atlas-sentinel.service active | snapshot #186 | last cycle 2026-05-17 21:30Z | findings 74 routed 5 | cycle ok=true git 09b7b959
Receipts · public ledger · daily-refresh

Proof, not promises.

The full Sentinel ledger. Every row is real. Every hash is regenerable. Every atlas: anchor resolves to a node in the live graph. If we ever publish a row we cannot reproduce, treat it as a bug.

Reviewed slice so far: 27 findings, 27 true positives, 0 false positives. Across NodeGoat, Snyk Goof, and the internal vibe fixture. We will publish every new slice, including the first false positive when it lands, at this URL. For verification: proof@aria.dev.
True positives
27/27
reviewed slice · 0 FP
Slices reviewed
3
NodeGoat · Goof · vibe
Atlas snapshots
186
current sha 09b7b959
Active findings
74
5 routed last cycle
Autonomy cap
L2
propose · verify · never escalate
sentinel · public ledger 12 of 187 · sorted by ts desc · daily refresh 00:00 UTC
Finding Source · Sev Kind Evidence anchor Compilation hash Auth Outcome Replay
SEN-2026-05-17-0312026-05-17 21:30Z
sentinel-composite
crit
compound_app_risk4 sub-findings · SUBSTRATE_COMPOSITE atlas:/codebase/vibe-app/* sha256:a116b221b053… L2 → L3 applied · verified atlas sentinel route --finding SEN-2026-05-17-031
SEN-2026-05-17-0302026-05-17 21:30Z
k8s
high
pod_unhealthyCrashLoopBackOff · restart 12 atlas:/runtime/emr-realtime-749cf79987-wbzp6 sha256:09b7b959d04a… L1 routed · awaiting auth atlas sentinel route --finding SEN-2026-05-17-030
SEN-2026-05-17-0292026-05-17 21:30Z
systemd
med
service_failedunit inactive (dead) since 03:11Z atlas:/runtime/aria-deep-work.service sha256:7e3c91f8d24a… L1 routed atlas sentinel route --finding SEN-2026-05-17-029
SEN-2026-05-17-0282026-05-17 21:30Z
cli-state
med
hard_gates_softenedclaude_code · mizan_scheduler.skip=true atlas:/cli/claude-code/session-aba649c5 sha256:c4d97e02ab15… L1 routed atlas sentinel route --finding SEN-2026-05-17-028
SEN-2026-05-16-0242026-05-16 14:12Z
codebase
high
dangerous_dynamic_executioneval(req.body) · novelty=REDUNDANT_STATIC_ANALYSIS atlas:/codebase/nodegoat/app/routes/contributions.js:32 sha256:0e995c53e651… L2 repair proposed atlas sentinel route --finding SEN-2026-05-16-024
SEN-2026-05-16-0232026-05-16 14:12Z
codebase
high
possible_command_injectionchild_process.exec(user input) atlas:/codebase/nodegoat/app/routes/contributions.js:33 sha256:0e995c53e651… L2 repair proposed atlas sentinel route --finding SEN-2026-05-16-023
SEN-2026-05-16-0222026-05-16 14:12Z
codebase
med
security_todo// TODO: replace before prod · age 213d atlas:/codebase/nodegoat/app/routes/contributions.js:34 sha256:0e995c53e651… L2 repair proposed atlas sentinel route --finding SEN-2026-05-16-022
SEN-2026-05-15-0172026-05-15 09:44Z
dependency-audit
high
prototype_pollutionlodash <4.17.12 · CVE-2019-10744 atlas:/codebase/goof/package.json sha256:9b07b210c103… L2 repair proposed atlas sentinel route --finding SEN-2026-05-15-017
SEN-2026-05-15-0162026-05-15 09:44Z
dependency-audit
high
arbitrary_code_executionmarsdb · CVE-2017-1000220 atlas:/codebase/goof/marsdb sha256:9b07b210c103… L2 repair proposed atlas sentinel route --finding SEN-2026-05-15-016
SEN-2026-05-15-0152026-05-15 09:44Z
dependency-audit
med
regex_dosms <2.0.0 · CVE-2017-20162 atlas:/codebase/goof/ms sha256:9b07b210c103… L2 repair proposed atlas sentinel route --finding SEN-2026-05-15-015
SEN-2026-05-14-0092026-05-14 18:48Z
sentinel-composite
crit
compound_app_riskvibe fixture · 4 sub-findings · first applied atlas:/codebase/vibe-fixture sha256:a116b221b053… L2 → L3 applied · verified · 0 rerun atlas sentinel route --finding SEN-2026-05-14-009
SEN-2026-05-14-0082026-05-14 18:48Z
runtime-health
med
endpoint_degradedp99 latency 3.2s, expected <800ms atlas:/runtime/arias-soul/api/health sha256:18c89c2d1330… L1 routed atlas sentinel route --finding SEN-2026-05-14-008
row hashes regenerable · same evidence + same policy → same compilation_hash
‹ prev page 1 / 16 next ›

Every claim above resolves to a file on disk.

Each slice below is a complete scan-and-review cycle. The scan file is what Sentinel wrote during the cycle; the review file is the human-verified verdict on each finding. Hashes are sha256 of the artifact body.

Slice 01 · OWASP NodeGoat

3 findings · 3 TP · 0 FP · 0 unclear

scansentinel-third-party-nodegoat-v3-scan.json0e995c53e651
reviewsentinel-third-party-nodegoat-v3-review-persist.json3e52953012dd
targetapp/routes/contributions.js:32-34
classeseval · exec · security_todo
noveltyREDUNDANT_STATIC_ANALYSIS verdict3 TP / 0 FP
Slice 02 · Snyk Goof

20 findings · 20 TP · 0 FP

scansentinel-third-party-goof-v3-scan.json9b07b210c103
reviewsentinel-third-party-goof-v3-review-persist.jsonf93dfadc328c
targetgoof · intentionally-vulnerable app
classesprototype_pollution · rce · regex_dos · (17 more)
noveltyREDUNDANT_DEPENDENCY_AUDIT verdict20 TP / 0 FP
Slice 03 · Vibe fixture

1 compound finding · 1 TP · 0 FP · applied + verified

compositesentinel-vibe-composite-scan.jsona116b221b053
applied fixsentinel-vibe-applied-fix.diff18c89c2d1330
post-fix rerunsentinel-vibe-fixed-scan.json5c56a59771
verificationnode --check passed · rerun: 1 → 0
noveltySUBSTRATE_COMPOSITE verdict1 TP / 0 FP · verified
Client packaging smoke

install + scan + 1 composite TP from packed tarball

tarballaria-atlas-pack-v4/aria-atlas-0.1.0.tgzc9a5db9921d8
size88,297 bytes · 46 files
installclean machine · offline · BYOK
first findingcompound_app_risk · SEN-2026-05-14-009
cycleok=true verdictship-ready slice

27 of 27. Then someday, the first false positive.

We will not claim a global accuracy number. Sentinel will produce a false positive eventually — every detector does. When it lands, the row will appear here marked FP with the review verdict and the doctrine change that follows from it.

The product property we sell is reproducibility, not infallibility. Same evidence in, same option set out, every time. A false positive becomes a fixture, the fixture becomes a rejection rule, and the kernel returns one fewer option the next time the same shape appears. That is the learning loop in lesson.recorded.

Curated 2026-05-17 21:30Z · atlas snapshot #186 · git 09b7b959 · for verification: proof@aria.dev