| Guide and code are inconsistent |
One of the most serious findings |
| "Secure" claimed without evidence |
Not scored |
| Keys/logs/code missing from the asset list |
What is not in the list is not protected |
| Threat table from general knowledge |
Project-specific threats get missed |
| Unrehearsed demonstration |
Time is wasted |
| Real password/key/personal data in the repo |
A serious security mistake; values must be synthetic |
| Live demo crashes with no backup / remaining-risk section left empty |
Looks like a lack of preparation and honest analysis |