> ## Documentation Index
> Fetch the complete documentation index at: https://docs.switchagents.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs moved from docs.flintai.dev to docs.switchagents.ai. Use docs.switchagents.ai for every link and request.
> To search these docs from an AI tool, connect the MCP server at https://docs.switchagents.ai/mcp. The page index is at https://docs.switchagents.ai/llms.txt.

# Scan results

> Read findings and prove you're ready to ship

**Scan complete.** Now turn findings into fixes — or confirm you're ready to ship.

## What's in your scan results

```json theme={null}
{
  "schema_version": "2.0",
  "framework_detected": "crewai",
  "findings": [
    {
      "id": "asi05_unexpected_code_execution_001",
      "category": "asi05_unexpected_code_execution",
      "ai_spm_severity": "Critical",
      "title": "Arbitrary Code Execution via eval()",
      "cvss_scores": { "base_score": 9.3 },
      "file_path": "src/agent.py",
      "line_number": 45,
      "evidence": "eval(user_input)",
      "remediation": "Use ast.literal_eval() for safe evaluation..."
    }
  ],
  "category_summary": {
    "asi05_unexpected_code_execution": 1
  }
}
```

## Understanding findings

Each finding shows:

**What's broken:**

* **`title`** - Clear description of the issue
* **`category`** - OWASP ASI01-ASI10 category (industry-standard mapping)
* **`evidence`** - The actual code that triggered the finding

**How severe:**

* **`ai_spm_severity`** - Critical, High, Medium, or Low
* **`cvss_scores.base_score`** - Industry-standard CVSS v4 score (0.0-10.0)

**Where to fix:**

* **`file_path`** - Exact file location
* **`line_number`** - Line where the issue appears
* **`remediation`** - How to fix it

## When a scan is incomplete

`flintai scan` runs several static analysis tools alongside its AI reasoning. If one of them isn't available, the scan finishes without it rather than failing. The summary names the tool under **Skipped** and warns that the findings are partial.

In practice this is usually OpenGrep. It's a standalone binary rather than a Python package, so `pip install flintai-cli` doesn't bring it along.

Your results file records the same detail under `scan_metadata.tools_skipped`, with a reason for each tool:

```json theme={null}
{
  "scan_metadata": {
    "tools_used": ["bandit", "detect-secrets", "pip-audit", "ai-reasoning:gemini-3.6-flash", "triage:gemini-3.6-flash"],
    "tools_skipped": [
      {
        "tool": "opengrep",
        "reason": "OpenGrep binary not found. Skipped the agent-specific rules; scan coverage is incomplete. Install from https://github.com/opengrep/opengrep/releases."
      }
    ]
  }
}
```

`tools_used` also lists the AI reasoning and triage layers with the model each one ran on, so you can tell from the results file alone whether those layers ran.

A skipped tool means a whole family of checks never ran, so a short findings list isn't proof of a clean codebase. Install what's missing, then re-scan. In CI, check that `scan_metadata.tools_skipped` is empty before you treat a scan as passing.

## What to do next

**Clean scan (no findings)?**

* Attach your results file (`scan_<timestamp>.json` by default) to your PR as proof
* Ship with confidence

**Issues found?**

<Steps>
  <Step title="Review findings">
    Check each finding's file path and line number.
  </Step>

  <Step title="Read remediation">
    Follow the fix guidance provided for each issue.
  </Step>

  <Step title="Fix the issues">
    Apply the recommended fixes to your agent code.
  </Step>

  <Step title="Re-scan to verify">
    ```bash theme={null}
    flintai scan /path/to/your/agent
    ```

    Confirm issues are resolved.
  </Step>

  <Step title="Ship with proof">
    Attach the clean scan to your PR.
  </Step>
</Steps>

## How severity is determined

Switch Trust Scan uses **CVSS v4.0** (Common Vulnerability Scoring System) to calculate severity:

| **Severity** | **CVSS Score** | **Examples** |
| - | - | - |
| **Critical** | 9.0-10.0 | Hardcoded credentials, arbitrary code execution |
| **High** | 7.0-8.9 | Prompt injection, missing auth |
| **Medium** | 4.0-6.9 | Unbounded loops, missing validation |
| **Low** | 0.1-3.9 | Deprecated functions, warnings |

Severity comes from the CVSS vector, not subjective judgment. This gives you standardized risk scores you can show to security teams.

## Advanced: What Switch Trust CLI filtered out

Your scan JSON may include:

**`triage_dismissed`** - Findings that describe expected behavior for your agent's purpose
**`triage_downgraded`** - Findings with disproportionate severity that were adjusted

This transparency shows what the Switch Trust CLI AI reasoning layer filtered and why, so you can verify the triage decisions.

See [How scanning works](/switch-trust-cli/scan/how-scanning-works) for details on the 4-layer pipeline.

## Next steps

<CardGroup cols={2}>
  <Card title="Run scans in CI" icon="gears" href="/switch-trust-cli/guides/ci-cd-integration">
    Scan every pull request and keep the results as build artifacts. Validation stops depending on anyone remembering to run it, and you build a history to compare against.
  </Card>

  <Card title="Send findings to your security tools" icon="shield" href="/switch-trust-cli/guides/ci-cd-integration#output-formats">
    Write SARIF with `--format sarif` and upload it to GitHub code scanning. Findings land in the Security tab and as annotations on the pull request.
  </Card>
</CardGroup>
