CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

2026-09-29T2134Z-audit

One pipeline fire, in full · audit run of 2026-09-29 · sub-agent allocation and telemetry, per-iteration verification verdicts and findings, source-list edits, coverage gaps, bridge invocations, and the run's own verification & coverage notes: what was published, what was dropped at the borderline or judged not relevant (and why), single-source carve-outs, and contradictions. Rendered from runs/2026-09-29/2026-09-29T2134Z-audit.md.

Run telemetry

2026-09-29T2134Z-audit audit prompt v4.16 publish ok
7h 36m duration 0 published 43 updates
Claude Opus 5.5 (claude-opus-5-5[1m]) main agent
SR1 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
11
Duration
15m 29s
Tool calls
not reported
Cited sources
11 of 11 in slice
SR2 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
9
Duration
14m 26s
Tool calls
not reported
Cited sources
9 of 9 in slice
SR3 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
7
Duration
16m 59s
Tool calls
not reported
Cited sources
7 of 7 in slice
T1 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
13
Duration
7m 24s
Tool calls
not reported
Cited sources
none
T2 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
11
Duration
7m 19s
Tool calls
not reported
Cited sources
none
T3 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
24
Duration
16m 12s
Tool calls
not reported
Cited sources
none
T4 Claude Sonnet 5.5 (claude-sonnet-5-5)
Items returned
20
Duration
10m 47s
Tool calls
not reported
Cited sources
none

Verification

#? NEEDS_FIXES · Sonnet 5.5 · t=10 e=6 a=5 #? NEEDS_FIXES · Sonnet 5.5 · t=23 e=3 a=8 #? NEEDS_FIXES · Sonnet 5.5 · t=14 e=8 a=15 #? NEEDS_FIXES · Sonnet 5.5 · t=5 e=1 a=6 #? NEEDS_FIXES · Sonnet 5.5 · t=1 e=0 a=3 #? NEEDS_FIXES · Sonnet 5.5 · t=5 e=0 a=2 #? NEEDS_FIXES · Sonnet 5.5 · t=4 e=3 a=5 #? NEEDS_FIXES · Sonnet 5.5 · t=7 e=3 a=3

Deep dive

·

Entries this run published (0) and updated (43)

Sources changed (this run)

Edits this run made to sources/sources.json · promotions, demotions, new candidates, and fetch-method / category / reliability / url corrections (the run record's sources_changed[]). Paginated; 10 per page.

No source-list edits recorded for this run.

Coverage gaps (this run)

Sources this run's brief needed that returned no usable content via any documented recipe. Bridge-recovered or quiet-day sources do NOT appear here. (Distinct from the independent source-accessibility probe at the foot of this section, which probes all active sources regardless of what any run needed.)

Source (uncovered)URL triedMethod chainStatus / classWhat the agent did instead
cisa-newshttps://www.cisa.gov/news.xmlbridge:feed → bridge:cisa feed → bridge:extract → bridge:url --direct → bridge:jina403 waf-blocknone available in-container: Akamai refuses every direct transport and the reader pool has no live key; operator recommendation in the audit report
cisa-directiveshttps://www.cisa.gov/news-events/directivesbridge:cisa page → bridge:extract → bridge:url --direct → bridge:jina403 waf-blockmax_staleness_days 180 set so the content check expects the publisher's cadence; transport unresolved
ssd-disclosurehttps://ssd-disclosure.com/advisories/bridge:url --direct → bridge:extract → bridge:feed → bridge:url --direct (WordPress REST) → bridge:url --direct (sitemap)202 captchaurl moved to the advisory listing; the sg-captcha wall blocks every in-container path

Verification findings · all iterations

Per-iteration finding detail. Each table is one verifier pass · what was flagged, how the main agent remediated it, and the outcome. Walking the tables top-to-bottom shows the verifier's debugging trail across iterations.

Iteration #? cap-breach

Cap-breach iteration recorded no per-finding detail. The dashboard cannot show WHAT the verifier flagged. See .claude/agents/cti-verification.md § Findings summary for the contract.

Verification & coverage notes

The run record's narrative body, verbatim. This is where the run accounts for its own judgement calls: every borderline drop and judged-not-relevant item with its reason, dedup decisions, single-source items and their carve-outs, contradictions, and per-source coverage gaps, so nothing the run considered disappears silently.

Verification & coverage notesrun record body

2026-09-29T2134Z-audit · audit · Opus 5.5 (1M context) · window 56.43 h · 0 entries published

Verification & coverage notes

Operator-directed out-of-cycle audit (2026-09-29): fix every open warning and error, correct the MovieReaper and ECA quote defects, clear the Oracle-product and fire-duration warnings, and make every source work and return relevant content with checks that test it. Report: docs/audits/2026-09-29-quality-audit.md.

Shipped ahead of the run commit. Prompt releases v4.13 (Series 5.5 optimisation, cited-page checks), v4.14 (operator directive: no time limits, every run ends, counts are guides) and v4.16 (content-aware source health, 28 source records changed) landed on main during the session (a8628bc, d0602e2, e8f019c). The source work went early so the repaired recipes reached the next intel fire, because the auto-merge resolves a sources.json conflict in favour of main. Main shipped its own v4.15 (entity attachment) in between, so the source-health release is numbered v4.16.

Cited-page backfill. Run first over entries active since 2026-09-01 (633 quotes checked, 14 flags) and then over entries active since 2026-07-01 (1,626 quotes, 31 quote-literal and 13 citation-cve flags). Four triage passes (T1 to T4) triaged every flag against the live page. Defects were found on 43 entries, each fixed through one changelog record for this run. Twelve are updates carrying news the entries had missed (Siemens Mendix revocation, PaperCut maintenance releases, Check Point management-server scope, Cisco ASA/FTD and FMC hardening releases, GeoServer CVE-2026-76904, nginx PoC public, WatchGuard 12.5.19 and narrower range, TeamDavid Rollout 528, Metabase and Dire Wolf, WatchGuard Fireware re-rating, Gridbox's two further exploited CVEs). One more change carrying news, the CRA platform FAQ, is an improvement record. After the fixes, and after clearing CERT/CC bodies cached before the gzip fix, the check over entries active since 2026-07-01 finds more than 1,680 quotes verbatim and reports no mismatch.

Tools fixed on the way. The PDF reader decoded Word-produced advisories as mojibake and now decodes per font. The bridge now decodes gzip bodies that kb.cert.org sends unrequested. The quote check strips markdown link targets. The CVE-citation check treats a clause with an unreadable page as unverifiable. EUVD, git.kernel.org and lore.kernel.org are now unverifiable hosts. The IOC scanner's version cues cover plurals.

Coverage. WordPress 7.1.2 is already covered (2026-09-24 entry). WordPress 7.1.1 does not clear the gate: 11 mostly authenticated fixes, none exploited, delivered by auto-update. Apple CVE-2026-86950 (KEV 2026-09-29, surfaced by verifier iteration 1) has no entry and is left to the next intel fire's KEV-window duty.

Transparency. Triage pass T1 read one cisa.gov alert through WebFetch, against the CLAUDE.md rule, to recover its current text, and source-repair pass SR1 sampled it for the source notes. The notes now record the observation only. Whether to allow it is recommendation 1 of the report.

Verifier loop. Eight iterations, the cap, with 21, 34, 37, 12, 4, 7, 12 and 13 findings. No pass returned CLEAN, so the run publishes under the fail-open rule with a residual count of 10, the final pass's truth and editorial findings. Every finding up to iteration 7 was fixed and re-read by the next pass. The main agent fixed iteration 8's findings against their sources after the cap, and no verifier pass has read those fixes. The one finding left open is the Apple CVE-2026-86950 coverage gap, which belongs to the next intel fire. The findings shrank from source-level defects to citation placement and wording, and a repeated class was undated present-tense text left behind after a record moved an entry's state. That class is the watch item the report names first.

Sub-agent models. Every sub-agent reported Sonnet 5.5 (claude-sonnet-5-5) from its own prompt line.

← Operations dashboard · day page 2026-09-29 · run-record contract: docs/pipeline.md