Reading Results
Understand score, verdict, stage evidence, findings, and scan status.
Read a result in this order: reliability, stage coverage, open critical/high findings, then score. A high score cannot override an incomplete warning.
Result header
- Status: running, completed, incomplete, or failed.
- Score: 0–100, calculated from active findings produced by completed checks.
- Source: dashboard, CLI, or hook.
- Target type: repository, local path, live server, or pasted configuration.
- MCP detected: whether a known MCP SDK or entrypoint was identified in source.
Stage timeline
The stage list shows cloning, static analysis, secrets, dependencies, tool-description check, and aggregation separately. Expand errors before acting on an empty findings list. Scanner stderr is redacted and shortened, but retains enough context to distinguish a finding exit code from a tool failure, timeout, image problem, or invalid response.
Findings
Each finding includes severity, source scanner, OWASP MCP category, title, explanation, location, remediation, triage status, and verification metadata where available. Open the detail page for the complete evidence rather than deciding from the list-row title alone.
Comparing scans
Repeat the same target type after remediation. A local-path scan and remote repository scan may see different files; a live URL scan has fundamentally less coverage. Resolve or dispute old findings with an audit reason instead of assuming a new score silently rewrites history.