Aevrin

Reading Results

Understand score, verdict, stage evidence, findings, and scan status.

Read a result in this order: reliability, stage coverage, open critical/high findings, then score. A high score cannot override an incomplete warning.

Result header

  • Status: running, completed, incomplete, or failed.
  • Score: 0–100, calculated from active findings produced by completed checks.
  • Source: dashboard, CLI, or hook.
  • Target type: repository, local path, live server, or pasted configuration.
  • MCP detected: whether a known MCP SDK or entrypoint was identified in source.

Stage timeline

The stage list shows cloning, static analysis, secrets, dependencies, tool-description check, and aggregation separately. Expand errors before acting on an empty findings list. Scanner stderr is redacted and shortened, but retains enough context to distinguish a finding exit code from a tool failure, timeout, image problem, or invalid response.

Findings

Each finding includes severity, source scanner, OWASP MCP category, title, explanation, location, remediation, triage status, and verification metadata where available. Open the detail page for the complete evidence rather than deciding from the list-row title alone.

Comparing scans

Repeat the same target type after remediation. A local-path scan and remote repository scan may see different files; a live URL scan has fundamentally less coverage. Resolve or dispute old findings with an audit reason instead of assuming a new score silently rewrites history.