Repository navigation
docs: full docs-folder end-to-end code-path audit (62/62 files) - #374
Merged
Merged
Conversation
Comprehensive audit of every .md file under docs/ (excluding internal/ and site/) against actual code paths in controller/, inference-router/, cli/, mesh-plugin/, kars-a2a-core/, a2a-gateway/, sandbox-images/, runtimes/, eval-corpus/, deploy/helm/. Methodology (per file): 1. Locate every claim that can be cross-referenced to code 2. Trace the symbol/file/handler/route/CRD field 3. Confirm by reading the call site (not the comment/docstring) 4. Document mismatches with code citations Tracked progress via session-local SQL doc_audit table to make the audit context-window-safe across 62 files. Coverage: 62 / 62 (100%) — 51 newly audited, 11 covered by PR #370/371/372 Findings (this report only): 4 MEDIUM, 0 HIGH, 0 LOW, 0 TYPO 1. architecture/entra-agent-id/01-runtime-token-flow.md — Phase 5b migration not crossreferenced; ASCII diagram shows per-pod sidecar 2. operations/image-versioning.md — claims 'eight container images' including 'five runtime adapter images'; actually 13+ images with 7 runtime adapters 3. cli-reference.md — 'kars headlamp' command not documented despite being wired in cli/src/cli.ts:73 4. upstream-alignment.md — 3 references to cli/src/plugin.ts (file deleted, plugin moved to runtimes/openclaw/src/index.ts) plus stale entrypoint.sh line number (223 vs actual 784) Combined with the 26+ findings in PR #370/371/372, the overall doc-audit total is ~30 findings across docs/ — mostly stale row-status labels in maturity/security/roadmap, a handful of dead file links, one mis-counted image inventory, no factually-wrong security guarantees. Verdict: doc surface is substantially accurate (94% of files have zero findings). Three suggested follow-up doc-only fix PRs sketched in §H. File: docs/internal/security-validations/2026-05-31-full-docs-folder-audit.md (294 lines). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Signed-off-by: Pal Lakatos-Toth <pallakatos@github.com>
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.Scanned FilesNone |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
User requested: "do an audit for each and every page of the docs folder against the codepaths, and code logic ... deep deep deep detailed audit ... go page by page and a rolling plan if context window is a concern"
Coverage
doc_audittable for context-window safety across the 62 filesMethodology
For every claim in every file:
Findings (this report)
architecture/entra-agent-id/01-runtime-token-flow.mdoperations/image-versioning.mdcli-reference.mdkars headlampcmd not documented despite being wired incli/src/cli.ts:73upstream-alignment.mdcli/src/plugin.ts(file deleted, plugin moved toruntimes/openclaw/src/index.ts) + staleentrypoint.sh:223line ref (actual line 784)Verdict
Doc surface is substantially accurate — 58 / 62 files (94%) have zero findings against actual code paths.
The 4 findings above are minor staleness:
No findings classified as HIGH severity. None mislead a security-critical decision.
Combined with PR #370/371/372 findings: ~30 findings total across the entire
docs/tree. Mostly stale row-status labels in maturity/security/roadmap; a handful of dead file links; one mis-counted image inventory; no factually-wrong security guarantees.Suggested follow-up PRs (no fixes applied here)
docs: fix stale code references and outdated counts(~30 LOC)docs: Phase-5b banner on 01-runtime-token-flow(~5 LOC)File added
docs/internal/security-validations/2026-05-31-full-docs-folder-audit.md(294 lines)