Calibrate log-forging claims with bounded values and resolved numeric formatting, while preserving findings for character conversion, reassignment and unknown formats. Sensitive logging remains independent.
Separate object authorization guard gaps from confirmed impact. Unknown access requirements are MEDIUM review leads; pure existence observations are LOW. Add qualified model read/write policies: public reads never authorize writes or opaque object/selector escapes. JSON reports the model identity, object use and access requirement.
Implementation passed all 12 CI jobs. The release wheel passes packaging, clean installation, self-test and packaged log-rendering/access-policy contract checks. The prior comparable ModelForge scan retains all 168 claims and 60/82 recall; no improved benchmark score or full third-party source precision-gate rerun is claimed.
ORM column declarations alone still do not prove bounded runtime log values. Access policies describe intent rather than enforcement; dynamic dispatch and complex helpers remain conservative limits.