scan_code_for_violations
Statically scan code for placeholder stubs, TODO/FIXME markers, and scaffold deception phrases before delivery. Returns line-numbered findings with a PASS/REVIEW/FAIL verdict.
Instructions
Statically scan code for Zero-Framework-Tolerance violations: TODO/FIXME markers, stub bodies (pass, ellipsis, NotImplementedError, unimplemented macros, panic stubs), empty function and catch bodies across Python, JavaScript, TypeScript, Java, Go and Rust, scaffold deception phrases ('rest of the implementation', 'omitted for brevity'), and iteration-deferral phrases ('left as an exercise', 'you can extend this'). Backed by the CodebaseCSI forensic detector plus Constitution prose rules; Python input additionally gets AST analysis so abstract stubs (Protocol/ABC/@abstractmethod) and markers inside string literals are not falsely flagged. Returns a JSON verdict (PASS/REVIEW/FAIL) with line-numbered findings. Use before delivering generated code. A PASS is necessary but not sufficient - still run gates G1-G5.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| code | Yes | The complete code to scan. | |
| language | No | Optional language hint, e.g. 'python', 'javascript', 'typescript', 'java', 'go', 'rust'. Selects the string-masking strategy and enables Python AST analysis. Omit to infer automatically. |