Self-Critique Loop
After you complete the initial analysis, complete a mandatory second pass before you deliver the report.
Universal Checks
- Evidence check: Every finding must cite a verified reference (
file:line, component, architecture element, or CVE ID). Remove any finding that does not have supporting evidence. - Coverage check: Verify that you evaluated all required categories and phases. State "None detected" for clean categories. Do not omit clean categories.
- Remediation check: Provide a specific, implementable fix for every Critical and High finding. Do not provide generic recommendations.
Domain Checks
SAST/SCA
- Taint trace completeness: Verify that you traced each discovered entry point from source to sink.
- Manifest coverage: Verify that you audited all discovered dependency manifests.
- Evidence completeness: Cite a verified
file:linereference and taint trace for each SAST finding. Cite a verified CVE ID and affected version range for each SCA finding. - Flaw category completeness: Confirm that you evaluated all flaw categories. State "No instances detected" for clean categories. Do not omit clean categories.
- Policy consistency: Verify that the PASS or FAIL policy verdict matches severity counts and policy threshold rules.
Threat Modeling
- STRIDE completeness: Verify that you evaluated all six STRIDE categories (S/T/R/I/D/E) for each trust boundary and data flow.
- Trust boundary audit: Verify that each identified trust boundary has at least one evaluated data flow crossing it.