PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

SCN-03

Scanner Output Contract

One scan can produce machine-readable findings, reviewable evidence, path inputs, and remediation-ready artifacts.

artifact stack

PROVENANCEAnalysis evidenceSource location and rule evidenceTrace or data-flow contextConfiguration and permission contextStructured findingsFindings JSONSARIFReviewable MarkdownPath and graph inputsEntity and relationship referencesEvidence-linked transitionsValidation and lifecycle stateRemediation and retestOwner and remediation recordRescan and retest resultRegression fixture when supportedCONSUMERSCI and developerworkflowAppSec reviewGraph and Attack PathAnalysis analysis

About this figure

A scanner output contract defines how a single scan becomes a durable artifact stack rather than a one-off report. It packages analysis evidence, source and rule context, trace or data-flow context, and configuration and permission state into structured findings that can be consumed by humans and machines alike. From the same scan, the contract can emit findings JSON, SARIF, and reviewable Markdown, while also producing path and graph inputs, entity and relationship references, and evidence-linked transitions for deeper analysis. It preserves validation and lifecycle state so findings can move cleanly from detection to remediation, retest, ownership assignment, and regression tracking, including fixture generation when supported. This turns scanner output into an interoperable record that supports CI and developer workflows, AppSec review, and graph or Attack Path Analysis analysis without duplicating interpretation at each stage.

Embed in a route

<FigureFromSource sourcePath="content/publications/figures/products/code-scanner.dsl.md" figureId="SCN-03" />

Citation

Scanner Output Contract (SCN-03). AI Security LLC Figure Library. https://aisecurity.llc/publication-dsl/figures/SCN-03