Skip to content

aegis inspect: risk-score semantics (the risk-score paradox) #80

Description

@quantifylabs

The heuristic memory-risk score can move in unintuitive directions and sits next to the benchmarked scanner, which is confusing.

Decision needed

Either:

  • Make it a meaningful, defensible measure, or
  • Shrink it to an unmistakably cosmetic indicator,

and surface the real benchmark number (benchmarks/results.json) distinctly from the heuristic.

Partially mitigated: the static map is now explicitly labeled heuristic/preliminary and separated from the benchmarked scanner — but the score's semantics still need work.

Source: docs/issues/inspect-followups.md (Risk score)

Metadata

Metadata

Assignees

No one assigned

    Labels

    inspectaegis inspect static analyzer

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions