drop semgrep finding export · parse rule id + file + confidence · runs locally
drop semgrep finding export · local only
heuristic screener · vendor schema varies · not definitive proof