REPRODUCIBLE EXAMPLES · PACK V1
Check the checks yourself.
Nine small, synthetic files. Expected findings you can inspect. Exact preview outputs you can compare.
For developers checking an OpenAPI 3.0 definition before an AWS API Gateway REST API import. These examples show what this browser-local checker changes, what it preserves, and where it stops.
Synthetic data and expected results only. No implementation source or customer definitions. Checked 6 October 2026.
A reproducible check, with a narrow claim
These are maintainer-run checks you can replay. They are not independent certification, an AWS acceptance test, or proof of production authorization. No AWS account, API import, deployment, IAM policy, or authorizer was tested.
Replay a case in a few steps
For replay testing, first choose No thanks in the optional usage-count prompt, or Turn off if counts are already on. Downloaded fixtures enter through the file-input path; turning counts off keeps these tests out of usage totals.
- Download an input below and open it in the checker. Choose the input file, not the expected-results file.
- Compare the finding titles, severity and source pointers with its expected results. The interface may display findings in a different order.
- For a preview case, select the inherited-security copies and inspect the full-file preview. Download only after reviewing it, then compare with the expected preview.
- Load that candidate again. There should be no further security-copy repair. For a no-preview case, the checker should leave the input untouched.
The machine-readable manifest records SHA-256 for every input, expected result and preview. Checksums verify bytes, not the correctness of a claim. Formatting and newline changes produce different hashes.
Nine cases, explicit expectations
Three cases produce an opt-in preview. Six have no eligible repair. Every case has an expected diagnostic report.
01 · REVIEWABLE PREVIEW
Copy inheritance and preserve explicit overrides
Exactly one GET security copy; root, POST [], PUT [{}], and extension values remain unchanged.
Input checksum
e2ec16861a860732b14261c8c7d033c5fc0a47496e1b942e7718d5de9e5a293102 · REVIEWABLE PREVIEW
Preserve optional root-security alternatives in YAML
Exactly one GET copy preserves the anonymous alternative in root and operation.
Input checksum
0aad6841ec6c6a4f34b094c0e233786353299d07abc10fa6f774764bfe19653a03 · REVIEWABLE PREVIEW
Handle the AWS ANY operation explicitly
Exactly one security copy into x-amazon-apigateway-any-method; no invented HTTP operations.
Input checksum
0fb4d43e112baa49c0ae3a9f3ff3ae72e970980eadf91649f25b6aa0d48c758704 · NO AUTOMATIC CHANGE
Leave nullable contract changes for manual review
Report unsupported nullable; do not delete or rewrite the schema keyword.
Input checksum
d8de6c18da95acccf7907d53c1e153836eb4d14ad9271d97d3b4b0689865005205 · NO AUTOMATIC CHANGE
Report an external reference without fetching it
Report blocked reference; no fixture-time fetch calls; do not invent the target schema.
Input checksum
b8be726a4d4caa01cc5d0da64746282891cab8c5a6b6d70cb0afd005463f69b806 · NO AUTOMATIC CHANGE
Reject automatic OpenAPI 3.1 conversion
Report unsupported version; no downgrade or preview candidate.
Input checksum
f53846f0e8c9705b023e28905733f0ca5923746163d416f201d066109a6cddb607 · NO AUTOMATIC CHANGE
Stop safely on malformed JSON
Report invalid JSON; no preview candidate.
Input checksum
f41585a07e185be4ac4e549c8f42f445f27cb828aa0d884052c4003d9addaa7608 · NO AUTOMATIC CHANGE
Apply the pinned structure check before repair
Missing responses fails structural validation even with root security; repair stays disabled.
Input checksum
708831ee9058f3ab423d4bbf01987f8789fdb79429612888a30bf0c87573150909 · NO AUTOMATIC CHANGE
Do not invent an absent security policy
No inherited-security repair is offered when the root has no security field.
Input checksum
4d8d96e131d8db64ad895d6c9081671d4abac27898cf2f33373bca0fb00ba570What was actually verified
- Each input was replayed twice through the existing worker handler in a local test harness, including the pinned OpenAPI 3.0 structure validator
- Eligible previews were computed twice and compared; separate assertions checked exact security copies and preserved values
- The three resulting candidates had no further eligible security-copy repair
- A fetch test double recorded no calls during these fixture executions, including the external-reference case
That last check covers these handler executions; actual browser Worker execution was not tested in this run. The website still loads assets; its optional, separately disclosed usage-count feature is outside this fixture test. Specification contents are processed locally. See Web privacy.
The manifest includes a fingerprint of the tested engine files. It identifies this test run’s source combination; it is not a public-source release or third-party source attestation.
What remains outside the evidence
These nine cases are not exhaustive. They do not validate every integration setting, service quota, permission, schema construct or authorization outcome. HTTP APIs, WebSocket APIs, Swagger 2.0 and OpenAPI 3.1+ are not supported repair targets. A clean diagnosis does not guarantee an AWS import.
The separate ChatGPT plugin sends supplied definitions to its processing server and has different limits. This pack tests the browser-local checker. Full supported checks and limits · Plugin processing details
Found a mismatch?
Keep the unchanged synthetic input. Record the case ID, pack version, expected finding and observed difference. Share a minimal reproduction through the support contact; don’t send credentials or a production/customer definition.
External feedback is welcome. No third-party evaluation, testimonial or endorsement is claimed here.