defirisk.co
rubric v1.7.0

Repo shows AI-tool co-authorship in critical files

Sanctum's assessment for RD-F-172 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

No AI-tool co-authorship metadata (Copilot Co-authored-by trailers) found in commit history for igneous-labs/S, inf-1.5, or sanctum-unstake-program. However, the inf-1.5 ctl-v2.0.0 release note references 'thanks codex 5.4 high (#173)' — 'codex' is ambiguous (possibly GitHub Copilot CLI or PR convention), raising a low-confidence signal of AI-assisted development in a V2 change. Rated yellow due to this ambiguous signal.

Sources #

  • GitHub
    igneous-labs/inf-1.5 Releasesinf-1.5 ctl-v2.0.0 release note — 'thanks codex 5.4 high (#173)' ambiguous codex referenceretrieved 2026-05-04

Methodology #

Determine whether critical security files show commits with AI-tool co-authorship metadata (GitHub Copilot, ChatGPT Code Interpreter).

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol sanctum factor RD-F-172 score yellow collected_at 2026-05-04 18:49:23