Skip to content

docs: full docs-folder end-to-end code-path audit (62/62 files) - #374

Merged
Pal Lakatos-Toth (pallakatos) merged 1 commit into
mainfrom
docs/full-docs-folder-audit
May 31, 2026
Merged

Pal Lakatos-Toth (pallakatos) merged 1 commit into
mainfrom
docs/full-docs-folder-audit

Conversation

@pallakatos

Copy link
Copy Markdown
Collaborator

Summary

User requested: "do an audit for each and every page of the docs folder against the codepaths, and code logic ... deep deep deep detailed audit ... go page by page and a rolling plan if context window is a concern"

Coverage

Methodology

For every claim in every file:

  1. Locate the corresponding symbol/file/handler/route/CRD field
  2. Trace through to the actual call site
  3. Confirm by reading the code, not the comment/docstring
  4. Document mismatches with code citations

Findings (this report)

Severity Count
🔴 HIGH 0
🟡 MEDIUM 4
🟢 LOW 0
🔵 TYPO 0
# File Finding
1 architecture/entra-agent-id/01-runtime-token-flow.md Phase 5b migration not crossreferenced; ASCII diagram still shows per-pod sidecar (UID 1002)
2 operations/image-versioning.md Claims "eight container images" / "five runtime adapter images"; actually 13+ images with 7 runtime adapters
3 cli-reference.md kars headlamp cmd not documented despite being wired in cli/src/cli.ts:73
4 upstream-alignment.md 3 dead refs to cli/src/plugin.ts (file deleted, plugin moved to runtimes/openclaw/src/index.ts) + stale entrypoint.sh:223 line ref (actual line 784)

Verdict

Doc surface is substantially accurate — 58 / 62 files (94%) have zero findings against actual code paths.

The 4 findings above are minor staleness:

  • 1 Phase-5b migration not yet crossreferenced
  • 1 image count outdated by 5
  • 1 missing CLI command docs
  • 1 file-path drift after a code refactor

No findings classified as HIGH severity. None mislead a security-critical decision.

Combined with PR #370/371/372 findings: ~30 findings total across the entire docs/ tree. Mostly stale row-status labels in maturity/security/roadmap; a handful of dead file links; one mis-counted image inventory; no factually-wrong security guarantees.

Suggested follow-up PRs (no fixes applied here)

  1. docs: fix stale code references and outdated counts (~30 LOC)
  2. docs: Phase-5b banner on 01-runtime-token-flow (~5 LOC)
  3. The 3 sibling PRs (docs: code-grounded review of maturity.md — finds 4 under-claims, 9 missing rows #370/docs: doc-wide under-claim audit — extends maturity review across all of docs/ #371/docs: deep CRD + architecture + AGT-boundary code-path audit #372) already cover the architecture/maturity surface

File added

docs/internal/security-validations/2026-05-31-full-docs-folder-audit.md (294 lines)

Comprehensive audit of every .md file under docs/ (excluding internal/
and site/) against actual code paths in controller/, inference-router/,
cli/, mesh-plugin/, kars-a2a-core/, a2a-gateway/, sandbox-images/,
runtimes/, eval-corpus/, deploy/helm/.

Methodology (per file):
  1. Locate every claim that can be cross-referenced to code
  2. Trace the symbol/file/handler/route/CRD field
  3. Confirm by reading the call site (not the comment/docstring)
  4. Document mismatches with code citations

Tracked progress via session-local SQL doc_audit table to make the
audit context-window-safe across 62 files.

Coverage: 62 / 62 (100%) — 51 newly audited, 11 covered by PR #370/371/372

Findings (this report only): 4 MEDIUM, 0 HIGH, 0 LOW, 0 TYPO
  1. architecture/entra-agent-id/01-runtime-token-flow.md — Phase 5b
     migration not crossreferenced; ASCII diagram shows per-pod sidecar
  2. operations/image-versioning.md — claims 'eight container images'
     including 'five runtime adapter images'; actually 13+ images with
     7 runtime adapters
  3. cli-reference.md — 'kars headlamp' command not documented despite
     being wired in cli/src/cli.ts:73
  4. upstream-alignment.md — 3 references to cli/src/plugin.ts (file
     deleted, plugin moved to runtimes/openclaw/src/index.ts) plus
     stale entrypoint.sh line number (223 vs actual 784)

Combined with the 26+ findings in PR #370/371/372, the overall
doc-audit total is ~30 findings across docs/ — mostly stale row-status
labels in maturity/security/roadmap, a handful of dead file links, one
mis-counted image inventory, no factually-wrong security guarantees.

Verdict: doc surface is substantially accurate (94% of files have zero
findings). Three suggested follow-up doc-only fix PRs sketched in §H.

File: docs/internal/security-validations/2026-05-31-full-docs-folder-audit.md
(294 lines).

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Pal Lakatos-Toth <pallakatos@github.com>
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@pallakatos
Pal Lakatos-Toth (pallakatos) merged commit 5005872 into main May 31, 2026
32 checks passed
@pallakatos
Pal Lakatos-Toth (pallakatos) deleted the docs/full-docs-folder-audit branch June 1, 2026 14:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant