Found by the same real-repo plausibility audit as the EQU-copybook detection issue: a galaxyscope scan of IBM's zopeneditor-sample (COBOL/PL-I/JCL/HLASM/REXX), engine main just after #2504/#3107.
What the scan shows
Spec Alignment (formerly Spec Match Risk Exposure) reads mode=100, median=50 across the repo (section 6 of the LLM brief). Any file with no [SPEC-n]/spec-tag convention reads at or near ceiling — and spec-tag traceability conventions are used by few shops, so for everyone else the vector is a constant.
Consequence: "Spec Match (100.0%)" appears in the Primary Risk Drivers line of effectively every entry in the Cumulative Risk hitlist — all 10 of the top 10 in this scan. That dilutes the informative drivers (State Flux, Safety Score) and invites an LLM narrator to call unspecced-but-ordinary code a risk hotspot.
The change (decided)
Make the vector opt-in — a config flag (e.g. spec_alignment: true in galaxyscope config / a CLI flag), default OFF.
When off:
- excluded from cumulative-risk sums;
- excluded from the section 6 table;
- excluded from Primary Risk Drivers in the LLM brief — absent, not zero, the same presentation discipline as the zero-dependency n/a rule in section 0.
When on: behavior unchanged.
Schema compatibility
risk_spec_match stays a column — the #2991 rename precedent keeps underlying keys stable. Off means not computed / not narrated, not renamed.
Explicitly out of scope
Documentation Surface has a similar ceiling-dominance pattern in Primary Risk Drivers (mode 100 on undocumented mainframe corpora). If a follow-up is wanted it should be its own issue with its own evidence — docs coverage is informative for far more shops than spec tags.
Found by the same real-repo plausibility audit as the EQU-copybook detection issue: a galaxyscope scan of IBM's zopeneditor-sample (COBOL/PL-I/JCL/HLASM/REXX), engine main just after #2504/#3107.
What the scan shows
Spec Alignment (formerly Spec Match Risk Exposure) reads mode=100, median=50 across the repo (section 6 of the LLM brief). Any file with no
[SPEC-n]/spec-tag convention reads at or near ceiling — and spec-tag traceability conventions are used by few shops, so for everyone else the vector is a constant.Consequence: "Spec Match (100.0%)" appears in the Primary Risk Drivers line of effectively every entry in the Cumulative Risk hitlist — all 10 of the top 10 in this scan. That dilutes the informative drivers (State Flux, Safety Score) and invites an LLM narrator to call unspecced-but-ordinary code a risk hotspot.
The change (decided)
Make the vector opt-in — a config flag (e.g.
spec_alignment: truein galaxyscope config / a CLI flag), default OFF.When off:
When on: behavior unchanged.
Schema compatibility
risk_spec_matchstays a column — the #2991 rename precedent keeps underlying keys stable. Off means not computed / not narrated, not renamed.Explicitly out of scope
Documentation Surface has a similar ceiling-dominance pattern in Primary Risk Drivers (mode 100 on undocumented mainframe corpora). If a follow-up is wanted it should be its own issue with its own evidence — docs coverage is informative for far more shops than spec tags.