Scorecard checks whether generated executable artifacts (compiled machine code, Java class files, Python bytecode, minified JavaScript and similar) are committed to the source repository. Such binaries cannot practically be reviewed against the source, may drift from it or be maliciously substituted, and let the build process atrophy. Files that are simultaneously source and executable (shell scripts), source generated by tools such as bison or yacc, and generated documentation are allowed. Remediation is to remove the binaries and build from source.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.