Skip to content
Fabrizio Salmi edited this page Sep 6, 2026 · 1 revision

FAQ

Why does a missing scanner fail my build?

Because unverified is not verified. A rule the runner cannot conclusively check returns INCONCLUSIVE, and the gate treats it as FAIL. Install the scanner and rerun: the report keeps Could not assess separate from the fix queue precisely so you can tell environment problems from surface problems.

My score dropped and I changed nothing

Read the environment block at the top of the report. A missing headless browser or scanner converts proofs into INCONCLUSIVE, which lowers the score without anything about the site changing.

Can I compare my score to another project's?

No. The score is level-relative, a ratio over the rules in scope at the declared level, and it is environment-sensitive. Compare medals: the medal is the claim.

The site is down and the report shows no score

That is UNSCANNABLE, by design, with the transport cause and exit code 3. A surface that cannot be fetched produces no verdict at all, so an unreachable host can never look like a merely imperfect one. Treat exit 3 in CI as an infrastructure alert.

Which profile and level should I declare?

Declare what the surface actually is. An L0 declaration on a page that carries analytics produces a permanently red gate describing decisions you already made. See Choosing a profile and level.

Can I waive a MUST?

No. AG-GOV-01, without exception. Waivers only ever suppress a failing SHOULD.

My waiver expired and the build went red

Working as intended: expiry is enforced against the runner's clock and a governance violation blocks the gate. That is what makes a waiver a deadline rather than a permanent exception.

Do I need Go to run it?

Not necessarily. The GitHub Action runs from a prebuilt image, and there is a container image at ghcr.io/fabriziosalmi/agssh. The go install path is for local use.

What does the MCP server let an agent do?

agssh_scan for a live URL, agssh_scan_config for an existing .airgap.yml with full CLI parity, and agssh_list_rules for the registry, which needs no network. Each scan returns a human summary and the full structured record.

Will the MCP server scan localhost?

Not by default. agssh_scan fetches a caller-supplied URL server-side, so it refuses loopback, private and link-local targets with an SSRF guard enforced at dial time on the resolved IP. Pass allow_private_targets when you actually mean it.

Can I publish the badge without breaking my own rules?

Yes, that is why it is self-hosted SVG: no web font, no external image, no third-party endpoint. Serving it from your own origin does not violate AG-NET-02.

Where is the authoritative rule text?

The PDF standard carries the normative why, check, fix, tool per rule. RULES.md is the browsable index, and both, plus the runner's rule manifest, are generated from one source, so the document and the runner cannot drift.

Some rules are always INCONCLUSIVE

A handful whose verification is process-specific or not yet automated in this build, such as reproducible-build comparison and deterministic-output diffing, are registered INCONCLUSIVE with the approach to wire in. They block until proven, and each is a single Checker in internal/rules if you want to contribute one.