# Audit Summary — rolling
summary-version: 8 — AUDIT COMPLETE
updated-at: 2026-06-26
batches-complete: 8 of 8 — **124/124 components audited** (words/palabras/chronos excluded per user directive)
(B1 overlays · B2 menus/overlays · B3 pickers+calendar · B4 fields · B5 collections+data · B6 disclosure+controls ·
B7 actions+feedback+misc · B8 eidos-only primitives: layout/typography/visual/composite+service/infra)
## Counts by severity (FINAL — cumulative B1..B8)
| Severity | B1 | B2 | B3 | B4 | B5 | B6 | B7 | B8 | TOTAL |
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
| CRITICAL | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | **0** |
| HIGH | 8 | 2 | 0 | 0 | 6 | 1 | 1 | 0 | **18** |
| MEDIUM | 17 | 23 | 21 | 22 | 14 | 11 | 18 | 3 | **129** |
| LOW | 5 | 17 | 11 | 5 | 2 | 5 | 3 | 12 | **60** |
## Final verdict
**The framework is in strong shape. 0 CRITICAL, 18 HIGH across 124 components — and the HIGH findings cluster into a
handful of systemic patterns with shared, mechanical fixes, not scattered one-offs.** The single highest-leverage fix is
**SYS-7** (the A31 O(N²) selection pattern: 9 components, 6 of them HIGH, one ~3-line `selectedSet`/`expandedSet` lift
each). After that it is mostly MEDIUM hygiene: **SYS-1 scope-drift** (~33 components, one definitional decision),
**THEME-SYS-1** (overlay z-index ladder, ~10 recipes, one tokenization sweep), and the smaller systemic patterns below.
The non-A31 HIGH findings are isolated and each well-grounded:
- **dialog-001** — Content `role`/`aria-roledescription` double-write (a11y race for `alertdialog` variant).
- **dialog-002** — dead/conflicting `[data-dialog-trigger]` CSS envelope after the Button migration.
- **combobox-001** — virtual+real focus mix (A17 / APG break).
- **select-001/002/003** — querySelector injection · `focus.trap` declared-not-implemented · keyboard-route divergence.
- **alert-dialog-001** — the only `: Morfo` annotation (degrades `createAttrs`).
- **navigation-menu-006** — an undisposed `$effect.root` (bounded leak).
- **collapsible-NEW-001** — `collapse` `sequence:'pre'` + handler-state (the Checkbox-244ms-lag mechanism).
- **breadcrumb-001** — `archetype:'item'` false-affordance on a display `
` (the bug Timeline explicitly avoided).
**Method honesty (recorded throughout):** every HIGH/CRITICAL was lead-verified against the cited source. The
adversarial-verify stage repeatedly earned its keep — it refuted a false CRITICAL (eidos-imports-soma on onion-menu), a
false HIGH (button archetype, inert because the part isn't runtime-registered), every CSS.escape-on-framework-value
HIGH/CRITICAL (grid selectors), and the non-canonical-role flags (content-color slots, not the 9 roles). The lead's own
independent greps caught real defects the agents missed (the A31 cluster pre-confirmed) AND made one error of its own
(a single-line grep wrongly cleared the field-family A30, which the workflow caught) — no single source was infallible;
the cross-check (grep × agent × verify × lead read) is what produced the verdict. The lead also corrected the verify in
both directions: elevated under-rated findings (range-calendar Home/End → systemic; collapsible seq-lag MEDIUM→HIGH) and
downgraded over-rated ones (tag-group rovingTarget HIGH→LOW; many magic-literals).
**Positive references (cite these when building/reviewing):** NumberField (renderProps + direct id-wiring + A13),
Popover (Close-via-Button, no role override, hover guards), DropdownMenu (roving-focus consistency, self-managed cleanup,
eidos-in-scope), Button (clean action recipe), Dialog's `data-color` subset (neutral/risk/threat), Timeline (correctly
omits `archetype:'item'`), VirtualList (SvelteMap), accordion + tabs (fully clean). The eidos theming layer is clean
(roles/variants/sizes/naming all canonical across 124 components).
## Counts by severity (per batch, historical)
> **B7 result:** the action/feedback layer is healthy. The two documented reactivity incidents **stayed fixed**:
> Toolbar A35 (`isTabStop` uses `untrack`, the counter was removed) and Form A36 (`form-core.svelte.ts:262
> return untrack(...)`) — both lead-verified, both REFUTED when an agent re-raised them. Timers route through
> `uix.timers` (toast/clipboard/drag-drop) → no A6 leaks. **Button is CLEAN — the reference action component** (its
> one archetype finding was inert: the Spinner part isn't runtime-registered, so `data-archetype` never reaches the
> DOM — the verify caught the false premise). The one real HIGH: **breadcrumb-001** — the Item part (a display `
`)
> declares `archetype:'item'` AND is runtime-registered (provider:123), so `data-archetype='item'` IS emitted and
> archetypes.css paints it with `cursor:pointer` + hover (a false affordance on a non-clickable container). The
> insight: **Timeline explicitly avoided this** (its morfo comments "no archetype:'item' — a display `
` omits it");
> breadcrumb didn't. A targeted, lead-verified contract bug — not systemic, but a clean example of the archetype-pull
> anti-pattern one sibling fixed and the other didn't.
> **B6 result:** the disclosure/selection controls are well-built — accordion + tabs are fully CLEAN, the sequence
> doctrine is correctly applied everywhere it was checked (checkbox/toggle/switch = `post`; accordion/tabs/radio-group/
> stepper set state at the call-site so `pre` is fine), slider has no gesture A6 leak. ONE real HIGH: **collapsible's
> `collapse` event is `sequence:'pre'` while setting state in the handler** — the verifier traced the runtime and
> proved it serializes (emit-then-handler), so `open=false` lags the full ~240ms `brief` hold (the same mechanism as
> the documented Checkbox 244ms-lag). The analyze agent AND the morfo's own comment marked it clean on a false
> "emit overlaps handler" assumption. **Lead note:** I initially downgraded it to MEDIUM ("it's the canonical
> emerge.dismiss `pre`") then RESTORED it to HIGH after re-reading — dialog masks the hold with a `data-event`/Presence
> exit animation, but collapsible's exit is keyed on the (delayed) `data-state`, so the 240ms is a real dead delay.
> Verifying the adversarial-verify's own catch corrected me — the cross-check cuts both ways.
> **B5 result:** the collections are where the **A31 O(N²) selection pattern lives** — 6 HIGH, all the SAME root
> cause: a per-item `$derived` calling `provider.isSelected(v)` / `provider.isExpanded(v)` that does `.includes()`
> on the global array (listbox, grid-list ×2, tree-view, tree-grid, tag-group). **All 6 lead-verified by direct read
> of the cited `.includes` method bodies** (matches an independent lead grep run before the workflow). SYS-7 now
> spans 7 components with ONE shared fix. The verify did its job: it refuted feed's A31 (per-item derived doesn't read
> global state), downgraded table's (engine-backed by `$libs/datagrid`), and confirmed virtual-list/grid as
> A33-clean (SvelteMap). The lead refuted one verifier-ADDED HIGH (tag-group-004 "rovingTarget A31") — `rovingTargetEl`
> is already LIFTED to a single provider `$derived` and the per-item check is an O(1) pointer compare; downgraded to a
> LOW A18 nit. Even verifier-added findings get verified.
> **B4 result:** the field family is healthy — **zero HIGH survived verification.** Dominated by SYS-1 scope-drift
> (nearly all 14), test gaps, a new systemic A30-doctrine deviation, and label-font/magic-literal nits. NumberField
> is confirmed the clean **reference** (correct renderProps + direct id-wiring + A13 hidden input). The analyze pass
> over-reported: the `field` agent emitted 6 "clean-check" pseudo-findings (impact = "no fix needed"); the verify
> refuted all 6, and the generator drops clean-checks. **Method-honesty note:** the lead's own independent grep for
> A30 violations used a single-line pattern and WRONGLY concluded "field family A30-clean"; the workflow's
> analyze+verify caught the multi-line `$effect` that the grep missed (SYS-A30-EFFECT below). No single source —
> grep, agent, verify, or lead — is infallible; the cross-check is what produced truth.
> **B3 result:** the picker + calendar family is in good shape — **zero HIGH survived verification** (the analyze
> pass raised 2 CRITICAL + several HIGH; all were CSS.escape-on-numeric/ISO-selectors or local-z-index, correctly
> downgraded to LOW, plus one keyboard-label drift the lead elevated to a systemic MEDIUM). The dominant B3 issues
> are SYS-1 scope-drift (all 10), inert `open`/`commit-reset` events (pickers), magic literals, and jsdom-only tests.
> Method note: the lead's own memory ("pickers don't fire close events") was STALE — an independent grep proved each
> picker now fires `trigger('close')`; the inert-events findings are about `open`/`commit-reset`, which the verify +
> grep agree ARE inert. Verifying against current code, not memory, mattered.
> **Method note (B2):** Batch 2 was run as an adversarially-verified workflow (one analyze agent per component →
> a skeptical verify agent that re-reads the cited code). The verify stage refuted/downgraded a large fraction of
> the analyze pass's claims (it caught a false-positive CRITICAL on onion-menu — "eidos imports soma" is the normal
> direction, not a frontier violation — and a false-positive HIGH A30 on context-menu). **Both surviving B2 HIGH
> findings were personally re-verified against the cited source by the lead before shipping.** This validates the
> standing rule "unverified agent finding = not a finding": the raw analyze pass over-reported ~15 HIGHs that
> collapsed to 2 after verification.
### B2 HIGH findings (both lead-verified)
- **alert-dialog-001 (HIGH, A)** — `export const alertDialogMorfo: Morfo = {…}` uses a `: Morfo` annotation instead
of `as const satisfies Morfo`; this widens literal types and degrades `createAttrs`/`compileMorfo` key narrowing.
The ONLY morfo in the audited set with this defect. (Lead-verified: alert-dialog.ts:4.)
- **navigation-menu-006 (HIGH, B/A6)** — `openedAtEffect = $effect.root(() => { $effect(() => …) })` (provider:523)
is a DETACHED reactive root whose disposer is stored but never called; each NavigationMenuTriggerProvider leaks one
root permanently subscribed to `isOpen`. A bare `$effect` (auto-disposed) is the correct tool. (Lead-verified: the
only `$effect.root` in any provider; no dispose anywhere in the file.)
## Counts by severity (Batch 1)
| Severity | Count |
| --- | --- |
| CRITICAL | 0 |
| HIGH | 8 |
| MEDIUM | 17 |
| LOW | 5 |
| **total** | **30** |
## Counts by component
| Component | C | H | M | L | headline |
| --- | --- | --- | --- | --- | --- |
| select | 0 | 4 | 5 | 2 | injection, focus.trap-unimpl, kbd-route divergence, kbd untested |
| dialog | 0 | 2 | 2 | 2 | role double-write (alertdialog race), dead trigger envelope |
| popover | 0 | 0 | 3 | 0 | cleanest — close double-write, magic-z, test gap |
| combobox | 0 | 2 | 3 | 0 | virtual+real focus mix (A17), kbd untested |
| dropdown-menu | 0 | 0 | 4 | 1 | most disciplined — nav dup, checkbox silent, magic-z |
## Counts by dimension (findings tagged with each)
| Dim | What | Count |
| --- | --- | --- |
| A (contract) | scope-drift, undeclared parts, aria-not-in-morfo, translationRef, checkbox silent, virtual-part data | 8 |
| B (behavior) | focus mix, kbd-route divergence, A31, loop off-by, sequence | 7 |
| C (selectors) | querySelector injection | 1 |
| D (frontier) | double-writes, dead trigger envelope, undeclared parts | 5 |
| E (TSC) | 0 (TSC usage was clean where present) | 0 |
| E-bis (theming) | magic z-index, em-font literal, magic opacity, raw rem, subset | 9 |
| F (tests) | jsdom-only + keyboard/focus/dismissal untested | 5 |
| G (redundancy) | directional-nav duplication | 2 |
## Top findings by impact
1. **combobox-001 (HIGH)** — Combobox mixes virtual focus (`aria-activedescendant`) with real `dom.focus()` on
items; violates A17 and the APG combobox contract (focus must stay on the textbox).
2. **dialog-001 (HIGH)** — Dialog Content double-writes `role` (syncAttrs `'dialog'` vs Svelte `variant`); for
`variant='alertdialog'` the accessible role is a non-deterministic race.
3. **select-001 (HIGH)** — `scrollSelectedIntoView` interpolates the user value into a `querySelector` without
`CSS.escape` (the safe helper it imports does escape — this path bypasses it).
4. **select-002 (HIGH)** — morfo declares `focus.trap:true` + `initial:'first-focusable'` but the provider
implements virtual focus (no FocusScope) — dead/contradictory contract.
5. **select-003 (HIGH)** — two keyboard routes (virtual trigger vs real-focus content) duplicate index math and
diverge; the content loop path lands `n-2` (off-by) and reads `activeElement` though the component is virtual.
6. **dialog-002 (HIGH)** — `[data-dialog-trigger]` full-chrome CSS envelope survives the trigger's migration to
a composed `