Skip to content

feat: add Hi Rockits outside-in audit v0.1 - #117

Draft
safal207 wants to merge 16 commits into
mainfrom
agent/hi-rockits-outside-in-audit-v0-1
Draft

safal207 wants to merge 16 commits into
mainfrom
agent/hi-rockits-outside-in-audit-v0-1

Conversation

@safal207

@safal207 safal207 commented Jul 25, 2026

Copy link
Copy Markdown
Owner

Summary

Introduces an independent, evidence-first Hi, Rockits! public audit across three lenses:

  • QA and content integrity;
  • system and content-model consistency;
  • business, buyer, and candidate-conversion impact.

The branch starts from exact main SHA 19d1cd72472666df21350c6f2b2e54591eb3f462.

What changed

  • added a bounded machine-readable audit contract for the official Russian and English origins;
  • added a sequential public-content probe using Python standard library only;
  • added a desktop/mobile Chromium matrix with screenshots, keyboard traces, and console/network summaries;
  • added fail-closed regression tests for origin, form, resume-upload, and authority boundaries;
  • added read-only GitHub Actions workflows with exact-attempt artifacts and checksum verification;
  • documented source-to-rendered adjudication;
  • added a collaboration brief containing only rendered observations.

Confirmed rendered candidates

  1. ROCK-002 — salary analytics prices use a potentially mis-scaled monetary unit — MEDIUM, intended price not confirmed;
  2. ROCK-004 — the Russian buyer landing contains the visible phrase 4,76 процент замен кандидатовLOW;
  3. ROCK-005 — the English acquisition surface contains visible editorial defects — LOW;
  4. ROCK-006 — the English acquisition surface contains Russian-language residue — LOW.

All four were reproduced in settled desktop and mobile profiles on exact source head ce323379d9a3d86e5ae3f416415125cb0c8ac439.

Needs evidence

  • ROCK-001 — KPI conflicts are present in the public response, but the alternate values are inside closed FAQ content and were not visible in passive settled renders;
  • ROCK-003 — duplicate/editorial candidate-page markers exist at source level, but the selected duplication and copy defects were not reproduced in the settled UI.

Hidden or source-only content is not promoted to a user-visible product defect.

Decision model

search or cached observation
→ NEEDS_EVIDENCE

current public response marker reproduced
→ PRODUCT_SIGNAL

settled desktop + mobile reproduction
→ CONFIRMED_PRODUCT_DEFECT_CANDIDATE

human semantic and impact review
→ final severity / collaboration decision

No public marker is treated as proof of internal root cause, the intended commercial price, or measured loss.

Safety boundary

Public allowlisted HTTPS pages and natural sequential GET/browser navigation only.

No authentication, form submission, resume upload, CTA activation, direct API testing, enumeration, fuzzing, load testing, active security testing, vulnerability claim, external contact, remediation, deployment, delivery, or merge is performed or authorized.

Exact validation

On source head ce323379d9a3d86e5ae3f416415125cb0c8ac439:

  • raw audit: success, 4/4 HTTP 2xx observations, five PRODUCT_SIGNAL, one NEEDS_EVIDENCE;
  • rendered audit: success, 8/8 bounded desktop/mobile observations, four CONFIRMED_PRODUCT_DEFECT_CANDIDATE, two NEEDS_EVIDENCE;
  • raw artifact: run 30150136273, artifact 8617356089, digest f6201f8c4f9eaf0a24ed75ef4ccd269fc0b0c24c6159b9f062cff7977d03ea37;
  • rendered artifact: run 30150136271, artifact 8617367290, digest a14b45936d36106a74ea58d43f74a5c1d16166305ee1d9e9425836548c10ca53;
  • authority-boundary, exact-attempt provenance, and checksum verification passed.

This PR remains draft pending the human collaboration and reporting decision.

@coderabbitai

coderabbitai Bot commented Jul 25, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 56c7ff27-f70e-476c-bd5f-124b7c76e7d4

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch agent/hi-rockits-outside-in-audit-v0-1

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Owner Author

Exact Hi, Rockits! evidence review

Reviewed the final raw and rendered artifacts on source head ce323379d9a3d86e5ae3f416415125cb0c8ac439.

Confirmed in settled desktop and mobile

  • ROCK-002 — salary analytics monetary-unit display;
  • ROCK-0044,76 процент замен кандидатов;
  • ROCK-005 — English editorial defects;
  • ROCK-006 — Russian-language residue in the English journey.

Not promoted

  • ROCK-001 remains NEEDS_EVIDENCE: alternate KPI values were present in the public response but hidden inside closed FAQ content in the passive settled render;
  • ROCK-003 remains NEEDS_EVIDENCE: selected source-level duplication/copy markers were not reproduced in the settled candidate UI.

Exact evidence

  • raw run 30150136273, artifact 8617356089, digest sha256:f6201f8c4f9eaf0a24ed75ef4ccd269fc0b0c24c6159b9f062cff7977d03ea37;
  • rendered run 30150136271, artifact 8617367290, digest sha256:a14b45936d36106a74ea58d43f74a5c1d16166305ee1d9e9425836548c10ca53;
  • both exact-attempt manifests identify source head ce323379d9a3d86e5ae3f416415125cb0c8ac439 separately from PR merge ref 0450e442331311a2b93c1f94dd37d885fa8406d7;
  • authority and checksum verification passed.

Root cause remains HYPOTHESIS_ONLY; intended commercial price and business impact remain unconfirmed. No external contact, submission, remediation, deployment, or merge is authorized.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant