Two scraper sources (scrapeGitHubAdvisory, scrapeOSVLightweightAPI) POSTed api.osv.dev/v1/query without package name, receiving HTTP 400 permanently while logging 0 results as normal. Empirical verification: 153/153 GHSA-malware npm already in IOC store via OSV MAL- dump. Zero coverage loss. Removed functions, wiring, misleading logs, feed-health rationalization, mocked tests. Docs aligned.