# Audit: feed audit-version: 1 audited-at: 2026-06-26 scope: method: adversarially-verified workflow (analyze → refute); HIGH lead-verified by direct read of the cited code. B5 ground-truth: the A31 O(N²) isSelected/isExpanded (.includes from a per-item $derived) is confirmed across listbox/grid-list/tree-view/tree-grid/tag-group (SYS-7); rovingTargetEl is correctly LIFTED everywhere (not A31); virtual-* use SvelteMap (A33-clean). provider: src/uix/soma/components/feed/feed-provider.svelte.ts ## Summary Counts (post-verification): CRITICAL 0 · HIGH 0 · MEDIUM 0 · LOW 0. ## Findings _No findings survived verification (clean component)._ ## No-findings dimensions A, C, D, E, E-bis, G ## Theming facts (E-bis) - magic z-index: none - magic literals: feed.css:147 outline-offset: 2px (should use --focus-ring-offset token or define local token) | feed.css:200-201 inline-size: 0.75rem; block-size: 0.75rem; (should use design token like --space-3 or define --_feed-spinner-size) | feed.css:206 animation: feed-spin 0.7s linear infinite (0.7s should use --duration-* token) | feed.css:217 animation-duration: 4s (4s should use --duration-* token, e.g., --duration-slowest) - undeclared parts: none - roles clean: true · variants clean: true ## Tests (F) - exists: true · env: jsdom (@vitest-environment jsdom) - covers: keyboard navigation (PageUp/PageDown/Ctrl+Home/Ctrl+End); article position calculation (posinset/setsize); nested thread level inheritance; sentinel IntersectionObserver integration; fallback to feed.onLoadMore when sentinel doesn't have onIntersect - untested: Performance under high item count (30+ articles — A31 hazard not tested); Dynamic article addition/removal with auto-reposition; RTL direction handling (CSS has RTL rules but no test coverage); Multiple feeds on same page (context isolation) ## Style observations (non-blocking) - feed.css:42 data-block attribute selector: uses `data-block` instead of `data-block=''` on root for boolean flags — matches component pattern (feed.svelte:42 sets data-block={block ? '' : undefined}) - feed.css:147 outline-offset: 2px differs from --focus-ring-offset (1px). Most components use --focus-ring-offset token; feed variant may be intentional for visual clarity but creates drift - feed.css:153 fallback font-weight: 600 in var() — fallback should not be used if token is guaranteed to exist; minor cosmetic issue - feed.css colors (lines 71-98) cascade via --_feed-accent / --_feed-accent-soft using 9 roles (primary, secondary, affirm, risk, threat, fulfill, loss, neutral). Follows project theming conventions correctly