Skip to content

Reading A Report

Fabrizio Salmi edited this page Sep 6, 2026 · 1 revision

Reading a report

AGSSH-STD-001 v1.6.0 — https://example.com/ @ Bronze/L0
Verdict: NON-CONFORMANT   Score: 42/86 (49%)
Rules: 7 PASS · 8 FAIL · 1 INCONCLUSIVE · 0 waived · 0 N/A

The four outcomes

Outcome Means Blocks the gate
PASS Proven to hold no
FAIL Proven not to hold yes
INCONCLUSIVE Could not be verified yes
N/A Out of scope at this profile or level no

INCONCLUSIVE blocking is the design, not a rough edge. A missing scanner, a check not implemented in this build, an environment without a headless browser: all of them mean the property is unproven, and unproven is not green.

The report keeps them apart deliberately: a Fix queue of FAILs ranked by severity, and a Could not assess list with the reason for each. Those are different problems. One is work on your surface, the other is work on your environment.

UNSCANNABLE is not a bad score

A surface whose live deployment cannot be fetched at all is reported UNSCANNABLE, with the transport cause, and emits no verdict, no score and no badge.

That distinction matters more than it looks. If an unreachable host produced a low score, the worst possible state, a site that is down, would look like a slightly imperfect one. Instead it produces nothing, which is the honest answer to "we could not look".

Exit codes reflect it:

Code Meaning
0 Conformant
1 Non-conformant
2 Usage or internal error
3 A surface was unscannable

Treat 3 in CI as an infrastructure alert rather than a conformance failure.

What makes the gate fail

Any failing MUST, any unwaived failing SHOULD, or any governance violation. Severity orders the fix queue and weights the score; it does not decide whether the gate blocks.

So a single CRITICAL and a single MEDIUM both block. Severity tells you what to do first, not what to ignore.

The score, and its limits

Weighted: Critical 8, High 4, Medium 2, Low 1. Two properties to keep in mind:

It is level-relative. A ratio over the rules in scope at the declared level, so it is not comparable across levels or, strictly, across surfaces with different declarations.

It is environment-sensitive. An INCONCLUSIVE caused by gitleaks missing from PATH lowers the score without anything about the surface having changed.

Hence the README's rule: compare medals, not numbers. The medal is a claim that reproduces from the record; the score is a development diagnostic.

Read the environment block

A degraded environment, no headless browser, a missing scanner, is called out at the top of the report, so a partial scan never looks as confident as a complete one.

This is the first thing to read when a score moves and you did not change anything. Nine times in ten the surface is the same and the runner lost a capability.

The verification planes

Knowing which plane a rule runs on tells you what a failure depends on:

Plane Needs
static, dns, tls, ci nothing beyond network access
dynamic a headless browser
supply gitleaks, osv-scanner on PATH
engine cosign, at Gold

The dynamic plane is the one that goes missing in CI containers, and it carries the runtime egress proofs, which are the most interesting rules in the standard. A CI image without a browser silently converts your strongest evidence into INCONCLUSIVE.

The badge

-badge out.svg emits a self-hosted SVG: no web font, no external image, no third-party endpoint, so publishing it cannot break your own AG-NET-02.

Conformant shows the earned tier as its metal. Non-conformant shows the grey target tier plus the score, which is the gap presented as a gap rather than as an achievement.

Clone this wiki locally