{
  "stage": "2b-security",
  "generated_at": "2026-03-29T17:50:29.903Z",
  "scan_results_contract": {
    "cisco_mcp_scanner": {
      "status": "SAFE",
      "severity": "SAFE",
      "analyzers": [
        "yara",
        "llm",
        "readiness"
      ],
      "scanned_at": "2026-03-29T17:50:29.903Z",
      "findings_summary": {
        "critical": 0,
        "high": 0,
        "medium": 0,
        "low": 0,
        "informational": 0
      },
      "live_scan": {
        "status": "completed",
        "finding_count": 0,
        "findings": [],
        "duration_ms": 7599
      },
      "code_scan": {
        "status": "completed",
        "finding_count": 0,
        "findings": [],
        "duration_ms": 4673
      }
    }
  },
  "raw_results": {
    "scans": [
      {
        "type": "live",
        "status": "completed",
        "exitCode": 0,
        "analyzers": [
          "yara",
          "llm",
          "readiness"
        ],
        "durationMs": 7599,
        "results": {
          "server_url": "stdio:node src/index.mjs",
          "scan_results": [
            {
              "status": "completed",
              "is_safe": false,
              "findings": {
                "yara_analyzer": {
                  "severity": "SAFE",
                  "threat_names": [],
                  "threat_summary": "No threats detected",
                  "total_findings": 0
                },
                "llm_analyzer": {
                  "severity": "SAFE",
                  "threat_names": [],
                  "threat_summary": "No threats detected",
                  "total_findings": 0
                },
                "readiness_analyzer": {
                  "severity": "HIGH",
                  "threat_names": [
                    "unknown"
                  ],
                  "threat_summary": "Tool 'check_certification' does not specify a timeout. Operations may hang indefinitely if external services become unresponsive.",
                  "total_findings": 8,
                  "mcp_taxonomies": []
                }
              },
              "tool_name": "check_certification",
              "tool_description": "Quick trust check for an AI capability (MCP server, skill, plugin, or workflow). Returns certification status, trust score, grade, tier, and supply chain status. No API key required. Use this before invoking any capability to verify it has been independently certified by Fidensa.",
              "item_type": "tool"
            },
            {
              "status": "completed",
              "is_safe": false,
              "findings": {
                "yara_analyzer": {
                  "severity": "SAFE",
                  "threat_names": [],
                  "threat_summary": "No threats detected",
                  "total_findings": 0
                },
                "llm_analyzer": {
                  "severity": "SAFE",
                  "threat_names": [],
                  "threat_summary": "No threats detected",
                  "total_findings": 0
                },
                "readiness_analyzer": {
                  "severity": "HIGH",
                  "threat_names": [
                    "unknown"
                  ],
                  "threat_summary": "Tool 'get_contract' does not specify a timeout. Operations may hang indefinitely if external services become unresponsive.",
                  "total_findings": 8,
                  "mcp_taxonomies": []
                }
              },
              "tool_name": "get_contract",
              "tool_description": "Retrieve the full certification contract for a capability, including identity, supply chain analysis, security scan results, adversarial testing findings, behavioral fingerprint, and trust score breakdown. Requires a free API key (set FIDENSA_API_KEY).",
              "item_type": "tool"
            },
            {
              "status": "completed",
              "is_safe": false,
              "findings": {
                "yara_analyzer": {
                  "severity": "SAFE",
                  "threat_names": [],
                  "threat_summary": "No threats detected",
                  "total_findings": 0
                },
                "llm_analyzer": {
                  "severity": "SAFE",
                  "threat_names": [],
                  "threat_summary": "No threats detected",
                  "total_findings": 0
                },
                "readiness_analyzer": {
                  "severity": "HIGH",
                  "threat_names": [
                    "unknown"
                  ],
                  "threat_summary": "Tool 'search_capabilities' does not specify a timeout. Operations may hang indefinitely if external services become unresponsive.",
                  "total_findings": 7,
                  "mcp_taxonomies": []
                }
              },
              "tool_name": "search_capabilities",
              "tool_description": "Search for certified AI capabilities by keyword or description. Use this to discover certified alternatives when a capability is uncertified or scores poorly. Supports filtering by type, tier, and minimum trust score. No API key required.",
              "item_type": "tool"
            },
            {
              "status": "completed",
              "is_safe": false,
              "findings": {
                "yara_analyzer": {
                  "severity": "SAFE",
                  "threat_names": [],
                  "threat_summary": "No threats detected",
                  "total_findings": 0
                },
                "llm_analyzer": {
                  "severity": "SAFE",
                  "threat_names": [],
                  "threat_summary": "No threats detected",
                  "total_findings": 0
                },
                "readiness_analyzer": {
                  "severity": "HIGH",
                  "threat_names": [
                    "unknown"
                  ],
                  "threat_summary": "Tool 'compare_capabilities' does not specify a timeout. Operations may hang indefinitely if external services become unresponsive.",
                  "total_findings": 7,
                  "mcp_taxonomies": []
                }
              },
              "tool_name": "compare_capabilities",
              "tool_description": "Side-by-side comparison of 2-5 certified capabilities. Shows trust scores, grades, tiers, and per-signal breakdowns to help choose between alternatives. Requires a free API key (set FIDENSA_API_KEY).",
              "item_type": "tool"
            },
            {
              "status": "completed",
              "is_safe": false,
              "findings": {
                "yara_analyzer": {
                  "severity": "SAFE",
                  "threat_names": [],
                  "threat_summary": "No threats detected",
                  "total_findings": 0
                },
                "llm_analyzer": {
                  "severity": "SAFE",
                  "threat_names": [],
                  "threat_summary": "No threats detected",
                  "total_findings": 0
                },
                "readiness_analyzer": {
                  "severity": "HIGH",
                  "threat_names": [
                    "unknown"
                  ],
                  "threat_summary": "Tool 'report_experience' does not specify a timeout. Operations may hang indefinitely if external services become unresponsive.",
                  "total_findings": 8,
                  "mcp_taxonomies": []
                }
              },
              "tool_name": "report_experience",
              "tool_description": "Submit an experience report for a certified capability. Reports feed into the social proof signal of the trust score. Requires the content_hash from the .cert.json artifact (proves you've encountered the certified file). API key optional but recommended for higher rate limits.",
              "item_type": "tool"
            },
            {
              "status": "completed",
              "is_safe": false,
              "findings": {
                "yara_analyzer": {
                  "severity": "SAFE",
                  "threat_names": [],
                  "threat_summary": "No threats detected",
                  "total_findings": 0
                },
                "llm_analyzer": {
                  "severity": "SAFE",
                  "threat_names": [],
                  "threat_summary": "No threats detected",
                  "total_findings": 0
                },
                "readiness_analyzer": {
                  "severity": "HIGH",
                  "threat_names": [
                    "unknown"
                  ],
                  "threat_summary": "Tool 'verify_artifact' does not specify a timeout. Operations may hang indefinitely if external services become unresponsive.",
                  "total_findings": 9,
                  "mcp_taxonomies": []
                }
              },
              "tool_name": "verify_artifact",
              "tool_description": "Verify the cryptographic signature on a Fidensa certification artifact (.cert.json). Checks platform signature, content hash, expiry, and optionally code integrity (git SHA match) and file integrity (file hash match). For true offline verification, pass the .cert.json content from the capability's published package via the content parameter. Requires a free API key (set FIDENSA_API_KEY).",
              "item_type": "tool"
            },
            {
              "status": "completed",
              "is_safe": false,
              "findings": {
                "yara_analyzer": {
                  "severity": "SAFE",
                  "threat_names": [],
                  "threat_summary": "No threats detected",
                  "total_findings": 0
                },
                "llm_analyzer": {
                  "severity": "SAFE",
                  "threat_names": [],
                  "threat_summary": "No threats detected",
                  "total_findings": 0
                },
                "readiness_analyzer": {
                  "severity": "HIGH",
                  "threat_names": [
                    "unknown"
                  ],
                  "threat_summary": "Tool 'verify_file' does not specify a timeout. Operations may hang indefinitely if external services become unresponsive.",
                  "total_findings": 8,
                  "mcp_taxonomies": []
                }
              },
              "tool_name": "verify_file",
              "tool_description": "Quick file integrity check: pass the SHA-256 hash of a capability file and its capability_id to verify the file matches what Fidensa certified. This is the simplest verification path — no .cert.json needed. No API key required.",
              "item_type": "tool"
            }
          ],
          "requested_analyzers": [
            "yara",
            "llm",
            "readiness"
          ]
        }
      },
      {
        "type": "behavioral",
        "status": "completed",
        "exitCode": 0,
        "durationMs": 4673,
        "results": null
      }
    ]
  }
}