---
name: read-findings
description: Read, filter and cite the public open-source findings published on uc.surf. Use it when you need the list of findings, the details or current status of one finding, or counts by category, severity, status or ecosystem.
---

# Read uc.surf findings

uc.surf publishes the bugs and vulnerabilities that Ugur's AI agents found in open-source
projects. Only publicly disclosed findings are listed. The data is a set of static JSON files
over HTTPS: read-only, with no key and no sign-up.

## Files

- `https://uc.surf/data/findings/index.json`: every public finding, newest first, with links.
  Start here.
- `https://uc.surf/data/findings/<id>.json`: one finding, the full record.
- `https://uc.surf/data/findings/stats.json`: counts by category, severity, status and ecosystem.
- `https://uc.surf/data/findings/schema.json`: JSON Schema for a finding (fields and allowed values).
- `https://uc.surf/data/findings/openapi.json`: OpenAPI 3.1 description of these files.
- `https://uc.surf/feed.xml`: Atom feed of new findings and blog posts.

Every page also has a Markdown copy. Add `index.md` to the page URL
(`https://uc.surf/findings/index.md`), or request the page with `Accept: text/markdown`.

## Steps

1. Fetch `index.json`. Each entry has `id`, `url` (the finding's page), `json_url`, `title`,
   `category`, `severity`, `status`, `ecosystem`, `project`, `summary`, `disclosed_at` and
   `updated_at`.
2. Filter the list yourself, for example by `ecosystem`, `severity`, `status` or `project.repo`.
3. For the full record, fetch the entry's `json_url`. `disclosure.url` and `pr.url` link to the
   public advisory, issue or pull request.

## Rules

- Cite the finding's page (`url`) and the public upstream link (`disclosure.url` or `pr.url`).
- Statuses change. Check `updated_at` and report the status as the data states it. `reported`
  means the maintainers were told. It does not mean the issue was confirmed or fixed.
- Don't add details that are not in the data or in the linked public sources.
- To report an error in a finding, email info@uc.surf (see the `contact-uc-surf` skill).
