Distilled from
docs/SPEC.mdin black-candle-technologies/Sentinel.
Sentinel produces findings at four levels:
Cyclomatic/cognitive complexity, nesting depth, function length, parameter counts.
Duplication detection, dead code, naming issues, comment coverage, file size.
Error-handling gaps, unchecked returns, risky patterns per language.
Import/layering rules, circular dependencies, package coupling metrics, architecture policy enforcement (company-specific rules live here).
Complexity combined with git churn and centrality: files that are both hard to understand and frequently changed.
Secret detection, raw SQL / injection patterns, dangerous exec calls. Critical findings auto-create deduplicated GitHub issues.
All findings use the stable JSON contract from crates/analyzer-protocol (schema_version: "1.0"): ScanRequest, Finding, ScanResponse. Incompatible versions are rejected loudly.
See also: Sentinel overview · Architecture