exec.com/openapi.json","llms_url":"https://fleet-body-redactor.0exec.com/llms.txt","health_url":"https://fleet-body-redactor.0exec.com/health","version_url":"https://fleet-body-redactor.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-body-redactor","url":"https://fleet-body-redactor.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). canonical sensitive-data redactor. /selftest + INTEGRATIONS.md shipped. ADR-0004. See services-registry/docs/adr/0004-fleet-body-redactor.md.","trl_ceiling":8,"version":{"deployed_at":"2026-08-27T14:45:10Z","sha":"df5e652","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-budget-tracker","domain":"fleet-budget-tracker.0exec.com","mesh":"0exec","host_port":18164,"category":"fleet_infra","title":"Fleet Budget Tracker","summary":"per-program scan-cost cap (atomic check-and-insert)","tags":["kind-container"],"openapi_url":"https://fleet-budget-tracker.0exec.com/openapi.json","llms_url":"https://fleet-budget-tracker.0exec.com/llms.txt","health_url":"https://fleet-budget-tracker.0exec.com/health","version_url":"https://fleet-budget-tracker.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-budget-tracker","url":"https://fleet-budget-tracker.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). per-program scan-cost cap (atomic check-and-insert). /selftest + INTEGRATIONS.md shipped. ADR-0014. See services-registry/docs/adr/0014-fleet-budget-tracker.md.","trl_ceiling":7,"version":{"deployed_at":"2026-08-07T11:54:44Z","sha":"f535829","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-call-tracer","domain":"fleet-call-tracer.0exec.com","mesh":"0exec","host_port":18161,"category":"fleet_infra","title":"Fleet Call Tracer","summary":"per-request call trace collector (Speedscope flamegraph output)","tags":["kind-container"],"openapi_url":"https://fleet-call-tracer.0exec.com/openapi.json","llms_url":"https://fleet-call-tracer.0exec.com/llms.txt","health_url":"https://fleet-call-tracer.0exec.com/health","version_url":"https://fleet-call-tracer.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-call-tracer","url":"https://fleet-call-tracer.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit of this shared fleet-infra per-request call-trace collector (Speedscope flamegraph output): found and fixed 2 real bugs hitting its two core features. (1) /flame/{trace_id} exported profiles that pass JSON Schema validation but real Speedscope actually rejects on import -- renderFlame flat-sorted spans ignoring parent_span_id, breaking well-nestedness for any ordinary concurrent fan-out; fixed by deriving events via a parent/child-tree DFS that guarantees well-nestedness by construction. (2) No idempotency on (trace_id, span_id) despite the API's own documented fire-and-forget/retry contract -- a retried batch silently aliased duplicate rows in the tree view, with the original data vanishing from display though still on disk; fixed with a unique index + ON CONFLICT DO NOTHING plus a dedup migration. Also fixed a scoping bug that made /selftest's flame-output check silently never actually run. trl held at 6 pending merge+soak (both bugs hit core features under ordinary non-adversarial conditions); trl_ceiling held at 8 -- clean, well-scoped implementation bugs, not evidence of an architectural flaw. See PR #4 (merged).","trl_ceiling":8,"version":{"deployed_at":"2026-08-08T08:42:05Z","sha":"49354b0","version":"0.1.4"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-capabilities","domain":"fleet-capabilities.0exec.com","mesh":"0exec","host_port":18206,"category":"observability","title":"Fleet Capabilities","summary":"G9 fleet capability aggregator. Walks the catalog and probes /openapi + /health + /version + /selftest on every kind=container entry in parallel; surfaces one aggregate at /capabilities.json (5-min in-process TTL, served stale during refresh). Plain net/http outbound (ADR-0024). Failed sub-probes recorded in errors[]; we never drop a service silently. Summary rollup (container_reachable, openapi_published, selftest_green/red/not_implemented) for one-glance fleet status.","openapi_url":"https://fleet-capabilities.0exec.com/openapi.json","llms_url":"https://fleet-capabilities.0exec.com/llms.txt","health_url":"https://fleet-capabilities.0exec.com/health","version_url":"https://fleet-capabilities.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-capabilities","url":"https://fleet-capabilities.0exec.com","example":"/capabilities.json","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":4,"trl_evidence":"NEW fleet primitive (G9, 2026-05-19). /selftest exercises the full aggregator path against an in-process httptest fleet. Unit-tested: container-only filter, per-service-error-no-drop, selftest 200/503/404 each counted, worker pool ceiling honoured, summary counts internally consistent, /refresh admin-gated, /capabilities.json served with Cache-Control max-age=300.","trl_ceiling":7,"version":{"deployed_at":"2026-08-27T15:55:05Z","sha":"4ca758b","version":"0.1.4"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-cert-watch","domain":"fleet-cert-watch.0exec.com","mesh":"0exec","host_port":18316,"category":"observability","title":"Fleet Cert Watch","summary":"Periodic raw-TLS-handshake probe of the fleet registry's own cert expiry, exposed as Prometheus metrics for fleet-prometheus/fleet-grafana.","tags":["kind-container","language-go","runtime-compose"],"openapi_url":"https://fleet-cert-watch.0exec.com/openapi.json","llms_url":"https://fleet-cert-watch.0exec.com/llms.txt","health_url":"https://fleet-cert-watch.0exec.com/health","version_url":"https://fleet-cert-watch.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/fleet-cert-watch","url":"https://fleet-cert-watch.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","version":{"deployed_at":"2026-08-27T16:02:05Z","sha":"3dc4af6","version":"0.2.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-content-normalizer","domain":"fleet-content-normalizer.0exec.com","mesh":"0exec","host_port":18172,"category":"fleet_infra","title":"Fleet Content Normalizer","summary":"MIME/charset/encoding normalizer (5MB cap)","tags":["kind-container"],"openapi_url":"https://fleet-content-normalizer.0exec.com/openapi.json","llms_url":"https://fleet-content-normalizer.0exec.com/llms.txt","health_url":"https://fleet-content-normalizer.0exec.com/health","version_url":"https://fleet-content-normalizer.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-content-normalizer","url":"https://fleet-content-normalizer.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). MIME/charset/encoding normalizer (5MB cap). /selftest + INTEGRATIONS.md shipped. ADR-0022. See services-registry/docs/adr/0022-fleet-content-normalizer.md.","trl_ceiling":7,"version":{"deployed_at":"2026-08-27T15:57:49Z","sha":"fb8ea5a","version":"0.1.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-counter","domain":"fleet-counter.0exec.com","mesh":"0exec","host_port":18275,"category":"fleet_infra","title":"Fleet Counter","summary":"Atomic distributed counters over HTTP — monotonic ids/build numbers, no DB","tags":["fleet-infra"],"openapi_url":"https://fleet-counter.0exec.com/openapi.json","llms_url":"https://fleet-counter.0exec.com/llms.txt","health_url":"https://fleet-counter.0exec.com/health","version_url":"https://fleet-counter.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-counter","url":"https://fleet-counter.0exec.com","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":7,"trl_evidence":"Live at counter.0exec.com /version=0.2.0, /health=200, /selftest=200; 5 sequential GETs returned strictly increasing 1-5, ?peek non-mutating, new int64-overflow guard returns 409 and preserves value, DELETE=204; 22 tests incl go test -race green; single-mutex atomic store, name validation, reserved-name 409, idle TTL+janitor, MaxCounters cap, per-IP write rate limit, nosniff/no-store headers.","trl_ceiling":7,"trl_ceiling_reason":"in-RAM non-durable — every counter resets to 0 on restart, cannot serve as a durable ledger","version":{"deployed_at":"2026-08-27T15:50:14Z","sha":"de1a621","version":"0.3.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-diff-engine","domain":"fleet-diff-engine.0exec.com","mesh":"0exec","host_port":18160,"category":"fleet_infra","title":"Fleet Diff Engine","summary":"structured diff: http_response|json|html|asset_set|text","tags":["kind-container"],"openapi_url":"https://fleet-diff-engine.0exec.com/openapi.json","llms_url":"https://fleet-diff-engine.0exec.com/llms.txt","health_url":"https://fleet-diff-engine.0exec.com/health","version_url":"https://fleet-diff-engine.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-diff-engine","url":"https://fleet-diff-engine.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). structured diff: http_response|json|html|asset_set|text. /selftest + INTEGRATIONS.md shipped. ADR-0010. See services-registry/docs/adr/0010-fleet-diff-engine.md.","trl_ceiling":7,"version":{"deployed_at":"2026-08-27T15:59:38Z","sha":"8069dda","version":"0.1.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-dig","domain":"fleet-dig.0exec.com","mesh":"0exec","host_port":18279,"category":"fleet_infra","title":"Fleet Dig","summary":"DNS lookups as a service — dig over curl from minimal containers","tags":["fleet-infra"],"openapi_url":"https://fleet-dig.0exec.com/openapi.json","llms_url":"https://fleet-dig.0exec.com/llms.txt","health_url":"https://fleet-dig.0exec.com/health","version_url":"https://fleet-dig.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-dig","url":"https://fleet-dig.0exec.com","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":7,"trl_evidence":"Live at dig.0exec.com, /version=0.2.0 deployed via fleet-runner with green direct smoke. Returns correct live DNS for A/MX/TXT/PTR and custom-resolver (?server=1.1.1.1). SSRF guard, port-scan lockdown (server:port rejected), control-char/NUL/oversize name rejection, type whitelist, per-lookup timeout, response-size caps, nosniff all verified live with 400/200 probes. 19 tests green through pre-commit gate.","trl_ceiling":7,"trl_ceiling_reason":"single-instance diagnostic proxy, no HA/auth/rate-limit hardening for production-grade SLA","version":{"deployed_at":"2026-08-27T16:00:42Z","sha":"29932a1","version":"0.3.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-discovery","domain":"fleet-discovery.0exec.com","mesh":"0exec","host_port":18201,"category":"observability","title":"Fleet Discovery","summary":"Prometheus http_sd endpoint emitting one target per fleet container service. Refreshes services.json every 60s and probes /metrics via host.docker.internal.","openapi_url":"https://fleet-discovery.0exec.com/openapi.json","llms_url":"https://fleet-discovery.0exec.com/llms.txt","health_url":"https://fleet-discovery.0exec.com/health","version_url":"https://fleet-discovery.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-metrics-hub","url":"https://fleet-discovery.0exec.com","example":"/sd","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit of go-fleet-metrics-hub (see fleet-grafana/fleet-prometheus entries for shared repo-wide findings). Found and fixed a real observability gap: the refresh loop's success/failure/staleness was only visible via a JSON /debug/targets endpoint Prometheus can't scrape or alert on -- /health stayed 200 ok even if the registry fetch had been silently broken for hours, with /sd serving stale targets undetected. Fixed by adding 3 correctly-typed Prometheus metrics (refresh_total Counter, last_success_timestamp_seconds Gauge, targets Gauge), already picked up by the existing scrape job. Confirmed no lost updates under 300 concurrent writes with go test -race (shared state behind sync.RWMutex, verified with a new stress test), and malformed/hostile catalog entries fail closed without crashing (6 new test cases). trl bumped 4-\u003e6 -- real, race-clean, well-tested code that fails closed on hostile external input and now has correct self-observability; trl_ceiling held at 7 -- structurally trusts an unversioned external catalog, a deliberately thin sd-shim. See PR #3 (merged).","trl_ceiling":7,"reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"HTTP 401"},{"slug":"fleet-dns-sync","domain":"fleet-dns-sync.0exec.com","mesh":"0exec","host_port":18141,"category":"infrastructure","title":"Fleet Dns Sync","summary":"Hetzner DNS reconciler. Targets the Hetzner Cloud API (api.hetzner.cloud/v1, Bearer auth, RRSet-oriented) — the canonical DNS surface that supersedes the deprecated dns.hetzner.com Console API. Reads services-registry/services.json, diffs against actual zone state, applies the delta. Pulls the Cloud API token from go-fleet-secrets. 30-min ticker. Extras never auto-deleted.","tags":["go-fleet"],"openapi_url":"https://fleet-dns-sync.0exec.com/openapi.json","llms_url":"https://fleet-dns-sync.0exec.com/llms.txt","health_url":"https://fleet-dns-sync.0exec.com/health","version_url":"https://fleet-dns-sync.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-dns-sync","url":"https://fleet-dns-sync.0exec.com","example":"/stats","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"reconcile_runs + reconcile_actions tables, dry_run mode, /reconcile manual trigger, /runs query, /selftest with httptest-stubbed Hetzner Cloud + registry (0 mutations in dry-run, 3 POSTs in apply)","trl_ceiling":8,"trl_ceiling_reason":"Per-zone instance; ceiling lifts with multi-zone via parallel deployments.","version":{"deployed_at":"2026-08-27T14:47:07Z","sha":"f5525cf","version":"0.3.7"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-engagement-timeline","domain":"fleet-engagement-timeline.0exec.com","mesh":"0exec","host_port":18162,"category":"fleet_infra","title":"Fleet Engagement Timeline","summary":"per-program event timeline aggregator (6 siblings)","tags":["kind-container"],"openapi_url":"https://fleet-engagement-timeline.0exec.com/openapi.json","llms_url":"https://fleet-engagement-timeline.0exec.com/llms.txt","health_url":"https://fleet-engagement-timeline.0exec.com/health","version_url":"https://fleet-engagement-timeline.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-engagement-timeline","url":"https://fleet-engagement-timeline.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). per-program event timeline aggregator (6 siblings). /selftest + INTEGRATIONS.md shipped. ADR-0012. See services-registry/docs/adr/0012-fleet-engagement-timeline.md.","trl_ceiling":7,"version":{"deployed_at":"2026-08-27T14:48:37Z","sha":"945aa60","version":"0.1.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-eventlog","domain":"fleet-eventlog.0exec.com","mesh":"0exec","host_port":18305,"category":"infrastructure","title":"Fleet Eventlog","summary":"Replayable per-topic event log with monotonic offsets. Publish events to named topics; consumers read from any offset and long-poll for new ones. v0.1 is in-RAM with per-topic retention cap; disk-backed durability is a planned follow-up.","openapi_url":"https://fleet-eventlog.0exec.com/openapi.json","llms_url":"https://fleet-eventlog.0exec.com/llms.txt","health_url":"https://fleet-eventlog.0exec.com/health","version_url":"https://fleet-eventlog.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-eventlog","url":"https://fleet-eventlog.0exec.com","example":"/topics","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"First-pass audit of this shared fleet-infra append-only event log: confirmed durability (in-RAM only, documented and verified via a real SIGKILL-and-restart test) and ordering (mutex-guarded offset assignment, verified with 500 concurrent live publish calls yielding unique contiguous offsets) both match documentation exactly. Found and fixed a real unbounded-growth bug -- nothing capped the number of distinct topics or topic-name length (20,000 single-event topics grew RSS from 12.5MB to 29MB; a ~500KB topic name was accepted with no validation). Fixed with a new EVENTLOG_MAX_TOPICS cap and a 256-byte name limit. trl held at 5 (one real bug found, now fixed); trl_ceiling=6 added -- the in-RAM-only design is a deliberate structural limitation, can't claim 'system of record' reliability while a restart silently loses all data. See PR #3 (merged).","version":{"deployed_at":"2026-08-27T15:58:53Z","sha":"d79da3d","version":"0.1.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-exec","domain":"fleet-exec.0exec.com","mesh":"0exec","host_port":18309,"category":"infrastructure","title":"Fleet Exec","summary":"Ephemeral, bounded code/command execution for fleet agents. POST /run {lang, code} executes in an isolated temp dir with a hard timeout, process-group SIGKILL, output caps, and minimal child env. Keystore-gated; NOT internet-exposed. v0.1 TRL 4.","openapi_url":"https://fleet-exec.0exec.com/openapi.json","llms_url":"https://fleet-exec.0exec.com/llms.txt","health_url":"https://fleet-exec.0exec.com/health","version_url":"https://fleet-exec.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-exec","url":"https://fleet-exec.0exec.com","example":"/langs","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"First-pass safety audit of this shared fleet-infra remote-script-execution service: confirmed no shell/command-injection vulnerability (args always passed as literal argv, never shell-interpreted; allowlist correctly rejects everything else) via direct adversarial testing. Found and fixed a real availability/DoS bug -- the 'hard timeout' guarantee could be bypassed by a submitted script detaching a descendant into its own process session (setsid/start_new_session), escaping the process-group kill and blocking the request handler indefinitely regardless of timeout_ms (live-confirmed). Fixed with a hard wait-delay cap so the handler always returns within timeout+2s no matter what the script does; the escaped process itself still needs deployment-level containment (cgroups/seccomp), which is documented but not verified enabled in production. trl held at 5 and trl_ceiling capped at 6 deliberately, pending that containment verification -- a production-grade rating for a command-execution surface needs the deployment to actually enforce what the README prescribes, not just document it. See PR #4 (merged).","version":{"deployed_at":"2026-08-27T16:01:45Z","sha":"4de2313","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-fake","domain":"fleet-fake.0exec.com","mesh":"0exec","host_port":18281,"category":"fleet_infra","title":"Fleet Fake","summary":"Fake/test data generator — fixtures and seed data over curl","tags":["fleet-infra"],"openapi_url":"https://fleet-fake.0exec.com/openapi.json","llms_url":"https://fleet-fake.0exec.com/llms.txt","health_url":"https://fleet-fake.0exec.com/health","version_url":"https://fleet-fake.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-fake","url":"https://fleet-fake.0exec.com","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":7,"trl_evidence":"First-pass audit of this shared fleet-infra fake-data generator: found and fixed a real bug -- the 'fresh' (unseeded) random-seed path derived solely from time.Now().UnixNano(), so concurrent requests landing on the same nanosecond tick got identical seeds and identical output. Empirically confirmed with a 20,000-request concurrent stress probe: 549 duplicate-uuid groups (128-bit UUIDs matching exactly is conclusive proof of seed collision, not chance). Fixed by seeding from crypto/rand instead of the wall clock; ?seed=N reproducibility untouched. Confirmed no shared-mutable-state race otherwise (fresh *rand.Rand per request) and no locale/format-correctness bugs. trl held at 7; trl_ceiling bumped 7-\u003e8 -- the old ceiling was in part propped up by this undiscovered concurrency bug in the exact area (randomness) audits prioritize; nothing here is structurally blocking further hardening. See PR #1 (merged).","trl_ceiling":7,"trl_ceiling_reason":"single-instance fake-data utility, no persistence/auth/SLA","version":{"deployed_at":"2026-08-27T16:03:04Z","sha":"243a7d7","version":"0.3.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-fingerprint-cache","domain":"fleet-fingerprint-cache.0exec.com","mesh":"0exec","host_port":18153,"category":"fleet_infra","title":"Fleet Fingerprint Cache","summary":"WAF/soft-404/CDN-noise classifier","tags":["kind-container"],"openapi_url":"https://fleet-fingerprint-cache.0exec.com/openapi.json","llms_url":"https://fleet-fingerprint-cache.0exec.com/llms.txt","health_url":"https://fleet-fingerprint-cache.0exec.com/health","version_url":"https://fleet-fingerprint-cache.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-fingerprint-cache","url":"https://fleet-fingerprint-cache.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). WAF/soft-404/CDN-noise classifier. /selftest + INTEGRATIONS.md shipped. ADR-0003. See services-registry/docs/adr/0003-fleet-fingerprint-cache.md.","trl_ceiling":8,"version":{"deployed_at":"2026-08-27T14:51:51Z","sha":"b8c5dc1","version":"0.1.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-grafana","domain":"fleet-grafana.0exec.com","mesh":"0exec","host_port":18202,"category":"observability","title":"Fleet Grafana","summary":"Grafana dashboards for the fleet metrics hub. Anonymous viewer-only; admin/signup disabled; keystore-gated at the gateway.","openapi_url":"https://fleet-grafana.0exec.com/openapi.json","llms_url":"https://fleet-grafana.0exec.com/llms.txt","health_url":"https://fleet-grafana.0exec.com/health","version_url":"https://fleet-grafana.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-metrics-hub","url":"https://fleet-grafana.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"First-pass audit of go-fleet-metrics-hub (covers all 3 catalog entries: fleet-grafana/fleet-prometheus/fleet-discovery in one repo). Found a real security issue: a live-shaped API key was hardcoded into a Grafana dashboard's link params in this PUBLIC repo, committed since an earlier commit and exposed the whole time -- replaced with the documented public demo token, but that specific key should be treated as compromised and rotated/revoked via the keystore independent of this fix, since a git fix can't undo its history exposure. Confirmed no unbounded-cardinality metrics-label risk (discovery's labels come from the curated ~250-entry registry, not raw/user input) and no other secrets anywhere in the repo (broad grep). trl bumped 4-\u003e5 -- provisioning is correct and now secret-free, but the leaked key sitting undetected is direct evidence there's no dashboard-JSON validation/secret-scanning gate in this repo's process; trl_ceiling held at 8. See PR #3 (merged).","trl_ceiling":8,"reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"HTTP 401"},{"slug":"fleet-graph","domain":"fleet-graph.0exec.com","mesh":"0exec","host_port":18143,"category":"infrastructure","title":"Fleet Graph","summary":"Fleet graph collector. Aggregates privacy-safe HTTP observation events from go-common/graph into retained SQLite buckets. The reader-authenticated /insights projection exposes declared versus observed service relationships, errors, freshness, and explicit count semantics; one end-to-end request can create an event at both instrumented ends. /viewer is a public no-data browser shell. Also serves writer ingest, a compact evidence-backed agent brief, expanded agent context, service neighbours, lookup, graph summary, and drift without exposing request paths, headers, payloads, credentials, or actor identity.","openapi_url":"https://fleet-graph.0exec.com/openapi.json","llms_url":"https://fleet-graph.0exec.com/llms.txt","health_url":"https://fleet-graph.0exec.com/health","version_url":"https://fleet-graph.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-graph","url":"https://fleet-graph.0exec.com","example":"/viewer","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Fleet graph collector v0.2.8: SQLite storage is bounded at the write path (the unused high-cardinality services_seen ledger is no longer populated), writes are serialized with a 500 ms busy timeout and request contexts, and periodic passive WAL checkpoints prevent unbounded disk growth. Production compaction on 2026-09-04 reduced the live database from 4.5 GB plus a 1.5 GB WAL to 176 KB while preserving every active graph edge and hourly rollup; direct /health and real /selftest both returned 200 after restart. The collector retains directed cycle-tolerant graph semantics, strict writer identity checks, canonical registry IDs, bounded agent contexts, and tested ingest-to-rollup retention.","trl_ceiling":8,"trl_ceiling_reason":"Single-node SQLite. Lifts to 8 once paired with periodic snapshot backup and a multi-collector consensus design for high-RPS callers.","version":{"deployed_at":"2026-09-11T07:27:39Z","sha":"d977afd","version":"0.4.6"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-har-builder","domain":"fleet-har-builder.0exec.com","mesh":"0exec","host_port":18157,"category":"fleet_evidence","title":"Fleet Har Builder","summary":"HAR 1.2 evidence formatter","tags":["kind-container"],"openapi_url":"https://fleet-har-builder.0exec.com/openapi.json","llms_url":"https://fleet-har-builder.0exec.com/llms.txt","health_url":"https://fleet-har-builder.0exec.com/health","version_url":"https://fleet-har-builder.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-har-builder","url":"https://fleet-har-builder.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). HAR 1.2 evidence formatter. /selftest + INTEGRATIONS.md shipped. ADR-0007. See services-registry/docs/adr/0007-fleet-har-builder.md.","trl_ceiling":7,"version":{"deployed_at":"2026-08-27T14:53:08Z","sha":"2e2c225","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-host-guard","domain":"fleet-host-guard.0exec.com","mesh":"0exec","host_port":18207,"category":"observability","title":"Fleet Host Guard","summary":"F7 disk pressure eviction + F9 memory leak detector. Dockerhost guardian daemon: every 5 min samples fs usage and runs `docker image prune --filter until=168h` + truncates oversized non-rotated /var/log/*.log; every 1 h samples container RSS via `docker stats` and fits a linear regression — flags containers whose slope \u003e 50 MB/h AND R² \u003e 0.7.","openapi_url":"https://fleet-host-guard.0exec.com/openapi.json","llms_url":"https://fleet-host-guard.0exec.com/llms.txt","health_url":"https://fleet-host-guard.0exec.com/health","version_url":"https://fleet-host-guard.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-host-guard","url":"https://fleet-host-guard.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Initial scaffold (2026-05-19). 11 unit tests across both primitives — injectable Runner + StatFS mocks; tests cover disk sweep below/above threshold (no-op / dry-run / real exec+parse), statfs failure path, log truncate keep-tail correctness, logrotate sibling skip, parseHumanBytes coverage, monotonic growth flagged (slope ~100MB/h, R² \u003e 0.99), flat noise NOT flagged (R² \u003c 0.7), noisy growth low R², leaky vs steady end-to-end ticker, docker-sock unreachable (state untouched, error surfaced). /selftest exercises regression + parsing primitives against in-memory data.","trl_ceiling":7,"trl_ceiling_reason":"Bounded by docker-stats RSS fidelity (cgroup memory.usage_in_bytes includes page cache). Lift to 7+ would require parsing /sys/fs/cgroup/memory/{slice}/memory.stat to separate RSS from cache.","version":{"deployed_at":"2026-08-27T14:56:31Z","sha":"9875494","version":"0.2.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-ip","domain":"fleet-ip.0exec.com","mesh":"0exec","host_port":18278,"category":"fleet_infra","title":"Fleet Ip","summary":"Echo your public IP plus request facts — your own ifconfig.me","tags":["fleet-infra"],"openapi_url":"https://fleet-ip.0exec.com/openapi.json","llms_url":"https://fleet-ip.0exec.com/llms.txt","health_url":"https://fleet-ip.0exec.com/health","version_url":"https://fleet-ip.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-ip","url":"https://fleet-ip.0exec.com","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":7,"trl_evidence":"First-pass audit of this shared fleet-infra 'what's my IP' echo utility: confirmed its X-Forwarded-For handling was already correctly fixed from a prior audit (trusts only right-most TrustedProxies entries, falls back to RemoteAddr) -- live-verified a spoofed XFF header had no effect. But found the SAME spoofable-header-trust bug class on a DIFFERENT header: /port's clientPort() echoed X-Forwarded-Port verbatim with zero validation, letting any external caller fabricate an arbitrary 'source port' -- live-confirmed (sent 9999, got back 9999) even though the fleet's own nginx never sets/overwrites this header. Fixed to always derive the port from the real, unforgeable RemoteAddr. Confirmed fetch-cache masking not applicable (no outbound HTTP calls). trl/trl_ceiling held at 7/7 -- single-instance echo/facts utility with no SLA/persistence/HA, not eligible for 8-9 regardless of the fix. See PR #1 (merged).","trl_ceiling":7,"trl_ceiling_reason":"single-instance echo/facts utility with no SLA, persistence, or HA","version":{"deployed_at":"2026-08-27T15:38:15Z","sha":"e3085aa","version":"0.4.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-lock","domain":"fleet-lock.0exec.com","mesh":"0exec","host_port":18303,"category":"infrastructure","title":"Fleet Lock","summary":"Distributed advisory locks, leases, and leader-election over HTTP. Every fresh acquire returns a monotonic fencing token; re-acquire by the same owner refreshes the lease in place (leader renewal). In-RAM, ephemeral by design — a restart releases every lock.","openapi_url":"https://fleet-lock.0exec.com/openapi.json","llms_url":"https://fleet-lock.0exec.com/llms.txt","health_url":"https://fleet-lock.0exec.com/health","version_url":"https://fleet-lock.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-lock","url":"https://fleet-lock.0exec.com","example":"/locks","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit of this shared fleet-infra distributed advisory-lock primitive: found and fixed the single most severe bug class checked for in this pass -- a TTL/wait_seconds integer overflow (any ttl_seconds \u003e= ~1e10, an ordinary JSON int) wrapped the computed lease duration negative, so the lock was immediately treated as expired; live-reproduced two callers both getting acquired:true for the same key simultaneously, exactly the 'two callers both think they hold the lock' failure mode this service exists to prevent. Fixed by clamping before multiplying instead of after. The core mutex-guarded locking logic itself was reviewed carefully and confirmed correct (200-goroutine stress tests clean under go test -race) -- the bug was purely in unvalidated duration arithmetic. trl bumped 5-\u003e6; trl_ceiling=7 added -- single-process/in-memory with no HA/replication story, a coordinator crash drops all locks fleet-wide. See PR #3 (merged).","version":{"deployed_at":"2026-08-27T15:32:04Z","sha":"9dbbf35","version":"0.1.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-mcp-gateway","domain":"fleet-mcp-gateway.0exec.com","mesh":"0exec","host_port":18313,"category":"infrastructure","title":"Fleet Mcp Gateway","summary":"Aggregates fleet services' agent contracts (GET /agent.json) into one Model Context Protocol Streamable HTTP endpoint at /mcp.","tags":["kind-container","language-go","runtime-compose"],"openapi_url":"https://fleet-mcp-gateway.0exec.com/openapi.json","llms_url":"https://fleet-mcp-gateway.0exec.com/llms.txt","health_url":"https://fleet-mcp-gateway.0exec.com/health","version_url":"https://fleet-mcp-gateway.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-mcp-gateway","url":"https://fleet-mcp-gateway.0exec.com","example":"/gateway/tools","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":4,"trl_evidence":"First ship. Real MCP wire-level tests pass (initialize -\u003e tools/list -\u003e tools/call, incl. caller-Authorization pass-through) against in-process aggregation. Fleet-wide registry-driven aggregation unproven in production -- zero services expose /agent.json yet (Phase 2 of a 5-phase rollout).","version":{"deployed_at":"2026-08-27T14:55:02Z","sha":"9aeee91","version":"0.5.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-md","domain":"fleet-md.0exec.com","mesh":"0exec","host_port":18282,"category":"fleet_infra","title":"Fleet Md","summary":"Render Markdown to terminal ANSI or sanitized HTML over curl","tags":["fleet-infra"],"openapi_url":"https://fleet-md.0exec.com/openapi.json","llms_url":"https://fleet-md.0exec.com/llms.txt","health_url":"https://fleet-md.0exec.com/health","version_url":"https://fleet-md.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-md","url":"https://fleet-md.0exec.com","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":8,"trl_evidence":"First-pass audit of this shared fleet-infra Markdown-to-{ANSI,HTML,plain} renderer (confirmed genuinely unrelated in code to utils-readcontent's HTML-source path -- no HTML-parsing-as-input code exists here at all): found and fixed a real data-integrity bug -- GFM task-list checked/unchecked state was silently destroyed on ?to=html and ?to=plain, because bluemonday's UGCPolicy has no allowance for the \u003cinput\u003e tag goldmark's tasklist extension renders, so [x] done and [ ] not done both rendered identically; only the separate ansi renderer (glamour) got it right. Fixed by narrowly allowing the specific checkbox input pattern back into the sanitizer policy, safe because raw user-typed \u003cinput\u003e tags are already neutralized upstream (added a test proving this invariant). Also patched an open CVE (golang.org/x/net HTML-parser DoS) directly relevant since this is a public unauthenticated endpoint parsing attacker-supplied markup on every call. Extensive adversarial battery (50-deep blockquotes, RTL/emoji, embedded backticks, etc) found no other data loss or XSS regression. trl bumped 7-\u003e8, trl_ceiling bumped 7-\u003e8 -- a deterministic pure-function converter, the prior ceiling described operational scope (no auth/SLA/persistence) rather than a structural correctness blocker; genuinely cannot reach 9 (needs cross-instance/SLA guarantees out of scope for this fleet role). See PR #1 (merged).","trl_ceiling":7,"trl_ceiling_reason":"single-instance stateless renderer, no auth/SLA/persistence","version":{"deployed_at":"2026-08-27T15:47:28Z","sha":"c66c1a8","version":"0.3.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-memory","domain":"fleet-memory.0exec.com","mesh":"0exec","host_port":18308,"category":"infrastructure","title":"Fleet Memory","summary":"Cross-session, cross-agent working memory with pure-CPU keyword recall. POST /remember to store a text doc with optional agent/key/tags; GET /recall?q= for TF-overlap ranked retrieval. Generalizes pentest-agent-state into a fleet-wide searchable store.","openapi_url":"https://fleet-memory.0exec.com/openapi.json","llms_url":"https://fleet-memory.0exec.com/llms.txt","health_url":"https://fleet-memory.0exec.com/health","version_url":"https://fleet-memory.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-memory","url":"https://fleet-memory.0exec.com","example":"/recall?q=example","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit of this shared fleet-infra key-value/memory store: genuinely clean, no PR needed. Thorough adversarial testing (read-after-write consistency, TTL boundary precision at 900ms/1100ms on a 1s lease, 40-way concurrent HTTP load, a real SIGKILL-and-restart crash simulation, MEMORY_MAX_DOCS eviction, oversized/malformed-payload DoS probes) found the service does exactly what it documents with zero discrepancies. trl bumped 5-\u003e6 given thorough independently-verified test coverage; trl_ceiling=7 added -- single-process in-memory store with no replication/backing store and an explicitly documented 'v0.1 scale' linear-scan tradeoff, structural limits on reaching SLA-grade.","version":{"deployed_at":"2026-08-27T19:50:55Z","sha":"9fb6423","version":"0.1.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-notify","domain":"fleet-notify.0exec.com","mesh":"0exec","host_port":18284,"category":"fleet_infra","title":"Fleet Notify","summary":"HTTP pub/sub — push a line to your phone or any subscriber","tags":["fleet-infra"],"openapi_url":"https://fleet-notify.0exec.com/openapi.json","llms_url":"https://fleet-notify.0exec.com/llms.txt","health_url":"https://fleet-notify.0exec.com/health","version_url":"https://fleet-notify.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-notify","url":"https://fleet-notify.0exec.com","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":7,"trl_evidence":"First-pass audit: corrected the task's framing -- not internal alerting dispatch, it's a deliberately public unauthenticated in-RAM pub/sub relay (ntfy.sh-alike), no auth by design. Confirmed delivery guarantees are solid (non-blocking fan-out, slow subscribers dropped not blocked, ring-buffer replay, race-free teardown) and confirmed fetch-cache masking does not apply (the only outbound call is a POST with a body, structurally ineligible for the GET-only cache). Found and fixed the SAME X-Forwarded-For spoofing bug independently found in go-fleet-port this batch -- the per-IP publish rate limiter trusted the leftmost client-controlled header entry, live-confirmed bypassing a 5-request limit entirely (8/8 succeeded) by rotating a fake header per call; since this service is intentionally unauthenticated, that limiter is its only defense against flooding. Fixed with the same 'only trust the header when the TCP peer is provably our own proxy' pattern. trl/trl_ceiling held at 7/7 -- in-RAM-only and no-auth are the stated design, not bugs; the best-effort ntfy forward is an honestly-labeled side channel. See PR #1 (merged).","trl_ceiling":7,"trl_ceiling_reason":"in-RAM ephemeral, single-node, at-most-once (slow-subs dropped); no persistence or HA by design","version":{"deployed_at":"2026-08-23T16:00:04Z","sha":"a7fcb48","version":"0.3.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-payload-corpus","domain":"fleet-payload-corpus.0exec.com","mesh":"0exec","host_port":18156,"category":"infrastructure","title":"Fleet Payload Corpus","summary":"versioned attack-payload corpus (125 payloads, 12 classes)","tags":["kind-container"],"openapi_url":"https://fleet-payload-corpus.0exec.com/openapi.json","llms_url":"https://fleet-payload-corpus.0exec.com/llms.txt","health_url":"https://fleet-payload-corpus.0exec.com/health","version_url":"https://fleet-payload-corpus.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-payload-corpus","url":"https://fleet-payload-corpus.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit of this shared fleet-infra security-testing payload corpus: found a serious integration break -- every real consumer (go_xss_scanner, go_crlf_tester, go-pentest-cors-misconfig-prober, go-pentest-authz-matrix, go-pentest-ssrf-prober) has been silently falling back to stale local vendored payload lists since a May 20 envelope-format change, because their hand-rolled decoders predate this service's {status,data} response envelope -- the entire 'single source of truth' promise has been quietly defeated for 2+ months with no errors raised (documented the fix pattern, consumer-side fixes are a separate follow-up). Also fixed a real bug rejecting the legitimate target_context='any' value for 2 real payloads, and a stale CorpusVersion that never bumped despite a payload-set change. Separately flagged (spun off as its own task) a real crash bug in the shared go-common metrics middleware: invalid-UTF-8 percent-encoding in a request path panics that connection, reachable pre-auth on every go-common-based service in the fleet. trl held at 6 (code itself is solid; the broken promise needs consumer-side fixes first); trl_ceiling corrected 8-\u003e7 -- the repo's own git history never supported a ceiling of 8. See PR #3 (merged).","trl_ceiling":8,"version":{"deployed_at":"2026-08-27T14:59:38Z","sha":"53b30e7","version":"0.2.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-persona","domain":"persona.0exec.com","mesh":"0exec","host_port":18209,"category":"fleet_infra","title":"Fleet Persona","summary":"cross-app + cross-origin display identity (nickname + name + avatar) for the mesh-* P2P fleet — L2 tier of fleetPersona in mesh-common","tags":["fleet-infra"],"openapi_url":"https://persona.0exec.com/openapi.json","llms_url":"https://persona.0exec.com/llms.txt","health_url":"https://persona.0exec.com/v1/health","version_url":"https://persona.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-persona","url":"https://persona.0exec.com","example":"/v1/health","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"NEW fleet primitive (2026-05-19). Pairs with mesh-common's fleetPersona (39 vitest tests). Server: 21 Go unit + handler tests covering validation, argon2id verify, fixed-window rate-limit, CORS preflight, read-only kill switch, oversized body. testing/smoke.sh runs the full lifecycle end-to-end against a running container. Strict-ASCII allowlist mirrors the client. Pure-Go SQLite (modernc.org/sqlite), CGO_ENABLED=0.","trl_ceiling":7,"version":{"deployed_at":"2026-08-27T19:46:30Z","sha":"c092fb9","version":"0.2.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-pipe","domain":"fleet-pipe.0exec.com","mesh":"0exec","host_port":18272,"category":"fleet_infra","title":"Fleet Pipe","summary":"Ephemeral, unauthenticated cross-machine copy/paste relay. POST/PUT a blob with `curl --data-binary @-`, get back a URL, pull it on another machine within a hard ≤5-minute TTL. In-RAM only (restart wipes everything), 10 MiB/blob with a total-RAM budget. Random base62 ids, write-once or last-write-wins (?replace) named slots, say-it-out-loud ids (?words), ?burn one-time reads, ?qr scannable links, ?notify read-receipts. Optional client-side E2E: `-e` (AES-256-CTR+HMAC, key in the URL #fragment — opens in a browser or decrypts with openssl) plus a browser ask-me-a-secret sealed-box (ECDH P-256). `curl …/install | sh` adds a `pipe` client with one-time wormhole codes and an end-to-end universal clipboard. Browser app at GET / for non-CLI users.","tags":["fleet-infra"],"openapi_url":"https://fleet-pipe.0exec.com/openapi.json","llms_url":"https://fleet-pipe.0exec.com/llms.txt","health_url":"https://fleet-pipe.0exec.com/health","version_url":"https://fleet-pipe.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-pipe","url":"https://fleet-pipe.0exec.com","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"v0.4.1 in-RAM TTL relay (PutOpts API, total-RAM byte budget, last-write-wins ?replace slots, read-receipt watch channels). Store unit tests: put/get, burn-on-read, TTL expiry via injected clock, write-once, replace, expired-name reclaim, max-entries + max-total-bytes budgets, byte accounting across burn/expire, clamp-TTL, base62 id shape/uniqueness over 1000 draws, PutRandom uniqueness over 500, 256-word list uniqueness, word-code shape. Handler/HTTP tests: random+named push/pull, write-once 409, replace overwrite, reserved/invalid name, burn-once-then-404, content negotiation (HTML app vs text vs ?shell/?app/?raw), word-code create, QR text+png, read-receipt notify+watch token/gone, safe headers, delete, 413. /selftest runs put→get-multi→burn→named→reserved→empty→ttl→replace→word-code→byte-budget end-to-end. Cross-impl crypto proven: AES-256-CTR+HMAC openssl↔WebCrypto round-trips (incl. 256 KB + macOS LibreSSL) and ECDH P-256 sealed-box round-trip + wrong-key rejection (node WebCrypto). Live real-browser verification (2026-06-01): terminal-encrypt→browser-decrypt, browser-compose→CLI-decrypt, and ask-me-a-secret reply sealed→inbox decrypt with the server holding ciphertext only. crypto/rand ids, rejection sampling (no modulo bias).","trl_ceiling":6,"trl_ceiling_reason":"Single-node, in-RAM, stateless relay by design — no persistence, no HA/clustering, no cross-checks. Deliberately minimal; further TRL would require features that contradict the ephemeral intent.","version":{"deployed_at":"2026-08-27T19:49:14Z","sha":"3137c13","version":"0.5.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-pixel","domain":"pixel.0exec.com","mesh":"0exec","host_port":18200,"category":"fleet_infra","title":"Fleet Pixel","summary":"1x1 transparent-GIF pageview beacon for the mesh-* static-Pages fleet","tags":["fleet-infra"],"openapi_url":"https://pixel.0exec.com/openapi.json","llms_url":"https://pixel.0exec.com/llms.txt","health_url":"https://pixel.0exec.com/health","version_url":"https://pixel.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-pixel","url":"https://pixel.0exec.com","example":"/pix.gif?app=mesh-test\u0026event=pv","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"NEW fleet primitive (2026-05-18). 1x1 transparent-GIF pageview beacon for the mesh-* static-Pages fleet. /selftest covers GIF roundtrip + DNT suppression + IP truncation. Optional Plausible self-host upstream.","trl_ceiling":6,"version":{"deployed_at":"2026-06-29T21:54:58Z","sha":"027a1c6","version":"0.4.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-poc-curl","domain":"fleet-poc-curl.0exec.com","mesh":"0exec","host_port":18158,"category":"infrastructure","title":"Fleet Poc Curl","summary":"redacted PoC curl emitter (bash -n parse-gated)","tags":["fleet-evidence","kind-container"],"openapi_url":"https://fleet-poc-curl.0exec.com/openapi.json","llms_url":"https://fleet-poc-curl.0exec.com/llms.txt","health_url":"https://fleet-poc-curl.0exec.com/health","version_url":"https://fleet-poc-curl.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-poc-curl","url":"https://fleet-poc-curl.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). redacted PoC curl emitter (bash -n parse-gated). /selftest + INTEGRATIONS.md shipped. ADR-0008. See services-registry/docs/adr/0008-fleet-poc-curl.md.","trl_ceiling":7,"version":{"deployed_at":"2026-08-27T14:58:12Z","sha":"a6cb8d2","version":"0.1.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-port","domain":"fleet-port.0exec.com","mesh":"0exec","host_port":18280,"category":"fleet_infra","title":"Fleet Port","summary":"Is a host:port reachable from the public internet? (SSRF-guarded check)","tags":["fleet-infra"],"openapi_url":"https://fleet-port.0exec.com/openapi.json","llms_url":"https://fleet-port.0exec.com/llms.txt","health_url":"https://fleet-port.0exec.com/health","version_url":"https://fleet-port.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-port","url":"https://fleet-port.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"First-pass audit: corrected the task's framing -- not a port-allocation registry (that logic lives entirely in services-registry, a separate system this service never touches), it's a stateless public SSRF-guarded TCP reachability prober. Confirmed the rate limiter's own locking is correct and race-free under 2000-goroutine stress testing. Found and fixed a real security bug: clientIP() (used to key the rate limiter) trusted the FIRST entry of a client-supplied X-Forwarded-For header instead of the trustworthy rightmost one appended by the fleet's own nginx gateway -- live-proved bypassing PORT_PROBES_PER_MIN entirely by rotating a fake leading IP per request on this public, unauthenticated, egress-dialing endpoint. Fixed to trust the rightmost hop. trl/trl_ceiling held at 7/8 -- core resolve-\u003eSSRF-guard-\u003edial-\u003eclassify path was already correct and race-free; the abuse-control gap is now closed with regression coverage. See PR #1 (merged).","trl_ceiling":8,"trl_ceiling_reason":"unauthenticated single-purpose probe with no HA/load evidence","version":{"deployed_at":"2026-08-08T08:50:59Z","sha":"ae5e85e","version":"0.3.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-preflight","domain":"fleet-preflight.0exec.com","mesh":"0exec","host_port":18142,"category":"infrastructure","title":"Fleet Preflight","summary":"Pre-deploy validation. POST /preflight {repo, secrets?} runs every required check in parallel: registry presence, DNS resolution, port collision, required secrets metadata. Returns 200 (all green) or 424 (any red) with detailed checklist. Read-only.","tags":["go-fleet"],"openapi_url":"https://fleet-preflight.0exec.com/openapi.json","llms_url":"https://fleet-preflight.0exec.com/llms.txt","health_url":"https://fleet-preflight.0exec.com/health","version_url":"https://fleet-preflight.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-preflight","url":"https://fleet-preflight.0exec.com","example":"/checks","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"check:image (crane HEAD ghcr.io), check:nginx (HTTPS+TLS expiry warn at 30d), 60s ETag-aware registry cache, /selftest against embedded service.yaml fixture with stubbed crane+DNS+HTTPS. 2026-09-04: second bounded Fleet Graph writer canary; source declares a dedicated finite vault credential and registry opt-in only observes preflight's own inbound calls.","trl_ceiling":8,"trl_ceiling_reason":"Each new check is one goroutine. Lift bound is breadth of checks.","version":{"deployed_at":"2026-09-09T05:17:05Z","sha":"36f6478","version":"0.3.6"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-priority-queue","domain":"fleet-priority-queue.0exec.com","mesh":"0exec","host_port":18169,"category":"fleet_infra","title":"Fleet Priority Queue","summary":"composite-scored findings priority ranker","tags":["kind-container"],"openapi_url":"https://fleet-priority-queue.0exec.com/openapi.json","llms_url":"https://fleet-priority-queue.0exec.com/llms.txt","health_url":"https://fleet-priority-queue.0exec.com/health","version_url":"https://fleet-priority-queue.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-priority-queue","url":"https://fleet-priority-queue.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). composite-scored findings priority ranker. /selftest + INTEGRATIONS.md shipped. ADR-0019. See services-registry/docs/adr/0019-fleet-priority-queue.md.","trl_ceiling":7,"version":{"deployed_at":"2026-08-27T15:02:21Z","sha":"120129b","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-prometheus","domain":"fleet-prometheus.0exec.com","mesh":"0exec","host_port":18203,"category":"observability","title":"Fleet Prometheus","summary":"Prometheus instance scraping each fleet container host_port/metrics via the fleet-discovery http_sd endpoint. Runs in host network mode, --web.listen-address=:18203.","openapi_url":"https://fleet-prometheus.0exec.com/openapi.json","llms_url":"https://fleet-prometheus.0exec.com/llms.txt","health_url":"https://fleet-prometheus.0exec.com/health","version_url":"https://fleet-prometheus.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-metrics-hub","url":"https://fleet-prometheus.0exec.com","example":"/-/healthy","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"First-pass audit of go-fleet-metrics-hub (see fleet-grafana/fleet-discovery entries for the shared repo-wide findings -- leaked API key removed, no unbounded-cardinality risk). Confirmed correct counter/gauge/histogram typing throughout the scrape/rule config, but fleet-alerts.yml claims 'promtool runs in CI on PR' and there is no CI in this repo at all -- that claim is stale, no automated config validation exists. trl bumped 4-\u003e5; trl_ceiling held at 8. See PR #3 (merged).","trl_ceiling":8,"reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"HTTP 401"},{"slug":"fleet-pwgen","domain":"fleet-pwgen.0exec.com","mesh":"0exec","host_port":18277,"category":"fleet_infra","title":"Fleet Pwgen","summary":"Stateless password and passphrase generator (crypto/rand) over curl","tags":["fleet-infra"],"openapi_url":"https://fleet-pwgen.0exec.com/openapi.json","llms_url":"https://fleet-pwgen.0exec.com/llms.txt","health_url":"https://fleet-pwgen.0exec.com/health","version_url":"https://fleet-pwgen.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-pwgen","url":"https://fleet-pwgen.0exec.com","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":8,"trl_evidence":"First-pass audit of this shared fleet-infra secure-password/token generator: the critical randomness check (highest priority for this class of service) came back clean -- exclusively crypto/rand, correct Lemire-style rejection sampling (not naive byte%poolSize), no shared-mutable-state races under go test -race. Found and fixed a real reliability bug: /selftest fetched a single 32-char draw and failed if it contained zero symbols -- with the default 74-char pool this has an intrinsic ~0.35% chance of a false failure purely by chance, confirmed empirically (75/20,000 draws), causing spurious 503s and failed pre-commit gates roughly 1 in 270 calls since this backs the deploy smoke gate. Fixed by sampling up to 8 independent draws before failing, dropping the false-failure rate to ~10^-20 while still catching a real regression with certainty. trl bumped 7-\u003e8, trl_ceiling bumped 7-\u003e8-\u003e9 -- nothing about this stateless crypto/rand-backed generator is structurally capped; the old ceiling (equal to trl) looked never re-examined rather than a genuine structural limit; the remaining step to 9 is field track record, not a structural block. See PR #1 (merged).","trl_ceiling":7,"trl_ceiling_reason":"unauthenticated stateless utility with no SLA/observability commitments","version":{"deployed_at":"2026-08-23T09:15:12Z","sha":"d4eb91d","version":"0.3.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-q","domain":"fleet-q.0exec.com","mesh":"0exec","host_port":18274,"category":"fleet_infra","title":"Fleet Q","summary":"Ephemeral in-RAM FIFO job queue over HTTP — a shell task-farm, no Redis","tags":["fleet-infra"],"openapi_url":"https://fleet-q.0exec.com/openapi.json","llms_url":"https://fleet-q.0exec.com/llms.txt","health_url":"https://fleet-q.0exec.com/health","version_url":"https://fleet-q.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-q","url":"https://fleet-q.0exec.com","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":8,"trl_evidence":"First-pass audit of this shared fleet-infra job/task queue (plain pop-and-remove FIFO, GET-is-the-ack by design, no auth by design -- both confirmed intentional, not bugs): confirmed no double-dequeue possible under go test -race and live 60-concurrent-GET stress testing (each of 30 items delivered exactly once). Found and fixed a real bug: no cap existed on the number of distinct queue names or total memory, and non-empty queues are never idle-reaped by design -- confirmed live (50 brand-new queue names all succeeded with no limit), and the ?wait=N long-poll read path could pre-create queue entries bypassing a naive queue-count cap. Fixed with a global queue-count cap and byte-budget limit that doesn't disrupt existing queues and closes the pre-creation bypass. trl bumped 7-\u003e8; trl_ceiling held at 8 -- reaching 9 would require a fundamentally different product (durable storage, at-least-once + lease/redrive, auth), explicitly out of scope for this component. See PR #1 (merged).","trl_ceiling":8,"trl_ceiling_reason":"in-RAM ephemeral with no durability or replication — a restart loses all queued work (by design), so it can't reach durable-system-of-record TRL-9","version":{"deployed_at":"2026-08-23T16:01:36Z","sha":"800ffd7","version":"0.4.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-read","domain":"fleet-read.0exec.com","mesh":"0exec","host_port":18283,"category":"fleet_infra","title":"Fleet Read","summary":"Reader-mode / readability — clean article text or markdown from a URL","tags":["fleet-infra"],"openapi_url":"https://fleet-read.0exec.com/openapi.json","llms_url":"https://fleet-read.0exec.com/llms.txt","health_url":"https://fleet-read.0exec.com/health","version_url":"https://fleet-read.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-read","url":"https://fleet-read.0exec.com","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":7,"trl_evidence":"First-pass audit of this shared fleet-infra Mozilla-Readability port (public, unauthenticated, SSRF-safe by design): confirmed genuinely differentiated from both go-fleet-md (text-in, never fetches a URL) and utils-readcontent (structured per-tag breakdown via cheerio, requires an API key) -- this is a single-clean-article extractor, different extraction model, different auth model, complementary not duplicate. Found and fixed 4 real bugs: (1) fetch-cache masking, contradicting the service's own 'every request is a fresh fetch' documentation; (2) complete markdown table-structure collapse (no \u003ctable\u003e case in the DOM walker, cells rendered as disconnected paragraphs) -- added a proper GFM pipe-table renderer; (3) silent-empty-200s -- go-readability's Parse never errors on no-content pages (JS-redirect shells), silently violating the documented 'no article -\u003e 422' contract, hit 16/153 successfully-fetched domains in the live sample, now correctly 422; (4) patched an open CVE (HTML-parser DoS) directly relevant since this public endpoint parses arbitrary attacker-directed HTML. trl/trl_ceiling held at 7/7 -- same structural JS-rendering limit as sibling utils-readcontent, directly evidenced by the JS-redirect-shell domains found live. See PR #1 (merged).","trl_ceiling":7,"trl_ceiling_reason":"single-instance stateless extractor, no JS rendering / paywall handling","version":{"deployed_at":"2026-08-25T22:45:16Z","sha":"49d0367","version":"0.4.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-resolver-quorum","domain":"fleet-resolver-quorum.0exec.com","mesh":"0exec","host_port":18155,"category":"fleet_infra","title":"Fleet Resolver Quorum","summary":"2-of-3 DNS resolver quorum","tags":["kind-container"],"openapi_url":"https://fleet-resolver-quorum.0exec.com/openapi.json","llms_url":"https://fleet-resolver-quorum.0exec.com/llms.txt","health_url":"https://fleet-resolver-quorum.0exec.com/health","version_url":"https://fleet-resolver-quorum.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-resolver-quorum","url":"https://fleet-resolver-quorum.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). 2-of-3 DNS resolver quorum. /selftest + INTEGRATIONS.md shipped. ADR-0005. See services-registry/docs/adr/0005-fleet-resolver-quorum.md.","trl_ceiling":8,"version":{"deployed_at":"2026-08-27T14:05:22Z","sha":"15ed394","version":"0.2.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-sandbox-targets","domain":"fleet-sandbox-targets.0exec.com","mesh":"0exec","host_port":18168,"category":"fleet_infra","title":"Fleet Sandbox Targets","summary":"internal-only sandbox vulnerable apps (10 endpoints)","tags":["kind-container"],"openapi_url":"https://fleet-sandbox-targets.0exec.com/openapi.json","llms_url":"https://fleet-sandbox-targets.0exec.com/llms.txt","health_url":"https://fleet-sandbox-targets.0exec.com/health","version_url":"https://fleet-sandbox-targets.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-sandbox-targets","url":"https://fleet-sandbox-targets.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). internal-only sandbox vulnerable apps (10 endpoints). /selftest + INTEGRATIONS.md shipped. ADR-0018. See services-registry/docs/adr/0018-fleet-sandbox-targets.md.","trl_ceiling":7,"version":{"deployed_at":"2026-06-29T21:59:38Z","sha":"237c135","version":"0.1.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-schema-validator","domain":"fleet-schema-validator.0exec.com","mesh":"0exec","host_port":18166,"category":"fleet_infra","title":"Fleet Schema Validator","summary":"JSON Schema catalog + validator (8 baseline schemas)","tags":["kind-container"],"openapi_url":"https://fleet-schema-validator.0exec.com/openapi.json","llms_url":"https://fleet-schema-validator.0exec.com/llms.txt","health_url":"https://fleet-schema-validator.0exec.com/health","version_url":"https://fleet-schema-validator.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-schema-validator","url":"https://fleet-schema-validator.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). JSON Schema catalog + validator (8 baseline schemas). /selftest + INTEGRATIONS.md shipped. ADR-0016. See services-registry/docs/adr/0016-fleet-schema-validator.md.","trl_ceiling":8,"version":{"deployed_at":"2026-08-07T12:30:19Z","sha":"c3b1a40","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-secrets","domain":"fleet-secrets.0exec.com","mesh":"0exec","host_port":18140,"category":"infrastructure","title":"Fleet Secrets","summary":"Encrypted secrets vault. Holds infrastructure tokens (Hetzner DNS, GitHub PAT, SMTP, platform API keys). NaCl secretbox at rest, per-secret nonce, scoped reads via gateway-injected X-Auth-User against consumers allowlist, separate X-Admin-Token for writes. Audit log per access.","tags":["go-fleet"],"openapi_url":"https://fleet-secrets.0exec.com/openapi.json","llms_url":"https://fleet-secrets.0exec.com/llms.txt","health_url":"https://fleet-secrets.0exec.com/health","version_url":"https://fleet-secrets.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-secrets","url":"https://fleet-secrets.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"audit_log with prefix-only redaction (no full tokens), consumer ACL test, rotate-returns-old-once, concurrent rotate (1 winner asserted), /selftest","trl_ceiling":8,"trl_ceiling_reason":"Single-node SQLite. Ceiling lifts to 8 once paired with sealed offsite master-key backup.","version":{"deployed_at":"2026-08-27T11:22:57Z","sha":"0a0648f","version":"0.3.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-selftest-aggregator","domain":"fleet-selftest-aggregator.0exec.com","mesh":"0exec","host_port":18165,"category":"fleet_infra","title":"Fleet Selftest Aggregator","summary":"/selftest poll-and-render aggregator","tags":["kind-container"],"openapi_url":"https://fleet-selftest-aggregator.0exec.com/openapi.json","llms_url":"https://fleet-selftest-aggregator.0exec.com/llms.txt","health_url":"https://fleet-selftest-aggregator.0exec.com/health","version_url":"https://fleet-selftest-aggregator.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-selftest-aggregator","url":"https://fleet-selftest-aggregator.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). /selftest poll-and-render aggregator. /selftest + INTEGRATIONS.md shipped. ADR-0015. See services-registry/docs/adr/0015-fleet-selftest-aggregator.md.","trl_ceiling":7,"version":{"deployed_at":"2026-09-02T16:44:46Z","sha":"f8ed669","version":"0.1.6"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-tail","domain":"fleet-tail.0exec.com","mesh":"0exec","host_port":18273,"category":"fleet_infra","title":"Fleet Tail","summary":"Ephemeral shared log streaming — tail -f across machines over curl, no SSH","tags":["fleet-infra"],"openapi_url":"https://fleet-tail.0exec.com/openapi.json","llms_url":"https://fleet-tail.0exec.com/llms.txt","health_url":"https://fleet-tail.0exec.com/health","version_url":"https://fleet-tail.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-tail","url":"https://fleet-tail.0exec.com","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":7,"trl_evidence":"First-pass audit of this shared fleet-infra log-tailing/streaming service: confirmed the streaming/backpressure design itself is sound (non-blocking fan-out, slow readers dropped without blocking the writer, no race, no unbounded-buffer bug). Found and fixed a severe bug: go-common's http.Server default timeouts (ReadTimeout=10s, WriteTimeout=30s) are single deadlines armed once at header-read time and never renewed by activity, and main.go never overrode them -- silently killing this service's entire advertised purpose. Live-reproduced both failure modes: a healthy actively-read GET /{stream} follow was severed at ~30s even with a perfectly healthy client, and a healthy streamed upload was truncated at ~10s WHILE THE SERVER STILL RETURNED 200 for only the partial data received -- silent data loss on exactly the CI/deploy-watch/tail -F recipes the README advertises. Fixed with configurable, much longer timeouts (default 24h, operator-tunable). trl/trl_ceiling held at 7/7 -- the ceiling's stated reason (in-RAM ephemeral relay, no durability/replication) is an unrelated, honest design tradeoff; this bug was a configuration defect masking the service's in-band advertised behavior, not evidence against the ceiling. See PR #1 (merged).","trl_ceiling":7,"trl_ceiling_reason":"in-RAM ephemeral relay — no durability, replication, or delivery guarantees by design; restart wipes all state","version":{"deployed_at":"2026-08-23T16:01:51Z","sha":"283ee2c","version":"0.4.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-target-reputation","domain":"fleet-target-reputation.0exec.com","mesh":"0exec","host_port":18171,"category":"fleet_infra","title":"Fleet Target Reputation","summary":"target reputation lookup (5 sources)","tags":["kind-container"],"openapi_url":"https://fleet-target-reputation.0exec.com/openapi.json","llms_url":"https://fleet-target-reputation.0exec.com/llms.txt","health_url":"https://fleet-target-reputation.0exec.com/health","version_url":"https://fleet-target-reputation.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-target-reputation","url":"https://fleet-target-reputation.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). target reputation lookup (5 sources). /selftest + INTEGRATIONS.md shipped. ADR-0021. See services-registry/docs/adr/0021-fleet-target-reputation.md.","trl_ceiling":7,"version":{"deployed_at":"2026-08-25T23:07:11Z","sha":"31e781b","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-tech-inferrer","domain":"fleet-tech-inferrer.0exec.com","mesh":"0exec","host_port":18159,"category":"fleet_infra","title":"Fleet Tech Inferrer","summary":"composite tech-stack inferrer (83 signals)","tags":["kind-container"],"openapi_url":"https://fleet-tech-inferrer.0exec.com/openapi.json","llms_url":"https://fleet-tech-inferrer.0exec.com/llms.txt","health_url":"https://fleet-tech-inferrer.0exec.com/health","version_url":"https://fleet-tech-inferrer.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-tech-inferrer","url":"https://fleet-tech-inferrer.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). composite tech-stack inferrer (83 signals). /selftest + INTEGRATIONS.md shipped. ADR-0009. See services-registry/docs/adr/0009-fleet-tech-inferrer.md.","trl_ceiling":7,"version":{"deployed_at":"2026-08-27T15:02:07Z","sha":"8b15dc2","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-token-ledger","domain":"fleet-token-ledger.0exec.com","mesh":"0exec","host_port":18314,"category":"infrastructure","title":"Fleet Token Ledger","summary":"Prepaid token balances for fleet callers, keyed on the existing keystore identity. POST /v1/charge deducts tokens and returns 402 with an x402-shaped body when balance is insufficient (ADR-0033).","openapi_url":"https://fleet-token-ledger.0exec.com/openapi.json","llms_url":"https://fleet-token-ledger.0exec.com/llms.txt","health_url":"https://fleet-token-ledger.0exec.com/health","version_url":"https://fleet-token-ledger.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-token-ledger","url":"https://fleet-token-ledger.0exec.com","example":"/v1/balance","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":4,"trl_evidence":"First ship. Atomic charge/credit + audit trail with unit test coverage (11 tests, storage + handler layers). Zero fleet services call /v1/charge yet; /v1/topup is admin-only by design -- no real payment rail (Stripe/x402) wired in this phase.","version":{"deployed_at":"2026-08-23T16:24:32Z","sha":"7f8c6be","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-vendor-disclosure-tracker","domain":"fleet-vendor-disclosure-tracker.0exec.com","mesh":"0exec","host_port":18167,"category":"fleet_infra","title":"Fleet Vendor Disclosure Tracker","summary":"vendor disclosure history tracker (PII-redacted)","tags":["kind-container"],"openapi_url":"https://fleet-vendor-disclosure-tracker.0exec.com/openapi.json","llms_url":"https://fleet-vendor-disclosure-tracker.0exec.com/llms.txt","health_url":"https://fleet-vendor-disclosure-tracker.0exec.com/health","version_url":"https://fleet-vendor-disclosure-tracker.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-vendor-disclosure-tracker","url":"https://fleet-vendor-disclosure-tracker.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). vendor disclosure history tracker (PII-redacted). /selftest + INTEGRATIONS.md shipped. ADR-0017. See services-registry/docs/adr/0017-fleet-vendor-disclosure-tracker.md.","trl_ceiling":7,"version":{"deployed_at":"2026-08-27T15:04:05Z","sha":"b0c71e5","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-visualizer","domain":"fleet-visualizer.0exec.com","mesh":"0exec","host_port":18144,"category":"visualization","title":"Fleet Visualizer","summary":"Fleet graph visualizer. Operator surface (keystore-auth) renders a force-directed live topology with click-to-drill, mesh filter, time-window selector, and a drift dialog comparing declared-vs-observed edges. Public surface at /public shows sanitised (caller -\u003e target) counts only — no latencies, no internal hosts. Frontend uses vis-network from CDN, vanilla JS, no build step.","openapi_url":"https://fleet-visualizer.0exec.com/openapi.json","llms_url":"https://fleet-visualizer.0exec.com/llms.txt","health_url":"https://fleet-visualizer.0exec.com/health","version_url":"https://fleet-visualizer.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-visualizer","url":"https://fleet-visualizer.0exec.com","example":"/public","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Second-pass re-audit of this fleet topology/TRL-heatmap dashboard: found and fixed 3 real bugs. (1) A data race in the ETag registry cache -- the 304 branch mutated a shared cache entry's fields in place while a concurrent Fetch call read those same fields unlocked, confirmed with go test -race; directly relevant since /dashboard, /graph.dot, and /trl-heatmap all hit the same cached URL concurrently. Fixed by making cache entries immutable-once-published. (2) A client-side XSS gap -- the operator dashboard built rows via innerHTML template-literal interpolation of collector-reported strings with zero escaping, unlike the SSR heatmap which correctly uses html.EscapeString; rewrote all sinks to use textContent/createElement and scheme-checked lookup URLs. (3) A malformed optional slice (services.depends.json) broke the entire read surface with a 502, despite the code's own comment claiming this case was tolerated -- the tolerance only covered fetch errors, not JSON decode errors; reproduced live, now returns 200. Confirmed /selftest is correctly wired (unlike sibling go-fleet-graph's dead-code bug) and no leaked secrets exist (unlike sibling go-fleet-metrics-hub). trl/trl_ceiling held at 7/7 -- the ceiling's stated rationale (no collector-failure circuit breaking/snapshot persistence) is unrelated to these bugs and still holds; all three are now fixed with regression tests. See PR #3 (merged).","trl_ceiling":7,"trl_ceiling_reason":"Vis-network handles ~500 nodes comfortably. Lifts to 7 with server-side layout caching + WebGL-backed renderer for \u003e500-node fleets.","version":{"deployed_at":"2026-08-27T15:04:05Z","sha":"24caf18","version":"0.2.6"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-webhook","domain":"fleet-webhook.0exec.com","mesh":"0exec","host_port":18276,"category":"fleet_infra","title":"Fleet Webhook","summary":"Ephemeral request bin — capture and watch webhooks live from the terminal","tags":["fleet-infra"],"openapi_url":"https://fleet-webhook.0exec.com/openapi.json","llms_url":"https://fleet-webhook.0exec.com/llms.txt","health_url":"https://fleet-webhook.0exec.com/health","version_url":"https://fleet-webhook.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-webhook","url":"https://fleet-webhook.0exec.com","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":7,"trl_evidence":"First-pass audit: corrected the task's framing -- not outbound webhook dispatch, it's an inbound ephemeral request-bin/capture service (like requestbin/webhook.site), never dials out. Confirmed sound locking (mutex-guarded Store/RateLimiter, non-blocking sends to slow watchers) under live adversarial testing (oversized payload correctly truncated at the 1MiB cap, malformed/traversal bin-id paths correctly 404, 50 concurrent captures all recorded with no drops). Found and fixed the SAME X-Forwarded-For spoofing bug found in go-fleet-port and go-fleet-notify this batch (the third instance) -- the rate limiter trusted the leftmost client-controlled header, defeating the only abuse control on this public unauthenticated endpoint and letting a caller flood WEBHOOK_MAX_BINS. Fixed with the same trust-boundary pattern (only honor forwarded headers when the immediate TCP peer is provably the fleet's own reverse-proxy). trl/trl_ceiling held at 7/7 -- small, well-bounded, in-memory, no persistence, no outbound calls; no deeper architectural ceiling exists for its scope. See PR #1 (merged).","trl_ceiling":7,"trl_ceiling_reason":"ephemeral in-RAM bins, no durability — restart or idle-TTL wipes all captures, so it can't reach 8-9 production-data-integrity tiers","version":{"deployed_at":"2026-08-23T16:03:53Z","sha":"88e6e46","version":"0.3.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fleet-webhook-verifier","domain":"fleet-webhook-verifier.0exec.com","mesh":"0exec","host_port":18170,"category":"fleet_infra","title":"Fleet Webhook Verifier","summary":"inbound webhook signature verifier (6 platforms)","tags":["kind-container"],"openapi_url":"https://fleet-webhook-verifier.0exec.com/openapi.json","llms_url":"https://fleet-webhook-verifier.0exec.com/llms.txt","health_url":"https://fleet-webhook-verifier.0exec.com/health","version_url":"https://fleet-webhook-verifier.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-fleet-webhook-verifier","url":"https://fleet-webhook-verifier.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"NEW fleet primitive (batch 4, 2026-05-16). inbound webhook signature verifier (6 platforms). /selftest + INTEGRATIONS.md shipped. ADR-0020. See services-registry/docs/adr/0020-fleet-webhook-verifier.md.","trl_ceiling":8,"version":{"deployed_at":"2026-08-27T15:05:45Z","sha":"1c837ea","version":"0.2.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"geo-geocode","domain":"geo-geocode.0exec.com","mesh":"0exec","host_port":18008,"category":"geo","title":"Geocode (TomTom)","summary":"Free-text address → lat/lon via TomTom.","tags":["geo","geo","geocoding"],"openapi_url":"https://geo-geocode.0exec.com/openapi.json","llms_url":"https://geo-geocode.0exec.com/llms.txt","health_url":"https://geo-geocode.0exec.com/health","version_url":"https://geo-geocode.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/geo-geocode","url":"https://geo-geocode.0exec.com","example":"/?text=Bucharest","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":4,"trl_evidence":"First-pass audit (Node/TS Express, multi-provider free-text geocoder wrapping 7 providers, confirmed not a duplicate of either geo sibling -- db-geo-geocode caches this exact service, geo-places is unrelated static reference data). Found a severe bug currently live in production: roughly 1 in 7 real requests (random provider selection) could crash the ENTIRE service -- a dead Bing Maps API key (403 DeniedCredentials) triggers an uncaught exception from inside a bluebird callback outside the app's own try/catch, and Winston's default exitOnError:true then kills the whole process; live-reproduced reliably 502ing everything including /health for several seconds until Docker's restart policy revived it. Fixed with a careful process-level exception handler (the 'obvious' fix via winston's own exceptionHandlers+exitOnError:false turned out to have its own bug -- survives exactly one crash then dies on the second -- so routed through the already-battle-tested logger.error() call instead). Also found (flagged, not fixed -- needs credential/ops decisions): 2 of 7 providers permanently dead (wrong API key type or expired), and unrelated hardcoded live Webshare proxy credentials plus YouTube API keys sitting in plaintext source as copy-paste debris. Added the repo's first test coverage. trl held at 4 -- 2/7 providers permanently broken, no accuracy test coverage, docs (force=) don't match actual behavior; trl_ceiling=7 added -- structurally can't reach SLA-grade without provider health-checking/cross-provider consensus. See PR #1 (merged).","version":{"deployed_at":"2026-05-28T21:03:16Z","sha":"d53c1c7","version":"0.1.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"geo-places","domain":"geo-places.0exec.com","mesh":"0exec","host_port":18010,"category":"geo","title":"GeoJSON Places API","summary":"Continents, countries, regions, states with GeoJSON geometries.","tags":["geo","geo","geojson","places"],"openapi_url":"https://geo-places.0exec.com/openapi.json","llms_url":"https://geo-places.0exec.com/llms.txt","health_url":"https://geo-places.0exec.com/health","version_url":"https://geo-places.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/geo-places","url":"https://geo-places.0exec.com","example":"/?query=coffee+Bucharest","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (Fastify service over the static geojson-places dataset for administrative-region search/reverse-geocode, confirmed genuinely non-overlapping with both geocode siblings -- opposite direction, no external network call at request time so fetch-cache masking doesn't apply). Found a real bug currently live in production: GET /health actually resolves to /health/health due to a fastify-autoload route-registration mismatch, so Docker's own HEALTHCHECK and the fleet catalog's health_url are both 404ing right now despite the app working fine -- a prior changelog entry claimed to have already fixed this but registered the route at the wrong path. Fixed by registering at / like every other route file. Also fixed a limit\u003c=0 validation gap that silently broke the result cap (100 matches leaking through with no error), and found the service's own smoke-test config has never actually matched the real API (GET /?query= vs the real GET /search?q=). trl held at 6; trl_ceiling=7 added -- entire dataset is a frozen snapshot of a pinned npm package with no freshness/drift-detection pipeline, geometries are simplified so border-adjacent reverse-geocode is inherently approximate, permanently scoped to administrative units only by design. See PR #2 (merged).","version":{"build_date":"2026-04-28T10:13:47Z","commit":"dc81efb","service":"geo-places","version":"dc81efb"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"go-session-fixation","domain":"go-session-fixation.0exec.com","mesh":"0exec","host_port":18031,"category":"security","title":"Go Session Fixation","summary":"Two-pass probe testing whether session cookies persist value across login. Cookie-name gazetteer covers PHPSESSID/JSESSIONID/ASP.NET_SessionId/etc.","tags":["go","pentest","security"],"openapi_url":"https://go-session-fixation.0exec.com/openapi.json","llms_url":"https://go-session-fixation.0exec.com/llms.txt","health_url":"https://go-session-fixation.0exec.com/health","version_url":"https://go-session-fixation.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_session_fixation","url":"https://go-session-fixation.0exec.com","example":"/go_session_fixation?target=https://github.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Two-pass probe with cookie-name gazetteer (PHPSESSID/JSESSIONID/etc), classic-flow login pages. 5 tests pass.","trl_ceiling":7,"trl_ceiling_reason":"SPA login flows (JSON POST with custom headers) not yet detected; CSRF-protected logins are misclassified.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://go-session-fixation.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"hermes-agent-tunnel-18318","domain":"dockerhost:18318","mesh":"0exec","host_port":18318,"category":"infrastructure","title":"hermes-agent tunnel :18318","summary":"hermes-agent SSH reverse tunnel — user `tunnel`, key `hermes-agent@hermes-agent`, forwarding 127.0.0.1:18318-18320 on the dockerhost (up since 2026-09-08). Not a fleet container and not managed by fleet-runner.","tags":["external","non-fleet","ssh-tunnel"],"openapi_url":"http://dockerhost:18318/openapi.json","llms_url":"http://dockerhost:18318/llms.txt","health_url":"http://dockerhost:18318/health","version_url":"http://dockerhost:18318/.deploy/version.json","repo_url":"https://hermes.lv3.org","url":"http://dockerhost:18318","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"HTTP 400"},{"slug":"hermes-agent-tunnel-18319","domain":"dockerhost:18319","mesh":"0exec","host_port":18319,"category":"infrastructure","title":"hermes-agent tunnel :18319","summary":"hermes-agent SSH reverse tunnel — see hermes-agent-tunnel-18318.","tags":["external","non-fleet","ssh-tunnel"],"openapi_url":"http://dockerhost:18319/openapi.json","llms_url":"http://dockerhost:18319/llms.txt","health_url":"http://dockerhost:18319/health","version_url":"http://dockerhost:18319/.deploy/version.json","repo_url":"https://hermes.lv3.org","url":"http://dockerhost:18319","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"HTTP 400"},{"slug":"hermes-agent-tunnel-18320","domain":"dockerhost:18320","mesh":"0exec","host_port":18320,"category":"infrastructure","title":"hermes-agent tunnel :18320","summary":"hermes-agent SSH reverse tunnel — see hermes-agent-tunnel-18318. This is the port that collided with fleet-cert-watch.","tags":["external","non-fleet","ssh-tunnel"],"openapi_url":"http://dockerhost:18320/openapi.json","llms_url":"http://dockerhost:18320/llms.txt","health_url":"http://dockerhost:18320/health","version_url":"http://dockerhost:18320/.deploy/version.json","repo_url":"https://hermes.lv3.org","url":"http://dockerhost:18320","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"HTTP 400"},{"slug":"html-proxy","domain":"html-proxy.0exec.com","mesh":"0exec","host_port":3002,"category":"proxy","title":"Html Proxy","summary":"Microservice for Go Html Proxy","tags":["go","proxy"],"openapi_url":"https://html-proxy.0exec.com/openapi.json","llms_url":"https://html-proxy.0exec.com/llms.txt","health_url":"https://html-proxy.0exec.com/health","version_url":"https://html-proxy.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-html-proxy","url":"https://html-proxy.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit: the repo contains two implementations -- a small unused root-module library using the correct safehttp client, and the ACTUALLY DEPLOYED src/ hexagonal service which hand-rolled its own SSRF/dial/cache stack. Found and fixed a critical bug in the deployed service: an SSRF-checking dialer was built but then unconditionally overridden by a plain DNS-caching dialer with zero SSRF check -- the default client profile never had transport-layer SSRF protection at all. Live-proved: pre-fix, the real factory-built client successfully dialed 127.0.0.1:1. Confirmed real fleet-wide reach -- several domain-analysis services (gdpr-compliance, broken-links, payment-detector, etc) route through this proxy as a fallback tier. Fixed by wiring the checker into the actual dial path for both client profiles, closing SSRF-via-redirect and DNS-rebind gaps too. Also fixed the recurring fetch-cache-masking bug (CacheMiddleware ignored Cache-Control entirely) and an unbounded response-body read for chunked responses (Content-Length -1 fell through to unbounded io.ReadAll). Flagged, not fixed: a credit/auth-bypass path trusts a client-supplied X-Real-IP header, safe only if the gateway always overwrites it -- needs deploy-topology context. trl held at 6; trl_ceiling=7 added, held back specifically because this security control passed its own unit test while the real wiring silently discarded it -- should be integration-verified before trusting above 7. See PR #11 (merged), plus 3 pre-existing stale PRs (#1/#2 dependency bumps, #7 a real headless-Chrome pool leak fix from 2026-06) now CONFLICTING against this fix and left for manual follow-up.","version":{"deployed_at":"2026-08-19T17:15:08Z","sha":"245e880","version":"0.5.6"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"infrastructure-fetch-cache","domain":"infrastructure-fetch-cache.0exec.com","mesh":"0exec","host_port":18205,"category":"infrastructure","title":"Fleet Fetch Cache","summary":"Fleet-wide HTTP fetch cache: producers share one upstream fetch per URL instead of each hitting origin. Redis-backed, zstd-compressed, singleflight-deduped. 60s default TTL, falls back to direct fetch when Redis is unreachable.","openapi_url":"https://infrastructure-fetch-cache.0exec.com/openapi.json","llms_url":"https://infrastructure-fetch-cache.0exec.com/llms.txt","health_url":"https://infrastructure-fetch-cache.0exec.com/health","version_url":"https://infrastructure-fetch-cache.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_infrastructure_fetch_cache","url":"https://infrastructure-fetch-cache.0exec.com","example":"/fetch?url=https://example.com/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"Real-data audit (2026-07-06 live-traffic investigation, previously unsynced to registry despite a merged fix): live traffic (~330-480 req/s aggregate) showed the shared Webshare rotating egress proxy intermittently dropping/refusing connections or failing CONNECT independent of target-origin health -- roughly half of all /fetch requests were failing 502/504 in a 30-min window. render=default (the path most of the ~220-service fleet uses via fleetfetch) was a single-hop chain with no fallback/retry, and because it runs inside a singleflight group, one bad proxy draw failed every fleet caller waiting on that URL at once -- this explains the batches-of-failures-then-batches-of-success symptom reported against sibling service go_cdn_detector. Fixed: directRenderer.Render now retries up to 3 attempts (150ms backoff) on transient transport errors, skipping SSRF/validation errors a retry can't fix; a retry on a rotate-mode proxy gets a fresh exit IP, which meaningfully improves odds of success. Bumped 0.3.13-\u003e0.3.14. trl bumped 4-\u003e5; trl_ceiling=7 -- the fix addresses the amplification/no-retry gap at the shared cache layer, but the underlying Webshare account may have a hard concurrency/RPS cap that no in-process retry can fully compensate for; needs a post-deploy live-traffic check to confirm the 502/504 rate actually dropped. See github.com/baditaflorin/go_infrastructure_fetch_cache PR #18 (merged).","version":{"deployed_at":"2026-09-10T07:24:14Z","sha":"473402d","version":"0.3.20"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"js-proxy","domain":"js-proxy.0exec.com","mesh":"0exec","host_port":18006,"category":"proxy","title":"Go Headless-Chrome Proxy","summary":"Renders the target page in headless Chromium and returns the post-JS HTML.","tags":["go","proxy","proxy","http","headless","javascript"],"openapi_url":"https://js-proxy.0exec.com/openapi.json","llms_url":"https://js-proxy.0exec.com/llms.txt","health_url":"https://js-proxy.0exec.com/health","version_url":"https://js-proxy.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-js-proxy","url":"https://js-proxy.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"First-pass safety audit of this fleet-wide JS-rendering proxy: found and fixed the most severe security gap of this session -- zero SSRF protection on a caller-supplied ?url= that gets full headless-Chrome navigation with JS execution and cookies (no scheme check, no block on private/loopback/link-local/CGNAT/cloud-metadata hosts). Worse than a typical SSRF gap since the target is fully rendered, not just fetched. The fleet already has the canonical fix (safehttp.CheckURL, already used by sibling go-html-proxy) -- this service simply never adopted it. Fixed by gating both the direct and Chrome engines before dispatch; one honest residual gap documented (Chrome does its own DNS resolution outside the guarded dialer, so a DNS-rebind between check and navigation isn't fully closed -- flagged as follow-up). Separately confirmed no resource-leak/crash-loop bug in this service specifically via a real (non-stubbed) Chrome instance stress test -- hung pages/redirect loops/resource-heavy pages all tear down cleanly, Chrome process count stable. No data races under go test -race; two concurrent tabs confirmed isolated (separate CDP realms). trl held at 7; trl_ceiling=7 added -- otherwise well-engineered (solid pool/tab management, good test coverage) but a JS-execution proxy that had zero SSRF protection until this fix caps how much higher it can honestly go before production burn-in and closing the DNS-rebind gap. See PR #4 (merged).","version":{"deployed_at":"2026-08-27T08:55:19Z","sha":"23ce6ba","version":"0.8.12"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"js-proxy-network","domain":"js-proxy-network.0exec.com","mesh":"0exec","host_port":18024,"category":"proxy","title":"Js Proxy Network","summary":"JS-render proxy returning rendered DOM plus full network log (every request fired, response headers, sizes, timing) + console + performance.","tags":["go","proxy","render"],"openapi_url":"https://js-proxy-network.0exec.com/openapi.json","llms_url":"https://js-proxy-network.0exec.com/llms.txt","health_url":"https://js-proxy-network.0exec.com/health","version_url":"https://js-proxy-network.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-js-proxy-network","url":"https://js-proxy-network.0exec.com","example":"/?url=https://example.com","auth":{"query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"2026-08-20: code audit found handleProxy validates the top-level ?url= target exactly once via safehttp.CheckURL, then hands it to a separate headless Chromium process (chromedp.Navigate) for the actual navigation, every redirect, and every sub-resource fetch the rendered page issues -- none of which pass through safehttp's own GuardedDialer/Dialer.Control re-check, which is what safehttp.CheckURL's own doc comment says is required to be safe against DNS rebinding for a non-safehttp-dialer connect path. Confirmed exploitable: an attacker's domain can resolve to a public IP when GuardHost first checks it, then rebind its DNS record to a private/link-local address (e.g. the cloud metadata IP 169.254.169.254) by the time Chromium actually connects moments later -- this service would then render and return that internal response to the caller as if it were the public page, for the top-level navigation and any redirect/sub-resource the page issues. Fixed by enabling the CDP Fetch domain (Request stage) and re-validating every intercepted request's host against safehttp.GuardHost/IsDomainDenied immediately before it proceeds (main_fetch_guard.go); respects the existing ALLOW_INTERNAL debug bypass. Added regression tests TestFetchTargetBlocked_ClosesDNSRebindGap/_DomainDenylist/_NonNetworkSchemesPassThrough (verified fail against the pre-fix code path, pass after); version bumped 0.6.5-\u003e0.6.6. Also checked and confirmed absent: the separate fleet-wide fetch-cache bug class (safehttp.NewClient()/fleetfetch.NewHTTPClient() built without .WithoutFetchCache()/.WithoutCache()) does not apply here -- this service never creates a Go http.Client for outbound fetches; all rendering goes through a real headless Chromium process, so go-common@v0.88.0's auto-installed DefaultFetchDelegate has nothing to attach to in this codebase. Fix is in open PR https://github.com/baditaflorin/go-js-proxy-network/pull/11 (unmerged as of this evidence) -- lowering TRL 7 -\u003e 6 pending merge/deploy, since the prior 'safehttp SSRF guard verified live (blocks 127/10/169.254.169.254)' claim covered only the single top-level-target check and did not hold against the actual render pipeline, where chromedp handles every redirect and sub-resource outside safehttp's own dialer.","version":{"deployed_at":"2026-09-10T17:01:27Z","sha":"4e63b51","version":"0.6.15"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"jsbundle-routes","domain":"jsbundle-routes.0exec.com","mesh":"0exec","host_port":18026,"category":"security","title":"Jsbundle Routes","summary":"Extracts React Router / Vue Router / Next.js / Express route configs from recovered JS bundles. Surfaces unlinked admin/internal routes.","tags":["go","pentest","security"],"openapi_url":"https://jsbundle-routes.0exec.com/openapi.json","llms_url":"https://jsbundle-routes.0exec.com/llms.txt","health_url":"https://jsbundle-routes.0exec.com/health","version_url":"https://jsbundle-routes.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_jsbundle_route_extractor","url":"https://jsbundle-routes.0exec.com","example":"/go_jsbundle_route_extractor?target=https://stripe.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"AST-like pattern match on recovered bundles for React/Vue/Next/Express routes. Surfaces unlinked admin/internal routes. 7 tests pass.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://jsbundle-routes.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"jsbundle-secrets","domain":"jsbundle-secrets.0exec.com","mesh":"0exec","host_port":18025,"category":"security","title":"Jsbundle Secrets","summary":"Recovers original source from JS bundles via sourcemaps, then scans with gitleaks-grade rules for secrets that vanish from minified output.","tags":["go","pentest","security"],"openapi_url":"https://jsbundle-secrets.0exec.com/openapi.json","llms_url":"https://jsbundle-secrets.0exec.com/llms.txt","health_url":"https://jsbundle-secrets.0exec.com/health","version_url":"https://jsbundle-secrets.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_jsbundle_secrets","url":"https://jsbundle-secrets.0exec.com","example":"/go_jsbundle_secrets?target=https://stripe.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Sourcemap recovery via go-common/jsbundle, embedded gitleaks-grade ruleset on recovered original source. 9 tests pass.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://jsbundle-secrets.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"jwt-pentest","domain":"jwt-pentest.0exec.com","mesh":"0exec","host_port":18029,"category":"security","title":"Jwt Pentest","summary":"Active JWT vulnerability battery: alg=none, weak-HMAC dictionary, kid traversal, jku/x5u SSRF, audience leakage, HS256↔RS256 confusion.","tags":["go","pentest","security"],"openapi_url":"https://jwt-pentest.0exec.com/openapi.json","llms_url":"https://jwt-pentest.0exec.com/llms.txt","health_url":"https://jwt-pentest.0exec.com/health","version_url":"https://jwt-pentest.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_jwt_pentest","url":"https://jwt-pentest.0exec.com","example":"/go_jwt_pentest?jwt=eyJhbGciOiJub25lIn0.eyJzdWIiOiJ0ZXN0In0.","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"alg=none, weak-HMAC dictionary, kid traversal, jku/x5u, audience leakage, HS256↔RS256 confusion. Offline path complete. 10 tests pass.","trl_ceiling":7,"trl_ceiling_reason":"Token-harvest path missing; caller must supply ?jwt=. Reaches TRL 7 with active replay against target's auth endpoint.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://jwt-pentest.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"linkedin-attributes","domain":"linkedin-attributes.0exec.com","mesh":"0exec","host_port":18017,"category":"content","title":"LinkedIn Profile Attributes","summary":"Extract structured fields from a LinkedIn profile page.","tags":["content","nlp","scraping","social"],"openapi_url":"https://linkedin-attributes.0exec.com/openapi.json","llms_url":"https://linkedin-attributes.0exec.com/llms.txt","health_url":"https://linkedin-attributes.0exec.com/health","version_url":"https://linkedin-attributes.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/linkedin-attributes","url":"https://linkedin-attributes.0exec.com","example":"/?url=https://www.linkedin.com/in/baditaflorin","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"A pre-existing open PR (#2, from an earlier session) already fixed the real bugs found by a full empirical audit: URL-scheme parsing gaps, dead proxy wiring with hardcoded creds, 503-vs-404 masking, and a broken test runner. This pass independently re-verified every claim with a fresh, disjoint 250-row sample (person-URL acceptance 91/96-\u003e95/96 confirmed) and fresh live HTTP testing rather than duplicating the work, then recommended merging it. Also confirmed fetch-cache-masking doesn't apply (pure Node/TypeScript, zero go-common dependency) and found a genuine architectural ceiling: LinkedIn's public badge only covers personal profiles -- 62% of real LinkedIn links tied to production domains are company/showcase pages that get rejected outright. trl bumped 4-\u003e6 now that PR #2 is merged; trl_ceiling=6, capped by LinkedIn's own anti-automation posture (reproduced live) and the person-only structural scope limit. See PR #2 (merged).","version":{"deployed_at":"2026-05-28T20:56:28Z","sha":"58e91b9","version":"0.1.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"nlp-extractinfo","domain":"nlp-extractinfo.0exec.com","mesh":"0exec","host_port":18011,"category":"nlp","title":"NLP Info Extractor (compromise)","summary":"Extract people, places, dates, organizations from text using compromise.js.","tags":["nlp","nlp"],"openapi_url":"https://nlp-extractinfo.0exec.com/openapi.json","llms_url":"https://nlp-extractinfo.0exec.com/llms.txt","health_url":"https://nlp-extractinfo.0exec.com/health","version_url":"https://nlp-extractinfo.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/nlp-extractinfo","url":"https://nlp-extractinfo.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (Node/TS Express + compromise.js, confirmed not Go so fetch-cache masking does not apply). Found and fixed 2 severe bugs on live production pages: (1) an OOM crash -- createCooccurrenceMatrix stored the entire unstripped-HTML source sentence uncapped as a graph edge attribute; a 271KB fetched page produced a 122MB response and crashed the Node process twice with a fatal allocation failure during testing; fixed by capping the stored snippet at 300 chars, dropping response size 67-100x with zero crashes across a 260-domain re-run. (2) The service's own flagship documented default usage (?text= alone, per README/llms.txt/openapi.json) returned a hard 400 in production -- one missing .optional() call; fixed. Also hardened the previously-unbounded ?url= outbound fetch with a timeout+size cap. Flagged, not fixed: no SSRF guard on ?url=, raw HTML never stripped before NLP tokenization, and hardcoded YouTube/proxy credentials sitting in dead never-imported code (the same pattern found repeatedly this session). Added the repo's first test coverage. trl held at 6; trl_ceiling=7 added -- compromise.js is a rule-based English-only tagger with no semantic disambiguation, reaching higher needs a different NLP engine. See PR #1 (merged).","version":{"deployed_at":"2026-08-27T22:51:44Z","sha":"c144b82","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"node-js-proxy","domain":"node-js-proxy.0exec.com","mesh":"0exec","host_port":18007,"category":"proxy","title":"Node Playwright Proxy","summary":"Playwright-driven Chromium that returns post-render HTML.","tags":["node","proxy","proxy","headless","javascript","playwright"],"openapi_url":"https://node-js-proxy.0exec.com/openapi.json","llms_url":"https://node-js-proxy.0exec.com/llms.txt","health_url":"https://node-js-proxy.0exec.com/health","version_url":"https://node-js-proxy.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/node-js-proxy","url":"https://node-js-proxy.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (TypeScript/Express/Playwright, confirmed genuine parallel implementation to go-js-proxy, not a duplicate -- forces every render through the fleet's residential Webshare proxy pool, a real functional difference against anti-bot IP blocking). Found and fixed 4 real bugs, all live-reproduced: (1) SSRF/LFI -- file:///etc/passwd was handed straight to page.goto() and its contents served back; private/internal IPs were only accidentally blocked by the residential proxy's CONNECT refusal, not a guard this service owned; fixed with real scheme/address validation. (2) Hardcoded, leaked Webshare proxy credentials and Google API keys committed to source (ignoring the env vars docker-compose already wires up) and logged in plaintext at startup -- these need rotating at Webshare/Google independent of this fix, still in git history. (3) A concurrency-slot lifetime bug reproduced as a full process crash -- the semaphore slot released on client-timeout instead of on real browser-context close, reintroducing exactly the resource-exhaustion class behind a documented 2026-05-29 fork-bomb incident; fixed by holding the slot for the render's real lifetime. (4) 9 known-vulnerable dependencies including a lodash pin the npm registry itself flags 'Bad release' -- npm audit now reports 0 vulnerabilities. trl bumped 4-\u003e6; trl_ceiling=7 added -- SSRF guard is pre-flight-only (not DNS-rebinding-proof), no response-size cap, legacy dead code remains. See PR #2 (merged).","version":{"deployed_at":"2026-08-27T22:48:26Z","sha":"4efc1c8","version":"0.1.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"node-proxy","domain":"node-proxy.0exec.com","mesh":"0exec","host_port":18004,"category":"proxy","title":"Node HTTP Proxy","summary":"Express+axios forward proxy. Multi-worker via Node cluster.","tags":["node","proxy","proxy","http"],"openapi_url":"https://node-proxy.0exec.com/openapi.json","llms_url":"https://node-proxy.0exec.com/llms.txt","health_url":"https://node-proxy.0exec.com/health","version_url":"https://node-proxy.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/node-proxy","url":"https://node-proxy.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"First-pass audit (plain Express+axios GET-only forward proxy, Node-clustered, mandatory Webshare egress). Found and fixed 3 real bugs: (1) an oversized-response memory blow-up masked as a fake 200 OK -- no maxContentLength/maxBodyLength on the axios call; a 2GB test response spiked worker RSS to ~3GB, and past V8's string-conversion limit axios's internal error still carried status=200, disguising a real failure as success; fixed with a 50MB cap. (2) NODE_ENV=test never started the server at all (cluster.isMaster defaults true when setupCluster() is skipped) -- likely why there was never a test suite; fixed. (3) error-handling data loss on 2xx/3xx branches. npm audit: 10 advisories (2 high) -\u003e 0, plus removed an entirely-unused vulnerable dependency. Honestly documented (not silently fixed) a real SSRF gap: no host/IP allowlist exists in-app, safety is entirely delegated to the mandatory external egress-proxy topology -- flagged as deserving its own dedicated PR. trl bumped 4-\u003e5; trl_ceiling=6 added -- SSRF safety fully delegated to external infra, no retries/circuit-breaker sophistication. See PR #1 (merged).","version":{"deployed_at":"2026-08-27T22:43:12Z","sha":"432729d","version":"0.1.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"node-search-bing","domain":"node-search-bing.0exec.com","mesh":"0exec","host_port":18016,"category":"search","title":"Bing Search (Node)","summary":"Bing search results via Node TS scraper.","tags":["node","search","search"],"openapi_url":"https://node-search-bing.0exec.com/openapi.json","llms_url":"https://node-search-bing.0exec.com/llms.txt","health_url":"https://node-search-bing.0exec.com/health","version_url":"https://node-search-bing.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/node-search-bing","url":"https://node-search-bing.0exec.com","example":"/?query=anthropic+claude","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"First-pass audit (Express/TypeScript cheerio-based Bing SERP scraper, routed through an internal C egress proxy). Found and fixed 4 real bugs: (1) bot-challenge/CAPTCHA pages (HTTP 200, 0 result nodes) misreported as 'no results', indistinguishable from a genuine zero-hit query -- added detection, now returns 503 with partial results preserved. (2) No fetch timeout at all (axios default) -- a real resource-exhaustion risk under concurrent load if the proxy/Bing stalls; added 15s timeouts. (3) A lodash override pinned to a version npm's own registry explicitly flags 'Bad release' -- the regressed attempted fix for a known code-injection CVE; repinned to the actually-clean release. (4) Several other stale vulnerable dependencies bumped (npm audit: 9 findings/2 high -\u003e 1 moderate residual, an Express-5-migration deliberately deferred). Also found the internal C-based egress proxy this service depends on is currently returning 502 for every request -- an infra issue flagged as out of scope for this repo. Added the repo's first real test suite. trl held at 5; trl_ceiling=6 added -- structurally capped by Bing's unversioned/changeable HTML and aggressive, empirically-confirmed anti-bot posture. See PR #2 (merged).","version":{"deployed_at":"2026-08-27T23:10:29Z","sha":"cc28e61","version":"0.1.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"node-search-duck","domain":"node-search-duck.0exec.com","mesh":"0exec","host_port":18015,"category":"search","title":"DuckDuckGo Search (Node)","summary":"DuckDuckGo search via Node TS. Same role as go-search-duck.","tags":["node","search","search","scraping"],"openapi_url":"https://node-search-duck.0exec.com/openapi.json","llms_url":"https://node-search-duck.0exec.com/llms.txt","health_url":"https://node-search-duck.0exec.com/health","version_url":"https://node-search-duck.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/node-search-duck","url":"https://node-search-duck.0exec.com","example":"/?query=anthropic+claude","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"First-pass audit of the Node/TS twin (confirmed genuinely intentional as a Go/Node port pair with go-search-duck, not an accidental duplicate -- independently audited today to the same trl/ceiling). Found and fixed 4 real bugs: (1) pagination completely broken -- DuckDuckGo switched to POST-based pagination, the code still looked for an \u003ca rel=\"next\"\u003e link that no longer exists, so every search silently truncated to page-1 (~10 results) regardless of the requested limit; fixed with a new POST-based next-page fetch, live-verified ?limit=15 now correctly returns 15 across 2 pages. (2) The same bot-challenge-misreported-as-empty-results pattern found repeatedly this batch; fixed, now a distinct 503. (3) A real concurrency data race -- a shared module-level rank counter corrupted result ranking under concurrent load; fixed by threading rank explicitly, verified with 20 concurrent live requests. (4) No request timeout, added. npm audit: 9 findings (2 high) -\u003e 4 (0 high), remaining 4 unreachable transitive deps of an Express-4 pin. Added the repo's first test suite. trl held at 5; trl_ceiling=6 added, same rationale as sibling go-search-duck. See PR #2 (merged).","version":{"deployed_at":"2026-08-27T23:10:30Z","sha":"98e308d","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"ocr-pdf","domain":"ocr-pdf.0exec.com","mesh":"0exec","host_port":18012,"category":"ocr","title":"PDF→Text (Fastify)","summary":"Convert a PDF to text via Fastify + pdf-parse.","tags":["ocr","ocr","pdf"],"openapi_url":"https://ocr-pdf.0exec.com/openapi.json","llms_url":"https://ocr-pdf.0exec.com/llms.txt","health_url":"https://ocr-pdf.0exec.com/health","version_url":"https://ocr-pdf.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/ocr-pdf","url":"https://ocr-pdf.0exec.com","example":"/?url=https://www.africau.edu/images/default/sample.pdf","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (Fastify + pdf-parse + shelling out to ocrmypdf): found the service was completely non-functional end-to-end, every issue reproduced locally before fixing. (1) The server couldn't boot at all -- 3 fastify plugins pinned to fastify-4-only majors after a prior commit bumped fastify itself to 5.x, every start threw a plugin-version-mismatch and silently exited (fastify's default logger is a no-op, zero log output). (2) OCR never actually ran -- the Dockerfile never installed ocrmypdf/tesseract/ghostscript, every request silently returned a fake 200 success with empty text. (3) The POST upload path was completely dead due to a routing bug. (4) --force-ocr destroyed good text layers (verified byte-for-byte). (5) Encrypted/corrupted PDFs and OCR failures silently swallowed into fake 200 success. (6) No OCR timeout -- a scan could hang indefinitely. (7) A real path-traversal vulnerability via upload filename that could have overwritten the service's own code, since the container chowns to the same user running the process. (8) Docker's own HEALTHCHECK was a no-op that would report healthy even while crash-looping. 13 of 17 dependency CVEs fixed. Non-Latin-script OCR mojibake documented as a ceiling driver, not fixed. Added a real integration test suite exercising all of this over HTTP against actual OCR fixtures. trl was a stale scaffold placeholder at 4, bumped to 6; trl_ceiling=7 added -- hardcoded single-language OCR with no failure signal, and an unmaintained ~2016-vintage bundled pdf.js showing real fragility, both structural. See PR #1 (merged).","version":{"deployed_at":"2026-05-28T21:00:37Z","sha":"1a3ea5f","version":"0.1.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"ocr-pdf-express","domain":"ocr-pdf-express.0exec.com","mesh":"0exec","host_port":18014,"category":"ocr","title":"PDF→Text (Express)","summary":"Same as ocr-pdf but via Express; supports url/text query params too.","tags":["ocr","ocr","pdf"],"openapi_url":"https://ocr-pdf-express.0exec.com/openapi.json","llms_url":"https://ocr-pdf-express.0exec.com/llms.txt","health_url":"https://ocr-pdf-express.0exec.com/health","version_url":"https://ocr-pdf-express.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/ocr-pdf-express","url":"https://ocr-pdf-express.0exec.com","example":"/?url=https://www.africau.edu/images/default/sample.pdf","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"First-pass audit (identical ocrmypdf --force-ocr + pdf-parse pipeline as sibling ocr-pdf, confirmed the real distinction is Express/GET-only-plus-stub-POST vs the sibling's working Fastify POST, not a faster/lighter tier): found the service has likely NEVER produced real OCR output in production -- ocrmypdf was never installed in the Docker image at all, every OCR call failed with 'command not found', silently swallowed into a fake 200 success with empty text. Also found: the documented POST / multipart upload literally didn't exist (threw 'not yet implemented'), /health required by the fleet's own deploy gate was never implemented, a fixed temp filename let concurrent requests race and corrupt each other's downloads (reproduced with 16 concurrent requests), no download size/timeout caps, and a real dependency defect in the bundled pdf-parse nondeterministically losing text even when OCR succeeded. npm audit: 2 high + 8 other vulnerable packages fixed. Added a real test suite. trl was effectively 1-2 in practice (silently non-functional); bumped to 5 post-fix; trl_ceiling=7 added -- fundamentally a single-OCR-engine wrapper with no cross-checking/redundancy. See PR #1 (merged).","version":{"deployed_at":"2026-08-27T22:57:05Z","sha":"c34f073","version":"0.2.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-agent-state","domain":"pentest-agent-state.0exec.com","mesh":"0exec","host_port":18146,"category":"infrastructure","title":"Pentest Agent State","summary":"Persistent agent memory for the pentest fleet. POST /snapshot upserts the 'where I left off' state for an autonomous agent; POST /journal appends events. SQLite (WAL). Closes the gap that makes every Claude conversation start at zero.","tags":["go-pentest"],"openapi_url":"https://pentest-agent-state.0exec.com/openapi.json","llms_url":"https://pentest-agent-state.0exec.com/llms.txt","health_url":"https://pentest-agent-state.0exec.com/health","version_url":"https://pentest-agent-state.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-agent-state","url":"https://pentest-agent-state.0exec.com","example":"/stats","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"optimistic-lock state with version history, lease primitive with TestLease_Concurrent50Goroutines (BEGIN IMMEDIATE pattern), /selftest with 409 stale-write + lease exclusivity","trl_ceiling":7,"trl_ceiling_reason":"Ceiling lifts once orchestrator + payoff-tracker route through it end-to-end and the loop has survived a week of unattended operation.","version":{"deployed_at":"2026-08-27T15:06:03Z","sha":"7060f00","version":"0.2.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-asset-inventory","domain":"pentest-asset-inventory.0exec.com","mesh":"0exec","host_port":18131,"category":"infrastructure","title":"Pentest Asset Inventory","summary":"Source of truth for every known asset per program. Recon services upsert; continuous-monitor diffs daily to fire scans only on NEW assets. The compounding-revenue substrate of the fleet.","tags":["go-pentest"],"openapi_url":"https://pentest-asset-inventory.0exec.com/openapi.json","llms_url":"https://pentest-asset-inventory.0exec.com/llms.txt","health_url":"https://pentest-asset-inventory.0exec.com/health","version_url":"https://pentest-asset-inventory.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-asset-inventory","url":"https://pentest-asset-inventory.0exec.com","example":"/stats","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"asset_history shadow table on tech/tags/status changes; /assets:bulk 5000-row tx benchmarked at 208ms (well under 500ms target); /assets/{id}/history; /selftest","trl_ceiling":7,"trl_ceiling_reason":"Single-node SQLite. Fine until ~1M assets per program; sharding by program or Postgres later.","version":{"deployed_at":"2026-08-27T15:07:26Z","sha":"23b3370","version":"0.2.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-asset-scope-resolver","domain":"pentest-asset-scope-resolver.0exec.com","mesh":"0exec","host_port":18126,"category":"recon","title":"Pentest Asset Scope Resolver","summary":"Wildcard scope expansion: composes cert-transparency + subfinder + scope-guard to expand a program wildcard scope into a concrete in-scope subdomain list.","tags":["go-pentest"],"openapi_url":"https://pentest-asset-scope-resolver.0exec.com/openapi.json","llms_url":"https://pentest-asset-scope-resolver.0exec.com/llms.txt","health_url":"https://pentest-asset-scope-resolver.0exec.com/health","version_url":"https://pentest-asset-scope-resolver.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-asset-scope-resolver","url":"https://pentest-asset-scope-resolver.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass safety audit of this internal scope-resolution tool (defensive/inventory use only, gates what this fleet's own authorized scanning pipeline is allowed to touch): found and fixed a real safety-relevant bug -- unescaped string interpolation building the JSON request to a downstream scope-guard service allowed a maliciously-crafted hostname (e.g. sourced from CT logs) to inject a '\"}' sequence, truncating the JSON body and dropping the 'program' field -- a path toward wrongly approving an out-of-scope target. Fixed by switching to json.Marshal on a typed struct plus a strict RFC 1035 hostname allowlist at the source. Confirmed fetch-cache masking doesn't apply (no caching layer, no DNS resolution in this service). trl held at 6, trl_ceiling held at 8 -- both honestly earned now that the fix and expanded adversarial test suite close a latent false-positive hole. See PR #5 (merged).","trl_ceiling":8,"trl_ceiling_reason":"Depends on upstream fleet services and live program scope data quality.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-asset-scope-resolver.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-attack-chainer","domain":"pentest-attack-chainer.0exec.com","mesh":"0exec","host_port":18149,"category":"uncategorized","title":"Pentest Attack Chainer","summary":"CORS exploitation chain validator. Cross-references a CORS misconfig finding with go-pentest-takeover-checker (attacker-controllable siblings) AND probes target for data-bearing endpoints. Classifies real_severity end-to-end: critical / high / medium / low / informational. Renders a working PoC HTML page when chain elements present.","tags":["chain-validation","cors","pentest"],"openapi_url":"https://pentest-attack-chainer.0exec.com/openapi.json","llms_url":"https://pentest-attack-chainer.0exec.com/llms.txt","health_url":"https://pentest-attack-chainer.0exec.com/health","version_url":"https://pentest-attack-chainer.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-attack-chainer","url":"https://pentest-attack-chainer.0exec.com","example":"/health","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"4/4 unit tests passing (base-domain inference, severity matrix, PoC rendering with/without chain). Verified end-to-end against accommodations.booking.com: 30 siblings + 12 endpoint probes in 1.2s, correctly downgrades prober high -\u003e informational.","trl_ceiling":7,"version":{"deployed_at":"2026-08-23T07:31:53Z","sha":"4beec57","version":"0.3.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-audit-log","domain":"pentest-audit-log.0exec.com","mesh":"0exec","host_port":18119,"category":"infrastructure","title":"Pentest Audit Log","summary":"Append-only audit log for the pentest fleet. Every scan-start / scope-denied / finding-submitted gets recorded. Legal floor + CYA.","tags":["go-pentest"],"openapi_url":"https://pentest-audit-log.0exec.com/openapi.json","llms_url":"https://pentest-audit-log.0exec.com/llms.txt","health_url":"https://pentest-audit-log.0exec.com/health","version_url":"https://pentest-audit-log.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-audit-log","url":"https://pentest-audit-log.0exec.com","example":"/stats","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Pure-Go SQLite, deterministic (ts,actor,action,target,program,tool) hash for dedup, append-only by design.","trl_ceiling":7,"version":{"deployed_at":"2026-08-27T15:08:59Z","sha":"6f64a7c","version":"0.2.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-authz-matrix","domain":"pentest-authz-matrix.0exec.com","mesh":"0exec","host_port":18152,"category":"security","title":"Pentest Authz Matrix","summary":"Pentest fleet service","tags":["go-pentest"],"openapi_url":"https://pentest-authz-matrix.0exec.com/openapi.json","llms_url":"https://pentest-authz-matrix.0exec.com/llms.txt","health_url":"https://pentest-authz-matrix.0exec.com/health","version_url":"https://pentest-authz-matrix.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-authz-matrix","url":"https://pentest-authz-matrix.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"/expanded matrix endpoint (5 verbs x N roles), peer-read bug detection, findings-store wire (1s timeout, fail-open), /selftest with in-process tiny-app","trl_ceiling":8,"reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-authz-matrix.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-bounty-scope-checker","domain":"pentest-bounty-scope-checker.0exec.com","mesh":"0exec","host_port":18110,"category":"recon","title":"Pentest Bounty Scope Checker","summary":"Given a domain, returns which bug-bounty programs include it in scope (sorted by max payout). Embedded seed of ~10 well-known programs (GitHub, GitLab, Shopify, PayPal, Anthropic, Google, Microsoft, Tesla, Uber, X).","tags":["go-pentest"],"openapi_url":"https://pentest-bounty-scope-checker.0exec.com/openapi.json","llms_url":"https://pentest-bounty-scope-checker.0exec.com/llms.txt","health_url":"https://pentest-bounty-scope-checker.0exec.com/health","version_url":"https://pentest-bounty-scope-checker.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-bounty-scope-checker","url":"https://pentest-bounty-scope-checker.0exec.com","example":"/check?target=api.github.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass safety audit of this internal bug-bounty-scope-checking tool: found and fixed 2 real safety-critical bugs -- an unanchored regex substring match could misclassify an out-of-scope target as in-scope (e.g. a github\\.com pattern matching evilgithub.com.attacker.net); and the fetch-cache-masking bug specifically on scope-policy fetches, meaning a program narrowing its scope could keep being served stale, wider scope data. Both fixed. Also flagged (not fixed, a product decision) that the HackerOne/Bugcrowd live-data integrations are fully built but never actually wired into main.go -- dead code since the commit that claimed to add them, so production only ever uses the embedded seed snapshot. trl held at 6 now that the fix is merged (recommended dropping to 5 only while the fix was unmerged); trl_ceiling held at 8 -- still blocked on the aggregator service and the decision to wire in live feeds. See PR #5 (merged).","trl_ceiling":8,"trl_ceiling_reason":"Production freshness depends on continuously updated program feeds.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-bounty-scope-checker.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-cert-transparency","domain":"pentest-cert-transparency.0exec.com","mesh":"0exec","host_port":18109,"category":"recon","title":"Pentest Cert Transparency","summary":"crt.sh wrapper with 24h SQLite cache. Returns SAN-derived subdomains or full cert records (issuer/dates/SANs).","tags":["go-pentest"],"openapi_url":"https://pentest-cert-transparency.0exec.com/openapi.json","llms_url":"https://pentest-cert-transparency.0exec.com/llms.txt","health_url":"https://pentest-cert-transparency.0exec.com/health","version_url":"https://pentest-cert-transparency.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-cert-transparency","url":"https://pentest-cert-transparency.0exec.com","example":"/cache/stats","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"crt.sh fetcher + SQLite cache (modernc) + wildcard-skip + SAN-suffix filter; tested for normalization, cache hits, subdomain filter.","trl_ceiling":8,"trl_ceiling_reason":"Add Censys + Google CT in parallel for redundancy.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-cert-transparency.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-chaos-sync","domain":"pentest-chaos-sync.0exec.com","mesh":"0exec","host_port":18128,"category":"recon","title":"Pentest Chaos Sync","summary":"Background syncer for ProjectDiscovery Chaos public dataset. SQLite-backed (modernc.org/sqlite, CGo-free) cache of subdomains keyed by root_domain; daily refresh; O(log N) lookups; zero target-network traffic.","tags":["pentest"],"openapi_url":"https://pentest-chaos-sync.0exec.com/openapi.json","llms_url":"https://pentest-chaos-sync.0exec.com/llms.txt","health_url":"https://pentest-chaos-sync.0exec.com/health","version_url":"https://pentest-chaos-sync.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-chaos-sync","url":"https://pentest-chaos-sync.0exec.com","example":"/sync/status","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"v0.2.0 adds dataset_version (sha256(url|last_updated)) tracking, cursor-paginated /delta and /export endpoints, /stats with distinct-version counts, and admin-gated POST /sync; SQLite WAL + busy_timeout=5000 for syncer/reader concurrency; skip-unchanged short-circuit avoids redownloading unchanged Chaos zips; per-zip 60s HTTP timeout; ≥6 unit tests covering full sync, lookup, delta windowing, cursor pagination correctness across ≥3 pages, dataset_version stability, and admin-token gating; httptest fixtures serve canned chaos index + canned subdomain zips so tests are CGO-free and offline.","trl_ceiling":7,"trl_ceiling_reason":"Delta-tracking and program ranking needed for 7+.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-chaos-sync.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-codec","domain":"pentest-codec.0exec.com","mesh":"0exec","host_port":18118,"category":"security","title":"Pentest Codec","summary":"Encode/decode + JWT segment decoder. 11 formats (base64 std/url/raw, base32, hex, url, html, gzip, zlib, json-string); alg=none/path-traversable-kid flags on JWT.","tags":["go-pentest"],"openapi_url":"https://pentest-codec.0exec.com/openapi.json","llms_url":"https://pentest-codec.0exec.com/llms.txt","health_url":"https://pentest-codec.0exec.com/health","version_url":"https://pentest-codec.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-codec","url":"https://pentest-codec.0exec.com","example":"/encode?algo=base64\u0026input=hello","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Audited 2026-08-08 (real code read + adversarial stress-testing, not a rubber stamp): pure-stdlib codec table (11 formats: base64 std/url/raw/auto, base32, hex, url, url-path, html-encode-only, gzip, zlib, json-string) plus a JWT segment decoder that flags alg=none and path-traversable kid headers. No outbound HTTP calls, so the fleet safehttp/SSRF bug class does not apply here. Found and fixed a real bug: a 2-segment JWT whose header or payload segment is the empty string (e.g. \"eyJhbGciOiJIUzI1NiJ9.\") base64url-decoded to zero bytes and passed validation; json.Marshal of the response then failed, and because handler.go's writeJSON discards the encode error, the API silently returned HTTP 200 with Content-Type: application/json and an empty/truncated body instead of a clear error -- exactly the kind of hostile-input case a pentest tool must handle. Fixed in v0.1.7 (jwt.go: decodeJWTSegment now rejects segments that don't decode to valid JSON) with 2 new regression tests plus a marshal-roundtrip fuzz-style test; full suite (6 tests) passes. PR open, unmerged: https://github.com/baditaflorin/go-pentest-codec/pull/10. Prior evidence (\"full roundtrip tests\") only covered the happy path for all 10 decode-capable formats plus 2 JWT cases -- no error-path, malformed-input, or fuzz coverage existed before this audit. That gap is real: this is a working, RFC-reasonable implementation with genuine test coverage, but the first adversarial pass turned up a live production bug, so \"battle-tested / SLA-grade\" (TRL 8-9) was premature. Downgrading to TRL 7 (real: correct parsing + genuine but not yet exhaustive test coverage) until a further adversarial/fuzz pass turns up nothing new.","trl_ceiling":9,"reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-codec.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-continuous-monitor","domain":"pentest-continuous-monitor.0exec.com","mesh":"0exec","host_port":18134,"category":"infrastructure","title":"Pentest Continuous Monitor","summary":"Daily cron-style scheduler that diffs asset-inventory per program and enqueues scan jobs only for NEW assets. Turns one-shot recon into a subscription — money compounds with the asset universe, not manpower.","tags":["go-pentest"],"openapi_url":"https://pentest-continuous-monitor.0exec.com/openapi.json","llms_url":"https://pentest-continuous-monitor.0exec.com/llms.txt","health_url":"https://pentest-continuous-monitor.0exec.com/health","version_url":"https://pentest-continuous-monitor.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-continuous-monitor","url":"https://pentest-continuous-monitor.0exec.com","example":"/stats","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Concurrent dispatch bounded by errgroup+semaphore, per-program advisory lock via running_until (RFC3339), deterministic idempotency_key sent to job-queue (composes with job-queue 0.2.0), /selftest","trl_ceiling":7,"trl_ceiling_reason":"Bounded by job-queue throughput. Sequential per-program scheduler keeps the reasoning simple.","version":{"deployed_at":"2026-08-27T15:12:44Z","sha":"31e5122","version":"0.3.4"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-cors-misconfig-prober","domain":"pentest-cors-misconfig-prober.0exec.com","mesh":"0exec","host_port":18124,"category":"security","title":"Pentest Cors Misconfig Prober","summary":"Active CORS-misconfig prober. 5 attacker-Origin probes (reflection, null-origin, suffix-bypass, pre-subdomain, case-fold). Reflection+Allow-Credentials=high.","tags":["go-pentest"],"openapi_url":"https://pentest-cors-misconfig-prober.0exec.com/openapi.json","llms_url":"https://pentest-cors-misconfig-prober.0exec.com/llms.txt","health_url":"https://pentest-cors-misconfig-prober.0exec.com/health","version_url":"https://pentest-cors-misconfig-prober.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-cors-misconfig-prober","url":"https://pentest-cors-misconfig-prober.0exec.com","example":"/probe?url=https%3A%2F%2Fexample.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"5 active probes, reflection+credentials high-sev detection, suffix-confusion + pre-subdomain bypass, case-fold. Tested positive (high) + negative.","trl_ceiling":8,"reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-cors-misconfig-prober.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-cvss","domain":"pentest-cvss.0exec.com","mesh":"0exec","host_port":18107,"category":"security","title":"Pentest Cvss","summary":"CVSS 3.1 base score calculator. Pure-Go FIRST.org spec implementation. Takes a vector, returns base/severity/impact/exploitability.","tags":["go-pentest"],"openapi_url":"https://pentest-cvss.0exec.com/openapi.json","llms_url":"https://pentest-cvss.0exec.com/llms.txt","health_url":"https://pentest-cvss.0exec.com/health","version_url":"https://pentest-cvss.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-cvss","url":"https://pentest-cvss.0exec.com","example":"/score?vector=CVSS%3A3.1%2FAV%3AN%2FAC%3AL%2FPR%3AN%2FUI%3AN%2FS%3AU%2FC%3AH%2FI%3AH%2FA%3AH","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":8,"trl_evidence":"TRL-8 re-audit 2026-08-08: cvss31.go checked line-by-line vs FIRST.org 3.1 spec (weights, ISS, roundup) -- no deviation. 6 canonical FIRST.org cases plus 5 real NVD-published CVE vectors (Log4Shell CVE-2021-44228=10.0, BlueKeep CVE-2019-0708=9.8, Zerologon CVE-2020-1472=10.0, Heartbleed CVE-2014-0160=7.5, Spring4Shell CVE-2022-22965=9.8) all match NVD exactly; no scoring bugs found. No outbound HTTP calls, so safehttp fetch-cache/HTTP2 bug class is N/A. go vet/build/test -race clean. Gap: handler.go (HTTP glue) has 0% direct coverage, only the scoring engine is tested (58% overall). NVD-vector regression tests added: github.com/baditaflorin/go-pentest-cvss PR #8 (unmerged, no functional change).","trl_ceiling":9,"trl_ceiling_reason":"CVSS 4.0 support pushes to 9.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-cvss.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-dedup-fingerprint","domain":"pentest-dedup-fingerprint.0exec.com","mesh":"0exec","host_port":18132,"category":"security","title":"Pentest Dedup Fingerprint","summary":"Semantic dedup of findings. Normalizes query-param order, UUIDs in path, timestamps, whitespace in body, then sha256s. Stops one XSS reported by 4 scanners from looking like 4 dupes.","tags":["go-pentest"],"openapi_url":"https://pentest-dedup-fingerprint.0exec.com/openapi.json","llms_url":"https://pentest-dedup-fingerprint.0exec.com/llms.txt","health_url":"https://pentest-dedup-fingerprint.0exec.com/health","version_url":"https://pentest-dedup-fingerprint.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-dedup-fingerprint","url":"https://pentest-dedup-fingerprint.0exec.com","example":"/stats","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"73-row scanner corpus across 4 scanners x 8 vulns: intra=100% / inter=0% collision rates; fp_version=v1; /forget admin-gated; /selftest","trl_ceiling":7,"trl_ceiling_reason":"Normalization rule corpus grows with bug-class variety; current 6 rules handle the common cases.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-dedup-fingerprint.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-dependency-cve","domain":"pentest-dependency-cve.0exec.com","mesh":"0exec","host_port":18125,"category":"security","title":"Pentest Dependency Cve","summary":"CPE -\u003e NVD JSON 2.0 + CISA KEV cross-flag. Per-request fetch (no local cache yet). Composes with go-pentest-httpx tech detection.","tags":["go-pentest"],"openapi_url":"https://pentest-dependency-cve.0exec.com/openapi.json","llms_url":"https://pentest-dependency-cve.0exec.com/llms.txt","health_url":"https://pentest-dependency-cve.0exec.com/health","version_url":"https://pentest-dependency-cve.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-dependency-cve","url":"https://pentest-dependency-cve.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"SQLite TTL cache (NVD/KEV/OSV), OSV.dev cross-source merge, /selftest with stubbed upstreams, 14 test funcs (was 0)","trl_ceiling":7,"trl_ceiling_reason":"TRL 7 with local CVE feed primitive caching NVD/GHSA delta-updates.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-dependency-cve.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-disclosure-policy-finder","domain":"pentest-disclosure-policy-finder.0exec.com","mesh":"0exec","host_port":18111,"category":"recon","title":"Pentest Disclosure Policy Finder","summary":"Probes 12 disclosure-policy paths and classifies bounty/VDP/safe-harbor/unknown/none. Extracts Contact/PGP from security.txt and detects platform hints (HackerOne/Bugcrowd/Intigriti/YesWeHack/Synack).","tags":["go-pentest"],"openapi_url":"https://pentest-disclosure-policy-finder.0exec.com/openapi.json","llms_url":"https://pentest-disclosure-policy-finder.0exec.com/llms.txt","health_url":"https://pentest-disclosure-policy-finder.0exec.com/health","version_url":"https://pentest-disclosure-policy-finder.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-disclosure-policy-finder","url":"https://pentest-disclosure-policy-finder.0exec.com","example":"/check?target=hackerone.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"12 probe paths, RFC 9116 parser, 9 bounty-platform regexes, 4 safe-harbor regexes, class-priority resolver. Extends fleet security-txt with VDP-vs-bounty classification.","trl_ceiling":8,"trl_ceiling_reason":"Add /security anchor crawl + submit-button scraping.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-disclosure-policy-finder.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-exploit-verifier","domain":"pentest-exploit-verifier.0exec.com","mesh":"0exec","host_port":18137,"category":"security","title":"Pentest Exploit Verifier","summary":"Gate between possible-finding and submit-bot. Runs deterministic confirmation per vuln class: SSRF via OOB callback, XSS via marker reflection, IDOR via session-stripped re-fetch, JWT alg-none, open-redirect, subdomain-takeover.","tags":["go-pentest"],"openapi_url":"https://pentest-exploit-verifier.0exec.com/openapi.json","llms_url":"https://pentest-exploit-verifier.0exec.com/llms.txt","health_url":"https://pentest-exploit-verifier.0exec.com/health","version_url":"https://pentest-exploit-verifier.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-exploit-verifier","url":"https://pentest-exploit-verifier.0exec.com","example":"/capabilities","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"verification ledger with BEGIN IMMEDIATE, idempotency replays from ledger without re-firing target, sensitive header redaction asserted by test, 3-stage /selftest (vulnerable/patched/inconclusive)","trl_ceiling":8,"trl_ceiling_reason":"Each verifier is a thin recipe — lifts as verifier coverage grows. Bounded by OOB collector quality for blind classes.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-exploit-verifier.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-favicon-hash","domain":"pentest-favicon-hash.0exec.com","mesh":"0exec","host_port":18117,"category":"recon","title":"Pentest Favicon Hash","summary":"Shodan-style mmh3 favicon hash with known-tech lookup (~60 seeds: Tomcat, Spring Boot, Jenkins, Grafana, Jupyter, phpMyAdmin, GitLab, FortiNet, F5, etc.).","tags":["go-pentest"],"openapi_url":"https://pentest-favicon-hash.0exec.com/openapi.json","llms_url":"https://pentest-favicon-hash.0exec.com/llms.txt","health_url":"https://pentest-favicon-hash.0exec.com/health","version_url":"https://pentest-favicon-hash.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-favicon-hash","url":"https://pentest-favicon-hash.0exec.com","example":"/lookup?hash=-1996286744","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"2026-08-20 re-audit against fresh clone of origin/main (ec848c8): mmh3 via twmb/murmur3 (race-safe, replaced spaolacci), Python-compatible base64.encodebytes (76-char wrap) hashing -- algorithm independently re-verified correct by hashing a live target's real favicon (https://ci.jenkins.io/favicon.ico) and matching a known reference value. Found and fixed 2 real bugs in the shipped ~60-entry fingerprint DB: (1) hash 81586312 was mislabeled \"Grafana\" -- it is actually Jenkins's real, version-stable default favicon.ico hash, confirmed via ci.jenkins.io (live) and jenkinsci/jenkins git history back to tag jenkins-1.625.3 (2016); the stale -247388890 \"Jenkins\" entry matched neither product and was replaced with Grafana's actual hash 2123863676 (grafana/grafana public/img/fav32.png, stable across main and v10.4.0). (2) httpClient used bare safehttp.NewClient() without .WithoutFetchCache(), risking a stale/cross-caller-cached favicon body instead of the live one when a fleet fetch-cache delegate is installed -- this defeats the tool's purpose (fingerprinting the CURRENT favicon of a target). Both fixed + regression-tested in PR #9 (https://github.com/baditaflorin/go-pentest-favicon-hash/pull/9, not yet merged as of this assessment -- TRL held at 7 pending merge/deploy; algorithm correctness and evidence-trail quality otherwise support 7). Remaining ~58 DB entries are still unverified OSINT-trend claims (source: shodan-trend), not independently cross-checked.","trl_ceiling":9,"reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-favicon-hash.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-finding-triage","domain":"pentest-finding-triage.0exec.com","mesh":"0exec","host_port":18135,"category":"security","title":"Pentest Finding Triage","summary":"Auto-grades raw findings into submit_ready / needs_review / drop using 8 rules (missing fields, fingerprint-dupe, scope-deny, noise-class, confidence floor, severity promote, evidence-present, verified-class). Reasons array surfaces every decision.","tags":["go-pentest"],"openapi_url":"https://pentest-finding-triage.0exec.com/openapi.json","llms_url":"https://pentest-finding-triage.0exec.com/llms.txt","health_url":"https://pentest-finding-triage.0exec.com/health","version_url":"https://pentest-finding-triage.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-finding-triage","url":"https://pentest-finding-triage.0exec.com","example":"/rules","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"SQLite decision ledger with /decisions query, dry_run mode returning would_decide, sony/gobreaker circuit breakers around scope-guard + dedup-fingerprint, degraded_mode in response, /selftest","trl_ceiling":7,"trl_ceiling_reason":"Lift bound is rule-corpus size. Adding ML or LLM-based triage would push the ceiling but break the pure-rule explainability.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-finding-triage.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-findings-store","domain":"pentest-findings-store.0exec.com","mesh":"0exec","host_port":18103,"category":"security","title":"Pentest Findings Store","summary":"Central deduplicated findings store for the pentest fleet. SQLite-backed (pure Go modernc); collapses same finding from multiple scanners via dedup_key with seen_count.","tags":["go-pentest"],"openapi_url":"https://pentest-findings-store.0exec.com/openapi.json","llms_url":"https://pentest-findings-store.0exec.com/llms.txt","health_url":"https://pentest-findings-store.0exec.com/health","version_url":"https://pentest-findings-store.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-findings-store","url":"https://pentest-findings-store.0exec.com","example":"/findings?limit=1","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"findings_history shadow table with SHA-256 evidence hashing, /findings/{id}/history endpoint, /selftest round-trip","trl_ceiling":7,"trl_ceiling_reason":"Single-node SQLite is fine until ~1M findings; horizontal shard or Postgres later.","version":{"deployed_at":"2026-06-29T22:48:00Z","sha":"2459701","version":"0.5.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-github-dorks","domain":"pentest-github-dorks.0exec.com","mesh":"0exec","host_port":18123,"category":"security","title":"Pentest Github Dorks","summary":"GitHub Search API dorking for leaked credentials: 31 curated patterns (AWS keys, .env, private keys, Slack/Stripe/PAT tokens, kubeconfig, npm/Docker creds). Rate-limit aware; pairs with go-pentest-trufflehog for verification.","tags":["pentest"],"openapi_url":"https://pentest-github-dorks.0exec.com/openapi.json","llms_url":"https://pentest-github-dorks.0exec.com/llms.txt","health_url":"https://pentest-github-dorks.0exec.com/health","version_url":"https://pentest-github-dorks.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-github-dorks","url":"https://pentest-github-dorks.0exec.com","example":"/dorks","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"38 curated dork patterns (creds + files + vendors + infra + k8s + per-vendor leaks); typed rate-limit handling (primary + secondary/abuse) with adaptive sleep; per-dork 4s + total 90s deadline; optional verification compose with go-pentest-trufflehog (TRUFFLEHOG_URL); domain qualifier (\\\"\u003cdomain\u003e\\\" in:file); production mode (MODE=production) refuses to start without GITHUB_TOKEN; 19 unit tests including httptest-mocked GitHub API (success / primary rate-limit / abuse / no-results) + trufflehog compose. Pure Go (CGO-free), no parallelism. Ceiling stays at 7 pending cross-dork dedup, snippet-level secret extraction, and findings-store fan-out.","trl_ceiling":6,"trl_ceiling_reason":"GitHub Search has no regex; semantic dedup + verifier-loop integration cap the climb at 6.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-github-dorks.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-http-replay","domain":"pentest-http-replay.0exec.com","mesh":"0exec","host_port":18130,"category":"infrastructure","title":"Pentest Http Replay","summary":"Captures + reproduces HTTP request/response pairs as bug-bounty evidence. Generates canonical curl PoC, replays for diff, imports raw HTTP from Burp. Uses go-common safehttp (SSRF-safe).","tags":["go-pentest"],"openapi_url":"https://pentest-http-replay.0exec.com/openapi.json","llms_url":"https://pentest-http-replay.0exec.com/llms.txt","health_url":"https://pentest-http-replay.0exec.com/health","version_url":"https://pentest-http-replay.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-http-replay","url":"https://pentest-http-replay.0exec.com","example":"/stats","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"go-common safehttp client; 256KB response cap; sha256 body-hash for rerun diff; 19 tests pass including curl-builder edge cases.","trl_ceiling":7,"trl_ceiling_reason":"Single-node SQLite. Fine for evidence retention at typical bug-bounty scale; lifts when paired with object storage for large bodies.","version":{"deployed_at":"2026-08-27T15:10:42Z","sha":"b23a88b","version":"0.3.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-httpx","domain":"pentest-httpx.0exec.com","mesh":"0exec","host_port":18113,"category":"recon","title":"Pentest Httpx","summary":"One HTTP fingerprint per request: status, title, server, TLS cert summary, ~25 tech-detection signatures. Parallel batch with worker cap. Replaces chaining tech-stack + security-headers + cdn-detector.","tags":["go-pentest"],"openapi_url":"https://pentest-httpx.0exec.com/openapi.json","llms_url":"https://pentest-httpx.0exec.com/llms.txt","health_url":"https://pentest-httpx.0exec.com/health","version_url":"https://pentest-httpx.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-httpx","url":"https://pentest-httpx.0exec.com","example":"/probe?url=https%3A%2F%2Fexample.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"2026-08-20: code audit + live re-test found httpClient (probe.go) built via safehttp.NewClient(...) WITHOUT .WithoutFetchCache(). Confirmed via go-common@v0.88.0 source (server/server.go:83-85) that server.New auto-installs a process-wide safehttp.DefaultFetchDelegate whenever FLEET_FETCH_CACHE_URL is set, so this tool's live probes would transparently route through the shared fleet fetch cache and could silently return stale status/title/tech/TLS data -- a correctness bug for a tool whose entire purpose is real-time fingerprinting. Added regression test TestProbe_BypassesFleetFetchCache (fails pre-fix: returns stub delegate's stale title instead of hitting origin; passes post-fix) and fixed by adding safehttp.WithoutFetchCache(). Live-verified core probe logic (status/title/server/TLS/tech) against https://example.com, correct. Redirect-chain handling already reports every hop explicitly (not swallowed by auto-follow, unlike the go_redirect_tracer bug class) and TLS verification is not disabled anywhere in safehttp -- no other correctness bugs found. Fix is in open PR https://github.com/baditaflorin/go-pentest-httpx/pull/10 (unmerged as of this evidence), so the previously self-reported \"Tested\" claim did not hold for the actual fleet-wide operational environment (FLEET_FETCH_CACHE_URL set) until this PR merges/deploys -- lowering TRL 7 -\u003e 6 pending merge.","trl_ceiling":8,"trl_ceiling_reason":"Wrap wappalyzergo for full 3000+ fingerprint DB.","version":{"deployed_at":"2026-06-29T22:50:13Z","sha":"05670c2","version":"0.2.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-job-queue","domain":"pentest-job-queue.0exec.com","mesh":"0exec","host_port":18133,"category":"infrastructure","title":"Pentest Job Queue","summary":"Durable workflow queue. POST jobs, workers /claim → /complete or /fail. Crash-resilient via SQLite WAL; expired leases auto-requeue every 15s with exponential backoff. Backbone for orchestrator + continuous-monitor + every long-running scan.","tags":["go-pentest"],"openapi_url":"https://pentest-job-queue.0exec.com/openapi.json","llms_url":"https://pentest-job-queue.0exec.com/llms.txt","health_url":"https://pentest-job-queue.0exec.com/health","version_url":"https://pentest-job-queue.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-job-queue","url":"https://pentest-job-queue.0exec.com","example":"/stats","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"idempotency_key column with partial UNIQUE index, /metrics short-circuit middleware, /selftest, TestEnqueue_IdempotencyKey_Concurrent (50-goroutine race)","trl_ceiling":7,"trl_ceiling_reason":"Single-node SQLite. Fine up to ~10k jobs/sec; graduates to NATS JetStream or Postgres skip-locked beyond that.","version":{"deployed_at":"2026-08-27T15:12:44Z","sha":"c2ad492","version":"0.2.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-leak-bounty-policy","domain":"pentest-leak-bounty-policy.0exec.com","mesh":"0exec","host_port":18145,"category":"recon","title":"Pentest Leak Bounty Policy","summary":"Curated registry: which bug-bounty programs PAY for credential-leak disclosures, broken down by leak class (own_employee / shared_secret / customer_cred / canary). Use BEFORE writing up a leaked-credential disclosure — most platforms treat customer-side leaks as goodwill-only; only Stripe / GitHub partner / AWS canary / GitLab pay per-leak. 25 programs seeded.","tags":["go-pentest"],"openapi_url":"https://pentest-leak-bounty-policy.0exec.com/openapi.json","llms_url":"https://pentest-leak-bounty-policy.0exec.com/llms.txt","health_url":"https://pentest-leak-bounty-policy.0exec.com/health","version_url":"https://pentest-leak-bounty-policy.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-leak-bounty-policy","url":"https://pentest-leak-bounty-policy.0exec.com","example":"/search?token=sk_live_xxx","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"30-row vendor policy seed (AWS/GitHub/Slack/Stripe/OpenAI/Anthropic/Twilio/Mailgun/GCP/Azure/etc.), BEGIN IMMEDIATE on both seed and ledger, secret-prefix-only persistence (TestLedger_NoSecretInRows enforces), /selftest","trl_ceiling":7,"trl_ceiling_reason":"Ceiling 7 with quarterly auto-refresh from each program's policy URL + admin /reload endpoint. Pure manual curation caps at 5 because policies drift faster than humans can re-audit at scale.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-leak-bounty-policy.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-notify","domain":"pentest-notify.0exec.com","mesh":"0exec","host_port":18108,"category":"infrastructure","title":"Pentest Notify","summary":"Multi-sink notification fanout for the pentest fleet (Telegram/Discord/Slack/email/webhook/ntfy/Matrix/Teams/etc.) via containrrr/shoutrrr.","tags":["go-pentest"],"openapi_url":"https://pentest-notify.0exec.com/openapi.json","llms_url":"https://pentest-notify.0exec.com/llms.txt","health_url":"https://pentest-notify.0exec.com/health","version_url":"https://pentest-notify.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-notify","url":"https://pentest-notify.0exec.com","example":"/sinks","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Wraps containrrr/shoutrrr v0.8 (20+ sinks). Default-from-env, per-request URL override, secret-hiding /sinks.\n\n2026-08-20 audit (claude-sonnet-5-trl-audit-2026-08-20): fresh clone of origin/main (519d4d5) reviewed end-to-end. Confirmed a real, live-verified SSRF vulnerability: the `generic` (and `generic+\u003cscheme\u003e`) shoutrrr scheme POSTs to a caller-supplied host via a bare net/http.DefaultClient with zero SSRF protection (containrrr/shoutrrr pkg/services/generic/generic.go doSend), so any caller holding a vetted-pentest keystore key could direct this service's outbound POST /send traffic at loopback/RFC1918/CGNAT/link-local addresses, including the cloud metadata IP 169.254.169.254. Reverted the fix locally and confirmed the pre-fix handler made real outbound TCP connection attempts to every host in safehttp.TestBlockedHosts and hung until timeout instead of rejecting them. Fixed in https://github.com/baditaflorin/go-pentest-notify/pull/7 (open, not merged): each request-supplied `generic` webhook URL's host is now validated with safehttp.GuardHost before the URL set reaches shoutrrr.CreateSender; other schemes (telegram/discord/slack/...) hit a fixed vendor API host and aren't affected the same way. Added TestSend_RejectsSSRFViaGenericWebhook, TestSend_AllowsGenericWebhookToPublicHost, TestRejectUnsafeGenericSink_IgnoresOtherSchemes; verified the blocked-host test hangs on live network calls against pre-fix code and passes cleanly after. Bumped 0.1.1-\u003e0.1.2. TRL 7 reaffirmed, not lowered -- the shoutrrr wrapper, sink-count, and secret-hiding /sinks behavior are all sound, and the SSRF gap was scoped to one scheme and is now closed pending PR merge. Note: smtp/ntfy/gotify/mattermost/matrix/rocketchat/zulip schemes also let the caller pick a self-hosted target host and share the same class of risk -- not yet guarded, flagged as a follow-up.","trl_ceiling":9,"trl_ceiling_reason":"Ceiling = shoutrrr sink count + HMAC webhook auth.","version":{"deployed_at":"2026-08-27T15:14:44Z","sha":"faf5b5d","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-nuclei","domain":"pentest-nuclei.0exec.com","mesh":"0exec","host_port":18115,"category":"security","title":"Pentest Nuclei","summary":"Nuclei wrapper: scope-guarded YAML-template scanner (cves/exposures/misconfigs/takeovers). Pre-flights every target through go-pentest-scope-guard; forwards findings to go-pentest-findings-store. Bundles nuclei binary in container.","tags":["pentest"],"openapi_url":"https://pentest-nuclei.0exec.com/openapi.json","llms_url":"https://pentest-nuclei.0exec.com/llms.txt","health_url":"https://pentest-nuclei.0exec.com/health","version_url":"https://pentest-nuclei.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-nuclei","url":"https://pentest-nuclei.0exec.com","example":"/templates","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"scope-guard preflight (fail-closed -\u003e 503), rate-coordinator per-host acquire (fail-open), findings-store wire on severity\u003e=medium, /selftest round-trips all 3 sibling stubs + runner","trl_ceiling":7,"trl_ceiling_reason":"Pinned-binary wrapping; templates refresh cadence + concurrency stress-testing gate the climb to 7.","version":{"deployed_at":"2026-05-27T18:56:11Z","sha":"1fab10d","version":"0.2.9"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-oob-collector","domain":"pentest-oob-collector.0exec.com","mesh":"0exec","host_port":18106,"category":"security","title":"Pentest Oob Collector","summary":"Out-of-band HTTP callback catcher for blind XSS/SSRF/RCE findings. Allocates short-lived tokens, public /c/{token} catch endpoint, authenticated polling API. v0.2 wraps projectdiscovery/interactsh for DNS exfil.","tags":["go-pentest"],"openapi_url":"https://pentest-oob-collector.0exec.com/openapi.json","llms_url":"https://pentest-oob-collector.0exec.com/llms.txt","health_url":"https://pentest-oob-collector.0exec.com/health","version_url":"https://pentest-oob-collector.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-oob-collector","url":"https://pentest-oob-collector.0exec.com","example":"/sessions?limit=1","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"token + hits store, 512B body cap with full SHA-256, catch-all subdomain dispatch (\u003ctoken\u003e.oob.\u003cbase\u003e), TTL expiry, /selftest with 4 sub-checks","trl_ceiling":8,"trl_ceiling_reason":"Ceiling unlocked once projectdiscovery/interactsh is wrapped for DNS+SMTP exfil. HTTP half remains useful as simple-case catcher.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-oob-collector.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-orchestrator","domain":"pentest-orchestrator.0exec.com","mesh":"0exec","host_port":18138,"category":"infrastructure","title":"Pentest Orchestrator","summary":"Master end-to-end pipeline. POST a campaign and the state machine drives scope→recon→scan→triage→verify→submit through every other go-pentest-* service. 30s ticker auto-advances. SUBMIT_DRY_RUN=1 by default — the unattended money loop.","tags":["go-pentest"],"openapi_url":"https://pentest-orchestrator.0exec.com/openapi.json","llms_url":"https://pentest-orchestrator.0exec.com/llms.txt","health_url":"https://pentest-orchestrator.0exec.com/health","version_url":"https://pentest-orchestrator.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-orchestrator","url":"https://pentest-orchestrator.0exec.com","example":"/stats","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"campaign state machine, transitions + campaign_artifacts tables, idempotency_key returns 201/200 same as job-queue pattern, /selftest drives scope-\u003erecon-\u003escan against httptest stubs","trl_ceiling":8,"trl_ceiling_reason":"Bounded by submit-bot's platform-API stability. Once submit-bot ships TRL 8, this trails one step behind at 7-8.","version":{"deployed_at":"2026-08-27T15:18:16Z","sha":"98ee143","version":"0.2.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-payloads","domain":"pentest-payloads.0exec.com","mesh":"0exec","host_port":18101,"category":"security","title":"Pentest Payloads","summary":"Serves payload corpora (XSS/SQLi/SSRF/SSTI/XXE/CRLF/NoSQLi/GraphQL/path-traversal) by class+variant. Random-sample API for taint fuzzing.","tags":["go-pentest"],"openapi_url":"https://pentest-payloads.0exec.com/openapi.json","llms_url":"https://pentest-payloads.0exec.com/llms.txt","health_url":"https://pentest-payloads.0exec.com/health","version_url":"https://pentest-payloads.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-payloads","url":"https://pentest-payloads.0exec.com","example":"/classes","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"9 classes seeded with real-world payloads (xss reflected+polyglot, sqli error+time, ssrf cloud-meta+local, ssti jinja2+twig, xxe, crlf, nosqli, graphql, path-traversal). Random + filter APIs tested.","trl_ceiling":9,"trl_ceiling_reason":"Ceiling = PayloadsAllTheThings as submodule.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-payloads.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-payoff-tracker","domain":"pentest-payoff-tracker.0exec.com","mesh":"0exec","host_port":18148,"category":"infrastructure","title":"Pentest Payoff Tracker","summary":"Self-evaluator. POST /predict captures what finding-triage said before submission; POST /outcome captures what the platform did with it (via triager-listener). GET /calibration returns per-rule precision + per-program ROI. Closes the learning loop.","tags":["go-pentest"],"openapi_url":"https://pentest-payoff-tracker.0exec.com/openapi.json","llms_url":"https://pentest-payoff-tracker.0exec.com/llms.txt","health_url":"https://pentest-payoff-tracker.0exec.com/health","version_url":"https://pentest-payoff-tracker.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-payoff-tracker","url":"https://pentest-payoff-tracker.0exec.com","example":"/stats","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"SQLite ledger with BEGIN IMMEDIATE ingest, amount_cents as INTEGER (no float for money), /stats with percentiles, /scoreboard ordered by payout, /selftest","trl_ceiling":7,"trl_ceiling_reason":"Ceiling lifts once at least ~20 real submissions have flowed through and /calibration is non-empty.","version":{"deployed_at":"2026-08-27T15:10:39Z","sha":"79836b8","version":"0.2.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-rate-coordinator","domain":"pentest-rate-coordinator.0exec.com","mesh":"0exec","host_port":18104,"category":"infrastructure","title":"Pentest Rate Coordinator","summary":"Global per-host token-bucket rate limiter. Every active prober calls POST /acquire {host, weight} before firing — prevents multiple scanners from collectively DDoS-ing a target.","tags":["go-pentest"],"openapi_url":"https://pentest-rate-coordinator.0exec.com/openapi.json","llms_url":"https://pentest-rate-coordinator.0exec.com/llms.txt","health_url":"https://pentest-rate-coordinator.0exec.com/health","version_url":"https://pentest-rate-coordinator.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-rate-coordinator","url":"https://pentest-rate-coordinator.0exec.com","example":"/stats","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"Prometheus /metrics (counter+histogram+gauges), /selftest spawns 100 concurrent acquirers, TestAcquire_Concurrent under -race; 0.2.1 fixes /metrics double-registration panic","trl_ceiling":7,"trl_ceiling_reason":"In-process state — single instance. Multi-instance needs Redis (sethvargo/go-limiter has the backend ready).","version":{"deployed_at":"2026-08-27T15:15:04Z","sha":"8808978","version":"0.2.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-report-templater","domain":"pentest-report-templater.0exec.com","mesh":"0exec","host_port":18114,"category":"security","title":"Pentest Report Templater","summary":"Turns a structured Finding into a platform-ready markdown report. Ships HackerOne/Bugcrowd/Intigriti templates. Optional CVSS enrichment via go-pentest-cvss. Highest-leverage service in the fleet.","tags":["go-pentest"],"openapi_url":"https://pentest-report-templater.0exec.com/openapi.json","llms_url":"https://pentest-report-templater.0exec.com/llms.txt","health_url":"https://pentest-report-templater.0exec.com/health","version_url":"https://pentest-report-templater.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-report-templater","url":"https://pentest-report-templater.0exec.com","example":"/templates","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"3 platform templates using stdlib text/template, custom func map (title/code/indent/add1), CVSS enrichment via go-pentest-cvss with graceful degrade. Tested for render + missing-template + per-platform output.","trl_ceiling":9,"trl_ceiling_reason":"Add org-specific templates + screenshot embed + direct HackerOne API submission.","version":{"deployed_at":"2026-06-29T22:54:56Z","sha":"918c833","version":"0.1.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-scope-guard","domain":"pentest-scope-guard.0exec.com","mesh":"0exec","host_port":18105,"category":"security","title":"Pentest Scope Guard","summary":"Hard scope check before any active prober fires. POST /check {target, program_id} -\u003e {allowed, reason, matched_by}. Matches hostname/wildcard/CIDR/regex; exclusions always win. Legal floor of the pentest fleet.","tags":["go-pentest"],"openapi_url":"https://pentest-scope-guard.0exec.com/openapi.json","llms_url":"https://pentest-scope-guard.0exec.com/llms.txt","health_url":"https://pentest-scope-guard.0exec.com/health","version_url":"https://pentest-scope-guard.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-scope-guard","url":"https://pentest-scope-guard.0exec.com","example":"/programs","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"SQLite persistence with 256-LRU, audit_log with /audit query, ReDoS pattern rejection at create-time, target-normalizer composition with 3-strike circuit breaker, /selftest","trl_ceiling":7,"trl_ceiling_reason":"Ceiling is whatever feeds it programs — once go-pentest-bounty-scope-checker exists, scope-guard is a CDN over its data.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-scope-guard.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-screenshot","domain":"pentest-screenshot.0exec.com","mesh":"0exec","host_port":18129,"category":"security","title":"Pentest Screenshot","summary":"Headless-Chromium screenshot evidence for pentest reports. POST /shot {url,viewport,before_js,after_js} → PNG + DOM hash + title + status. 24h SQLite cache keyed by sha256 of inputs.","tags":["go-pentest"],"openapi_url":"https://pentest-screenshot.0exec.com/openapi.json","llms_url":"https://pentest-screenshot.0exec.com/llms.txt","health_url":"https://pentest-screenshot.0exec.com/health","version_url":"https://pentest-screenshot.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-screenshot","url":"https://pentest-screenshot.0exec.com","example":"/shot?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"chromedp + Chromium in Alpine container; pure-Go SQLite cache; 14 tests pass via fake Capturer (no Chromium needed to build).","trl_ceiling":7,"trl_ceiling_reason":"Bounded by Chromium-headless RAM (1 GiB shm) and the fact that one container is one Chromium instance.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-screenshot.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-secrets-scanner","domain":"pentest-secrets-scanner.0exec.com","mesh":"0exec","host_port":18122,"category":"security","title":"Pentest Secrets Scanner","summary":"Regex+entropy secret scanner. ~30 vendor rules (AWS, GitHub, GitLab, Slack, Stripe, Google, Twilio, SendGrid, Mailgun, Anthropic, OpenAI, HF, Discord, npm, JWT, RSA/EC/OpenSSH/PGP keys).","tags":["go-pentest"],"openapi_url":"https://pentest-secrets-scanner.0exec.com/openapi.json","llms_url":"https://pentest-secrets-scanner.0exec.com/llms.txt","health_url":"https://pentest-secrets-scanner.0exec.com/health","version_url":"https://pentest-secrets-scanner.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-secrets-scanner","url":"https://pentest-secrets-scanner.0exec.com","example":"/rules","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"~30 vendor rules, Shannon-entropy gate via math.Log2, line+context+redaction. Tested vs real-looking fixtures.","trl_ceiling":8,"trl_ceiling_reason":"TRL 8 with verified-secret feature (call vendor API to confirm key is live).","version":{"deployed_at":"2026-06-30T14:49:18Z","sha":"475d228","version":"0.5.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-session-state","domain":"pentest-session-state.0exec.com","mesh":"0exec","host_port":18151,"category":"security","title":"Pentest Session State","summary":"Pentest fleet service","tags":["go-pentest"],"openapi_url":"https://pentest-session-state.0exec.com/openapi.json","llms_url":"https://pentest-session-state.0exec.com/llms.txt","health_url":"https://pentest-session-state.0exec.com/health","version_url":"https://pentest-session-state.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-session-state","url":"https://pentest-session-state.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"2026-08-20 fresh-clone audit (origin/main @ 21f9cb5, go-common@v0.88.0 post-fleet-bump). Confirmed the fleet-wide safehttp fetch-cache bug class does NOT apply: this service makes zero outbound HTTP calls (pure in-memory AuthContext store; no safehttp/NewClient/FetchDelegate anywhere in the repo). Found and live-verified a real credential leak in GET /sessions -- the endpoint self-described as 'redacted' (doc comments + @response docs): redact() stripped Primary/Secondary cookies+headers but never touched AuthContext.Refresh. RefreshFlow.RefreshToken is a raw, inline-rotated secret by design, and RefreshFlow.Headers can carry a live bearer token used to mint it -- both leaked verbatim to any caller holding the fleet API key, unscoped by owner when queried without ?owner=. Reproduced live: POST /session with refresh.refresh_token=\u003cmarker\u003e + refresh.headers.Authorization=\u003cmarker\u003e, then GET /sessions returned both in plaintext on unpatched main. Fix opened as github.com/baditaflorin/go-pentest-session-state PR #7 (fix/list-endpoint-refresh-token-leak, NOT merged): store.go List() now nils Refresh entirely; added TestStore_ListRedactsRefreshToken (fails against pre-fix store.go, passes after); bumped v0.1.2-\u003ev0.1.3. Lowering TRL 7-\u003e6 because the deployed main branch still carries this leak as of this assessment -- restore to 7 once PR #7 merges. Everything else self-reported holds up: session IDs use crypto/rand (9 bytes/72 bits, not predictable/sequential), TTL bounds enforced (60s floor, 7d ceiling), 30s GC ticker reaps expired sessions, /selftest create-\u003eget-\u003edelete round-trip passes, 6 unit tests pass (5 pre-existing + 1 new regression test).","trl_ceiling":8,"trl_ceiling_reason":"TRL 8 requires encrypted-at-rest (SQLite + key-from-go-fleet-secrets) and cross-instance replication (v0.2, not yet landed).","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-session-state.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-ssrf-prober","domain":"pentest-ssrf-prober.0exec.com","mesh":"0exec","host_port":18150,"category":"security","title":"Pentest Ssrf Prober","summary":"Pentest fleet service","tags":["go-pentest"],"openapi_url":"https://pentest-ssrf-prober.0exec.com/openapi.json","llms_url":"https://pentest-ssrf-prober.0exec.com/llms.txt","health_url":"https://pentest-ssrf-prober.0exec.com/health","version_url":"https://pentest-ssrf-prober.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-ssrf-prober","url":"https://pentest-ssrf-prober.0exec.com","example":"/?target=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"2026-08-20 fresh-clone audit (origin/main @ b4ed921, go-common@v0.88.0 post-fleet-bump). Confirmed the fleet-wide safehttp fetch-cache bug class DOES apply here (unlike some siblings): proberOutbound was built via safehttp.NewClient() with no .WithoutFetchCache(), and this service's own pollOOBPage (probe_poll.go) cursor-polls the OOB collector on a 500ms cadence during collectHits -- exactly the kind of call that must never be served stale. Once a fleet deployment sets FLEET_FETCH_CACHE_URL, server.New auto-wires a process-wide DefaultFetchDelegate (go-common/server/fetchcache.go) that transparently intercepts this GET; a cached response for the same token+cursor would repeat the last page forever, so a real live confirmed_ssrf callback landing after the cache warmed could go entirely unobserved -- silently downgrading a genuine finding to a false clean/suspected verdict, the worst failure mode for a vuln scanner. Separately confirmed a real secrets-handling bug: this service's own metadata-class payloads deliberately target credential-issuing endpoints (AWS IMDS iam/security-credentials, GCP/Azure service-account token endpoints, file:///proc/self/environ), but Finding.BodyExcerpt persisted the raw response body verbatim with no redaction, so a successful probe against a real vulnerable target would hand the live SecretAccessKey / session Token / OAuth access_token / PEM private key straight back in this service's own /probe JSON response. Scope-guard and OOB-alloc calls are POST (not cache-eligible) and were unaffected; the paired-control WAF differential, single-use run-scoped correlation IDs, and body-signal reflection-check logic are all sound -- the local 30-case corpus eval (TestCorpus_FPRate: 15 TP incl. adversarial, 15 TN incl. adversarial) passes 100% both before and after this fix, confirming the fix didn't regress detection. Fixed both: added safehttp.WithoutFetchCache() to newProberClient; added redactSecrets() to scrub credential values while preserving evidentiary fields (AccessKeyId, Expiration, field names). Added TestNewProberClientBypassesFetchCache (fails without the fix, verified) and TestRedactSecrets_*/TestRecordHTTPResponse_RedactsBodyExcerpt covering AWS/GCP/Azure/PEM shapes. Bumped 0.3.3-\u003e0.3.4. Fix opened as github.com/baditaflorin/go-pentest-ssrf-prober PR #10 (fix/prober-fetchcache-and-secret-redaction, NOT merged). Lowering TRL 7-\u003e6 because the deployed main branch still carries both bugs as of this assessment -- restore to 7 once PR #10 merges.","trl_ceiling":8,"reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-ssrf-prober.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-subfinder","domain":"pentest-subfinder.0exec.com","mesh":"0exec","host_port":18112,"category":"recon","title":"Pentest Subfinder","summary":"Multi-source passive subdomain enumeration: crt.sh (via our own cert-transparency), HackerTarget, AnubisDB, Wayback. Free sources only.","tags":["go-pentest"],"openapi_url":"https://pentest-subfinder.0exec.com/openapi.json","llms_url":"https://pentest-subfinder.0exec.com/llms.txt","health_url":"https://pentest-subfinder.0exec.com/health","version_url":"https://pentest-subfinder.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-subfinder","url":"https://pentest-subfinder.0exec.com","example":"/sources","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"4 passive sources fanned out in parallel with per-source timing + error capture, merged with dedup + suffix filter. No paid keys required.","trl_ceiling":8,"trl_ceiling_reason":"Add Shodan/Censys/Chaos/SecurityTrails when keys configured.","version":{"deployed_at":"2026-05-27T19:22:07Z","sha":"3b2e92c","version":"0.3.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-submit-bot","domain":"pentest-submit-bot.0exec.com","mesh":"0exec","host_port":18136,"category":"security","title":"Pentest Submit Bot","summary":"Files findings to HackerOne / Bugcrowd / Intigriti via their APIs, or via security.txt email as fallback. Rate-limit + daily-cap aware. Dry-run mode for verification. The actual money step.","tags":["go-pentest"],"openapi_url":"https://pentest-submit-bot.0exec.com/openapi.json","llms_url":"https://pentest-submit-bot.0exec.com/llms.txt","health_url":"https://pentest-submit-bot.0exec.com/health","version_url":"https://pentest-submit-bot.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-submit-bot","url":"https://pentest-submit-bot.0exec.com","example":"/quota","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"SQLite ledger with BEGIN IMMEDIATE on *sql.Conn (canonical pattern), idempotency_key (50-goroutine race test asserts 1 platform call), dry_run mode, /selftest with stubbed platform API","trl_ceiling":8,"trl_ceiling_reason":"Ceiling lifts to 8 once real H1/BC/Intigriti creds are verified end-to-end and the rendered-markdown shape is confirmed against the platforms' parsers.","version":{"deployed_at":"2026-06-29T23:00:35Z","sha":"dbaf41a","version":"0.3.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-takeover-checker","domain":"pentest-takeover-checker.0exec.com","mesh":"0exec","host_port":18121,"category":"security","title":"Pentest Takeover Checker","summary":"Subdomain-takeover scanner. Resolves CNAME, probes HTTP, matches signatures from go-pentest-takeover-fingerprints. Severity none/possible/likely.","tags":["go-pentest"],"openapi_url":"https://pentest-takeover-checker.0exec.com/openapi.json","llms_url":"https://pentest-takeover-checker.0exec.com/llms.txt","health_url":"https://pentest-takeover-checker.0exec.com/health","version_url":"https://pentest-takeover-checker.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-takeover-checker","url":"https://pentest-takeover-checker.0exec.com","example":"/check?host=example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"2-of-3 multi-resolver quorum, confirmed-tier registration probes (GitHub/S3/Heroku), findings-store wire with fail-open, 20 tests across 4 packages","trl_ceiling":7,"reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-takeover-checker.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-takeover-fingerprints","domain":"pentest-takeover-fingerprints.0exec.com","mesh":"0exec","host_port":18116,"category":"security","title":"Pentest Takeover Fingerprints","summary":"Subdomain takeover signature DB. 17 curated vendors (AWS S3, GitHub Pages, Heroku, Fastly, Shopify, Vercel, Netlify, Azure, Cargo, WordPress, Tumblr, Zendesk, Surge, Ghost, ReadMe, Intercom, Unbounce).","tags":["go-pentest"],"openapi_url":"https://pentest-takeover-fingerprints.0exec.com/openapi.json","llms_url":"https://pentest-takeover-fingerprints.0exec.com/llms.txt","health_url":"https://pentest-takeover-fingerprints.0exec.com/health","version_url":"https://pentest-takeover-fingerprints.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-takeover-fingerprints","url":"https://pentest-takeover-fingerprints.0exec.com","example":"/fingerprints","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"17 curated signatures from can-i-take-over-xyz + in-the-wild. CNAME+status+body multi-signal match. Tested positive (S3) + negative cases.","trl_ceiling":8,"reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-takeover-fingerprints.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-target-normalizer","domain":"pentest-target-normalizer.0exec.com","mesh":"0exec","host_port":18102,"category":"infrastructure","title":"Pentest Target Normalizer","summary":"Canonicalizes free-form pentest targets (URL/host/IP/CIDR). Returns kind, eTLD+1, private-IP flag. Foundation primitive every active prober calls before doing anything else.","tags":["go-pentest"],"openapi_url":"https://pentest-target-normalizer.0exec.com/openapi.json","llms_url":"https://pentest-target-normalizer.0exec.com/llms.txt","health_url":"https://pentest-target-normalizer.0exec.com/health","version_url":"https://pentest-target-normalizer.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-target-normalizer","url":"https://pentest-target-normalizer.0exec.com","example":"/?q=https://EXAMPLE.com/path","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"55-row //go:embed golden corpus, /selftest with idempotency assertion, NormalizedVia evidence trail, psl_version in /version","trl_ceiling":8,"trl_ceiling_reason":"Ceiling is whatever publicsuffix list covers; no external deps to break.","version":{"deployed_at":"2026-08-25T23:16:57Z","sha":"4159267","version":"0.2.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-triager-listener","domain":"pentest-triager-listener.0exec.com","mesh":"0exec","host_port":18147,"category":"security","title":"Pentest Triager Listener","summary":"Inbound half of submit-bot. POST /watch registers a submitted bounty report; a 15-min ticker polls HackerOne / Bugcrowd / Intigriti and records state changes (new -\u003e triaged -\u003e duplicate/informative/n_a/resolved). Without it the fleet cannot learn its own duplicate rate or payoff per program.","tags":["go-pentest"],"openapi_url":"https://pentest-triager-listener.0exec.com/openapi.json","llms_url":"https://pentest-triager-listener.0exec.com/llms.txt","health_url":"https://pentest-triager-listener.0exec.com/health","version_url":"https://pentest-triager-listener.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-triager-listener","url":"https://pentest-triager-listener.0exec.com","example":"/stats","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"First-pass audit: corrected the task's framing -- not a findings-ingestion endpoint, it registers bounty-platform reports (HackerOne/Bugcrowd/Intigriti) by {platform,external_id} and polls for status transitions into an audit log. Found and fixed 3 real bugs: (1) fetch-cache masking on adapter clients AND the fleet-secrets vault client -- carrying live bounty-platform credentials and plaintext vault secrets, a confidentiality risk beyond the usual staleness concern; (2) missing mandatory SQLite safety config (SetMaxOpenConns(1)/busy_timeout), matching the exact pattern behind a previously-documented fleet incident (go-apikey-service thread-explosion); (3) a real TOCTOU race in ApplyUpdate -- 20 concurrent identical calls produced 9 duplicate change rows instead of 1, corrupting the audit log; fixed by making the read-then-write atomic. trl bumped 4-\u003e5; trl_ceiling=6 added -- adapters remain unexercised against real platform accounts and the fetch-cache-bypass fix hasn't been validated against a live cache deployment. See PR #3 (merged).","trl_ceiling":6,"trl_ceiling_reason":"Bounded by platform API stability — H1/BC/Intigriti reshape attributes regularly and there's no signed contract.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-triager-listener.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-trufflehog","domain":"pentest-trufflehog.0exec.com","mesh":"0exec","host_port":18120,"category":"security","title":"Pentest Trufflehog","summary":"Trufflehog wrapper: scans repos/git/filesystem for VERIFIED secrets (--only-verified). 700+ detectors live-tested against providers. Upgrades go-pentest-secrets-scanner with verification.","tags":["pentest"],"openapi_url":"https://pentest-trufflehog.0exec.com/openapi.json","llms_url":"https://pentest-trufflehog.0exec.com/llms.txt","health_url":"https://pentest-trufflehog.0exec.com/health","version_url":"https://pentest-trufflehog.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-trufflehog","url":"https://pentest-trufflehog.0exec.com","example":"/","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"wraps pinned trufflehog binary (v3.83.0) with cmdRunner injection seam → ≥13 unit tests covering verified hits, mixed verified/unverified, scope-deny + fail-open, scan timeout, multi-detector summary, async cutover, concurrency cap. Per-finding output carries detector, source(file:line), commit, redacted (first/last 4), raw_match_hash (sha256), severity. Composes with go-pentest-scope-guard (POST /check, fail-open with note), go-pentest-findings-store (POST /findings, dedup_key includes fingerprint), go-pentest-job-queue (POST /jobs at \u003e30s estimated runtime). Hard caps: 4 concurrent scans, 5min wall-clock per scan, 1MiB request body, argv-injection-safe flag value sanitisation.","trl_ceiling":7,"trl_ceiling_reason":"Wraps upstream trufflehog binary; advancing requires custom concurrency control and deduplication.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-trufflehog.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-walkthrough","domain":"pentest-walkthrough.0exec.com","mesh":"0exec","host_port":18139,"category":"infrastructure","title":"Pentest Walkthrough","summary":"HTTP equivalent of go-pentest-cli — single-domain pentest flow as REST API. /preflight, /recon, /findings, /report + /sessions for async scan with per-finding manual triage override. Pause/resume per session.","tags":["go-pentest"],"openapi_url":"https://pentest-walkthrough.0exec.com/openapi.json","llms_url":"https://pentest-walkthrough.0exec.com/llms.txt","health_url":"https://pentest-walkthrough.0exec.com/health","version_url":"https://pentest-walkthrough.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-walkthrough","url":"https://pentest-walkthrough.0exec.com","example":"/preflight","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"4 baked-in markdown templates (ssrf/xss/sqli/idor) via //go:embed, sensitive-header redaction (Cookie/Authorization/X-API-Key -\u003e prefix-only), /selftest exercises all 4 templates","trl_ceiling":8,"trl_ceiling_reason":"Same ceiling as orchestrator — bounded by submit-bot end-to-end verification.","version":{"deployed_at":"2026-08-27T15:29:14Z","sha":"b57cc10","version":"0.3.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-wayback-urls","domain":"pentest-wayback-urls.0exec.com","mesh":"0exec","host_port":18127,"category":"recon","title":"Pentest Wayback Urls","summary":"Historical URL discovery via web.archive.org CDX. Returns every URL ever crawled with status + MIME + auto-flagged interesting extensions (.bak/.sql/.env/.zip).","tags":["go-pentest"],"openapi_url":"https://pentest-wayback-urls.0exec.com/openapi.json","llms_url":"https://pentest-wayback-urls.0exec.com/llms.txt","health_url":"https://pentest-wayback-urls.0exec.com/health","version_url":"https://pentest-wayback-urls.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-wayback-urls","url":"https://pentest-wayback-urls.0exec.com","example":"/urls?domain=example.com\u0026limit=5","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":7,"trl_evidence":"2026-08-20 audit against a fresh clone of origin/main (commit 3bba02d, post go-common@v0.88.0 bump): confirmed the CDX client, retry/backoff (503/429-aware, linear backoff), archive-state classification, URL canonicalization/scope-filtering, and interesting-path/extension dedup all work as documented (existing 8-test suite passes). Found and fixed one real, live-confirmed reliability bug: Fetch() queried the CDX API as url=*.\u003cscope\u003e/* (compound leading+trailing wildcard) to cover the domain + subdomains across all paths. Verified live against web.archive.org: this returns byte-identical rows to the simpler url=\u003cscope\u003e\u0026matchType=domain for hackerone.com, testphp.vulnweb.com, and github.io, but the wildcard form is dramatically slower on IA's CDX backend -- 8-9s for hackerone.com and an outright timeout past 40s for testphp.vulnweb.com (exceeding the service's own 30s HTTP client timeout), vs ~1s for matchType=domain on all three. Against an API this service's own retry logic already treats as slow/rate-limited, the slower query shape burned timeout/retry budget for no benefit and could exhaust max_attempts on ordinary domains. Also confirmed the recurring fleet HTTP-client-cache bug class does NOT apply here: the CDX GET is a legitimate caching candidate (historical URL lists aren't time-sensitive), and the separate live-liveness recheck in verify.go (used for promotion decisions) issues an HTTP HEAD, which safehttp's fetch-cache delegate never routes (GET-only, confirmed in go-common@v0.88.0 safehttp/extras_extras_transport.go) -- so promotion is unaffected by caching either way. Fixed the query construction to url=\u003cscope\u003e\u0026matchType=domain, added a regression test asserting the outbound query has no wildcard and carries matchType=domain (confirmed it fails against the pre-fix query and passes post-fix), re-verified end-to-end against testphp.vulnweb.com (previously timed out; now 1 attempt / ~1.1s), and bumped the service to v0.4.5. Fixed in PR #11 (https://github.com/baditaflorin/go-pentest-wayback-urls/pull/11, not yet merged as of this assessment). TRL held at 7 pending merge/deploy; evidence trail and test coverage otherwise support 7, ceiling unchanged at 8 (no structural blocker).","trl_ceiling":8,"reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-wayback-urls.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"pentest-wordlists","domain":"pentest-wordlists.0exec.com","mesh":"0exec","host_port":18100,"category":"security","title":"Pentest Wordlists","summary":"Serves curated pentest wordlists (dirs, subdomains, params, fuzz) by category with SHA256 integrity. Random-sample API. Designed to grow via SecLists submodule.","tags":["go-pentest"],"openapi_url":"https://pentest-wordlists.0exec.com/openapi.json","llms_url":"https://pentest-wordlists.0exec.com/llms.txt","health_url":"https://pentest-wordlists.0exec.com/health","version_url":"https://pentest-wordlists.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-pentest-wordlists","url":"https://pentest-wordlists.0exec.com","example":"/lists","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Disk-backed catalog with SHA256, reservoir-sample random API, paged reads. Ships with starter dirs/subdomains/params. CPU-only.","trl_ceiling":9,"trl_ceiling_reason":"Ceiling = SecLists submodule contents.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://pentest-wordlists.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"plausible","domain":"dockerhost:18204","mesh":"0exec","host_port":18204,"category":"infrastructure","title":"Plausible Analytics","summary":"Self-hosted Plausible Analytics (ghcr.io/plausible/community-edition). Third-party upstream container — its own docker-compose lives at /opt/services/plausible/ and is managed by hand (NOT by fleet-runner). Registered here so allocate-port and audit-port know host_port 18204 is claimed.","tags":["analytics","external","third-party"],"openapi_url":"http://dockerhost:18204/openapi.json","llms_url":"http://dockerhost:18204/llms.txt","health_url":"http://dockerhost:18204/api/health","version_url":"http://dockerhost:18204/.deploy/version.json","repo_url":"https://github.com/plausible/community-edition","url":"http://dockerhost:18204","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"HTTP 400"},{"slug":"postmessage","domain":"postmessage.0exec.com","mesh":"0exec","host_port":18027,"category":"security","title":"Postmessage","summary":"Static scan for window.postMessage listeners missing origin checks (XS-Leak risk)","tags":["go","pentest","security"],"openapi_url":"https://postmessage.0exec.com/openapi.json","llms_url":"https://postmessage.0exec.com/llms.txt","health_url":"https://postmessage.0exec.com/health","version_url":"https://postmessage.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_postmessage_listener_finder","url":"https://postmessage.0exec.com","example":"/go_postmessage_listener_finder?target=https://stripe.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"v0.2.0 (TRL 6) — AST-aware classification via tdewolff/parse/v2/js.\nFindings carry per-listener missing|weak|strong taxonomy for both\norigin and source checks, plus the dangerous method name when weak\n(indexOf, includes, startsWith, endsWith, search, match, test, exec).\nRegex remains as a fallback for unparseable JS, marked confidence=regex.\n24 unit tests cover: missing-origin (high), weak indexOf (high),\nweak includes (high), strong origin alone (medium), strong both (low),\nonmessage assignment, Object.defineProperty, arrow handlers, regex\nfallback path, line/col location, summary aggregation, verdict\nrollup, and POST-body / ?url= handler shapes.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://postmessage.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"proto-pollution","domain":"proto-pollution.0exec.com","mesh":"0exec","host_port":18028,"category":"security","title":"Proto Pollution","summary":"Static scan for prototype-pollution sink patterns (Object.assign, lodash.merge, deepmerge) in recovered JS bundles.","tags":["go","pentest","security"],"openapi_url":"https://proto-pollution.0exec.com/openapi.json","llms_url":"https://proto-pollution.0exec.com/llms.txt","health_url":"https://proto-pollution.0exec.com/health","version_url":"https://proto-pollution.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go_prototype_pollution_static","url":"https://proto-pollution.0exec.com","example":"/go_prototype_pollution_static?target=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Static scan for known sink patterns (Object.assign, lodash.merge by hash). Active probe documented but not wired. 6 tests pass.","trl_ceiling":7,"trl_ceiling_reason":"Static-only without endpoint discovery; reaches TRL 7 once wired to api-extractor for auto-probe targets.","reachable":false,"last_checked":"2026-09-11T21:09:08Z","error":"Get \"https://proto-pollution.0exec.com/.deploy/version.json\": remote error: tls: unrecognized name"},{"slug":"proxy","domain":"proxy.0exec.com","mesh":"0exec","host_port":18002,"category":"proxy","title":"Proxy (Go)","summary":"HTTP proxy with rotation (?url=)","tags":["go","proxy"],"openapi_url":"https://proxy.0exec.com/openapi.json","llms_url":"https://proxy.0exec.com/llms.txt","health_url":"https://proxy.0exec.com/health","version_url":"https://proxy.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-proxy","url":"https://proxy.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass) of this general HTTP proxy, primed to check for the SSRF-guard-built-but-bypassed bug class found in multiple sibling proxies this initiative. Confirmed exactly that: the SSRF validator ran a one-time DNS lookup at request-validation time, but the actual outbound client used a bare http.Transport with no custom DialContext/CheckRedirect -- vulnerable to DNS-rebind/TOCTOU (two independent lookups seconds apart) and redirect-based SSRF (Go's default client follows redirects with zero re-validation of Location). Direct SSRF payloads were already correctly blocked; it was the second-order paths that were open. Fixed by migrating to go-common/safehttp.NewClient() (the fleet's own documented SSRF-safe dialer that re-validates on every dial including redirects), plus added WithoutFetchCache/WithForceHTTP2 and capped previously-unbounded request/response body sizes (DoS gap). Live-tested against real SSRF payloads (169.254.169.254, localhost, internal IPs, file://) -- all rejected post-fix; legitimate traffic unaffected. trl bumped 5-\u003e6; trl_ceiling=8. See github.com/baditaflorin/go-proxy PR #4 (merged).","version":{"deployed_at":"2026-08-26T16:09:34Z","sha":"c69ee1d","version":"0.2.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"python-proxy","domain":"python-proxy.0exec.com","mesh":"0exec","host_port":18177,"category":"proxy","title":"Python aiohttp Proxy","summary":"aiohttp-based forward proxy with rotating user-agent.","tags":["proxy","python","proxy","http","scraping"],"openapi_url":"https://python-proxy.0exec.com/openapi.json","llms_url":"https://python-proxy.0exec.com/llms.txt","health_url":"https://python-proxy.0exec.com/health","version_url":"https://python-proxy.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/python-proxy","url":"https://python-proxy.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (aiohttp.web forward proxy through a Webshare upstream), tested adversarially against a real local test harness. Found and fixed 3 real bugs: (1) SSRF with no real guard -- validate_url() only checked URL shape, never resolved IPs; proved exploitable reaching an internal test service via a public DNS name resolving to loopback, and confirmed cloud-metadata (169.254.169.254) and a literal address in the fleet's own docker-mesh subnet shape both passed validation; fixed with real IP-range resolution/blocking, re-checked on every redirect hop (one residual TOCTOU DNS-rebind gap honestly documented, not overclaimed). (2) Unbounded response buffering -- a decompression-bomb response (100KB-\u003e100MB, aiohttp auto_decompress) ballooned process RSS from 19MB to 899MB under 8 concurrent requests, enough to OOM the fleet's default 1g container; fixed with a streaming capped reader. (3) Status-code swallowing -- always returned HTTP 200 regardless of real upstream status. Also bumped a pinned aiohttp version GitHub's own push-protection flags with 40 known vulnerabilities (request smuggling + the zip-bomb advisory above). trl bumped 4-\u003e6; trl_ceiling=7 added -- single upstream vendor, no failover/circuit-breaker, no JS rendering. See PR #1 (merged).","version":{"deployed_at":"2026-09-09T03:53:04Z","sha":"942d384","version":"0.1.1"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"random-proxy","domain":"random-proxy.0exec.com","mesh":"0exec","host_port":18019,"category":"proxy","title":"Round-Robin Proxy Front","summary":"Round-robins requests across c-proxy, go-proxy, node-proxy, python-proxy.","tags":["proxy","proxy","load-balancer"],"openapi_url":"https://random-proxy.0exec.com/openapi.json","llms_url":"https://random-proxy.0exec.com/llms.txt","health_url":"https://random-proxy.0exec.com/health","version_url":"https://random-proxy.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/random-proxy","url":"https://random-proxy.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"First-pass audit of this round-robin proxy-pool rotator: found a real bug that is CURRENTLY LIVE in production -- zero dead-backend failover, confirmed via 12 live requests against production showing a repeating 301/200/200/502 pattern, meaning ~25% of all production traffic is currently failing with no self-healing. Fixed with bounded retry to the next host on dial/connect failure (capped at len(hosts) attempts so a fully-dead pool fails fast), a response-write tracker so a backend that starts streaming and dies mid-response is never double-written, and body-buffering so retries resend the request body intact. Also fixed a /health contract mismatch (service.yaml declares 200, real behavior was 400). Confirmed the round-robin index itself was already correctly atomic/race-free (verified under go test -race) and no credential leak in logs. trl bumped 3-\u003e5; trl_ceiling=8 added -- the round-robin core was always sound, the gap was zero tests plus a confirmed live production failure mode, now fixed and tested; no structural blocker to reaching 6-7 with modest further work (active health checks, /selftest). See PR #1 (merged).","version":{"deployed_at":"2026-08-27T15:34:42Z","sha":"628f699","version":"0.1.3"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"search-duck","domain":"search-duck.0exec.com","mesh":"0exec","host_port":18013,"category":"search","title":"Search DuckDuckGo (Go)","summary":"DuckDuckGo SERP scraper in Go (?query=)","tags":["go","search"],"openapi_url":"https://search-duck.0exec.com/openapi.json","llms_url":"https://search-duck.0exec.com/llms.txt","health_url":"https://search-duck.0exec.com/health","version_url":"https://search-duck.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-search-duck","url":"https://search-duck.0exec.com","example":"/?query=anthropic+claude","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"First-pass audit of go-search-duck (Go, proxies every request through go-html-proxy via a hand-rolled client, never imports go-common -- confirmed fetch-cache masking does not apply here). Confirmed genuinely distinct from siblings search-duck-go (a more mature go-common-based rewrite, direct DDG fetch, in-process cache) and node-search-duck (a functional Node/TS twin) -- not a duplicate of either, more of a planned-successor relationship with search-duck-go. Live DDG testing confirmed the parsing/CAPTCHA/zero-result logic is genuinely correct against today's markup. Found and fixed 2 real bugs: (1) a timeout-detection check (err == context.DeadlineExceeded) that could never actually match, since net/http always wraps transport errors differently -- confirmed unreachable with a standalone repro, replaced with an errors.Is-based helper. (2) flag.Parse() called from init(), which broke 'go test ./...' entirely and is almost certainly why this repo had zero tests until now -- fixed by moving config loading into main(). Added the repo's first test suite (10 cases from live DDG fixtures). Noted (not fixed here, sibling's own scope): search-duck-go has the fetch-cache-masking bug, flagged for that repo's own audit. Also noted a live-ops issue: the deployed instance returned 502 from its own configured proxy on every query at audit time. trl held at 5 (grounding the catalog's existing low-effort assessment in real evidence); trl_ceiling=6 added -- structurally a CSS-selector scrape of an adversarial third-party page proxied through another internal service. See PR #2 (merged).","version":{"deployed_at":"2026-05-19T16:23:33Z","sha":"eac7b6e","version":"0.1.2"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"url-categorizer-api","domain":"url-categorizer-api.0exec.com","mesh":"0exec","host_port":18244,"category":"nlp","title":"Url Categorizer Api","summary":"URL categorization API - classifies URLs by topic/category","tags":["categorization","go"],"openapi_url":"https://url-categorizer-api.0exec.com/openapi.json","llms_url":"https://url-categorizer-api.0exec.com/llms.txt","health_url":"https://url-categorizer-api.0exec.com/health","version_url":"https://url-categorizer-api.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/go-url-categorizer-api","url":"https://url-categorizer-api.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":5,"trl_evidence":"v1.6.226 CUSTOM_SEARCH_API_KEY env support added; service running in domainscope staging stack.","version":{"deployed_at":"2026-08-30T14:43:56Z","sha":"2d7f811c","version":"1.98.22"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"utils-readcontent","domain":"utils-readcontent.0exec.com","mesh":"0exec","host_port":18018,"category":"content","title":"Read Content Extractor","summary":"Extract readable text/markdown from a URL or raw HTML.","tags":["content","nlp","scraping","content-extraction"],"openapi_url":"https://utils-readcontent.0exec.com/openapi.json","llms_url":"https://utils-readcontent.0exec.com/llms.txt","health_url":"https://utils-readcontent.0exec.com/health","version_url":"https://utils-readcontent.0exec.com/.deploy/version.json","repo_url":"https://github.com/baditaflorin/utils-readcontent","url":"https://utils-readcontent.0exec.com","example":"/?url=https://example.com","auth":{"header":"X-API-Key","query_param":"api_key","type":"api_key"},"auth_help":"api_key required (header X-API-Key or ?api_key=)","trl":6,"trl_evidence":"First-pass audit (fresh 220-domain sample, live before/after on a running fleet instance): found and fixed 4 real bugs -- encoding corruption on non-UTF-8 pages, output=markdown (the primary documented use case) being completely broken (0/49 real markdown outputs before the fix, 36/49 after across 9 languages), log-flooding from an ignored LOG_LEVEL env var (33.9MB of logs per 100 requests before, 4KB after), and dead code containing a hardcoded live-looking Google API key plus proxy credentials (removed). Confirmed this is a real shared dependency for at least 5 downstream services (go_price_range, go_cognitive_load, go_emotional_tone, go_google_taxonomy, go_remote_detector). Confirmed the fetch-cache-masking bug class doesn't apply (pure Node/TypeScript, no go-common dependency). trl held at 6 -- a documented multipart file/text-upload capability doesn't exist in code at all, flagged separately. trl_ceiling=7 added -- static-HTML-only fetch, no JS rendering. See PR #3 (merged).","version":{"deployed_at":"2026-05-19T17:03:05Z","sha":"87853f7","version":"0.1.0"},"reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"accent-coach","domain":"baditaflorin.github.io/accent-coach/","mesh":"pages","category":"wellness","title":"Accent Coach","summary":"Private browser-based accent coach that analyzes speech and drills phoneme-level pronunciation.","health_url":"https://baditaflorin.github.io/accent-coach/","repo_url":"https://github.com/baditaflorin/accent-coach","url":"https://baditaflorin.github.io/accent-coach/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"First-pass audit of this browser-based accent/phoneme coach (classical 12th-order LPC + Durand-Kerner formant analysis, no WASM/ML model): privacy claim verified clean via live network capture during load, mic-denial, and analysis -- zero external calls anywhere, matches README/SECURITY.md exactly. Core functionality handled silence/empty/very-short/very-long clips and no-mic-permission gracefully. Found and fixed a real bug: analyzeFormants enters an infinite loop if sampleRate is 0, negative, or non-finite (hopSize rounds to 0, so the scan offset never advances) -- not reachable via the actual recording pipeline today, but a genuine unguarded hang other code could trigger; fixed with an early-return guard and a hopSize floor. No XSS surface, accessibility basics solid. trl held at 4; trl_ceiling=6 added -- classical LPC-based formant tracking has genuine structural accuracy limits (harmonic/formant confusion, only 3 curated practice sentences) blocking it from 'production, SLA-grade' without a fundamentally different acoustic-model architecture. See PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"anon-conf-poll","domain":"baditaflorin.github.io/anon-conf-poll/","mesh":"pages","category":"app","title":"Anon Conf Poll","summary":"Static, anonymous live polling with CRDT sync, zk one-vote proofs, and local analytics.","health_url":"https://baditaflorin.github.io/anon-conf-poll/","repo_url":"https://github.com/baditaflorin/anon-conf-poll","url":"https://baditaflorin.github.io/anon-conf-poll/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"First-pass audit of this anonymous conference-polling app (real @semaphore-protocol v4.12.1 zk-SNARK library, y-webrtc/Yjs CRDT mesh, libsodium Ed25519 host signing): the anonymity/one-vote claim verified as genuine, not a placeholder -- every vote is independently re-verified by every peer via real verifyProof before tallying, and the one-vote guarantee is enforced through the Semaphore nullifier (deduped in tally logic), not client-side state; confirmed clearing localStorage/incognito/replay all fail to bypass it. Found and fixed a real CRDT bug: tallyVotes/summarizeDuplicateVotes/uniqueQuestions picked the dedup 'winner' by sorting on createdAt alone -- when two records from the same nullifier tied on createdAt (millisecond-identical), the tie-break depended on each peer's local Y.Map iteration order (network-arrival-dependent), so two honest, fully-synced peers could disagree on the tally for a tied pair; reproduced concretely with a standalone multi-peer Yjs simulation. Fixed with a deterministic tie-break keyed on the record's unique id. Vote counts themselves were never wrong -- only which record wins a tie could diverge. trl bumped 3-\u003e4; trl_ceiling=5 added -- no server component to hold to a higher bar, anonymity strength is explicitly room-size-dependent per the project's own honest privacy docs, and one-vote enforcement's Sybil-resistance ultimately rests on the host distributing exactly one invite per attendee (an operational trust assumption, not a code flaw). See PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"audience-field-sculpture","domain":"baditaflorin.github.io/audience-field-sculpture/","mesh":"pages","category":"app","title":"Audience Field Sculpture","summary":"A privacy-preserving browser artwork — phones read a sculpture tag and shift visuals/audio from local viewing patterns. No surveillance.","health_url":"https://baditaflorin.github.io/audience-field-sculpture/","repo_url":"https://github.com/baditaflorin/audience-field-sculpture","url":"https://baditaflorin.github.io/audience-field-sculpture/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"First-pass audit of this ArUco-marker-based privacy-preserving browser artwork (js-aruco2 camera detection, no NFC/QR/Bluetooth): privacy claim verified true via full source + built-bundle grep -- zero fetch/XHR/WebSocket/RTCPeerConnection anywhere, camera frames go straight to an offscreen canvas and are never serialized or sent anywhere, mic never requested. All DOM writes use textContent (no XSS/injection path for tag-derived data). Found and fixed a real bug: the requestAnimationFrame render loop had no exception containment -- a single throw inside tick() (from the third-party detector library, or canvas/Web Audio calls) would abort the callback before it re-scheduled itself, silently and permanently freezing the artwork with no error shown and no recovery short of a page reload -- a real risk for an always-on public installation. Fixed with a Result-returning wrapper matching the codebase's existing idiom; on a caught exception the app now stops cleanly with a persistent, actionable error. trl held at 3; trl_ceiling=4 added -- genuinely well-engineered early-stage project (strict TS, 93%+ tested-layer coverage) but shouldn't go above 4 until someone runs the real-phone measurement pass the project's own docs already flag as outstanding. See PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"audio-repair-lab","domain":"baditaflorin.github.io/audio-repair-lab/","mesh":"pages","category":"app","title":"Audio Repair Lab","summary":"Browser-based audio repair toolkit for noise removal, vocal isolation, and quick podcast/music cleanup.","health_url":"https://baditaflorin.github.io/audio-repair-lab/","repo_url":"https://github.com/baditaflorin/audio-repair-lab","url":"https://baditaflorin.github.io/audio-repair-lab/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"First-pass audit of this browser audio-repair toolkit (corrected the catalog's 'WASM DSP/ML model' framing -- it's pure TypeScript FFT-based spectral noise gating and heuristic mid/side/bandpass 'vocal isolation,' no WASM, no ML source separation): privacy verified via a full network-panel watch through a real import-\u003eprocess-\u003eexport cycle in an actual browser -- nothing left the machine. Core processing correct across 9 real-world fixtures plus 14 synthetic edge cases (silence, clipping, 1-sample clips, 192kHz, 5.1 downmix) with deterministic output. Found and fixed a real memory bug: no real ceiling existed for large files (only a soft 30s/10MB warning, nothing blocking), and processAudioData redundantly cloned already-normalized channel buffers a second time for zero benefit -- measured a synthetic 30-minute 48kHz stereo clip (this app's stated use case, a full podcast episode) pushing worker RSS to ~2.5GB against only ~690MB of raw decoded PCM, a real risk of a crashed/hung tab. Fixed by removing the redundant clone and wiring up the hard \u003e450MB ceiling an existing ADR documented as intent but never implemented. trl bumped 4-\u003e5; trl_ceiling=6 added -- well-engineered, honestly-scoped tool (extensive ADRs, real-fixture test suite) but has a real structural ceiling: no ML source separation, just spectral gating/heuristics on a single worker with no streaming, will never match server-side/paid tools for source-separation quality. See PR #8 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"automata-lab","domain":"baditaflorin.github.io/automata-lab/","mesh":"pages","category":"app","title":"Automata Lab","tags":["kind-static","language-html","runtime-github-pages"],"health_url":"https://baditaflorin.github.io/automata-lab/","repo_url":"https://github.com/baditaflorin/automata-lab","url":"https://baditaflorin.github.io/automata-lab/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":6,"trl_evidence":"First-pass audit (never assessed before, no summary in catalog): confirmed real and complete -- 3 correctly-implemented cellular-automaton simulators (Conway's Life B3/S23, Gray-Scott reaction-diffusion, Lenia/Orbium), 24/24 tests pass (blinker period-2 oscillation, glider translation, Gray-Scott boundedness/determinism, Lenia kernel normalization all verified as real correctness invariants, not just smoke tests). Verified live in-browser under adversarial parameter extremes (all sliders maxed simultaneously at 20x speed) with no NaN/crash; the animation loop already caps ticks-per-frame at a budget of 6 before scheduling the next frame -- a deliberate, already-present guard against exactly the 'heavy sim freezes the tab' bug class. Grid sizes are hardcoded constants (no user control to grow them, so unbounded-grid-size hang doesn't exist as an attack surface) and all parameters are range-clamped HTML inputs (invalid rule input structurally impossible from the UI). No real bug found -- genuinely clean audit, no PR needed. trl=6, trl_ceiling=7 -- mathematically-correct, well-documented implementations (cited Gray-Scott/Lenia references) with genuine unit-test coverage, clean build, verified working end-to-end; capped below 8-9 since it's a static single-purpose client-side demo with no backend/SLA concept.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"bilateral-memory-processing","domain":"baditaflorin.github.io/bilateral-memory-processing/","mesh":"pages","category":"archive","title":"Bilateral Memory Processing","summary":"Private browser-based EMDR-inspired audio journaling with local transcription, reflection prompts, and no trauma uploads.","health_url":"https://baditaflorin.github.io/bilateral-memory-processing/","repo_url":"https://github.com/baditaflorin/bilateral-memory-processing","url":"https://baditaflorin.github.io/bilateral-memory-processing/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"First-pass audit of this EMDR-inspired local audio-journaling app (Whisper transcription + WebLLM reflection, both fully client-side): privacy claim verified holds up via full network-call trace (only model-weight fetches, never audio/text). Found and fixed a real data-loss-appearing bug: sessionRepository.listSessions() validated each IndexedDB row with SavedSessionSchema.parse() inside .map(), which throws on the first row that doesn't match the schema, rejecting the whole call -- the UI then silently showed 'Nothing has been saved in this browser,' indistinguishable from real data loss, even though every session was still intact on disk. Fixed by switching to safeParse per row (bad rows skipped, left untouched, never deleted); also memoized a previously-leaked-per-call IndexedDB connection. trl bumped 2-\u003e4 (current trl=2 undersold real multi-step logic and genuine local Whisper/WebLLM integration); no trl_ceiling -- static browser-only app by design, but nothing structurally blocks maturing toward 6-8 with dependency hygiene, CI, and broader test coverage. Separately flagged: 21 known vulnerabilities (1 critical, 9 high) in transitive devDependencies, dev/build-time only. See PR #9 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"castle-archive-memory-vault","domain":"baditaflorin.github.io/castle-archive-memory-vault/","mesh":"pages","category":"archive","title":"Castle Archive Memory Vault","summary":"Private, local-first voice reflection vault for retreats. Whisper + sentence-transformers + age + DuckDB + Markdown export, all in the browser.","health_url":"https://baditaflorin.github.io/castle-archive-memory-vault/","repo_url":"https://github.com/baditaflorin/castle-archive-memory-vault","url":"https://baditaflorin.github.io/castle-archive-memory-vault/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"First-pass audit of this local-first voice-reflection vault for retreats (Whisper + WebLLM, both running fully client-side via ONNX/WASM in Web Workers -- only model *weights* are fetched remotely, never audio/text): privacy/local-first claim verified genuinely holds up via full network-call trace. Data persistence (IndexedDB/OPFS) sound, no bug found there. Found and fixed a real data-corruption bug: embed() and transcribe() each lazily create one shared Worker reused by every caller with no request-correlation id, so if a user switched to the Search tab while a reflection was still saving in the background, a search query's embedding could silently get attached to the wrong saved entry (or vice versa), permanently corrupting that entry's semantic-search ranking with no visible error. Fixed with per-request correlation ids. trl held at 3 (a real, previously-unnoticed correctness bug just surfaced in the core search pipeline, and no evidence of real-world multi-attendee usage yet); trl_ceiling=6 added -- solo-maintainer project, no CI pipeline, manual/technical key-sharing UX that's a real support burden for non-technical retreat attendees, Whisper-tiny is a low-accuracy tradeoff. See PR #15 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"chatwrapped","domain":"baditaflorin.github.io/chatwrapped/","mesh":"pages","category":"app","title":"Chatwrapped","tags":["kind-static","language-html","runtime-github-pages"],"health_url":"https://baditaflorin.github.io/chatwrapped/","repo_url":"https://github.com/baditaflorin/chatwrapped","url":"https://baditaflorin.github.io/chatwrapped/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":7,"trl_evidence":"First-pass audit (never assessed before): confirmed real, complete, and working -- a client-side 'Spotify Wrapped'-style chat-export stat generator, zero backend, deployed live. Privacy claim (100% on-device) verified genuinely true via full source grep -- no fetch/XHR/WebSocket/analytics anywhere. Found and fixed a real bug: the emoji-counting regex (\\p{Extended_Pictographic}) missed flag emoji (regional-indicator pairs) and keycap sequences entirely, so a chat full of country flags or a countdown would show zero for those glyphs in the advertised 'Top emoji' feature. trl=7, trl_ceiling=8 -- fully built, deployed, correctly functioning app with a real 35-test automated suite and a working build/smoke gate, well past prototype; capped below 9 since there's no CI (manual local smoke gate stands in) and, by privacy-first design, no telemetry exists to evidence sustained real-world usage. See PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"complete-gardener-planner","domain":"baditaflorin.github.io/complete-gardener-planner/","mesh":"pages","category":"app","title":"Complete Gardener Planner","summary":"Static-first planner for plant ID, crop rotation, sun, soil, watering, frost, and harvest forecasts.","health_url":"https://baditaflorin.github.io/complete-gardener-planner/","repo_url":"https://github.com/baditaflorin/complete-gardener-planner","url":"https://baditaflorin.github.io/complete-gardener-planner/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"First-pass audit of this static-first garden/crop-rotation planner: found and fixed 2 real bugs. (1) Crop rotation anchored on the alphabetically-first selected crop only, ignoring the rest of the bed -- concretely, selecting marigold+tomato anchored on marigold ('flower') and completely missed that tomato (nightshade family) shouldn't be replanted for years, recommending a real horticultural error while claiming to move away from pressure; fixed to consider every selected crop's family. (2) Share links caused silent, repeating data loss -- loading a shared plan from the URL hash never cleared the hash, so reloading that tab or revisiting a bookmarked link would silently overwrite the user's own autosaved local plan every time with no confirmation or recovery path; fixed by clearing the hash once consumed. No XSS found (pure JSX interpolation); plant-ID is honestly labeled as heuristic, not a hidden ML claim. trl bumped 3-\u003e4; trl_ceiling=6 added -- genuinely working, well-documented static PWA with real computation (SunCalc solar-position math, a yield model) and honest labeling, but a single-maintainer hobby project with a heuristic (not trained-ML) plant-ID feature. See PR #7 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"cookiecutter-data-science","domain":"drivendata.github.io/cookiecutter-data-science/","mesh":"pages","category":"app","title":"Cookiecutter Data Science","summary":"A logical, reasonably standardized, but flexible project structure for doing and sharing data science work.","health_url":"http://drivendata.github.io/cookiecutter-data-science/","repo_url":"https://github.com/baditaflorin/cookiecutter-data-science","url":"http://drivendata.github.io/cookiecutter-data-science/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"First-pass audit: confirmed a genuine, unmodified fork of the well-known upstream DrivenData cookiecutter-data-science template (isFork:true, byte-for-byte identical template payload at the fork point) -- correctly left the vendored template's core structure alone rather than attempting a risky upstream re-sync. Real local finding: 12 commits since the fork point had accidentally propagated this fleet's onboarding automation (CLAUDE.md, SERVICE-TEMPLATE.md, git hooks) into this unrelated public repo, publishing internal fleet ops detail (auth flow, token-rotation playbook, mesh domains -- no literal secrets, but real information disclosure about unrelated infrastructure) with no bearing on what this repo actually is. Removed. trl held at 4; trl_ceiling=6 added -- the template itself is genuinely functional (verified end-to-end: generation, install, tests all pass) but this fork is frozen ~4+ years behind upstream with no CI of its own; periodic re-sync from upstream is the only lever, not local engineering. See PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"crystal-growth-simulator","domain":"baditaflorin.github.io/crystal-growth-simulator/","mesh":"pages","category":"app","title":"Crystal Growth Simulator","summary":"Live browser simulator for snowflake, dendrite, and coral-like crystal growth with WebGPU visuals and sonified physics.","health_url":"https://baditaflorin.github.io/crystal-growth-simulator/","repo_url":"https://github.com/baditaflorin/crystal-growth-simulator","url":"https://baditaflorin.github.io/crystal-growth-simulator/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"First-pass audit of this browser phase-field (Allen-Cahn-style) crystal-growth simulator (WebGPU compute shader with a CPU JS fallback): found a critical bug -- the stochastic noise term was gated by (1-phase), non-zero across the ENTIRE grid rather than just the growth interface, and at the shipped undercooling/nutrient values background (phase=0) is a linearly unstable fixed point, so noise spontaneously nucleated solid across the whole domain at once around step ~20-25 (confirmed via instrumented radius-growth tracing: 5.5%%-\u003e138%% of center-to-edge in one step, reproduced for all 3 presets independent of grid size); at real frame rates the 'snowflake' would explode into full-screen static within about a second of pressing Start, meaning the app essentially never showed a real crystal in any normal session. Fixed by gating noise with front (phase*(1-phase), zero in untouched background) in both the CPU and WGSL paths, verified mathematically and live in-browser (~50s sustained run at ~80fps, smooth gradual growth, no errors). Also flagged 3 lower-severity issues, not fixed: the 'Coral mineral' preset renders as a 7-pointed star rather than the amorphous disk its own code comment documents; a toroidal grid boundary causes a maze-fill on long runs once a crystal reaches the edge; the CPU-fallback lower-resolution claim in the postmortem is never actually implemented. trl/trl_ceiling held at 4/4 -- the core 'does it actually grow a recognizable crystal' promise was broken in every normal session before this fix, and the 3 flagged-not-fixed issues are real user-visible gaps worth triaging before raising the ceiling. See PR #7 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"cursorparty","domain":"baditaflorin.github.io/cursorparty/","mesh":"pages","category":"app","title":"Cursorparty","summary":"Shared cursors and sticky notes on an infinite canvas. P2P over a self-hosted WebRTC mesh. GitHub-Pages-only, no backend.","health_url":"https://baditaflorin.github.io/cursorparty/","repo_url":"https://github.com/baditaflorin/cursorparty","url":"https://baditaflorin.github.io/cursorparty/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"First-pass audit of this P2P shared-cursor/sticky-note infinite-canvas app (Yjs CRDT over y-webrtc, self-hosted signaling/TURN): confirmed the exact classic CRDT bug the audit was primed to look for -- Y.Map#delete() loses unconditionally to any concurrent set() on the same key, so deleting a note another peer is mid-edit on always resurrects it with the edit's content regardless of real-time ordering; reproduced with real multi-Y.Doc merges. Also found and fixed a real crash: nothing validates the runtime shape of Y.Map values from peers, so a peer writing e.g. null for a note key crashes the sort call with no try/catch anywhere in the chain and no ErrorBoundary in the app -- one bad peer write breaks every other peer's live sync. Fixed both: delete now uses a deleted:true tombstone via set() (same deterministic LWW rule as any edit, no asymmetric resurrection bias), plus runtime validation guards. Added the repo's first-ever tests. No privacy leak found (visibility matches the honestly-documented threat model). Catalog's 'infinite canvas' claim doesn't match reality -- no pan/zoom exists, just a fixed-viewport 0-1 fractional-position canvas (noted, not fixed). trl held at 3; trl_ceiling=6 added -- honestly toy-stage (no tests existed before this fix, one malformed peer write could crash every session) but the core CRDT engine is sound; structurally a backend-less serverless P2P toy, can't reach production/SLA-grade. See PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"deep-searcher","domain":"zilliztech.github.io/deep-searcher/","mesh":"pages","category":"app","title":"Deep Searcher","summary":"Open Source Deep Research Alternative to Reason and Search on Private Data. Written in Python.","health_url":"https://zilliztech.github.io/deep-searcher/","repo_url":"https://github.com/baditaflorin/deep-searcher","url":"https://zilliztech.github.io/deep-searcher/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"First-pass audit: confirmed a pure, unmodified 6-month-stale fork of zilliztech/deep-searcher (isFork:true, zero application-file changes vs the merge-base -- every local commit beyond it is fleet-doc-propagation noise, not app code). Privacy claim ('search on private data') verified honest with an important nuance correctly disclosed: only the user's query, collection names/descriptions (for routing), and already-retrieved chunk text ever get formatted into an LLM prompt -- never the full/un-retrieved corpus -- but 'private' means the corpus stays in your own local vector store (embedded Milvus-lite by default), not that zero bytes reach a cloud LLM; the default config actually uses OpenAI for both LLM and embeddings unless you opt into a local provider (Ollama/FastEmbed/SentenceTransformer, all present and functional) -- this is disclosed behavior in the README, not a discrepancy. Found 3 real bugs, all confirmed identical in the merge-base and current upstream/master (an unbounded firecrawl-py dependency pin breaking on fresh installs, matching an already-open upstream PR #262; a hardcoded 3-model embedding-dimension whitelist throwing KeyError for any other model; a malformed closing tag in a RAG prompt) -- per instructions to be conservative with third-party code, correctly declined to patch any of them or open a PR, since fixing upstream-inherited bugs in a passively-mirrored fork would only deepen the exact divergence problem this audit exists to catch. Also noted the repo's own pytest CI step is present but commented out, so its test suite never actually runs. trl held at 4, trl_ceiling=6 -- a legitimate, moderately mature multi-provider RAG framework, not toy-tier, but reaching 'real' (6-7) requires the owner to merge the 12 pending upstream commits, pin dependencies, and re-enable the disabled CI step.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"earthquake-wave-propagation","domain":"baditaflorin.github.io/earthquake-wave-propagation/","mesh":"pages","category":"app","title":"Earthquake Wave Propagation","summary":"Interactive WebGPU demo: click a fault to see and hear P-waves and S-waves propagate across terrain.","health_url":"https://baditaflorin.github.io/earthquake-wave-propagation/","repo_url":"https://github.com/baditaflorin/earthquake-wave-propagation","url":"https://baditaflorin.github.io/earthquake-wave-propagation/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"First-pass audit of this interactive WebGPU seismic-wave demo (P/S-wave visualization + sonification): confirmed physically correct -- P-wave velocity \u003e S-wave velocity in every scenario preset, CPU and WebGPU kernels implement identical Ricker-wavelet/attenuation formulas, audio sonification schedules pulses at the same distance/velocity formulas driving the visual arrival readouts (sound and visuals physically consistent). WebGPU-\u003eCPU fallback verified live in an isolated headless Chromium with no WebGPU adapter; no GPU/audio-node leak under sustained rapid-strike use. Found and fixed a real bug that broke the app's headline 'see the waves propagate' feature: updateArrivalRings scaled each P/S arrival ring uniformly on x/y/z via scale.setScalar(radius), but the ring geometry has a fixed y=1.2 hover height above the terrain, so that hover height got multiplied by the wave radius too -- rings went rocketing kilometers into the sky as the wavefront expanded, visually confirmed as a floating ellipse detached from the terrain, broken for anything beyond the first second or two. Fixed by scaling only the flat x/z footprint, verified via a Playwright screenshot series showing rings now correctly hugging the terrain across the wave's lifetime. One test-environment false alarm (render loop appearing to never fire) correctly diagnosed as sandbox tab-backgrounding, not an app bug, confirmed by reproducing cleanly in an isolated headless instance. trl bumped 4-\u003e5; trl_ceiling=6 added -- a self-described 'educational analytic wavefront model, not a validated scientific solver' per its own postmortem, static client-only with no backend, structurally depends on a browser engine feature (WebGPU) with still-inconsistent cross-browser support (CPU fallback keeps it fully functional everywhere, so not a hard blocker, but caps how far it can honestly claim toward production/SLA-grade). See PR #5 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"elder-care-coordinator","domain":"baditaflorin.github.io/elder-care-coordinator/","mesh":"pages","category":"app","title":"Elder Care Coordinator","summary":"Local-first elder care coordination for meds, appointments, insurance drafts, and emergency packets.","health_url":"https://baditaflorin.github.io/elder-care-coordinator/","repo_url":"https://github.com/baditaflorin/elder-care-coordinator","url":"https://baditaflorin.github.io/elder-care-coordinator/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"First-pass audit of this local-first elder-care coordination app (meds/appointments/insurance, IndexedDB/Yjs, no backend): privacy/local-first claim verified clean -- no analytics/telemetry anywhere, only non-user-initiated network call is a read-only GitHub commits-endpoint fetch with no care data. Found and fixed 2 real, compounding bugs with genuine safety stakes in the medication-reminder core: (1) the 'due' (overdue) status was practically unreachable -- the scheduler always rolled a passed dose time forward to the next occurrence BEFORE checking confirmation, so a missed dose silently became 'tomorrow, upcoming' instead of flagged overdue, meaning the dashboard's overdue-medication alert essentially never fired. (2) medications store one lastConfirmedAt timestamp per medication, not per dose-time, so confirming a twice-daily medication's 08:00 dose retroactively marked its still-not-given 20:00 dose as confirmed too -- a caregiver could see 'Done' and skip giving it. Fixed both (dose slots stay 'due' until actually confirmed; confirmation now requires the confirmation clock-time to be at/after the specific dose's scheduled time); one existing test was found to have been unknowingly encoding the bug's own symptom, now corrected. trl held at 4 pending this fix landing and CI going green; trl_ceiling=5 added -- genuinely local-first/no-backend/no-telemetry with real schema validation and tests, but no at-rest encryption for local IndexedDB, no DST-transition test coverage. See PR #8 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"fake-text","domain":"baditaflorin.github.io/fake-text/","mesh":"pages","category":"app","title":"Fake Text","tags":["kind-static","language-html","runtime-github-pages"],"health_url":"https://baditaflorin.github.io/fake-text/","repo_url":"https://github.com/baditaflorin/fake-text","url":"https://baditaflorin.github.io/fake-text/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":6,"trl_evidence":"First-pass audit of this fabricated iMessage/SMS/Tweet screenshot generator (never assessed before, catalog name suggested Lorem-Ipsum but it's actually a meme-image tool): confirmed real and complete -- clean typecheck/build/smoke, deployed live. No XSS found (all user text via textContent; the one innerHTML use only ever receives numeric formatCount() output). Found and fixed a real layout bug: an unbroken character run (long URL, hashtag, base64 blob) in a chat bubble blew the CSS layout width out to ~4.85 million px, because flex items default to min-width:auto and word-wrap:break-word doesn't affect min-content sizing -- the phone frame's overflow:hidden then silently clipped the text past ~380px in both the live preview and the exported PNG, with no crash but no graceful handling either. Fixed with min-width:0 plus overflow-wrap:anywhere; also added a shared MAX_TEXT_LEN=4000 cap to the chat-bubble textarea (previously uncapped, unlike the tweet-text field). An initial suspicion that this also hung PNG export did not hold up under cross-check with real Chrome via Playwright -- correctly walked back rather than overclaimed. trl=6, no ceiling -- real, genuine tests, builds/runs end-to-end, deployed, no backend surface; young and no CI, but nothing structurally caps it from climbing higher with more field use. See PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"field-recording-mirror","domain":"baditaflorin.github.io/field-recording-mirror/","mesh":"pages","category":"archive","title":"Field Recording Mirror","summary":"A private browser instrument that records 30 seconds of now and replays it as a subtly altered sonic mirror.","health_url":"https://baditaflorin.github.io/field-recording-mirror/","repo_url":"https://github.com/baditaflorin/field-recording-mirror","url":"https://baditaflorin.github.io/field-recording-mirror/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"First-pass audit of this browser field-recording-loop instrument (WebAudio, OPFS/Whisper/Pyodide workers): privacy claim verified genuine -- audio only ever moves via postMessage (transferred ArrayBuffer) into a local Worker, no exfiltration anywhere. Found and fixed 2 real bugs: (1) a reentrancy race in engine.stop() -- the running guard was only cleared AFTER await audioContext.close(), so a fast double-click on Stop could call AudioContext.close() twice on the same context, throwing an uncaught InvalidStateError and leaving the UI stuck mid-teardown; fixed by flipping the guard synchronously before the first await. (2) a Whisper/Pyodide worker leak -- every click of 'Transcribe'/'Analyse' created a brand-new client/Worker without disposing the previous one, growing memory by hundreds of MB per click, directly contradicting the docs' own 'second run is instant' claim; fixed by caching one client per session and reusing it. trl bumped 3-\u003e4; trl_ceiling=7 added -- client-only art piece with no server component and a subjective 'does it sound right' success criterion, 8-9 doesn't apply. See PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"flowfield","domain":"baditaflorin.github.io/flowfield/","mesh":"pages","category":"app","title":"Flowfield","tags":["kind-static","language-html","runtime-github-pages"],"health_url":"https://baditaflorin.github.io/flowfield/","repo_url":"https://github.com/baditaflorin/flowfield","url":"https://baditaflorin.github.io/flowfield/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":6,"trl_evidence":"First-pass audit of this Perlin/flow-field generative-art tool (never assessed before, no summary in catalog): confirmed real and complete -- 17 pre-existing tests, clean build, correct-looking generative art verified visually. Found and fixed a real bug: since the app's whole premise is reproducible/shareable-by-link, decodeSettings() parsed numeric URL-hash fields with only a finiteness check, no clamping to the app's own slider limits (particles 50-3000, steps 40-600) even though a clamp() helper already existed for exactly this -- a crafted or shared link bypasses every slider cap and feeds straight into spawn()/render() on page load. Live-proved: a link with 200,000 particles (17x over the cap) crashed the process with an out-of-memory fatal error; 5,000,000 particles hung the tab for 30+ seconds without completing even 2 animation frames. Fixed by clamping every numeric field to the same LIMITS the sliders enforce, narrowing the type so it's enforced at compile time too. The separate classic 'uncanceled RAF loop' bug is NOT present -- render() correctly cancels before restarting, resize is debounced. trl=6, no ceiling -- real, working, well-tested client-side tool at its stated scope; genuinely a hobby/toy generative-art app by design (no backend/auth/accounts), so not a candidate for 7-9, but far past 'toy/no tests' territory. See PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"gentle-adhd-flow","domain":"baditaflorin.github.io/gentle-adhd-flow/","mesh":"pages","category":"app","title":"Gentle Adhd Flow","summary":"Local-first ADHD self-management: voice brain-dumps become tasks, focus sessions, habits, and gentle planning.","health_url":"https://baditaflorin.github.io/gentle-adhd-flow/","repo_url":"https://github.com/baditaflorin/gentle-adhd-flow","url":"https://baditaflorin.github.io/gentle-adhd-flow/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"First-pass audit of this local-first ADHD self-management app (Whisper STT + Flan-T5 refine, both in-browser via WASM/WebGPU): found and fixed a real privacy leak -- the browser-TTS fallback (used only if the local Piper engine fails) used the native SpeechSynthesisUtterance API, which on some browsers (notably Chrome) can route to a network TTS voice, silently sending derived personal task text off-device despite the 'local-first' claim, with no UI disclosure; fixed to require an explicitly local voice or stay silent. Also found and fixed a real data-loss bug in the core voice-to-task pipeline: extractBrainDump's sentence splitter only broke on newlines/periods/semicolons/bullets, so realistic rambling/voice-transcribed input with no punctuation (e.g. 'call mom and email boss and buy milk...') collapsed into one garbled task, silently losing 3 of 4 distinct actionable items; fixed with conjunction-aware splitting that still keeps plain item lists as one task. Focus timer verified immune to the classic setInterval drift bug (recomputes from Date.now() each tick). trl bumped 3-\u003e4; trl_ceiling=5 added -- real client-side-only architecture with genuine self-audits already done, but extraction is still a heuristic regex/keyword classifier, no external usability testing, no cross-device sync. Separately flagged: GitHub shows 24 Dependabot vulnerabilities (1 critical, 9 high) on the default branch, out of scope for this audit. See PR #9 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"granular-physics-lab","domain":"baditaflorin.github.io/granular-physics-lab/","mesh":"pages","category":"app","title":"Granular Physics Lab","summary":"Browser-based granular sandbox for teaching sand, gravel, and snow behavior with WASM physics and WebGPU visuals.","health_url":"https://baditaflorin.github.io/granular-physics-lab/","repo_url":"https://github.com/baditaflorin/granular-physics-lab","url":"https://baditaflorin.github.io/granular-physics-lab/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"First-pass audit of this browser granular-material teaching sandbox (Three.js/WebGPU-or-WebGL, a tiny WASM contact kernel with a TS fallback): confirmed no uncapped-particle-count or uncanceled-animation-loop leak (GranularScene.dispose() correctly tears down everything, particleBudget always enforced) -- clean bill of health on the hypothesized bug classes. Found a real physics-correctness bug instead: resolvePair()'s inter-particle friction impulse cap was a fixed +-0.08 constant that ignored the material's actual friction coefficient entirely, so sand (0.7), gravel (0.62), and snow (0.86) all resisted sliding at essentially the same rate -- measured a resting sand pile in the app's own default setup settling to only ~13.5deg and sliding to the outer wall within 15 simulated seconds instead of holding a slope, undermining the app's own stated teaching claim ('clean avalanche angle,' 'jammed pile'). Fixed by scaling the friction cap to the material's coefficient with a basic Coulomb stick/slip model -- the same scenario now holds ~21deg and stays clear of the wall. Also fixed a broken pre-commit test hook (Node's built-in localStorage global wasn't being overridden by vitest's jsdom environment). trl bumped 4-\u003e5; trl_ceiling=6 added -- permanently committed (per its own ADR/postmortem) to a simplified non-Chrono-parity 2.5D approximation with no backend, no path to SLA-grade for a client-side teaching sandbox. See PR #5 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"group-theory-visualizer","domain":"baditaflorin.github.io/group-theory-visualizer/","mesh":"pages","category":"app","title":"Group Theory Visualizer","summary":"Interactive finite-group and symmetry explorer using WASM math, Three.js, and graph visualization.","health_url":"https://baditaflorin.github.io/group-theory-visualizer/","repo_url":"https://github.com/baditaflorin/group-theory-visualizer","url":"https://baditaflorin.github.io/group-theory-visualizer/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"First-pass audit of this interactive finite-group/symmetry explorer (hand-authored WASM table-lookup kernel + Three.js): mathematical correctness verified clean via an independent from-scratch reimplementation (not reusing the app's own algebra.ts/cayley.ts) run against all 18 catalog groups -- full associativity/closure/identity/inverse/Latin-square checks pass for every group, Q8's table matches an independently coded Hamilton quaternion product exactly, S3/A4/S4 element-order distributions match known character-table facts exactly. No math bugs found. Found and fixed a severe rendering bug instead: the 3D-visualization camera was built but camera.lookAt() was never called, so a fresh camera faces local -Z while every group's geometry is centered at the origin (~41 degrees off boresight, well outside the 24-degree half-FOV) -- the '3D' tab silently rendered nothing but background color for EVERY group in the catalog, with no console error and status text still claiming 'live WebGL.' Confirmed live in-browser before/after across C1, D4, and S4 (order 24). The existing e2e smoke test only asserted the canvas was visible, not that it contained real content -- exactly why this shipped unnoticed. Fixed with one camera.lookAt(0,0,0) call. trl bumped 4-\u003e5; trl_ceiling=7 added -- solidly 'developing' (curated catalog, multi-step group-theory logic, now-verified real test coverage) but not yet 'real' (6-7) since it has no external/RFC-style input parsing or operational evidence trail; capped below 8-9 since 'battle-tested, SLA-grade' isn't a meaningful target for a static no-backend GitHub Pages demo. See PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"highlight-recall","domain":"baditaflorin.github.io/highlight-recall/","mesh":"pages","category":"app","title":"Highlight Recall","summary":"Local-first EPUB/PDF highlight review with semantic search and spaced repetition.","health_url":"https://baditaflorin.github.io/highlight-recall/","repo_url":"https://github.com/baditaflorin/highlight-recall","url":"https://baditaflorin.github.io/highlight-recall/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"First-pass audit of this local-first EPUB/PDF highlight-review app (spaced repetition + semantic search): privacy claim holds up -- no fetch/XHR/sendBeacon/analytics anywhere in src/, all persistence is IndexedDB/localStorage, the only network-capable code is dynamic import() of pdfjs-dist/jszip/optional AI libs, none of which ever receive document/highlight content. Found and fixed 2 real bugs. (1) scheduleReview() computed a first 'hard' review's interval as intervalDays*1.2, but intervalDays on a new highlight is just the random 0-14 day import jitter, not a real interval -- so a 'hard' (worse) grade could schedule further out than 'good' or 'easy' on the same highlight, inverting the difficulty ordering; fixed by anchoring the first 'hard' repetition to 1 day, matching how good/easy already special-case repetitions===0. (2) A real, well-formed EPUB fixture returned 0 highlights before the fix -- Element.textContent concatenates adjacent paragraphs with no separator, so a short non-sentence line (page footer, heading) between two real paragraphs glued onto the next paragraph and the whole merged run got discarded by the 'Page N' metadata filter, silently dropping legitimate highlights; fixed by preserving paragraph breaks through extraction and treating them as hard boundaries independent of punctuation (also fixes the same bug class for plain-text/Markdown import). Password-protected/corrupted PDFs handled correctly (verified with real qpdf-encrypted and truncated fixtures). Also restored docs/privacy.md, which along with 1,300+ lines of architecture/deploy/ADR docs had silently vanished in a 'build:' commit 40+ commits ago with nobody noticing, leaving README links dead (rest flagged, not restored, to keep the PR focused). trl held at 3 (real bugs just found in both the core scheduling and extraction paths -- genuinely early-stage, not gold-plated); trl_ceiling=5 added -- well-scoped single-user no-backend app with no fundamental design flaws found, but no CI, previously-broken lint/tests on main, and zero tests for two of three importers before this PR. See PR #7 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"implemment-the-following-time-displaced-ears","domain":"baditaflorin.github.io/implemment-the-following-time-displaced-ears/","mesh":"pages","category":"app","title":"Implemment The Following Time Displaced Ears","summary":"A browser audio lab for hearing live microphone input delayed, pitch-shifted, and spectrally transformed.","health_url":"https://baditaflorin.github.io/implemment-the-following-time-displaced-ears/","repo_url":"https://github.com/baditaflorin/implemment-the-following-time-displaced-ears","url":"https://baditaflorin.github.io/implemment-the-following-time-displaced-ears/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"First-pass audit of this live-mic delay/pitch-shift/spectral-effects browser toy (20 ADRs, real OfflineAudioContext DSP regression tests, honest postmortems documenting bugs caught by testing): privacy confirmed clean via full source grep -- only network hits are an optional Pyodide CDN load (no audio in the request) and same-origin service-worker asset caching; the offline-analysis feature runs librosa entirely inside a Worker via Pyodide, audio never crosses a network boundary. Found and fixed a real hearing-safety gap: the live-mic effects chain (delay + pitch shift + output gain clamped to 2x) had no dynamics processing anywhere in the audio graph -- outGain connected straight to the AnalyserNode/destination -- combined with echoCancellation/noiseSuppression/autoGainControl intentionally disabled on mic capture, and this being a tool people plausibly run through speakers (not headphones) given its whole premise, a hot mic input or acoustic feedback plus a maxed output slider had no ceiling before hitting the user's ears. Fixed by adding a DynamicsCompressorNode (threshold -6dB, ratio 20:1, 3ms attack, 250ms release) as the final stage before both the analyser and destination; WAV export now taps post-limiter so recordings match what's actually heard. Documented in a new ADR. Delay/pitch/output-gain clamping and mic-permission-denied handling all verified correct; mid-session mic disconnect degrades to silence per Web Audio semantics rather than crashing (minor polish gap, not a bug). trl bumped 2-\u003e5 (significantly understated by the prior value -- real DSP-correctness regression tests, not just mocked units, plus gated local CI); trl_ceiling=7 added -- structural limit, not temporary: single-developer fully client-side creative tool with no backend/SLA, and no cross-browser testing exists despite README claims. See PR #9 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"life-in-weeks","domain":"baditaflorin.github.io/life-in-weeks/","mesh":"pages","category":"app","title":"Life In Weeks","tags":["kind-static","language-html","runtime-github-pages"],"health_url":"https://baditaflorin.github.io/life-in-weeks/","repo_url":"https://github.com/baditaflorin/life-in-weeks","url":"https://baditaflorin.github.io/life-in-weeks/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":7,"trl_evidence":"First-pass audit of this 'Life in Weeks' poster generator (never assessed before, no summary in catalog): confirmed real, complete, and well-architected -- deployed live, 24 pre-existing tests. Date-math correctness (the priority check for this class of tool) verified with no bugs found across leap-day (Feb 29 2000), future-mistake-birthdate, 126-year-old-past-expectancy, born-today/yesterday, and exact-grid-boundary edge cases -- all UTC-midnight-based floor arithmetic, no off-by-one anywhere. Privacy confirmed as advertised (no fetch/XHR/analytics anywhere). Found and fixed a real bug: milestones are packed into the shareable URL hash as date~label~color, and the label is passed through encodeURIComponent, but ~ is an RFC 3986 unreserved character that encodeURIComponent does NOT escape -- so a milestone label containing a literal tilde (e.g. 'Won ~1000 dollars') smuggled extra separators into the packed string, and the naive 3-part split then misfired, silently dropping the entire milestone on the next page load or shared-link open with no error shown. Fixed with first/last-tilde splitting instead of a naive 3-way split (backward-compatible). trl=7, trl_ceiling=8 -- deployed, functioning correctly, privacy claims verified, one real bug found and fixed; deliberately small single-purpose backend-free tool, so 8 reflects its realistic maximum maturity (9 reserved for things needing field-usage telemetry at scale, which this intentionally has none of by design). See PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"little-voice-stories","domain":"baditaflorin.github.io/little-voice-stories","mesh":"pages","category":"app","title":"Little Voice Stories","summary":"Turn a kid’s drawing into a bedtime story narrated in a parent’s voice, entirely in the browser.","health_url":"https://baditaflorin.github.io/little-voice-stories","repo_url":"https://github.com/baditaflorin/little-voice-stories","url":"https://baditaflorin.github.io/little-voice-stories","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"First-pass audit of this 'kid's drawing into a bedtime story narrated in a parent's voice' app (sensitive categories: child content + voice-biometric-adjacent data, so privacy verification was the priority): thoroughly verified no undisclosed transmission of any of it. Drawing analysis is 100% in-browser canvas pixel math (color histogram, ink coverage, edge energy) plus filename-keyword regex, no vision API call. Default story generation is a deterministic local template engine seeded by a hash of the inputs; the optional local-LLM path (@mlc-ai/web-llm, Qwen2.5-0.5B) downloads only model weights after explicit opt-in, inference runs locally via WebGPU, the prompt itself never crosses the network. Voice 'cloning' is honestly not neural voice cloning -- it's local AudioContext analysis (RMS, zero-crossing pitch, warmth) tuning the browser's built-in SpeechSynthesis; the raw recording Blob is discarded from memory immediately after analysis, never persisted, only derived non-identifying acoustic parameters are stored. Share links deliberately exclude the drawing image and voice profile from their payload, unlike the full session export. Found and fixed a real data-loss bug: the session-restore effect returned early after loading a #share= link, before reaching the finally block that sets hasLoaded(true); since the debounced autosave effect is gated on hasLoaded, opening any shared story link silently disabled autosave for the rest of that browser session -- a newly recorded parent voice profile or freshly generated story made afterward would show a normal 'saved' toast but vanish on refresh/close with no warning. Fixed with one line plus a new e2e regression test. trl held at 3; trl_ceiling=5 added -- the privacy architecture is sound and would support real hardening without an architecture rework, but today's 'AI' is honestly simple heuristics/templates and there was a genuine silent data-loss bug, consistent with early/toy-stage rather than higher until the fix ships with real CI coverage (currently none). See PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"local-proofreader","domain":"baditaflorin.github.io/local-proofreader/","mesh":"pages","category":"app","title":"Local Proofreader","summary":"Local-first grammar, spelling, style, and rewrite assistant for the browser with no draft data sent to servers.","health_url":"https://baditaflorin.github.io/local-proofreader/","repo_url":"https://github.com/baditaflorin/local-proofreader","url":"https://baditaflorin.github.io/local-proofreader/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"First-pass audit of this local grammar/style/rewrite assistant (corrected the task's premise -- not an LLM/WASM/WebGPU app, it's a purely deterministic rule-based checker: regex grammar rules, a Hunspell dictionary via nspell, hand-written style rules, no model of any kind runs client-side): privacy/local-first claim verified TRUE -- only fetches are same-origin dictionary/version files, DuckDB-WASM is self-hosted not CDN-fetched, no analytics/telemetry anywhere, the browser extension's broad host permission only runs local regex on manual click with zero network calls. Found and fixed a real bug: an entire advertised feature -- style/jargon/hedging checks (weasel words, 'utilize', etc) -- was defined, unit-tested in isolation, and imported, but never actually called in the real analysis pipeline; confirmed live that a sentence full of jargon returned zero suggestions despite the README advertising exactly this check. Fixed with a one-line pipeline wire-in plus a new end-to-end regression test (the existing tests only covered the rule table in isolation, not the real pipeline -- exactly the kind of test that would have caught this). Data-loss check: no bug found, drafts autosave to IndexedDB on a 250ms debounce with a recoverable error message on analysis failure. trl/trl_ceiling held at 4/4 -- honestly assessed as near its structural maximum for a hand-rolled regex/Hunspell engine, not the ML/LLM system its 'LanguageTool-style'/'Vale-style' branding implies; its heuristics also look tuned closely to its own test fixtures, so real-world coverage is thinner than advertised. See PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"localhuman-mail","domain":"baditaflorin.github.io/localhuman-mail/","mesh":"pages","category":"app","title":"Localhuman Mail","summary":"Privacy-first AI email client with local mailbox indexing, semantic search, and assistive drafting.","health_url":"https://baditaflorin.github.io/localhuman-mail/","repo_url":"https://github.com/baditaflorin/localhuman-mail","url":"https://baditaflorin.github.io/localhuman-mail/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"First-pass audit of this privacy-first AI email client (manual .eml import only, not a live IMAP client): privacy claim verified genuine -- no cloud AI service exists anywhere in the codebase (grepped for OpenAI/Anthropic/API-key patterns, nothing), only local Ollama with a non-network template fallback; 'semantic search' is honestly disclosed as aspirational (plain SQL LIKE substring search today, not real ranking). No credential-storage issue since there's no IMAP/SMTP login flow anywhere -- nothing to leak. Found and fixed a real bug: countPart() reused the 2MB indexing cap as a hard cap when measuring attachment size, so any attachment over 2MB got a silently wrong, truncated SizeBytes (verified: a real 3,145,728-byte attachment reported as 2,097,153); fixed by removing the unnecessary cap. trl held at 3; trl_ceiling=5 added -- solid, tested, honestly-documented local .eml triage tool, but no live IMAP sync or real semantic ranking yet, enough room to reward hardening the current scope without implying 'production email client' status. Separately flagged: 27 Dependabot vulnerabilities (7 critical, 9 high) on the default branch, out of scope for this audit. See PR #16 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"localingo","domain":"baditaflorin.github.io/localingo/","mesh":"pages","category":"app","title":"Localingo","summary":"A private, gamified language tutor with local speech, review, grammar, and lesson generation.","health_url":"https://baditaflorin.github.io/localingo/","repo_url":"https://github.com/baditaflorin/localingo","url":"https://baditaflorin.github.io/localingo/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"First-pass audit of this gamified local-first language tutor (local speech/pitch scoring, SM-2-style spaced repetition, no backend): privacy claim verified genuine -- the only outbound network call in the whole app is a GitHub commit-hash display fetch, no learner data involved; speech scoring, review/SRS, and grammar checking are 100%% local computation. SRS scheduler verified correct (ease-factor updates, interval growth/reset, timezone-safe absolute-timestamp dueAt comparisons). Found and fixed a real timezone bug in the streak/gamification logic: updateStreak() computed 'today'/'yesterday' via date.toISOString().slice(0,10) -- the UTC calendar day, not the learner's local day -- so a learner in a timezone ahead of UTC (e.g. Sydney, UTC+10) practicing late at night and again the next morning (two genuinely different local days) would land on the same UTC day and silently fail to increment their streak; live-reproduced before fixing, resolved with a localDateKey() helper used consistently across recordAttempt/reviewCard/updateStreak. trl held at 4; trl_ceiling=5 added -- solid, honest, privacy-correct small app with decent test coverage, but single-maintainer hobby-scale with no dedicated CI workflow and 'pronunciation scoring' is an honest but crude pitch/energy heuristic rather than real ASR. See PR #11 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mandala-studio","domain":"baditaflorin.github.io/mandala-studio/","mesh":"pages","category":"app","title":"Mandala Studio","tags":["kind-static","language-html","runtime-github-pages"],"health_url":"https://baditaflorin.github.io/mandala-studio/","repo_url":"https://github.com/baditaflorin/mandala-studio","url":"https://baditaflorin.github.io/mandala-studio/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"First-pass audit of this radial/kaleidoscope drawing canvas (never assessed before, no summary in catalog): confirmed real, complete, and working -- no stub code, no TODOs, 19 pre-existing tests pass, live deployment matches local build. Symmetry correctness verified live (12-fold and max 24-fold rotation with/without mirror render correctly, no crash at max segment count + mirror). No persistence by design (README accurately states drawings live only in the tab until exported) and privacy confirmed 100%% client-side. Found and fixed a real bug, precisely measured: canvas resize (window resize, orientation change, DevTools toggle) after drawing anything silently distorted already-drawn strokes, because Stroke.points are stored in absolute canvas-pixel coordinates but rendering always expands strokes about the CURRENT center, and resizeCanvas() never adjusted stored points when the center moved -- measured a 24-segment mirrored stroke's bloom radius growing from 76px to 112px (~47%% distortion) on a real resize with zero new strokes drawn. Fixed by tracking the last-known center and translating existing strokes by the delta on resize. trl=3 (was None), trl_ceiling=3 -- small, complete, single-purpose client-side tool with no backend/auth/persistence; 3 is an honest ceiling for its actual scope, not a placeholder. See PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-agenda-runner","domain":"baditaflorin.github.io/mesh-agenda-runner/","mesh":"pages","category":"peer_to_peer","title":"Mesh Agenda Runner","summary":"A shared, live agenda for lightweight facilitated sessions.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-agenda-runner/","repo_url":"https://github.com/baditaflorin/mesh-agenda-runner","url":"https://baditaflorin.github.io/mesh-agenda-runner/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-bench-archive","domain":"baditaflorin.github.io/mesh-bench-archive/","mesh":"pages","category":"peer_to_peer","title":"Mesh Bench Archive","summary":"Peer-to-peer mesh: voice notes tied to a place. Scan a QR sticker on a bench, hear the last visitors. Audio lives only in browsers that have scanned.","health_url":"https://baditaflorin.github.io/mesh-bench-archive/","repo_url":"https://github.com/baditaflorin/mesh-bench-archive","url":"https://baditaflorin.github.io/mesh-bench-archive/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"First-pass audit of this P2P mesh voice-notes-tied-to-a-place app (QR-sticker scan -\u003e Yjs CRDT sync): found a real privacy-disclosure gap -- the app's own dedicated privacy doc claims 'no location data,' but MeshShell unconditionally fires an analytics beacon on every page load sending the room id (the physical bench's place label from the sticker itself, e.g. 'park-bench-A'), a truncated peer id, referrer, version, and timestamp; it's opt-out-able and disclosed in the in-app Settings drawer, but the dedicated threat-model doc and README summary never mentioned it -- a real false-as-shipped privacy claim. Fixed by correcting the privacy doc and README (the beacon itself is shared fleet-wide infrastructure in a separate repo, already has an opt-out, left unchanged). Found and fixed a real P2P concurrency bug: the FIFO 30-clip cap logic decided how much to trim from each peer's own possibly-stale view, so when 2+ peers publish concurrently while at the cap (a busy-bench scenario), the merged archive could hold cap+(writers-1) clips instead of 30, silently exceeding the documented ~7-9MB memory bound until another publish happens (no clips lost/duplicated -- convergence itself was sound); fixed with self-healing enforcement wired into the Yjs observe callback so every peer corrects overshoot as soon as it observes the converged state. trl bumped 4-\u003e5; trl_ceiling=6 added -- real CRDT P2P sync with a genuine cross-peer e2e test and, after this PR, an accurate privacy doc plus concurrency-correctness unit tests; capped by ADR-0001's intentionally serverless/unauthenticated design with no backend to add integration/evidence-trail tests against. See PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-bingo-blitz","domain":"baditaflorin.github.io/mesh-bingo-blitz/","mesh":"pages","category":"games","title":"Mesh Bingo Blitz","summary":"A browser-local social bingo board with individual claims.","health_url":"https://baditaflorin.github.io/mesh-bingo-blitz/","repo_url":"https://github.com/baditaflorin/mesh-bingo-blitz","url":"https://baditaflorin.github.io/mesh-bingo-blitz/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-book-club-lottery","domain":"baditaflorin.github.io/mesh-book-club-lottery/","mesh":"pages","category":"peer_to_peer","title":"Mesh Book Club Lottery","summary":"A browser-local book-club lottery with one nomination per peer and a transparent draw.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-book-club-lottery/","repo_url":"https://github.com/baditaflorin/mesh-book-club-lottery","url":"https://baditaflorin.github.io/mesh-book-club-lottery/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-bookmark-board","domain":"baditaflorin.github.io/mesh-bookmark-board/","mesh":"pages","category":"productivity","title":"Mesh Bookmark Board","summary":"A peer-attributed shared board for useful links in the room.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-bookmark-board/","repo_url":"https://github.com/baditaflorin/mesh-bookmark-board","url":"https://baditaflorin.github.io/mesh-bookmark-board/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-borrow-board","domain":"baditaflorin.github.io/mesh-borrow-board/","mesh":"pages","category":"peer_to_peer","title":"Mesh Borrow Board","summary":"A browser-local lending board for things neighbours can borrow and return.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-borrow-board/","repo_url":"https://github.com/baditaflorin/mesh-borrow-board","url":"https://baditaflorin.github.io/mesh-borrow-board/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-breakout-pairs","domain":"baditaflorin.github.io/mesh-breakout-pairs/","mesh":"pages","category":"peer_to_peer","title":"Mesh Breakout Pairs","summary":"Facilitator-led peer breakout rotations for small group conversations.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-breakout-pairs/","repo_url":"https://github.com/baditaflorin/mesh-breakout-pairs","url":"https://baditaflorin.github.io/mesh-breakout-pairs/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-budget-pot","domain":"baditaflorin.github.io/mesh-budget-pot/","mesh":"pages","category":"peer_to_peer","title":"Mesh Budget Pot","summary":"Browser-local peer-to-peer Mesh Common service","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-budget-pot/","repo_url":"https://github.com/baditaflorin/mesh-budget-pot","url":"https://baditaflorin.github.io/mesh-budget-pot/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-caption-clash","domain":"baditaflorin.github.io/mesh-caption-clash/","mesh":"pages","category":"games","title":"Mesh Caption Clash","summary":"A shared caption contest with one entry and independent votes per peer.","health_url":"https://baditaflorin.github.io/mesh-caption-clash/","repo_url":"https://github.com/baditaflorin/mesh-caption-clash","url":"https://baditaflorin.github.io/mesh-caption-clash/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-card-sorter","domain":"baditaflorin.github.io/mesh-card-sorter/","mesh":"pages","category":"peer_to_peer","title":"Mesh Card Sorter","summary":"Browser-local peer-to-peer Mesh Common service","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-card-sorter/","repo_url":"https://github.com/baditaflorin/mesh-card-sorter","url":"https://baditaflorin.github.io/mesh-card-sorter/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-carpool-bingo","domain":"baditaflorin.github.io/mesh-carpool-bingo/","mesh":"pages","category":"peer_to_peer","title":"Mesh Carpool Bingo","summary":"Peer-to-peer mesh: road-trip bingo. Per-phone unique 5x5 cards, shared claim space across the car. First to a line wins.","health_url":"https://baditaflorin.github.io/mesh-carpool-bingo/","repo_url":"https://github.com/baditaflorin/mesh-carpool-bingo","url":"https://baditaflorin.github.io/mesh-carpool-bingo/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass). Found and fixed a real bug live-verified in-browser: the per-device bingo-card seed was regenerated via crypto.randomUUID() on every mount instead of being persisted, so a page reload silently handed players a completely different card -- contradicting the app's own documented 'same card across reloads' guarantee, and directly relevant to this app's spotty-mobile-connectivity car-trip use case. Fixed via localStorage persistence matching the existing room/name pattern. Card generation, win detection (rows/cols/diagonals), XSS handling, secret hygiene, claim-conflict resolution, and privacy-network-call claims were all independently verified sound. trl bumped 3-\u003e4; trl_ceiling=5. See github.com/baditaflorin/mesh-carpool-bingo PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-choice-board","domain":"baditaflorin.github.io/mesh-choice-board/","mesh":"pages","category":"decisions","title":"Mesh Choice Board","summary":"A shared, multi-select decision board for small groups.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-choice-board/","repo_url":"https://github.com/baditaflorin/mesh-choice-board","url":"https://baditaflorin.github.io/mesh-choice-board/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-codenames","domain":"baditaflorin.github.io/mesh-codenames/","mesh":"pages","category":"app","title":"Mesh Codenames","tags":["kind-static","language-html","peer-to-peer","runtime-github-pages"],"health_url":"https://baditaflorin.github.io/mesh-codenames/","repo_url":"https://github.com/baditaflorin/mesh-codenames","url":"https://baditaflorin.github.io/mesh-codenames/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"First-ever audit of this P2P Codenames game (Yjs/y-webrtc, no backend beyond signaling/TURN). Found and fixed a real bug: cn:phase/cn:game are room-wide Yjs maps, and 'Lobby'/'New game'/'Deal a board' wrote to them with no confirmation and no restriction on when clickable -- any single connected peer, including a bystander who never joined a team, could instantly and irreversibly wipe an in-progress board and every revealed tile for the entire room, with no resume path. Reproduced via a raw Yjs-map script and a new Vitest suite driving the real component. Fixed by gating all three actions behind confirm() only when a game is genuinely in progress. No XSS/secrets found; privacy claims hold. trl bumped from unassessed to 3; trl_ceiling=4 -- working app with one real fixed bug now under regression coverage, but no CI configured to auto-gate future regressions of this class. See github.com/baditaflorin/mesh-codenames PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-cohort-scheduler","domain":"baditaflorin.github.io/mesh-cohort-scheduler/","mesh":"pages","category":"productivity","title":"Mesh Cohort Scheduler","summary":"A browser-local shared availability picker for small cohorts.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-cohort-scheduler/","repo_url":"https://github.com/baditaflorin/mesh-cohort-scheduler","url":"https://baditaflorin.github.io/mesh-cohort-scheduler/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-countdown-wall","domain":"baditaflorin.github.io/mesh-countdown-wall/","mesh":"pages","category":"peer_to_peer","title":"Mesh Countdown Wall","summary":"Browser-local mesh service built with mesh-common","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-countdown-wall/","repo_url":"https://github.com/baditaflorin/mesh-countdown-wall","url":"https://baditaflorin.github.io/mesh-countdown-wall/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-crowd-map","domain":"baditaflorin.github.io/mesh-crowd-map/","mesh":"pages","category":"peer_to_peer","title":"Mesh Crowd Map","summary":"A privacy-safe shared board for coarse, short-lived observations.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-crowd-map/","repo_url":"https://github.com/baditaflorin/mesh-crowd-map","url":"https://baditaflorin.github.io/mesh-crowd-map/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-daily-question","domain":"baditaflorin.github.io/mesh-daily-question/","mesh":"pages","category":"peer_to_peer","title":"Mesh Daily Question","summary":"A browser-local daily question room for one thoughtful answer per peer.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-daily-question/","repo_url":"https://github.com/baditaflorin/mesh-daily-question","url":"https://baditaflorin.github.io/mesh-daily-question/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-deadline-pact","domain":"baditaflorin.github.io/mesh-deadline-pact/","mesh":"pages","category":"peer_to_peer","title":"Mesh Deadline Pact","summary":"A browser-local peer commitment room with shared deadlines and check-ins.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-deadline-pact/","repo_url":"https://github.com/baditaflorin/mesh-deadline-pact","url":"https://baditaflorin.github.io/mesh-deadline-pact/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-decision-room","domain":"baditaflorin.github.io/mesh-decision-room/","mesh":"pages","category":"productivity","title":"Mesh Decision Room","summary":"A browser-local ranked decision room for small groups.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-decision-room/","repo_url":"https://github.com/baditaflorin/mesh-decision-room","url":"https://baditaflorin.github.io/mesh-decision-room/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-exit-ticket","domain":"baditaflorin.github.io/mesh-exit-ticket/","mesh":"pages","category":"education","title":"Mesh Exit Ticket","summary":"A browser-local end-of-session feedback board.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-exit-ticket/","repo_url":"https://github.com/baditaflorin/mesh-exit-ticket","url":"https://baditaflorin.github.io/mesh-exit-ticket/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-firefly-walk","domain":"baditaflorin.github.io/mesh-firefly-walk/","mesh":"pages","category":"peer_to_peer","title":"Mesh Firefly Walk","summary":"Peer-to-peer mesh: phones pulse soft yellow in clock-synced unison for a swarm-of-fireflies effect on a night walk.","health_url":"https://baditaflorin.github.io/mesh-firefly-walk/","repo_url":"https://github.com/baditaflorin/mesh-firefly-walk","url":"https://baditaflorin.github.io/mesh-firefly-walk/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass). Corrected assumption: this is a WebRTC/Yjs clock-synchronized ambient pulse effect (median-offset mesh clock, phones brighten in unison), not a geolocation app -- no geolocation API anywhere in source. Found and fixed two issues: (1) the pulse-period input had no upper clamp despite a documented 500-10000ms range, live-reproduced typing a huge value permanently darkened the app with no error; (2) privacy docs claimed zero non-clock data in the wire payload, but mesh-common's MeshShell fires an undisclosed pageview beacon carrying the room ID on every join (has a working DNT opt-out, verified live) -- fixed the disclosure gap in docs/privacy.md rather than the (working) opt-out mechanism. Stale-peer cleanup and adversarial-peer-data handling verified sound. trl bumped 3-\u003e4; trl_ceiling=5. See github.com/baditaflorin/mesh-firefly-walk PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-five-second-rule","domain":"baditaflorin.github.io/mesh-five-second-rule/","mesh":"pages","category":"peer_to_peer","title":"Mesh Five Second Rule","summary":"A fast, peer-to-peer answer game where every voice gets five seconds.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-five-second-rule/","repo_url":"https://github.com/baditaflorin/mesh-five-second-rule","url":"https://baditaflorin.github.io/mesh-five-second-rule/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-flashcard-swarm","domain":"baditaflorin.github.io/mesh-flashcard-swarm/","mesh":"pages","category":"peer_to_peer","title":"Mesh Flashcard Swarm","summary":"A browser-local peer-authored flashcard review room.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-flashcard-swarm/","repo_url":"https://github.com/baditaflorin/mesh-flashcard-swarm","url":"https://baditaflorin.github.io/mesh-flashcard-swarm/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-focus-sprint","domain":"baditaflorin.github.io/mesh-focus-sprint/","mesh":"pages","category":"productivity","title":"Mesh Focus Sprint","summary":"A browser-local shared focus sprint with an honest timer.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-focus-sprint/","repo_url":"https://github.com/baditaflorin/mesh-focus-sprint","url":"https://baditaflorin.github.io/mesh-focus-sprint/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-gift-exchange","domain":"baditaflorin.github.io/mesh-gift-exchange/","mesh":"pages","category":"peer_to_peer","title":"Mesh Gift Exchange","summary":"A fair, private gift draw that stays directly between the people in your room.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-gift-exchange/","repo_url":"https://github.com/baditaflorin/mesh-gift-exchange","url":"https://baditaflorin.github.io/mesh-gift-exchange/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-habit-sprint","domain":"baditaflorin.github.io/mesh-habit-sprint/","mesh":"pages","category":"peer_to_peer","title":"Mesh Habit Sprint","summary":"A time-boxed peer-to-peer habit challenge with shared check-ins and progress.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-habit-sprint/","repo_url":"https://github.com/baditaflorin/mesh-habit-sprint","url":"https://baditaflorin.github.io/mesh-habit-sprint/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-heads-up","domain":"baditaflorin.github.io/mesh-heads-up/","mesh":"pages","category":"peer_to_peer","title":"Mesh Heads Up","summary":"A browser-local clue passing game for a room of peers.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-heads-up/","repo_url":"https://github.com/baditaflorin/mesh-heads-up","url":"https://baditaflorin.github.io/mesh-heads-up/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-host-handoff","domain":"baditaflorin.github.io/mesh-host-handoff/","mesh":"pages","category":"coordination","title":"Mesh Host Handoff","summary":"A shared peer-to-peer host handoff board for facilitation without accounts.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-host-handoff/","repo_url":"https://github.com/baditaflorin/mesh-host-handoff","url":"https://baditaflorin.github.io/mesh-host-handoff/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-idea-market","domain":"baditaflorin.github.io/mesh-idea-market/","mesh":"pages","category":"peer_to_peer","title":"Mesh Idea Market","summary":"A peer-to-peer idea market where every participant invests a shared budget.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-idea-market/","repo_url":"https://github.com/baditaflorin/mesh-idea-market","url":"https://baditaflorin.github.io/mesh-idea-market/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-improv-director","domain":"baditaflorin.github.io/mesh-improv-director/","mesh":"pages","category":"peer_to_peer","title":"Mesh Improv Director","summary":"A browser-local shared prompt director for accessible improv sessions.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-improv-director/","repo_url":"https://github.com/baditaflorin/mesh-improv-director","url":"https://baditaflorin.github.io/mesh-improv-director/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-invite-pocket","domain":"baditaflorin.github.io/mesh-invite-pocket/","mesh":"pages","category":"peer_to_peer","title":"Mesh Invite Pocket","summary":"Browser-local mesh service built with mesh-common","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-invite-pocket/","repo_url":"https://github.com/baditaflorin/mesh-invite-pocket","url":"https://baditaflorin.github.io/mesh-invite-pocket/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-lightning-flash","domain":"baditaflorin.github.io/mesh-lightning-flash/","mesh":"pages","category":"peer_to_peer","title":"Mesh Lightning Flash","summary":"Peer-to-peer mesh: all phone flashlights strobe in single-millisecond sync to light a group photo from many angles at once.","health_url":"https://baditaflorin.github.io/mesh-lightning-flash/","repo_url":"https://github.com/baditaflorin/mesh-lightning-flash","url":"https://baditaflorin.github.io/mesh-lightning-flash/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass). Corrected assumption: this is a P2P photography aid where one phone broadcasts a synchronized fire time and others flash/torch-strobe in unison, not a reflex game. Found and fixed a core-usability bug via live two-tab testing: the camera's FLASH button became permanently disabled after the first flash of any session, because pending-fire state was only recomputed on Yjs array mutations rather than on a timer, so its 500ms wall-clock grace window never actually expired in the UI -- confirmed the button stayed disabled for 9+ seconds when it should clear in ~2.2s. Fixed with a timer-driven recheck plus a soonest-fireAt event-selection fix. Epilepsy-safety, secrets/XSS, and privacy claims (camera frame never rendered/transmitted) all verified sound. trl bumped 3-\u003e4. See github.com/baditaflorin/mesh-lightning-flash PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-lightning-poll","domain":"baditaflorin.github.io/mesh-lightning-poll/","mesh":"pages","category":"peer_to_peer","title":"Mesh Lightning Poll","summary":"A one-choice-per-peer live poll.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-lightning-poll/","repo_url":"https://github.com/baditaflorin/mesh-lightning-poll","url":"https://baditaflorin.github.io/mesh-lightning-poll/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-lost-found","domain":"baditaflorin.github.io/mesh-lost-found/","mesh":"pages","category":"peer_to_peer","title":"Mesh Lost Found","summary":"A browser-local shared missing and found board with private claimant flow.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-lost-found/","repo_url":"https://github.com/baditaflorin/mesh-lost-found","url":"https://baditaflorin.github.io/mesh-lost-found/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-lucky-draw","domain":"baditaflorin.github.io/mesh-lucky-draw/","mesh":"pages","category":"peer_to_peer","title":"Mesh Lucky Draw","summary":"A peer-to-peer lucky draw for a room.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-lucky-draw/","repo_url":"https://github.com/baditaflorin/mesh-lucky-draw","url":"https://baditaflorin.github.io/mesh-lucky-draw/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-mafia","domain":"baditaflorin.github.io/mesh-mafia/","mesh":"pages","category":"peer_to_peer","title":"Mesh Mafia","summary":"Peer-to-peer Werewolf: phones are role cards assigned via cryptographic commit-reveal; no server ever learns who's the wolf.","health_url":"https://baditaflorin.github.io/mesh-mafia/","repo_url":"https://github.com/baditaflorin/mesh-mafia","url":"https://baditaflorin.github.io/mesh-mafia/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass), specifically primed to check for the information-leakage bug class common to hidden-role games. Found and fixed exactly that: every peer computed and stored the FULL {peerId: role} map for the whole table in long-lived React state, even though the UI only ever rendered the local player's own role -- any player could read every other player's role, including who the mafia were, straight out of devtools. Live-proved: a villager's own state contained the full role assignment for all 4 players. Also found and fixed a second real bug: mafiaCount is a per-device localStorage setting fed into the deterministic role-derivation math, so phones with different stale local values disagreed about who was mafia for the identical deal -- live-proved with 6 peers. Fixed by only storing each peer's own role+teammates, and by syncing mafiaCount into the shared doc at deal time. trl bumped 3-\u003e5 -- not ceilinged, could be hardened further via per-recipient encrypted role delivery without a redesign. See github.com/baditaflorin/mesh-mafia PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-memory-match","domain":"baditaflorin.github.io/mesh-memory-match/","mesh":"pages","category":"peer_to_peer","title":"Mesh Memory Match","summary":"An accessible browser-local matching game for small groups.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-memory-match/","repo_url":"https://github.com/baditaflorin/mesh-memory-match","url":"https://baditaflorin.github.io/mesh-memory-match/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-message-drop","domain":"baditaflorin.github.io/mesh-message-drop/","mesh":"pages","category":"social","title":"Mesh Message Drop","summary":"A lightweight peer-to-peer message stream for a shared room.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-message-drop/","repo_url":"https://github.com/baditaflorin/mesh-message-drop","url":"https://baditaflorin.github.io/mesh-message-drop/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-metronome","domain":"baditaflorin.github.io/mesh-metronome/","mesh":"pages","category":"peer_to_peer","title":"Mesh Metronome","summary":"Peer-to-peer mesh: 4 phones become a polyrhythm grid, each playing a clock-synced subdivision of the same BPM.","health_url":"https://baditaflorin.github.io/mesh-metronome/","repo_url":"https://github.com/baditaflorin/mesh-metronome","url":"https://baditaflorin.github.io/mesh-metronome/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass). Confirmed sample-accurate Web Audio API scheduling throughout (no setTimeout-based audio timing). Found and fixed a real bug: the clock-sync layer trusted remote peers' clock.t/bpm awareness data with only a typeof-number check, which doesn't reject NaN/Infinity -- any peer (no auth, default room) could poison meshNow() for the whole room, silently and permanently killing all audio with no visible error (the exception was swallowed by a try/catch elsewhere). Reproduced with a new unit test confirmed to fail pre-fix. Also found and fixed a privacy-disclosure gap: an undisclosed pageview beacon and a fleet-persona identity panel wired by default, neither mentioned in docs/privacy.md -- regenerated the doc via the project's own generator plus an explicit addendum. trl bumped 4-\u003e5; trl_ceiling=6 pending upstream mesh-common privacy-story tightening. See github.com/baditaflorin/mesh-metronome PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-milestone-map","domain":"baditaflorin.github.io/mesh-milestone-map/","mesh":"pages","category":"peer_to_peer","title":"Mesh Milestone Map","summary":"A peer-to-peer shared milestone map.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-milestone-map/","repo_url":"https://github.com/baditaflorin/mesh-milestone-map","url":"https://baditaflorin.github.io/mesh-milestone-map/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-mirror","domain":"baditaflorin.github.io/mesh-mirror/","mesh":"pages","category":"peer_to_peer","title":"Mesh Mirror","summary":"Peer-to-peer mesh: phones in a ring show each other's live camera feed — phone N's screen shows phone (N+1)'s view, creating a low-fi infinite mirror.","health_url":"https://baditaflorin.github.io/mesh-mirror/","repo_url":"https://github.com/baditaflorin/mesh-mirror","url":"https://baditaflorin.github.io/mesh-mirror/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"First-ever audit of this ring-topology WebRTC camera-mirroring app (Yjs awareness carries low-fps JPEG frames, not real video tracks, per the app's own ADR). Confirmed live two-peer testing shows the core cross-mesh mirroring genuinely works, including the no-own-camera discriminator case. Found and fixed a real camera-leak bug: unprotected await/throw points between acquiring the camera and returning the stop-capable handle left the camera running indefinitely on any setup failure (video.play() rejecting, canvas context null), with no in-app way to release it or retry. Fixed with try/catch cleanup plus a 'Try again' recovery path; a new Playwright test using a fake device confirmed the leak pre-fix and its absence post-fix. No server-side frame exfiltration found (traced all network calls). trl bumped from unassessed to 5; trl_ceiling=6 -- by-design limits reasonable for a peer_to_peer novelty app. See github.com/baditaflorin/mesh-mirror PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-most-likely","domain":"baditaflorin.github.io/mesh-most-likely/","mesh":"pages","category":"app","title":"Mesh Most Likely","tags":["kind-static","language-html","peer-to-peer","runtime-github-pages"],"health_url":"https://baditaflorin.github.io/mesh-most-likely/","repo_url":"https://github.com/baditaflorin/mesh-most-likely","url":"https://baditaflorin.github.io/mesh-most-likely/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":2,"trl_evidence":"First-ever audit of this P2P 'Most Likely To' voting game (Yjs/y-webrtc). Verified architecture and privacy claims against source. Found and fixed two real gameplay bugs via a two-peer CRDT test harness: (1) a per-card vote key missing the round seed, so replaying a deck resurrected stale votes from the previous shuffle onto a completely different reshuffled prompt; (2) a reveal verdict computed from an unfiltered vote tally, so a departed/refreshed peer could be crowned winner while absent from the leaderboard shown directly beneath -- live-verified with linked peers ('Ghost' crowned survivor-of-a-zombie-apocalypse while showing 0 on the leaderboard). Both fixed with regression tests. A related gap (stale-voter count inflation on non-peer-indexed vote kinds) needs a mesh-common library change, flagged as follow-up. trl=2, trl_ceiling=3 -- real bugs just found and fixed in core scoring logic, genuinely early-stage. See github.com/baditaflorin/mesh-most-likely PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-note-pile","domain":"baditaflorin.github.io/mesh-note-pile/","mesh":"pages","category":"peer_to_peer","title":"Mesh Note Pile","summary":"Peer-to-peer browser service built with mesh-common.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-note-pile/","repo_url":"https://github.com/baditaflorin/mesh-note-pile","url":"https://baditaflorin.github.io/mesh-note-pile/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-one-word-wall","domain":"baditaflorin.github.io/mesh-one-word-wall/","mesh":"pages","category":"peer_to_peer","title":"Mesh One Word Wall","summary":"A shared one-word wall for group reflection and check-ins.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-one-word-wall/","repo_url":"https://github.com/baditaflorin/mesh-one-word-wall","url":"https://baditaflorin.github.io/mesh-one-word-wall/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-open-house","domain":"baditaflorin.github.io/mesh-open-house/","mesh":"pages","category":"peer_to_peer","title":"Mesh Open House","summary":"A browser-local RSVP board for a welcoming shared event.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-open-house/","repo_url":"https://github.com/baditaflorin/mesh-open-house","url":"https://baditaflorin.github.io/mesh-open-house/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-pair-mixer","domain":"baditaflorin.github.io/mesh-pair-mixer/","mesh":"pages","category":"work_learning","title":"Mesh Pair Mixer","summary":"A browser-local shared pair maker for small groups.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-pair-mixer/","repo_url":"https://github.com/baditaflorin/mesh-pair-mixer","url":"https://baditaflorin.github.io/mesh-pair-mixer/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-particles","domain":"baditaflorin.github.io/mesh-particles/","mesh":"pages","category":"devices_and_spaces","title":"Mesh Particles","summary":"Installation rehearsal: synchronized screen light, optional torch, and local multi-angle capture.","tags":["art-installation","rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-particles/","repo_url":"https://github.com/baditaflorin/mesh-particles","url":"https://baditaflorin.github.io/mesh-particles/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-pass-the-phone","domain":"baditaflorin.github.io/mesh-pass-the-phone/","mesh":"pages","category":"peer_to_peer","title":"Mesh Pass The Phone","summary":"A browser-local rotating prompt game for a room of peers.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-pass-the-phone/","repo_url":"https://github.com/baditaflorin/mesh-pass-the-phone","url":"https://baditaflorin.github.io/mesh-pass-the-phone/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-picker","domain":"baditaflorin.github.io/mesh-picker/","mesh":"pages","category":"app","title":"Mesh Picker","tags":["kind-static","language-html","peer-to-peer","runtime-github-pages"],"health_url":"https://baditaflorin.github.io/mesh-picker/","repo_url":"https://github.com/baditaflorin/mesh-picker","url":"https://baditaflorin.github.io/mesh-picker/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"First-ever audit of this P2P random-picker/decision app (Yjs/y-webrtc). Confirmed core RNG/shuffle math (mulberry32, seeded Fisher-Yates, single-cycle derangement for Secret Santa) is sound -- no modulo bias, no self-assignment, edge cases handled, 24 existing unit tests. Found and fixed two real bugs via the project's own mock-room test harness (each verified to fail pre-fix): (1) a room-wide crash from an unvalidated shared 'mode' value indexed into a lookup table -- any peer writing an unrecognized value crashes every connected peer's render; (2) a split-brain reveal -- teams/winner were recomputed from the live roster on every render instead of a value snapshotted at Draw time, so transient roster disagreement between peers (propagation lag, clock skew, mid-draw joins) could produce different results from an identical shared seed. Also corrected a false 'commit-reveal' security claim in the README/tagline -- salts are published in the clear and Reroll is unlimited/unilateral, verified by tracing mesh-common's useFairRng. trl=4, trl_ceiling=6 pending a real fix to the shared fairness-protocol gap (flagged as a follow-up task against mesh-common). See github.com/baditaflorin/mesh-picker PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-pixel-party","domain":"baditaflorin.github.io/mesh-pixel-party/","mesh":"pages","category":"creative","title":"Mesh Pixel Party","summary":"A compact shared pixel-art canvas for small rooms.","health_url":"https://baditaflorin.github.io/mesh-pixel-party/","repo_url":"https://github.com/baditaflorin/mesh-pixel-party","url":"https://baditaflorin.github.io/mesh-pixel-party/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-playlist-pass","domain":"baditaflorin.github.io/mesh-playlist-pass/","mesh":"pages","category":"creative","title":"Mesh Playlist Pass","summary":"Browser-local shared listening queue for passing the next pick between friends","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-playlist-pass/","repo_url":"https://github.com/baditaflorin/mesh-playlist-pass","url":"https://baditaflorin.github.io/mesh-playlist-pass/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-privacy-drop","domain":"baditaflorin.github.io/mesh-privacy-drop/","mesh":"pages","category":"peer_to_peer","title":"Mesh Privacy Drop","summary":"QR-paired, short-lived encrypted file transfer directly between browsers.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-privacy-drop/","repo_url":"https://github.com/baditaflorin/mesh-privacy-drop","url":"https://baditaflorin.github.io/mesh-privacy-drop/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-prompt-deck","domain":"baditaflorin.github.io/mesh-prompt-deck/","mesh":"pages","category":"peer_to_peer","title":"Mesh Prompt Deck","summary":"A shared conversation prompt deck for a group in one room.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-prompt-deck/","repo_url":"https://github.com/baditaflorin/mesh-prompt-deck","url":"https://baditaflorin.github.io/mesh-prompt-deck/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-prompt-ladder","domain":"baditaflorin.github.io/mesh-prompt-ladder/","mesh":"pages","category":"peer_to_peer","title":"Mesh Prompt Ladder","summary":"A browser-local staged discussion prompt ladder for groups.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-prompt-ladder/","repo_url":"https://github.com/baditaflorin/mesh-prompt-ladder","url":"https://baditaflorin.github.io/mesh-prompt-ladder/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-queue","domain":"baditaflorin.github.io/mesh-queue/","mesh":"pages","category":"peer_to_peer","title":"Mesh Queue","summary":"A shared take-a-number queue that works directly between browsers.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-queue/","repo_url":"https://github.com/baditaflorin/mesh-queue","url":"https://baditaflorin.github.io/mesh-queue/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-quick-draw-duel","domain":"baditaflorin.github.io/mesh-quick-draw-duel/","mesh":"pages","category":"peer_to_peer","title":"Mesh Quick Draw Duel","summary":"A browser-local two-peer drawing race with a shared timer and accessible fallback controls.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-quick-draw-duel/","repo_url":"https://github.com/baditaflorin/mesh-quick-draw-duel","url":"https://baditaflorin.github.io/mesh-quick-draw-duel/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-rating-board","domain":"baditaflorin.github.io/mesh-rating-board/","mesh":"pages","category":"peer_to_peer","title":"Mesh Rating Board","summary":"A shared five-star room temperature check.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-rating-board/","repo_url":"https://github.com/baditaflorin/mesh-rating-board","url":"https://baditaflorin.github.io/mesh-rating-board/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-reaction","domain":"baditaflorin.github.io/mesh-reaction/","mesh":"pages","category":"app","title":"Mesh Reaction","tags":["kind-static","language-html","peer-to-peer","runtime-github-pages"],"health_url":"https://baditaflorin.github.io/mesh-reaction/","repo_url":"https://github.com/baditaflorin/mesh-reaction","url":"https://baditaflorin.github.io/mesh-reaction/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"First-ever audit of this P2P reaction-speed game (Yjs/y-webrtc). Found and fixed a 100%-reproducible React render-phase violation: the mesh-median clock sync object was built inside useMemo, but its constructor synchronously publishes onto shared WebRTC awareness state, which synchronously fires a parent component's setState mid-render -- illegal in React, reproduced on every single page load (confirmed via console errors). Fixed by moving clock construction into a properly-keyed useEffect. Scoring/false-start/tie-break logic (pure, unit-tested) verified correct; no XSS (tested live with an injection payload in the name field); no hardcoded secrets. Noted but out-of-scope: clock sync has no RTT/2 latency correction (lives in shared mesh-common), though each peer's own recorded reaction time is unaffected by the bias. trl=3, trl_ceiling=4. See github.com/baditaflorin/mesh-reaction PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-reaction-wall","domain":"baditaflorin.github.io/mesh-reaction-wall/","mesh":"pages","category":"social","title":"Mesh Reaction Wall","summary":"A shared, de-duplicated reaction wall powered by mesh-common.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-reaction-wall/","repo_url":"https://github.com/baditaflorin/mesh-reaction-wall","url":"https://baditaflorin.github.io/mesh-reaction-wall/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-recipe-relay","domain":"baditaflorin.github.io/mesh-recipe-relay/","mesh":"pages","category":"peer_to_peer","title":"Mesh Recipe Relay","summary":"A browser-local, turn-based recipe relay with one safe step per peer.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-recipe-relay/","repo_url":"https://github.com/baditaflorin/mesh-recipe-relay","url":"https://baditaflorin.github.io/mesh-recipe-relay/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-remote-retro-standup","domain":"baditaflorin.github.io/mesh-remote-retro-standup/","mesh":"pages","category":"peer_to_peer","title":"Mesh Remote Retro Standup","summary":"A browser-local, time-boxed remote standup with one validated update per peer.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-remote-retro-standup/","repo_url":"https://github.com/baditaflorin/mesh-remote-retro-standup","url":"https://baditaflorin.github.io/mesh-remote-retro-standup/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-role-draw","domain":"baditaflorin.github.io/mesh-role-draw/","mesh":"pages","category":"peer_to_peer","title":"Mesh Role Draw","summary":"A first-claim role picker for a small group.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-role-draw/","repo_url":"https://github.com/baditaflorin/mesh-role-draw","url":"https://baditaflorin.github.io/mesh-role-draw/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-room-norms","domain":"baditaflorin.github.io/mesh-room-norms/","mesh":"pages","category":"peer_to_peer","title":"Mesh Room Norms","summary":"A browser-local shared agreement board for group room norms.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-room-norms/","repo_url":"https://github.com/baditaflorin/mesh-room-norms","url":"https://baditaflorin.github.io/mesh-room-norms/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-round-counter","domain":"baditaflorin.github.io/mesh-round-counter/","mesh":"pages","category":"peer_to_peer","title":"Mesh Round Counter","summary":"Peer-to-peer browser service built with mesh-common.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-round-counter/","repo_url":"https://github.com/baditaflorin/mesh-round-counter","url":"https://baditaflorin.github.io/mesh-round-counter/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-scoreboard","domain":"baditaflorin.github.io/mesh-scoreboard/","mesh":"pages","category":"peer_to_peer","title":"Mesh Scoreboard","summary":"A small shared score board for browser-local games and challenges.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-scoreboard/","repo_url":"https://github.com/baditaflorin/mesh-scoreboard","url":"https://baditaflorin.github.io/mesh-scoreboard/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-shared-checklist","domain":"baditaflorin.github.io/mesh-shared-checklist/","mesh":"pages","category":"peer_to_peer","title":"Mesh Shared Checklist","summary":"A shared, assigned checklist for small groups.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-shared-checklist/","repo_url":"https://github.com/baditaflorin/mesh-shared-checklist","url":"https://baditaflorin.github.io/mesh-shared-checklist/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-shared-window","domain":"baditaflorin.github.io/mesh-shared-window/","mesh":"pages","category":"peer_to_peer","title":"Mesh Shared Window","summary":"Peer-to-peer mesh: 2-4 friends in different homes each point their camera at a view they like; every phone tiles all the others' feeds into one composite.","health_url":"https://baditaflorin.github.io/mesh-shared-window/","repo_url":"https://github.com/baditaflorin/mesh-shared-window","url":"https://baditaflorin.github.io/mesh-shared-window/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass). Corrected assumption: this is a tiled-grid low-fps camera-snapshot sharing app over Yjs awareness (not a shared-cursor surface). Found and fixed two real bugs: (1) editing the tile-label field re-triggered the camera-acquisition effect on every keystroke, flashing the whole tile to 'opening...'; (2) with no auth by design, any peer could publish malformed awareness data (e.g. non-string label) that threw inside a shared change handler, freezing the tile grid for the entire room off one bad message. Both fixed and covered by new unit/e2e regression tests confirmed to fail pre-fix. Late-joiner sync, XSS, and secrets all verified sound. trl bumped 4-\u003e5. See github.com/baditaflorin/mesh-shared-window PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-silence-counter","domain":"baditaflorin.github.io/mesh-silence-counter/","mesh":"pages","category":"peer_to_peer","title":"Mesh Silence Counter","summary":"Peer-to-peer mesh: group meditation timer. Phones detect stillness via accelerometer and aggregate the count anonymously.","health_url":"https://baditaflorin.github.io/mesh-silence-counter/","repo_url":"https://github.com/baditaflorin/mesh-silence-counter","url":"https://baditaflorin.github.io/mesh-silence-counter/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass, which also mis-scored this the lowest trl of any mesh app). Corrected assumption: this is an accelerometer-based DeviceMotionEvent stillness detector for group meditation, not a mic app -- no getUserMedia anywhere, so mic-privacy concerns don't apply. Found and fixed two silent WebRTC bootstrapping bugs: (1) the self-heal path for a stale cached signaling URL returned an empty string instead of the live default -- new WebSocket('') doesn't throw, so peer discovery broke permanently with zero error for any browser that ever cached the dead URL; (2) the WebRTC room was constructed synchronously reading ICE servers from localStorage while the TURN-credential fetch ran in parallel, so every user's first join ran STUN-only despite the app existing specifically to work around NAT via TURN. Both live-verified and fixed. trl bumped 2-\u003e4. See github.com/baditaflorin/mesh-silence-counter PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-skill-challenge","domain":"baditaflorin.github.io/mesh-skill-challenge/","mesh":"pages","category":"peer_to_peer","title":"Mesh Skill Challenge","summary":"An accessible browser-local board for small shared skill challenges.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-skill-challenge/","repo_url":"https://github.com/baditaflorin/mesh-skill-challenge","url":"https://baditaflorin.github.io/mesh-skill-challenge/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-social-battery","domain":"baditaflorin.github.io/mesh-social-battery/","mesh":"pages","category":"peer_to_peer","title":"Mesh Social Battery","summary":"A browser-local, accessible shared social-energy check-in.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-social-battery/","repo_url":"https://github.com/baditaflorin/mesh-social-battery","url":"https://baditaflorin.github.io/mesh-social-battery/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-sound-guess","domain":"baditaflorin.github.io/mesh-sound-guess/","mesh":"pages","category":"peer_to_peer","title":"Mesh Sound Guess","summary":"An accessible browser-local shared sound and emoji clue guessing game.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-sound-guess/","repo_url":"https://github.com/baditaflorin/mesh-sound-guess","url":"https://baditaflorin.github.io/mesh-sound-guess/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-speed-type","domain":"baditaflorin.github.io/mesh-speed-type/","mesh":"pages","category":"peer_to_peer","title":"Mesh Speed Type","summary":"A shared, peer-to-peer typing sprint with a live WPM leaderboard.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-speed-type/","repo_url":"https://github.com/baditaflorin/mesh-speed-type","url":"https://baditaflorin.github.io/mesh-speed-type/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-spot-it","domain":"baditaflorin.github.io/mesh-spot-it/","mesh":"pages","category":"peer_to_peer","title":"Mesh Spot It","summary":"An accessible browser-local shared matching-symbol race.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-spot-it/","repo_url":"https://github.com/baditaflorin/mesh-spot-it","url":"https://baditaflorin.github.io/mesh-spot-it/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-sticky-board","domain":"baditaflorin.github.io/mesh-sticky-board/","mesh":"pages","category":"work_learning","title":"Mesh Sticky Board","summary":"A shared spatial sticky-note board for quick group thinking.","health_url":"https://baditaflorin.github.io/mesh-sticky-board/","repo_url":"https://github.com/baditaflorin/mesh-sticky-board","url":"https://baditaflorin.github.io/mesh-sticky-board/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-taboo-clues","domain":"baditaflorin.github.io/mesh-taboo-clues/","mesh":"pages","category":"peer_to_peer","title":"Mesh Taboo Clues","summary":"A peer-to-peer clue game with shared turns, timer, and taboo flags.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-taboo-clues/","repo_url":"https://github.com/baditaflorin/mesh-taboo-clues","url":"https://baditaflorin.github.io/mesh-taboo-clues/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-tap-symphony","domain":"baditaflorin.github.io/mesh-tap-symphony/","mesh":"pages","category":"peer_to_peer","title":"Mesh Tap Symphony","summary":"Peer-to-peer mesh: each phone is one drum; 30 seconds of taps records a synced loop that replays on every phone.","health_url":"https://baditaflorin.github.io/mesh-tap-symphony/","repo_url":"https://github.com/baditaflorin/mesh-tap-symphony","url":"https://baditaflorin.github.io/mesh-tap-symphony/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass). Confirmed sample-accurate Web Audio scheduling (no setTimeout drift) and correct late-joiner CRDT replay of the shared drum loop. Found and fixed a real, high-severity crash: the shared tap-event array was written by every peer with zero validation, so a malformed entry (bad slot value, from a malicious/buggy peer or stray devtools write) threw during render with no error boundary anywhere in the app -- crashed the whole tree to a white screen for every current AND future joiner, since the bad entry replays from the shared CRDT. Fixed with input validation at the CRDT-to-render boundary plus a MeshErrorBoundary wrap; added the repo's first unit tests. trl bumped 3-\u003e4. See github.com/baditaflorin/mesh-tap-symphony PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-tug-of-war","domain":"baditaflorin.github.io/mesh-tug-of-war/","mesh":"pages","category":"app","title":"Mesh Tug Of War","summary":"Two teams tap frantically — the rope moves live on every phone","tags":["kind-static","language-html","peer-to-peer","runtime-github-pages"],"health_url":"https://baditaflorin.github.io/mesh-tug-of-war/","repo_url":"https://github.com/baditaflorin/mesh-tug-of-war","url":"https://baditaflorin.github.io/mesh-tug-of-war/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"First-ever audit of this P2P tug-of-war game (Yjs/y-webrtc). Tally aggregation and win detection verified immune to double-counting by construction (keyed-map sums, not deltas). Found and fixed a real, live-reproduced bug: team-switch buttons were unconditionally disabled for the whole countdown/pull phase, so a peer who reloaded mid-match (flaky wifi, tab backgrounding -- a realistic scenario for a co-located party game) got a fresh, teamless peerId and was permanently benched as a spectator with no way back in. Fixed by only locking team-switching once a peer already has a team this match. Verified with a new e2e test confirmed to fail pre-fix. No XSS/secrets found. A known, documented gap (raw Date.now() phase transitions instead of the available clockSync primitive) was flagged but not fixed. trl bumped from unassessed to 5. See github.com/baditaflorin/mesh-tug-of-war PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-turn-taker","domain":"baditaflorin.github.io/mesh-turn-taker/","mesh":"pages","category":"coordination","title":"Mesh Turn Taker","summary":"A browser-local shared turn order for small groups.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-turn-taker/","repo_url":"https://github.com/baditaflorin/mesh-turn-taker","url":"https://baditaflorin.github.io/mesh-turn-taker/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-volunteer-desk","domain":"baditaflorin.github.io/mesh-volunteer-desk/","mesh":"pages","category":"community","title":"Mesh Volunteer Desk","summary":"A browser-local capacity-safe volunteer shift desk.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-volunteer-desk/","repo_url":"https://github.com/baditaflorin/mesh-volunteer-desk","url":"https://baditaflorin.github.io/mesh-volunteer-desk/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-wave-canvas","domain":"baditaflorin.github.io/mesh-wave-canvas/","mesh":"pages","category":"peer_to_peer","title":"Mesh Wave Canvas","summary":"Peer-to-peer mesh: arrange phones in a row; tap one and a ripple expands across all phones as if they were one continuous canvas.","health_url":"https://baditaflorin.github.io/mesh-wave-canvas/","repo_url":"https://github.com/baditaflorin/mesh-wave-canvas","url":"https://baditaflorin.github.io/mesh-wave-canvas/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass). Corrected assumption: this is a shared ripple/tap-pulse effect across a physical row of phones (Yjs/y-webrtc), not a stroke-drawing canvas. Found and fixed two real bugs: (1) untrusted peer awareness data let NaN/Infinity through a weak typeof check, poisoning the mesh clock offset for the whole room and baking permanent, un-garbage-collectable NaN entries into the shared doc; (2) the periodic ripple GC deleted dead entries by count-from-front rather than by identity, an assumption that breaks under concurrent multi-peer taps and could delete a live ripple while a dead one survived. Both fixed and regression-tested (2 of 3 new tests confirmed to fail pre-fix). Also corrected a false privacy claim: docs claimed encrypted SDP signaling, but y-webrtc's encryption is opt-in and never enabled here, so signaling is plaintext (TLS-in-transit only) -- doc corrected rather than bolting on a false sense of security. trl bumped 3-\u003e5. See github.com/baditaflorin/mesh-wave-canvas PR #1 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-word-chain","domain":"baditaflorin.github.io/mesh-word-chain/","mesh":"pages","category":"peer_to_peer","title":"Mesh Word Chain","summary":"A quick peer-to-peer word chain with shared turns and a round clock.","tags":["typescript"],"health_url":"https://baditaflorin.github.io/mesh-word-chain/","repo_url":"https://github.com/baditaflorin/mesh-word-chain","url":"https://baditaflorin.github.io/mesh-word-chain/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-word-cloud","domain":"baditaflorin.github.io/mesh-word-cloud/","mesh":"pages","category":"peer_to_peer","title":"Mesh Word Cloud","summary":"A shared one-word reflection cloud for live groups.","tags":["rootless-computing"],"health_url":"https://baditaflorin.github.io/mesh-word-cloud/","repo_url":"https://github.com/baditaflorin/mesh-word-cloud","url":"https://baditaflorin.github.io/mesh-word-cloud/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"mesh-word-relay","domain":"baditaflorin.github.io/mesh-word-relay/","mesh":"pages","category":"games","title":"Mesh Word Relay","summary":"A browser-local word and micro-story relay for groups.","health_url":"https://baditaflorin.github.io/mesh-word-relay/","repo_url":"https://github.com/baditaflorin/mesh-word-relay","url":"https://baditaflorin.github.io/mesh-word-relay/","example":"/","auth":{"type":"none"},"auth_help":"no auth","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"newsletter-flow","domain":"baditaflorin.github.io/newsletter-flow/","mesh":"pages","category":"app","title":"Newsletter Flow","summary":"Local-first writing desk for researching, drafting, polishing, and repurposing newsletters without SaaS bloat.","health_url":"https://baditaflorin.github.io/newsletter-flow/","repo_url":"https://github.com/baditaflorin/newsletter-flow","url":"https://baditaflorin.github.io/newsletter-flow/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass) of this local-first newsletter drafting/repurposing tool. Found and fixed a real XSS vulnerability: source.url and discussionUrl fields (sourced from untrusted RSS/Atom/HTML/OPML imports, or an auto-loading shared Project JSON payload reachable via a #project= link with no confirmation) were rendered as raw \u003ca href\u003e with no scheme check -- a javascript: URL would execute in the app's own origin with access to every local project in IndexedDB, directly undermining the app's 'local-first, doesn't collect draft/source contents' privacy claim. Fixed with a sanitizeUrl() helper blocking javascript:/data:/vbscript:/file:/blob: schemes including tab/newline scheme-splitting bypasses, applied at both render sites. Autosave/draft-persistence logic checked specifically for the early-return-disables-autosave pattern found elsewhere in this initiative -- not present here. trl bumped 4-\u003e4 with real security hardening; trl_ceiling=5. See github.com/baditaflorin/newsletter-flow PR #7 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"numen","domain":"baditaflorin.github.io/numen/","mesh":"pages","category":"app","title":"Numen","summary":"Static-first academic writing platform for drafting, citations, literature review, figures, and submission-ready PDFs.","health_url":"https://baditaflorin.github.io/numen/","repo_url":"https://github.com/baditaflorin/numen","url":"https://baditaflorin.github.io/numen/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass) of this local-first academic-writing workbench. Verified privacy claim true via live browser network trace on a production build (zero external requests during normal use). Independently fuzz-tested the PDF line-wrapping algorithm against 500 random paragraphs using real pdf-lib font metrics (not the test suite's mocked measure) -- no overflow, no dropped content. Found and fixed a real bug: escapeLatex() only escaped 4 of 10 LaTeX special characters, so ordinary academic text ('O(n^2)', 'cost $5', 'dataset #1') produced a .tex export that fails to compile, undermining the app's 'submission-ready' claim. Fixed with a single-pass regex covering all special characters (avoiding a double-escape trap from naive chained replaceAll calls). Live-tested autosave survives a hard reload. trl bumped 3-\u003e4; trl_ceiling=5 pending real TeX-engine compilation testing of the export pipeline. See github.com/baditaflorin/numen PR #16 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"open-indie-studio","domain":"baditaflorin.github.io/open-indie-studio/","mesh":"pages","category":"app","title":"Open Indie Studio","summary":"Browser-based toolkit for making, testing, packaging, and documenting small 2D/casual indie games.","health_url":"https://baditaflorin.github.io/open-indie-studio/","repo_url":"https://github.com/baditaflorin/open-indie-studio","url":"https://baditaflorin.github.io/open-indie-studio/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass) of this browser-based 2D game-prototyping toolkit. Confirmed local-first privacy claim true (only network call is an explicit, user-configured local LLM endpoint). Verified the exported playtest HTML is genuinely playable (collision/pickup/hazard/win-loss logic all correct via a scripted animation-frame harness) and properly escapes injected XSS payloads in project name/goal fields. Found and fixed a real, live-reproduced data-loss bug: no text input enforced the underlying Zod schema's max lengths, and storage.ts silently discarded any save that failed validation, falling back to the starter project -- typing an ordinary 98-character title permanently and silently wiped the entire project on next reload, with the very next autosave overwriting the old save. Fixed by clamping input at the state-setter level plus matching maxLength attributes as defense-in-depth. trl bumped 3-\u003e4; trl_ceiling=5 -- editing loop is still minimal (no reposition/remove/re-import), a completeness gap not a correctness bug. See github.com/baditaflorin/open-indie-studio PR #7 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"open-school-lab","domain":"baditaflorin.github.io/open-school-lab/","mesh":"pages","category":"app","title":"Open School Lab","summary":"Browser-based science, math, and engineering labs for classrooms without physical equipment.","health_url":"https://baditaflorin.github.io/open-school-lab/","repo_url":"https://github.com/baditaflorin/open-school-lab","url":"https://baditaflorin.github.io/open-school-lab/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass) of this static, client-side educational lab-widget app. Confirmed zero data collection (only network call is the app's own service worker caching its own same-origin assets) and no XSS surface (all inputs are bounded range sliders, no free text). Found and fixed two real bugs: (1) a critical one -- switching between any two labs corrupted every metric to NaN because the renderer had no React key, so component state (and its stale control keys from the previous lab) was reused instead of remounted, breaking the app's core educational output on every single lab switch; (2) an unhandled localStorage.setItem exception (confirmed the repo's own test suite already failed on a clean checkout from this exact line) that could blank the whole app under realistic classroom conditions (Safari private browsing, LMS iframe embedding, quota errors) with no error boundary anywhere. Both fixed with regression tests; formulas hand-verified correct once NaN was fixed. trl bumped 3-\u003e4; trl_ceiling=6. See github.com/baditaflorin/open-school-lab PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"openphoto-studio","domain":"baditaflorin.github.io/openphoto-studio/","mesh":"pages","category":"app","title":"Openphoto Studio","summary":"Browser-based photo editor with WASM imaging tools and local WebGPU AI features.","health_url":"https://baditaflorin.github.io/openphoto-studio/","repo_url":"https://github.com/baditaflorin/openphoto-studio","url":"https://baditaflorin.github.io/openphoto-studio/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass) of this local-first photo editor. Verified the privacy claim true beyond just tracing calls: uploaded a synthetic JPEG with real GPS EXIF data, watched the full network log through import/edit/export (nothing external ever), and confirmed byte-for-byte that the exported file contains no EXIF/GPS markers (the canvas round-trip inherently strips all metadata) while EXIF orientation is correctly honored on import. Found and fixed three real, live-reproduced bugs: (1) Export ignored the Original/Edited compare toggle, always encoding the edited pixels even when Original was shown; (2) Save Local/Load Last always repackaged the pristine original blob, silently discarding destructive edits like 2x upscale or background removal; (3) Undo dropped adjustment-slider state, not just the destructive edit that triggered it. All three verified before/after at the pixel level with new regression tests. trl bumped 4-\u003e5; trl_ceiling=6 -- 'WebGPU ready'/'AI' framing overstates heuristic-only local processing per the project's own self-audit docs, no versioned project file format. See github.com/baditaflorin/openphoto-studio PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"osm-poster","domain":"baditaflorin.github.io/osm-poster/","mesh":"pages","category":"app","title":"Osm Poster","summary":"Beautiful map posters from OpenStreetMap, generated in your browser. No backend, no API keys.","health_url":"https://baditaflorin.github.io/osm-poster/","repo_url":"https://github.com/baditaflorin/osm-poster","url":"https://baditaflorin.github.io/osm-poster/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":6,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass) of this client-side OpenStreetMap poster generator (MapLibre GL + OpenFreeMap tiles + Nominatim geocoding, no backend or API keys, all disclosed). Found and fixed a severe security bug: the shareable-URL feature encodes full app state into the URL hash and rehydrates it on load with zero sanitization -- four fields flowed unescaped into innerHTML that runs automatically on page boot, and a live PoC confirmed a crafted share link executes arbitrary JS with zero clicks (unauthenticated, zero-interaction stored XSS). Fixed by escaping all four sites with the project's existing helper; re-tested the same payloads live post-fix, all blocked. Also found and fixed a domain-correctness bug: the PDF export's hand-authored mm-dimension table had drifted from the live CSS preview (story frame off by ~26%, screen/4K sizes had no mm table at all and silently defaulted to A4-portrait) -- fixed with a single CSS-synced source of truth, verified against the real jsPDF library for all 30 frame x size combinations. trl bumped 4-\u003e6 pending merge; trl_ceiling=7. See github.com/baditaflorin/osm-poster PR #2 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"parse-address","domain":"hassansin.github.io/parse-address/","mesh":"pages","category":"app","title":"Parse Address","summary":"US Street Address Parser","health_url":"http://hassansin.github.io/parse-address/","repo_url":"https://github.com/baditaflorin/parse-address","url":"http://hassansin.github.io/parse-address/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass that had scored this the highest trl in its batch without ever running the test suite -- 6 subtests were already failing on main). Found and fixed 10 real bugs in this US street-address parser: incorrect street-type classification defaulting unrecognized words to a plausible-looking match instead of empty; mis-parsing of no-comma addresses with abbreviated street types; comma-before-bare-ZIP wiping the whole address; trailing-comma breaking dictionary lookups; undetectable \u0026/@ intersections; dropped city on non-comma-separated intersections; a UTF-8 byte-slicing bug in title-casing that corrupted accented first letters (real impact: Puerto Rico place names); possible invalid-UTF-8 emission from input truncation; input validation bypassed for 4 of 5 API request types; and a reflected/self-XSS in the embedded test GUI (live-confirmed executing payload) contradicting the README's explicit XSS-protection claim. All fixed with regression tests; all 6 previously-failing tests now pass. No network calls anywhere (fully local). trl dropped 5-\u003e3 pending a monitoring window post-merge and a broader address-corpus regression suite; no hard structural ceiling. See github.com/baditaflorin/parse-address PR #2 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pentest-dashboard","domain":"baditaflorin.github.io/go-pentest-dashboard/","mesh":"pages","category":"visualization","title":"Pentest Dashboard","summary":"Browser dashboard for the pentest fleet. Single-page HTML app (Tailwind CDN, vanilla JS) with tabs for Preflight, Programs, Recon, Scan, Findings, Report. Calls every passive scanner via the api_key in browser localStorage. Human-facing GUI for the same flow go-pentest-cli and go-pentest-walkthrough automate.","tags":["go-pentest"],"health_url":"https://baditaflorin.github.io/go-pentest-dashboard/","repo_url":"https://github.com/baditaflorin/go-pentest-dashboard","url":"https://baditaflorin.github.io/go-pentest-dashboard/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":7,"trl_evidence":"sibling fan-out aggregator with 30s TTL cache, /overview HTML with html/template auto-escape (asserted by test), /selftest with 4 sibling stubs, sibling-down does not crash (degraded[] flag)","trl_ceiling":7,"trl_ceiling_reason":"Bounded by what the fleet exposes; active probing tools need auth + deploy before they can be surfaced safely.","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"physical-kanban-sync","domain":"baditaflorin.github.io/physical-kanban-sync/","mesh":"pages","category":"app","title":"Physical Kanban Sync","summary":"Browser-first physical sticky-note Kanban that scans AprilTags and syncs board state to collaborators.","health_url":"https://baditaflorin.github.io/physical-kanban-sync/","repo_url":"https://github.com/baditaflorin/physical-kanban-sync","url":"https://baditaflorin.github.io/physical-kanban-sync/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass) of this local-first camera-based physical-kanban-board tracker (vendored WASM AprilTag detector, tag-ID-keyed card matching, IndexedDB autosave). Verified privacy (camera frames never leave the browser), XSS safety (live injection test), and data persistence (live reload test) all sound. Found and fixed a real camera-leak bug: a scan-failure code path (worker crash, WASM init failure) never called stopCamera(), unlike the symmetric start-failure path -- left the camera stream, AprilTag worker, and scan interval running indefinitely while the UI misleadingly reverted to a 'start camera' button; clicking it again opened a second getUserMedia stream and orphaned the first, keeping the camera hardware/LED on indefinitely. Fixed to match the existing symmetric cleanup pattern, with a regression test confirmed to fail pre-fix. Flagged (not fixed): the default sync room name is a shared constant across all installs, a privacy footgun if two strangers both press Join without changing it. trl bumped 3-\u003e4; trl_ceiling=5. See github.com/baditaflorin/physical-kanban-sync PR #7 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"pockettalkie","domain":"baditaflorin.github.io/pockettalkie/","mesh":"pages","category":"app","title":"Pockettalkie","summary":"Encrypted push-to-talk rooms in the browser. P2P audio mesh over a self-hosted WebRTC stack. GitHub-Pages-only, no backend.","health_url":"https://baditaflorin.github.io/pockettalkie/","repo_url":"https://github.com/baditaflorin/pockettalkie","url":"https://baditaflorin.github.io/pockettalkie/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass) of this WebRTC mesh push-to-talk app. Confirmed voice audio is genuinely peer-to-peer (DTLS-SRTP), signaling carries no audio, and mic-release-on-leave is correct. Found and fixed a real reliability bug live-reproduced against the production signaling server in two real browser tabs: the peer-announce 'hello' was a one-shot timeout fired once 200ms after connect with no retry, so two peers joining the same room could get permanently stuck showing 'alone' -- confirmed live, and confirmed fixed by adding a periodic 4s re-announce. Also fixed a related gap: ICE connection failures triggered immediate peer teardown with no restart attempt, so any transient network blip permanently ended that leg of a call -- added up to 3 ICE-restart attempts before falling back. Repo had zero automated tests; added a fake-WebSocket/RTCPeerConnection regression suite covering both fixes. trl bumped 3-\u003e5. See github.com/baditaflorin/pockettalkie PR #5 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"polyglot-nlp-toolkit","domain":"baditaflorin.github.io/polyglot-nlp-toolkit/","mesh":"pages","category":"app","title":"Polyglot Nlp Toolkit","summary":"Multilingual NLP pipeline for corpus analysis: tokenize, tag, parse, NER, embed, and cluster text.","health_url":"https://baditaflorin.github.io/polyglot-nlp-toolkit/","repo_url":"https://github.com/baditaflorin/polyglot-nlp-toolkit","url":"https://baditaflorin.github.io/polyglot-nlp-toolkit/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass, which had scored this the highest trl in its batch) of this Go+Python multi-language NLP toolkit. Found and fixed the fleet's recurring CJK/multi-byte-script handling bug class: the tokenizer's unicode-aware greedy regex swallowed entire Chinese/Japanese sentences (no ASCII whitespace) into a single 'token' -- live-tested with a 40,000-char Chinese string tokenizing as exactly 1 token, and confirmed this reproduces through the exact code path the project's own Docker image ships for Japanese (no SudachiPy or per-language model actually installed, silently falls back to spaCy's blank whitespace-only tokenizer). Fixed with targeted Han/Kana re-segmentation, deliberately excluding space-delimited Korean. Also found and fixed a CSV formula-injection bug (CWE-1236) in the token exporter, and corrected a privacy doc that contradicted the app's actual unconditional localStorage autosave of raw corpus text. Wired a previously dead, never-CI'd test file into the build. trl dropped 5-\u003e4 pending a live Docker-deployment pass with real spaCy models; trl_ceiling=6. See github.com/baditaflorin/polyglot-nlp-toolkit PR #5 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"project-bootstrap-meta","domain":"baditaflorin.github.io/project-bootstrap-meta/","mesh":"pages","category":"app","title":"Project Bootstrap Meta","summary":"A GitHub Pages-first bootstrap map for disciplined project setup.","tags":["adr","github-pages","project-bootstrap","react","vite"],"health_url":"https://baditaflorin.github.io/project-bootstrap-meta/","repo_url":"https://github.com/baditaflorin/project-bootstrap-meta","url":"https://baditaflorin.github.io/project-bootstrap-meta/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":2,"trl_evidence":"bootstrapping tool, minimal logic","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"react-data-grid","domain":"adazzle.github.io/react-data-grid/","mesh":"pages","category":"app","title":"React Data Grid","summary":"Feature-rich and customizable data grid React component","health_url":"https://adazzle.github.io/react-data-grid/","repo_url":"https://github.com/baditaflorin/react-data-grid","url":"https://adazzle.github.io/react-data-grid/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":6,"trl_evidence":"React component, mature data grid, comprehensive features","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"read-later-curriculum","domain":"baditaflorin.github.io/read-later-curriculum/","mesh":"pages","category":"app","title":"Read Later Curriculum","summary":"A local-first read-later app that turns saved articles into a dependency-ordered reading curriculum.","health_url":"https://baditaflorin.github.io/read-later-curriculum/","repo_url":"https://github.com/baditaflorin/read-later-curriculum","url":"https://baditaflorin.github.io/read-later-curriculum/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"reading app, article curation","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"research-flow","domain":"baditaflorin.github.io/research-flow/","mesh":"pages","category":"app","title":"Research Flow","summary":"Private browser research workspace for clustering papers, finding gaps, drafting outlines, and exporting cited Word/LaTeX.","health_url":"https://baditaflorin.github.io/research-flow/","repo_url":"https://github.com/baditaflorin/research-flow","url":"https://baditaflorin.github.io/research-flow/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"research tool, workflow pipeline","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"roamless-notes","domain":"baditaflorin.github.io/roamless-notes/","mesh":"pages","category":"app","title":"Roamless Notes","summary":"Local-first outliner with backlinks, graph search, semantic recall, and optional peer-to-peer sync.","tags":["crdt","duckdb","github-pages","knowledge-graph","local-first","notes","yjs"],"health_url":"https://baditaflorin.github.io/roamless-notes/","repo_url":"https://github.com/baditaflorin/roamless-notes","url":"https://baditaflorin.github.io/roamless-notes/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"note-taking app, basic linking","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"room-vj","domain":"baditaflorin.github.io/room-vj/","mesh":"pages","category":"app","title":"Room Vj","summary":"Browser-based live room visuals that react to music, people, and synced nearby devices.","tags":["audio-reactive","mediapipe","threejs","webgpu","webrtc"],"health_url":"https://baditaflorin.github.io/room-vj/","repo_url":"https://github.com/baditaflorin/room-vj","url":"https://baditaflorin.github.io/room-vj/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"VJ app, real-time visuals","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"schlieren-imaging-simulator","domain":"baditaflorin.github.io/schlieren-imaging-simulator/","mesh":"pages","category":"app","title":"Schlieren Imaging Simulator","summary":"Browser-based Schlieren simulator for visualizing heat, sound, and gas density gradients with WebGPU and Three.js.","health_url":"https://baditaflorin.github.io/schlieren-imaging-simulator/","repo_url":"https://github.com/baditaflorin/schlieren-imaging-simulator","url":"https://baditaflorin.github.io/schlieren-imaging-simulator/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"physics simulator, optics model","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"show-me-the-way","domain":"osmlab.github.io/show-me-the-way/","mesh":"pages","category":"app","title":"Show Me The Way","summary":"See OSM edits happen in real time.","health_url":"http://osmlab.github.io/show-me-the-way/","repo_url":"https://github.com/baditaflorin/show-me-the-way","url":"http://osmlab.github.io/show-me-the-way/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"navigation app, routing logic","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"stellar-evolution-simulator","domain":"baditaflorin.github.io/stellar-evolution-simulator/","mesh":"pages","category":"app","title":"Stellar Evolution Simulator","summary":"Browser-based stellar lifecycle simulator using Pyodide, Plotly, and a MESA-inspired model subset.","health_url":"https://baditaflorin.github.io/stellar-evolution-simulator/","repo_url":"https://github.com/baditaflorin/stellar-evolution-simulator","url":"https://baditaflorin.github.io/stellar-evolution-simulator/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"astronomy simulator, stellar physics","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"string-portrait","domain":"baditaflorin.github.io/string-portrait/","mesh":"pages","category":"app","title":"String Portrait","tags":["kind-static","language-html","runtime-github-pages"],"health_url":"https://baditaflorin.github.io/string-portrait/","repo_url":"https://github.com/baditaflorin/string-portrait","url":"https://baditaflorin.github.io/string-portrait/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":6,"trl_evidence":"First-ever audit of this browser-only string-art (thread-portrait) generator. Confirmed genuine, provably-convergent greedy solver (residual monotonically decreases) and a verified-true privacy claim (no fetch/XHR/analytics anywhere in source or built bundle). Found and fixed a real correctness bug live-reproduced via a scripted mid-run slider drag: the nail-count setting was re-read live from settings mid-generation instead of snapshotted at run start, so dragging the Nails slider during a run (ordinary UI use) desynced the anti-oscillation edge-hash space partway through, silently breaking the 'never redraw the same chord' guarantee. Fixed by snapshotting nail count at run start. Non-square photo handling and malformed-file-upload handling both already worked cleanly; no XSS surface. trl bumped from unassessed to 6; trl_ceiling=7 -- a canvas/JS greedy solver naturally tops out here. See github.com/baditaflorin/string-portrait PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"substance-sampler","domain":"baditaflorin.github.io/substance-sampler/","mesh":"pages","category":"app","title":"Substance Sampler","summary":"Browser-based photo-to-PBR texture creation for indie game and 3D artists, powered by WebGPU and WASM.","health_url":"https://baditaflorin.github.io/substance-sampler/","repo_url":"https://github.com/baditaflorin/substance-sampler","url":"https://baditaflorin.github.io/substance-sampler/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"sample/chemistry app, material properties","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"tagboard","domain":"baditaflorin.github.io/tagboard/","mesh":"pages","category":"app","title":"Tagboard","summary":"AprilTag-anchored AR sticky notes. Print a marker, point your camera, shared notes appear. P2P over a self-hosted WebRTC mesh. No backend.","health_url":"https://baditaflorin.github.io/tagboard/","repo_url":"https://github.com/baditaflorin/tagboard","url":"https://baditaflorin.github.io/tagboard/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"tag-based app, simple organization","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"trust-no-one-anonymizer","domain":"baditaflorin.github.io/trust-no-one-anonymizer/","mesh":"pages","category":"app","title":"Trust No One Anonymizer","summary":"Client-side face and voice anonymizer for private browser-based video calls.","tags":["mediapipe","privacy","static-site","webaudio","webrtc"],"health_url":"https://baditaflorin.github.io/trust-no-one-anonymizer/","repo_url":"https://github.com/baditaflorin/trust-no-one-anonymizer","url":"https://baditaflorin.github.io/trust-no-one-anonymizer/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"privacy tool, anonymization logic","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"universal-document-workbench","domain":"baditaflorin.github.io/universal-document-workbench/","mesh":"pages","category":"app","title":"Universal Document Workbench","summary":"Drop documents in, extract text and metadata, OCR scans, detect entities, and convert outputs to Markdown, DOCX, or EPUB.","health_url":"https://baditaflorin.github.io/universal-document-workbench/","repo_url":"https://github.com/baditaflorin/universal-document-workbench","url":"https://baditaflorin.github.io/universal-document-workbench/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"document editor, multi-format support","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"urban-farm-year","domain":"baditaflorin.github.io/urban-farm-year/","mesh":"pages","category":"app","title":"Urban Farm Year","summary":"A static, offline-friendly planner for garden calendars, daily care, harvest logs, and next-year growing decisions.","health_url":"https://baditaflorin.github.io/urban-farm-year/","repo_url":"https://github.com/baditaflorin/urban-farm-year","url":"https://baditaflorin.github.io/urban-farm-year/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"farm planning app, seasonal calendar","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"vagus-reset-coach","domain":"baditaflorin.github.io/vagus-reset-coach/","mesh":"pages","category":"wellness","title":"Vagus Reset Coach","summary":"A private browser-based 2-minute breath coach using webcam rPPG and local HRV logging.","health_url":"https://baditaflorin.github.io/vagus-reset-coach/","repo_url":"https://github.com/baditaflorin/vagus-reset-coach","url":"https://baditaflorin.github.io/vagus-reset-coach/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"Second-pass re-audit (supersedes an unreliable 2026-05-14 cursory pass) of this webcam-rPPG + breathing-pacer wellness app, held to extra rigor given the health-adjacent domain. Live-verified in real Chromium (fake camera device via Playwright) that breathing-phase timing is drift-free (elapsed-time modulo, not accumulated) and the session timer stayed accurate to the second across a simulated 5s background-tab freeze. Privacy claim verified true (only network call is a scoped GitHub API check, zero non-localhost requests during a session). Found and fixed two real robustness bugs: no top-level React error boundary anywhere (an unhandled render exception mid-session would blank the whole app with no recovery); and the webcam/rPPG sampling and session-timer/completion logic shared one unguarded setInterval block, so a throwing camera/pulse step could silently freeze the pacer forever and prevent the session from ever finishing or saving. Both fixed and regression-tested. trl bumped 3-\u003e4; trl_ceiling unchanged -- the rPPG HR/HRV estimate remains inherently best-effort (app already self-discloses 'not a medical device'). See github.com/baditaflorin/vagus-reset-coach PR #6 (merged).","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"vcard-personal-portfolio","domain":"codewithsadee.github.io/vcard-personal-portfolio/","mesh":"pages","category":"app","title":"Vcard Personal Portfolio","summary":"vCard is a fully responsive personal portfolio website, responsive for all devices.","health_url":"https://codewithsadee.github.io/vcard-personal-portfolio/","repo_url":"https://github.com/baditaflorin/vcard-personal-portfolio","url":"https://codewithsadee.github.io/vcard-personal-portfolio/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"portfolio app, vCard format","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"webcam-dither-lab","domain":"baditaflorin.github.io/webcam-dither-lab/","mesh":"pages","category":"app","title":"Webcam Dither Lab","summary":"Live webcam dithering and filter comparison lab with auto best-detail scoring.","health_url":"https://baditaflorin.github.io/webcam-dither-lab/","repo_url":"https://github.com/baditaflorin/webcam-dither-lab","url":"https://baditaflorin.github.io/webcam-dither-lab/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":3,"trl_evidence":"image processing app, dithering effects","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"yq","domain":"kislyuk.github.io/yq/","mesh":"pages","category":"app","title":"Yq","summary":"Command-line YAML and XML processor - jq wrapper for YAML/XML documents","health_url":"https://kislyuk.github.io/yq/","repo_url":"https://github.com/baditaflorin/yq","url":"https://kislyuk.github.io/yq/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":5,"trl_evidence":"YAML query tool, RFC-aligned parsing","reachable":true,"last_checked":"2026-09-11T21:09:08Z"},{"slug":"z3-smt-game","domain":"baditaflorin.github.io/z3-smt-game/","mesh":"pages","category":"app","title":"Z3 Smt Game","summary":"A browser puzzle lab where Z3-WASM solves logic games and a local LLM explains the constraints.","health_url":"https://baditaflorin.github.io/z3-smt-game/","repo_url":"https://github.com/baditaflorin/z3-smt-game","url":"https://baditaflorin.github.io/z3-smt-game/","example":"/","auth":{"type":"none"},"auth_help":"no auth","trl":4,"trl_evidence":"logic game, SMT solver integration","reachable":true,"last_checked":"2026-09-11T21:09:08Z"}]}
