Raw agent output
- src/auth/login.rs in scope
- src/auth/session.rs in scope
- src/auth/policy.rs in scope
- +3 files outside contract scope collapsed
- src/billing/subscription.rs never_touch
- src/billing/invoice.rs never_touch
- src/billing/plan.rs never_touch
risk markers
- never_touch violations are indistinguishable from valid edits
- no contract hash — impossible to verify what was approved
- acceptance criteria exist, but no proof they were tested