{
  "version": 1,
  "publishedAt": "2026-09-02T07:30:00Z",
  "overallScore": 7.3,
  "verdict": "Beta · Limited Live Capability",
  "methodology": "Static codebase scan against HEAD d2cd5626 on main + reuse of self-published evidence (docs/AUDIT_REPORT_2026-08.md, docs/oag-r12-1000-tasks-audit.md, docs/oag-competitive-audit.md, docs/oag-antigravity-blueprint.md, reports/quality/live-benchmark-report.md Mode: live 2026-09-02). Recomputed from file:line-evidenced reports 01-10 in reports/audit-2026-09-02/.",
  "auditCommit": "d2cd5626",
  "dimensions": [
    {
      "id": "architecture",
      "label": "Architecture & System Design",
      "score": 7.5,
      "weight": 0.1,
      "severity": "P2",
      "evidence": "ADK canonical; module ownership enforced by npm run lint:boundaries; 27 files >1,000 lines; legacy runtime migration in-progress"
    },
    {
      "id": "security",
      "label": "Security Posture",
      "score": 7.5,
      "weight": 0.18,
      "severity": "P2",
      "evidence": "P0 license mint + P0 CSRF + P0 unsafe-inline script-src all closed; style-src unsafe-inline + 40% Zod coverage remain"
    },
    {
      "id": "ai",
      "label": "AI / Agent System",
      "score": 7.5,
      "weight": 0.14,
      "severity": "P1",
      "evidence": "44 ADK agents, 1000-task rehearsal 100% PASS, real token accounting; sandbox provisioner INFRA BACKLOG (P1 — honest): GOOGLE CLOUD RUN API SIMULATION"
    },
    {
      "id": "reliability",
      "label": "Reliability & Resilience",
      "score": 7.0,
      "weight": 0.12,
      "severity": "P1",
      "evidence": "Backup drill not scheduled; no automated canary/rollback; RPO=24h/RTO=4h documented"
    },
    {
      "id": "performance",
      "label": "Performance & Scalability",
      "score": 6.5,
      "weight": 0.1,
      "severity": "P2",
      "evidence": "k6 scripts present; reports/load/README.md committed (k6 Go binary gate, honest placeholder)"
    },
    {
      "id": "testing",
      "label": "Testing & Quality Gates",
      "score": 7.0,
      "weight": 0.1,
      "severity": "P1",
      "evidence": "452 test files, 46.0%/41.5%/47.2% coverage (real, from coverage-final.json); live benchmark Mode: live since 2026-09-02"
    },
    {
      "id": "devex",
      "label": "Developer Experience",
      "score": 7.0,
      "weight": 0.06,
      "severity": "P2",
      "evidence": "205 any usages; 27 monoliths; .env.example missing ~40 env vars"
    },
    {
      "id": "compliance",
      "label": "Compliance & Operations",
      "score": 5.5,
      "weight": 0.04,
      "severity": "P1",
      "evidence": "RTO/RPO now documented; no vendor-risk doc; no SOC2/ISO controls matrix"
    },
    {
      "id": "liveCapability",
      "label": "Live Capability (Oracle R12 + Fusion)",
      "score": 8.5,
      "weight": 0.12,
      "severity": "P1",
      "evidence": "1000-task rehearsal 100% PASS; 72 OKF md files; 5-layer workspace isolation; ORACLE_AGENT_REAL_EXECUTION_ENABLED=false (opt-in)"
    },
    {
      "id": "ux",
      "label": "UI / UX / Antigravity Experience",
      "score": 7.5,
      "weight": 0.04,
      "severity": "P2",
      "evidence": "2,899-line Chat Center + 15 slash commands; design system enforced; no committed a11y or mobile-viewport test"
    }
  ],
  "overall": { "score": 7.3, "band": "Beta · Limited Live Capability", "max": 10 }
}
