Security & code observations
Static observations, ordered by severity then confidence. Each one states how it could be wrong. Nothing here has been executed, proven, or verified against a running system.
These are review leads, not vulnerabilities. This engine has no type checker, no data-flow analysis and no runtime knowledge. It can see that a route mutates and contains no auth call; it cannot see a middleware matcher, a platform rule, or an ownership predicate inside a query. Read the caveat on every row before acting on it.
No observations.
Run: yci analyze