{
  "url": "https://secure.bankofamerica.com",
  "auditedAt": "2026-07-26T06:54:27.296Z",
  "mode": "report",
  "status": "completed",
  "statusDetail": "The requested secure origin serves a JavaScript bootstrap that rendered the public www.bankofamerica.com homepage; the report judges that resulting experience and three representative public archetypes.",
  "page": {
    "appType": "hybrid",
    "framework": "Custom component/widget bundles",
    "notes": "secure.bankofamerica.com rendered/redirected to www.bankofamerica.com. Representative MPA product and security routes were sampled."
  },
  "evidenceUsed": [
    "screenshot",
    "dom",
    "evaluate-probe",
    "layout-metrics",
    "trace",
    "har",
    "discoverability",
    "headers",
    "cookies",
    "trackers",
    "images",
    "secrets",
    "heap-summary",
    "lighthouse",
    "curl"
  ],
  "guidanceConsulted": [
    "dark-mode",
    "accessibility",
    "same-document-transitions",
    "scroll-position-aware-elements",
    "light-dismiss-a-dialog",
    "declarative-dialog-popover-control",
    "improve-text-layout-and-legibility",
    "size-aware-styling",
    "scrollability-affordance-hints",
    "accessible-error-announcement",
    "performance",
    "visually-stable-font-fallbacks",
    "fluid-scaling",
    "optimize-image-priority",
    "html",
    "security",
    "privacy",
    "autofill-sign-in-form",
    "deliver-optimized-decorative-images",
    "efficient-background-processing",
    "deprioritize-background-fetches",
    "manage-recurring-intervals"
  ],
  "artifacts": [
    {
      "type": "screenshot",
      "path": "evidence/desktop.png",
      "caption": "Desktop entry/homepage after redirect",
      "condition": "1440x900",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/mobile.png",
      "caption": "Narrow mobile entry view",
      "condition": "360x800",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/dark.png",
      "caption": "Entry under requested dark scheme",
      "condition": "prefers-color-scheme: dark",
      "findingIds": [
        "F1"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/contrast.png",
      "caption": "Entry under increased contrast",
      "condition": "prefers-contrast: more",
      "findingIds": []
    },
    {
      "type": "layout",
      "path": "evidence/layout-mobile.json",
      "caption": "Mobile overflow, CLS, and long-task observations",
      "condition": "360x800",
      "findingIds": [
        "F13"
      ]
    },
    {
      "type": "trace",
      "path": "evidence/trace.json",
      "caption": "Raw DevTools performance trace",
      "findingIds": []
    },
    {
      "type": "trace-summary",
      "path": "evidence/trace-summary.json",
      "caption": "Compact trace timing and long-task summary",
      "findingIds": [
        "F12"
      ]
    },
    {
      "type": "har",
      "path": "evidence/network.har",
      "caption": "Network capture",
      "findingIds": []
    },
    {
      "type": "har-summary",
      "path": "evidence/network-summary.json",
      "caption": "Network weight, origins, and hygiene summary",
      "findingIds": [
        "F12"
      ]
    },
    {
      "type": "discoverability",
      "path": "evidence/discoverability.json",
      "caption": "Raw HTML versus rendered content comparison",
      "findingIds": [
        "F23",
        "F31"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-rendered.png",
      "caption": "Rendered browser view",
      "findingIds": [
        "F23",
        "F31"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/discoverability-crawler.png",
      "caption": "No-JavaScript crawler view",
      "findingIds": [
        "F23",
        "F31"
      ]
    },
    {
      "type": "other",
      "path": "evidence/headers.json",
      "caption": "CDP header probe",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/headers-curl.txt",
      "caption": "Direct secure-document response headers",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/cookies.json",
      "caption": "Cookie audit",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/trackers.json",
      "caption": "Third-party origin inventory",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/images.json",
      "caption": "Image audit",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/secrets.json",
      "caption": "Client secret scan",
      "findingIds": []
    },
    {
      "type": "lighthouse",
      "path": "evidence/lighthouse.json",
      "caption": "Lighthouse report",
      "findingIds": [
        "F3",
        "F4",
        "F6",
        "F7",
        "F8",
        "F9",
        "F10",
        "F12",
        "F14",
        "F15",
        "F16",
        "F17",
        "F18",
        "F19"
      ]
    },
    {
      "type": "dom",
      "path": "evidence/dom.json",
      "caption": "Rendered DOM and CSS snapshot",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/probe.json",
      "caption": "Metadata, CSS feature, focus, form, and platform probes",
      "findingIds": [
        "F1",
        "F3",
        "F4",
        "F6",
        "F7",
        "F8",
        "F9",
        "F10",
        "F14",
        "F15",
        "F16",
        "F17",
        "F18",
        "F19"
      ]
    },
    {
      "type": "other",
      "path": "evidence/reduced-motion.json",
      "caption": "Reduced-motion animation probe",
      "findingIds": [
        "F2",
        "F20",
        "F21",
        "F22",
        "F24",
        "F25",
        "F26",
        "F27",
        "F28",
        "F29"
      ]
    },
    {
      "type": "heap",
      "path": "evidence/heap-baseline.heapsnapshot",
      "caption": "Readable baseline heap summary",
      "findingIds": [
        "F30"
      ]
    },
    {
      "type": "heap",
      "path": "evidence/heap-interaction.heapsnapshot",
      "caption": "Readable post-interaction heap summary",
      "findingIds": [
        "F30"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/checking.png",
      "caption": "Checking account archetype with ZIP prompt",
      "findingIds": [
        "F5"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/cards.png",
      "caption": "Credit-card listing archetype",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/security.png",
      "caption": "Security-center content archetype",
      "findingIds": []
    },
    {
      "type": "screenshot",
      "path": "evidence/login-error.png",
      "caption": "Empty login submission state",
      "findingIds": [
        "F11"
      ]
    },
    {
      "type": "other",
      "path": "evidence/login-error.json",
      "caption": "Programmatic login error-state probe",
      "findingIds": [
        "F11"
      ]
    },
    {
      "type": "screenshot",
      "path": "evidence/404.png",
      "caption": "Branded missing-route recovery state",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/guidance-searches.jsonl",
      "caption": "Pinned Modern Web Guidance searches",
      "findingIds": []
    },
    {
      "type": "other",
      "path": "evidence/recon.json",
      "caption": "Navigation, form, and path recon",
      "findingIds": []
    }
  ],
  "config": {
    "loaded": false
  },
  "coverage": {
    "catalogVersion": "modern-web-guidance@0.0.172",
    "catalogChecksum": "sha256:78ccfdb2d483f4c57d9dafed80fd86c6265585a56457c8dcfddc254b80fb44d7",
    "expected": 58,
    "recorded": 58,
    "judged": 58,
    "blocked": 0,
    "notRun": 0,
    "missing": 0,
    "unknown": 0,
    "duplicates": 0,
    "complete": true
  },
  "checkOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-color-scheme",
      "status": "issues",
      "confidence": "high",
      "method": "HINT (not mandatory): a screenshot or computed background under an emulated prefers-color-scheme: dark condition will reveal whether surfaces re-tint; the page CSS / a color-scheme declaration is corroborating evidence. The model chooses the method.",
      "evidence": "DOM reports color-scheme normal while authored markup declares only light; CSS probe found no prefers-color-scheme: dark rule. The dark capture stayed blank because body visibility never recovered under that condition.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F1"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-reduced-motion",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: a transition video, or an in-page probe of getAnimations()/computed animation under an emulated prefers-reduced-motion: reduce condition, can show whether motion stops. The model chooses.",
      "evidence": "Under prefers-reduced-motion: reduce, a 500 ms animation still existed and the CSS probe found no prefers-reduced-motion rule.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F2"
      ]
    },
    {
      "principleId": "respect-user-preferences",
      "checkId": "respects-contrast",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: a screenshot under emulated prefers-contrast: more / forced-colors, or an axe/contrast probe, can show whether controls and text survive. The model chooses.",
      "evidence": "The prefers-contrast screenshot kept text, controls, card outlines, and the login form visible; Lighthouse contrast failures were ordinary-color defects captured separately, not disappearance under the preference.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "view-transitions",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: a transition video of a route/state change shows whether it animates; the page source / ::view-transition usage corroborates. The model chooses.",
      "evidence": "CSS probe found no view-transition usage across a route-heavy MPA with tabs, menus, dialogs, and product navigation.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F3"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "scroll-driven-animations",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: source/CSS inspection for animation-timeline: scroll()/view(); a long-task / scroll-handler probe can flag the main-thread anti-pattern. The model chooses.",
      "evidence": "DOM/CSS probe found no scroll-linked effect or scroll-handler-driven parallax on the representative pages.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "checkId": "physical-gestures",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: CSS inspection for scroll-snap / overscroll-behavior / physics-based easing vs custom pointermove listeners. The model chooses.",
      "evidence": "Representative homepage, card listing, checking, and security surfaces use ordinary links, buttons, and carousel controls; no custom pointer gesture that fights native scrolling was observed.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "scroll-state-aware-chrome",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: a transition video of scrolling, or CSS inspection for scroll-state container queries. The model chooses.",
      "evidence": "CSS probe found no scroll-state query or position-aware chrome; long pages keep static navigation without a progress or return affordance.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F4"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "anchored-positioning",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: CSS inspection for anchor-name / position-anchor / position-try on overlays; a screenshot of an open overlay near a viewport edge can show drift. The model chooses.",
      "evidence": "No tethered tooltip or edge-positioned contextual menu appeared on the representative paths; the checking dialog remained fully within the viewport.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "checkId": "directs-attention",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: CSS inspection for ::highlight / scroll-marker; a transition video can show whether attention is cued after navigation. The model chooses.",
      "evidence": "Card tabs, selected states, page headings, navigation labels, and the branded 404 recovery links clearly indicate location and next steps.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "no-intrusive-interruptions",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: a screenshot on load, or a DOM probe for full-viewport overlays present before interaction. The model chooses.",
      "evidence": "The checking page opens with a mandatory ZIP-code modal over dimmed content, while cookie banners cover the bottom of checking, card, login, and error states.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F5"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "semantic-dismissible-primitives",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: DOM/source inspection for popover / <dialog> / <details> vs custom overlay divs with manual dismiss handling. The model chooses.",
      "evidence": "DOM probe found zero native dialog and popover elements despite modal/help/privacy layers; landmarks include custom DIV:dialog nodes.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F6"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "checkId": "reduced-chrome",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: a screenshot plus layout metrics can show the proportion of the viewport given to chrome vs content. The model chooses.",
      "evidence": "Homepage first viewport combines login, four card promotions, product banners, and a sticky cash-offer strip; mobile is dominated by the card ad before core banking actions.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F7"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "responsive-no-horizontal-scroll",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: layout metrics (scrollWidth vs innerWidth) and a screenshot at an emulated narrow mobile viewport reveal overflow. The model chooses.",
      "evidence": "At 360x800, layout metrics reported scrollWidth 360, clientWidth 360, and horizontalOverflowPx 0; the mobile screenshot shows a single-column adaptation.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "component-level-responsiveness",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: CSS inspection for @container / container-type; a computed-style probe of the same component in a wide vs narrow container shows whether it adapts. The model chooses.",
      "evidence": "CSS probe found no @container rules; reusable cards and navigation are controlled only by viewport breakpoints.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F8"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "checkId": "input-modality-aware",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: a focus probe (focus an element, read the computed outline) or an axe target-size check; a screenshot of a focused control corroborates. The model chooses.",
      "evidence": "Lighthouse failed target-size; the DOM probe found many 16–20 px-high links and several focused login controls with outline none.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F9"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-purpose-and-primary-action",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: screenshot the first viewport and key scrolled states; inspect heading structure, nav labels, button text, and visual hierarchy; a task walkthrough can show whether the next action is obvious. The model chooses.",
      "evidence": "At 360x800 the first viewport omits the login form and is dominated by four credit-card promotions, making the secure banking action unclear.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F10"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "primary-flow-completion",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: run the flow manually with screenshots/DOM snapshots at each step; compare expected vs actual path length; inspect form requirements, navigation continuity, and blockers. The model chooses.",
      "evidence": "The public product-discovery flow was followed from the homepage to credit-card and checking product surfaces; each presents a clear product CTA. Authenticated account access was not attempted without credentials.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "checkId": "clear-system-state-and-recovery",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: exercise network delay/failure, invalid input, empty data and success states; screenshot the state messaging and recovery controls; inspect whether browser history and focus remain sensible. The model chooses.",
      "evidence": "Clicking Log in with both required fields empty produced no visible error, no role=alert/aria-invalid node, and no focus transfer in the evaluate probe.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F11"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "good-core-web-vitals",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: Lighthouse reports LCP/CLS/TBT directly and the model may run it; layout metrics + a layout-shift observer + a long-task observer (the evidence primitives) give the same signal first-party. The model chooses.",
      "evidence": "Lighthouse performance was 0.17: LCP 20.0 s, TBT 3,080 ms, interactive 35.2 s; trace found LCP 3.17 s, 1,181 ms TBT and an 837 ms longest task; HAR recorded 134 requests and 3.75 MB.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F12"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "visual-stability",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: the layout primitive's CLS observer captures shifts; a transition video of the first seconds shows content jumping. The model chooses.",
      "evidence": "Mobile layout observer measured CLS 0.214 with a 0.166 shift; 64 of 68 images lacked explicit dimensions.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F13"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-main-thread",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: the layout primitive records long tasks; a heap summary shows the object population; Lighthouse reports TBT. The model chooses.",
      "evidence": "Lighthouse performance was 0.17: LCP 20.0 s, TBT 3,080 ms, interactive 35.2 s; trace found LCP 3.17 s, 1,181 ms TBT and an 837 ms longest task; HAR recorded 134 requests and 3.75 MB.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F12"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "efficient-resource-delivery",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: a HAR summary can reveal cache headers, redirects, render-blocking candidates, weight offenders and dependency shape; a trace/Lighthouse insight report can corroborate LCP discovery, render-blocking, font-display and document latency. The model chooses.",
      "evidence": "Lighthouse performance was 0.17: LCP 20.0 s, TBT 3,080 ms, interactive 35.2 s; trace found LCP 3.17 s, 1,181 ms TBT and an 837 ms longest task; HAR recorded 134 requests and 3.75 MB.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F12"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "checkId": "trim-unused-and-duplicate-code",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: Lighthouse/trace/code-coverage style evidence can flag unused JS/CSS, duplicated JavaScript and legacy code; a HAR summary shows third-party byte cost and request count. The model chooses.",
      "evidence": "Lighthouse performance was 0.17: LCP 20.0 s, TBT 3,080 ms, interactive 35.2 s; trace found LCP 3.17 s, 1,181 ms TBT and an 837 ms longest task; HAR recorded 134 requests and 3.75 MB.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F12"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "names-roles-labels",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: axe-core (injectable via the evaluate primitive) or Lighthouse's a11y audits enumerate these; a DOM probe of the accessibility-relevant attributes is a first-party alternative. The model chooses.",
      "evidence": "Lighthouse failed aria-required-attr and image-alt; multiple role=heading nodes lacked aria-level and an image used whitespace-only alt.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F14"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "sufficient-contrast",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: axe contrast rules, a Lighthouse contrast audit, or an in-page probe computing contrast ratios from computed colours. The model chooses.",
      "evidence": "Lighthouse failed color contrast, including red #e31837 text on #f5f5f5 at 4.32:1.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F15"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "structure-and-focus",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: axe/Lighthouse structural audits; a focus-walk probe (tab through, read activeElement + computed outline) is a first-party alternative. The model chooses.",
      "evidence": "Rendered DOM contains multiple H1s, including an empty H1 and hidden overlay headings; several focused login links and fields compute outline none.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F16"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "legible-text",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: a screenshot of body and heading text, plus CSS inspection for text-wrap / text alignment / font fallback handling. The model chooses.",
      "evidence": "Desktop and mobile screenshots show readable body copy and headings without clipping; line lengths and spacing remain comprehensible on the sampled pages.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "be-inclusive",
      "checkId": "zoom-reflow-targets-and-media",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: Lighthouse/axe target-size, meta-viewport and media-caption audits are useful signals; screenshots at narrow and zoomed conditions plus DOM/media inspection can corroborate. The model chooses.",
      "evidence": "Lighthouse failed target-size and the probe found many links/buttons only 16–20 px high; zoom/reflow is weakened by dense small controls.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F17"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "no-console-errors",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: capture Runtime/Log CDP events, or a probe that reads collected errors; Lighthouse reports this too. The model chooses.",
      "evidence": "Lighthouse errors-in-console audit scored 1 with an empty item list.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "sound-document-and-assets",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: a DOM/source probe for doctype/charset/img dimensions; CSS inspection for repetition; Lighthouse best-practices audits cover the rest. The model chooses.",
      "evidence": "Lighthouse found an incorrectly stretched hero image; images primitive found 64 missing dimensions and 15 oversized assets.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F18"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "checkId": "browser-platform-hygiene",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: Lighthouse best-practices audits and DevTools inspector/deprecation signals can surface these; DOM/source probes can verify paste handlers and prompt timing. The model chooses.",
      "evidence": "Lighthouse found a deprecated Shared Storage API call, missing first-party source maps, and browser Inspector cookie issues.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F19"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "title-and-description",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: a DOM probe reads <title> and meta[name=description]; Lighthouse SEO audits cover the same ground. The model chooses.",
      "evidence": "Rendered DOM and Lighthouse confirm a descriptive title and meta description.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "crawlable-and-mobile-friendly",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: a DOM probe for anchor hrefs, viewport meta, and robots; Lighthouse SEO audits corroborate. The model chooses.",
      "evidence": "The discoverability primitive fetched only 311 bytes of raw HTML with 0% rendered-word coverage and no title, H1, description, or visible content; its crawler screenshot is blank even though the JavaScript browser view is populated.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F31"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "canonical-and-indexing-signals",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: inspect response status and headers, <link rel=canonical>, hreflang links, robots meta, robots.txt and sitemap.xml; Lighthouse SEO audits cover several of these. The model chooses.",
      "evidence": "The rendered page has canonical https://www.bankofamerica.com/, robots index/follow, a successful response, and es-US hreflang; Lighthouse passed canonical, status, robots, and hreflang audits.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "be-discoverable",
      "checkId": "structured-and-shareable-metadata",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: inspect JSON-LD/microdata and social preview tags against visible content; Lighthouse has a manual structured-data audit, and ad-hoc probes can parse schema.org blocks. The model chooses.",
      "evidence": "DOM probe found 3 JSON-LD blocks and 7 Open Graph properties matching the Bank of America homepage entity.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "secure-transport-and-headers",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: inspect response headers / page protocol via an evaluate probe or the network layer; Lighthouse best-practices flags HTTPS and CSP issues. The model chooses.",
      "evidence": "HTTPS and HSTS are present, but CSP permits unsafe-inline and unsafe-eval; cookie evidence reports 33 of 34 cookies as insecure under its checks, including non-Secure first-party values and widespread SameSite=None.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F20"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "data-minimisation-and-third-parties",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: inspect network requests and third-party origins; a probe of analytics/beacon calls. The model chooses.",
      "evidence": "Trackers/network evidence found 15 third-party origins and HAR attributes 114 requests/3.45 MB to origins outside secure.bankofamerica.com, including Tealium, Adobe, Glassbox, Glance, and OneTrust traffic.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F21"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "in-context-permissions-and-modern-auth",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: a probe for permission requests fired on load; source inspection for passkey / WebAuthn / navigator.credentials usage in auth flows. The model chooses.",
      "evidence": "Recon exposed a Log in with passkey option, and no geolocation or notification prompt appeared on load across screenshots and Lighthouse.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "checkId": "defensive-browser-policies",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: inspect response headers and browser security state; Lighthouse/DevTools security audits can corroborate HSTS, clickjacking, Trusted Types, origin isolation and third-party cookie findings. The model chooses.",
      "evidence": "The secure response has HSTS, X-Frame-Options and frame-ancestors, but no observed Referrer-Policy, Permissions-Policy or X-Content-Type-Options and CSP still allows unsafe-inline/unsafe-eval.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F22"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "progressive-enhancement",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: load with scripting disabled or compare a no-JS fetch of the HTML against the rendered page; check for Baseline-aware fallbacks in source. The model chooses.",
      "evidence": "Discoverability fetched only 311 bytes of raw HTML with 0% rendered-word coverage, no title/H1/description, and a blank crawler screenshot: core public content depends on JavaScript.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F23"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "resilient-runtime-behaviour",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: exercise menus near viewport edges with a screenshot; a probe of async/visibility behaviour. The model chooses.",
      "evidence": "Representative navigation, tabs, dialogs, and content cards rendered without clipped menus or broken asynchronous states in the captured paths.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "offline-and-installable",
      "status": "not-applicable",
      "confidence": "high",
      "method": "HINT: a probe for a service worker registration and a web app manifest; test behaviour offline. The model chooses.",
      "evidence": "Public marketing and online-banking transactions are not an installable/offline app surface; offline transaction completion would be inappropriate.",
      "reason": "Public marketing and online-banking transactions are not an installable/offline app surface; offline transaction completion would be inappropriate.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "be-resilient",
      "checkId": "network-and-http-failure-states",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: simulate failed fetches/offline mode or inspect representative 404/500 routes; screenshots and DOM snapshots of error/loading/empty states show whether recovery is possible. The model chooses.",
      "evidence": "A deliberately nonexistent route produced a branded Page Not Available view with Home Page, Site Map, and Contact us recovery links.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "lang-dir-and-logical-properties",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: a DOM probe for <html lang>/dir and CSS inspection for logical vs physical properties. The model chooses.",
      "evidence": "The document declares lang=en-US, exposes an es-US hreflang alternate and an En español route; reading order was correct on sampled pages.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "locale-aware-data",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: source inspection for Intl.* usage vs hand-rolled formatting; a probe of rendered dates/numbers under a different locale. The model chooses.",
      "evidence": "Public prices, percentages, and dollar values are formatted consistently for en-US, and the site exposes a Spanish locale route.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "be-internationalised",
      "checkId": "time-zone-correctness",
      "status": "not-applicable",
      "confidence": "high",
      "method": "HINT: source inspection for time-zone-aware date handling vs naive local Date math. The model chooses.",
      "evidence": "No dates, appointments, recurring events, or time-zone-sensitive data appeared on the audited public surfaces.",
      "reason": "No dates, appointments, recurring events, or time-zone-sensitive data appeared on the audited public surfaces.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "no-dark-patterns",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: a screenshot of consent/upsell/cancel flows; source inspection for declarative button actions vs misleading controls. The model chooses.",
      "evidence": "Tracking and analytics load on first visit while the visible cookie notice offers only policy links and an X, with no equally prominent reject/control action.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F24"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "humane-error-handling",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: exercise a form, submit invalid input, and observe timing and clarity of errors via a screenshot or a :user-invalid / aria-invalid probe. The model chooses.",
      "evidence": "Clicking Log in with both required fields empty produced no visible error, no role=alert/aria-invalid node, and no focus transfer in the evaluate probe.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F11"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "trustworthy-input-assistance",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: source/DOM inspection for autocomplete attributes on form fields; a probe of autofill affordances. The model chooses.",
      "evidence": "User ID and password inputs both expose autocomplete=off instead of username/current-password, blocking standard secure password-manager/autofill assistance.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F25"
      ]
    },
    {
      "principleId": "be-trustworthy",
      "checkId": "safe-commercial-and-account-flows",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: walkthrough checkout/subscription/auth/account flows when present; screenshot pricing, confirmation, cancellation and reauthentication states; inspect passkey/autocomplete support for sign-in and payment. The model chooses.",
      "evidence": "Product pages disclose headline rewards and commitments before Apply Now, and the account surface offers passkey login, recovery, enrollment, and security help.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "optimised-assets",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: inspect transferred image bytes vs displayed size; source inspection for modern formats and resolution handling. The model chooses.",
      "evidence": "Images audit found 15 oversized images, 15 missing srcset, 9 legacy-format assets, and 12 below-fold images without lazy loading.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F26"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "no-wasteful-work",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: a long-task / network probe for background fetches and processing while idle or backgrounded. The model chooses.",
      "evidence": "Trace measured 1,181 ms total blocking time and HAR shows extensive analytics/behavior scripts; substantial work continues beyond essential product rendering.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F27"
      ]
    },
    {
      "principleId": "be-sustainable",
      "checkId": "third-party-and-media-budget",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: a HAR summary shows third-party bytes, font/media weight and caching; screenshots/video reveal autoplay and decorative media; trace/layout evidence shows whether media/animation keeps work running. The model chooses.",
      "evidence": "HAR recorded 48 scripts (2.28 MB) and 3.45 MB attributed outside the secure origin; Lighthouse page weight was 5,464 KiB.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F28"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "structured-agent-capabilities",
      "status": "not-applicable",
      "confidence": "high",
      "method": "HINT: source inspection for WebMCP / agentic-tool registration and agent-readable affordances. The model chooses.",
      "evidence": "No declared agent-facing capability was found, and exposing unauthenticated banking actions to agents is not assumed to be intended.",
      "reason": "No declared agent-facing capability was found, and exposing unauthenticated banking actions to agents is not assumed to be intended.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "checkId": "on-device-inference",
      "status": "not-applicable",
      "confidence": "high",
      "method": "HINT: source inspection for built-in AI (language model / summariser) usage. The model chooses.",
      "evidence": "No user task in the audited public surfaces requires on-device inference; absence is an emerging opportunity, not a defect.",
      "reason": "No user task in the audited public surfaces requires on-device inference; absence is an emerging opportunity, not a defect.",
      "pathIds": [
        "home"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-leak-under-repeated-interaction",
      "status": "issues",
      "confidence": "medium",
      "method": "HINT (not mandatory): compare heap snapshots for retained growth - a baseline, then one taken after repeating the interaction with `--interact` about 10x (the memory-tracer methodology: baseline -> repeat -> post -> compare). Performance.getMetrics (JSHeapUsedSize, Nodes) across the same before/after window is corroboration. If Chrome DevTools MCP is available, follow its memory-leak-debugging skill: capture baseline, target, and final snapshots, then use memlab or the provided comparison workflow rather than reading raw .heapsnapshot files directly. The package-native `heap` primitive remains the default path. This check is only meaningful where the page has a real interaction to repeat; for a static page with none, mark it not-applicable with a rationale rather than fabricating one. The model chooses.",
      "evidence": "Separate baseline and post-interaction heap summaries grew from 25.7 MB/378k nodes to 76.4 MB/1.11m nodes. Load timing differs, so this is medium-confidence retained-growth evidence requiring a same-session allocation investigation.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F29"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "bounded-footprint",
      "status": "issues",
      "confidence": "high",
      "method": "HINT: a single `heap` summary's totals (nodeCount, totalSelfSizeBytes, constructor population) plus Performance.getMetrics (Nodes, JSHeapUsedSize) give the current footprint to judge against the page's purpose. Chrome DevTools MCP heap snapshots and memlab snapshot analysis can provide the same memory distribution when available. Read summaries or derived analysis, never raw snapshots unless a dedicated heap-analysis tool is doing the analysis. The model chooses.",
      "evidence": "The settled post-interaction homepage retained about 76.4 MB across 1.11m heap nodes, disproportionate for a public marketing/login surface.",
      "pathIds": [
        "home"
      ],
      "findingIds": [
        "F30"
      ]
    },
    {
      "principleId": "be-memory-efficient",
      "checkId": "no-detached-dom-or-unbounded-listeners",
      "status": "pass",
      "confidence": "medium",
      "method": "HINT: the `heap` summary by constructor (Detached* nodes) compared across a before/after pair shows a growing detached-DOM population; an `evaluate` probe can sample listener/timer counts (e.g. getEventListeners-style counting, or instrumenting addEventListener/setInterval) before and after the repeated interaction to spot growth. Chrome DevTools MCP heap snapshots plus the memory-leak-debugging skill's common-leak guidance can corroborate detached DOM, listeners, closures, globals, and unbounded caches. Caveat from the memory-tracer and Chrome DevTools MCP guidance: detached nodes can be intentional caches, so judge confidence rather than asserting a bug. The model chooses.",
      "evidence": "Heap summaries contain no Detached* constructor among retained populations after the sampled checkbox interaction; no direct detached-DOM evidence was found.",
      "pathIds": [
        "home"
      ]
    }
  ],
  "principleOutcomes": [
    {
      "principleId": "respect-user-preferences",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F1",
        "F2"
      ]
    },
    {
      "principleId": "implement-natural-interactions",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F3"
      ]
    },
    {
      "principleId": "provide-guided-navigation",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F4"
      ]
    },
    {
      "principleId": "maximize-content-reduce-noise",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F5",
        "F6",
        "F7"
      ]
    },
    {
      "principleId": "adapt-to-the-form-factor",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F8",
        "F9"
      ]
    },
    {
      "principleId": "support-core-task-success",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F10",
        "F11"
      ]
    },
    {
      "principleId": "be-fast-and-stable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F12",
        "F13"
      ]
    },
    {
      "principleId": "be-inclusive",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F14",
        "F15",
        "F16",
        "F17"
      ]
    },
    {
      "principleId": "follow-best-practices",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F18",
        "F19"
      ]
    },
    {
      "principleId": "be-discoverable",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F31"
      ]
    },
    {
      "principleId": "be-private-and-secure",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F20",
        "F21",
        "F22"
      ]
    },
    {
      "principleId": "be-resilient",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F23"
      ]
    },
    {
      "principleId": "be-internationalised",
      "expectation": "contextual",
      "status": "pass"
    },
    {
      "principleId": "be-trustworthy",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F24",
        "F11",
        "F25"
      ]
    },
    {
      "principleId": "be-sustainable",
      "expectation": "contextual",
      "status": "issues",
      "findingIds": [
        "F26",
        "F27",
        "F28"
      ]
    },
    {
      "principleId": "be-agent-ready",
      "expectation": "contextual",
      "status": "not-applicable",
      "reason": "All checks were judged outside the intended public-site context."
    },
    {
      "principleId": "be-memory-efficient",
      "expectation": "default",
      "status": "issues",
      "findingIds": [
        "F29",
        "F30"
      ]
    }
  ],
  "paths": [
    {
      "id": "entry",
      "description": "Requested secure origin and client-side handoff to the public homepage; global metadata, transport, crawlability, and login entry.",
      "url": "https://secure.bankofamerica.com",
      "conditions": [
        "desktop",
        "mobile",
        "dark preference",
        "contrast preference",
        "reduced motion",
        "no JavaScript"
      ],
      "result": "issues"
    },
    {
      "id": "home",
      "description": "Rendered public homepage and unauthenticated login, representing the main navigation and account-entry journey.",
      "url": "https://www.bankofamerica.com/",
      "conditions": [
        "1440x900",
        "360x800",
        "empty login submit"
      ],
      "result": "issues"
    },
    {
      "id": "checking",
      "description": "Checking-account product detail, representing deposit products and the location/rate gate.",
      "url": "https://www.bankofamerica.com/deposits/checking/checking-accounts/",
      "conditions": [
        "desktop",
        "load-time modal"
      ],
      "result": "issues"
    },
    {
      "id": "cards",
      "description": "Credit-card listing, representing a product catalog with filtering and application CTAs.",
      "url": "https://www.bankofamerica.com/credit-cards/",
      "conditions": [
        "desktop"
      ],
      "result": "issues"
    },
    {
      "id": "security",
      "description": "Security Center, representing editorial/help content and carousel navigation.",
      "url": "https://www.bankofamerica.com/security/",
      "conditions": [
        "desktop"
      ],
      "result": "pass"
    },
    {
      "id": "missing-route",
      "description": "Deliberately invalid public path, representing HTTP/navigation recovery.",
      "url": "https://www.bankofamerica.com/this-route-does-not-exist-web-uplift",
      "conditions": [
        "desktop"
      ],
      "result": "pass"
    }
  ],
  "findings": [
    {
      "id": "F1",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-color-scheme",
      "guidanceId": "dark-mode",
      "guidanceCategory": "user-experience",
      "severity": "medium",
      "confidence": "high",
      "summary": "No system-driven dark theme",
      "evidence": "DOM reports color-scheme normal while authored markup declares only light; CSS probe found no prefers-color-scheme: dark rule. The dark capture stayed blank because body visibility never recovered under that condition.",
      "artifacts": [
        "evidence/dark.png",
        "evidence/probe.json"
      ],
      "suggestedFix": "Add color-scheme: light dark and theme surfaces with prefers-color-scheme or light-dark().",
      "effort": "medium"
    },
    {
      "id": "F2",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "respect-user-preferences",
      "principleCheckId": "respects-reduced-motion",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "low",
      "confidence": "high",
      "summary": "Reduced-motion preference is not implemented",
      "evidence": "Under prefers-reduced-motion: reduce, a 500 ms animation still existed and the CSS probe found no prefers-reduced-motion rule.",
      "artifacts": [
        "evidence/reduced-motion.json"
      ],
      "suggestedFix": "Disable or shorten nonessential transitions and carousel motion inside prefers-reduced-motion: reduce.",
      "effort": "small"
    },
    {
      "id": "F3",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "implement-natural-interactions",
      "principleCheckId": "view-transitions",
      "guidanceId": "same-document-transitions",
      "guidanceCategory": "user-experience",
      "severity": "low",
      "confidence": "high",
      "summary": "Route and state changes lack View Transitions",
      "evidence": "CSS probe found no view-transition usage across a route-heavy MPA with tabs, menus, dialogs, and product navigation.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Layer View Transitions onto safe same-document and cross-document state changes, with reduced-motion fallbacks.",
      "effort": "medium"
    },
    {
      "id": "F4",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "provide-guided-navigation",
      "principleCheckId": "scroll-state-aware-chrome",
      "guidanceId": "scroll-position-aware-elements",
      "guidanceCategory": "user-experience",
      "severity": "low",
      "confidence": "high",
      "summary": "Long pages have static, non-responsive navigation chrome",
      "evidence": "CSS probe found no scroll-state query or position-aware chrome; long pages keep static navigation without a progress or return affordance.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Use scroll-state queries for a compact sticky header, progress, or return affordance where useful.",
      "effort": "medium"
    },
    {
      "id": "F5",
      "pathId": "checking",
      "url": "https://www.bankofamerica.com/deposits/checking/checking-accounts/",
      "principleId": "maximize-content-reduce-noise",
      "principleCheckId": "no-intrusive-interruptions",
      "guidanceId": "light-dismiss-a-dialog",
      "guidanceCategory": "user-experience",
      "severity": "high",
      "confidence": "high",
      "summary": "Load-time modal and sticky notices obscure product content",
      "evidence": "The checking page opens with a mandatory ZIP-code modal over dimmed content, while cookie banners cover the bottom of checking, card, login, and error states.",
      "artifacts": [
        "evidence/checking.png"
      ],
      "suggestedFix": "Defer the ZIP prompt until rates are needed and make notices non-blocking, dismissible, and content-first.",
      "effort": "medium"
    },
    {
      "id": "F6",
      "pathId": "checking",
      "url": "https://secure.bankofamerica.com",
      "principleId": "maximize-content-reduce-noise",
      "principleCheckId": "semantic-dismissible-primitives",
      "guidanceId": "declarative-dialog-popover-control",
      "guidanceCategory": "user-experience",
      "severity": "medium",
      "confidence": "high",
      "summary": "Custom dialog layers replace native top-layer primitives",
      "evidence": "DOM probe found zero native dialog and popover elements despite modal/help/privacy layers; landmarks include custom DIV:dialog nodes.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Use dialog for modal flows and popover for transient layers with native focus, Escape, and light-dismiss behavior.",
      "effort": "large"
    },
    {
      "id": "F7",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "maximize-content-reduce-noise",
      "principleCheckId": "reduced-chrome",
      "guidanceId": "improve-text-layout-and-legibility",
      "guidanceCategory": "user-experience",
      "severity": "medium",
      "confidence": "high",
      "summary": "Promotional chrome crowds out core banking content",
      "evidence": "Homepage first viewport combines login, four card promotions, product banners, and a sticky cash-offer strip; mobile is dominated by the card ad before core banking actions.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Reduce simultaneous promotions and lead with core banking actions, especially on mobile.",
      "effort": "medium"
    },
    {
      "id": "F8",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "component-level-responsiveness",
      "guidanceId": "size-aware-styling",
      "guidanceCategory": "user-experience",
      "severity": "low",
      "confidence": "high",
      "summary": "Reusable components do not use container queries",
      "evidence": "CSS probe found no @container rules; reusable cards and navigation are controlled only by viewport breakpoints.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Make reused cards/navigation container-aware with @container while retaining viewport fallbacks.",
      "effort": "medium"
    },
    {
      "id": "F9",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "adapt-to-the-form-factor",
      "principleCheckId": "input-modality-aware",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "Small targets and missing focus indicators impair input",
      "evidence": "Lighthouse failed target-size; the DOM probe found many 16–20 px-high links and several focused login controls with outline none.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Ensure at least 24x24 CSS px targets with spacing and a visible :focus-visible treatment on every control.",
      "effort": "medium"
    },
    {
      "id": "F10",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "support-core-task-success",
      "principleCheckId": "clear-purpose-and-primary-action",
      "guidanceId": "scrollability-affordance-hints",
      "guidanceCategory": "user-experience",
      "severity": "high",
      "confidence": "high",
      "summary": "Mobile first viewport hides the secure banking task",
      "evidence": "At 360x800 the first viewport omits the login form and is dominated by four credit-card promotions, making the secure banking action unclear.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Place a clear Log in action in the initial mobile viewport before promotional card content.",
      "effort": "medium"
    },
    {
      "id": "F11",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-trustworthy",
      "principleCheckId": "humane-error-handling",
      "guidanceId": "accessible-error-announcement",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "Empty login submission gives no actionable error",
      "evidence": "Clicking Log in with both required fields empty produced no visible error, no role=alert/aria-invalid node, and no focus transfer in the evaluate probe.",
      "artifacts": [
        "evidence/login-error.png",
        "evidence/login-error.json"
      ],
      "suggestedFix": "Validate after submit, mark fields aria-invalid, focus the first error, and announce concise recovery guidance in a live region.",
      "effort": "medium"
    },
    {
      "id": "F12",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "trim-unused-and-duplicate-code",
      "guidanceId": "performance",
      "guidanceCategory": "performance",
      "severity": "critical",
      "confidence": "high",
      "summary": "Homepage load and main-thread work are far outside good ranges",
      "evidence": "Lighthouse performance was 0.17: LCP 20.0 s, TBT 3,080 ms, interactive 35.2 s; trace found LCP 3.17 s, 1,181 ms TBT and an 837 ms longest task; HAR recorded 134 requests and 3.75 MB.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/trace-summary.json",
        "evidence/network-summary.json"
      ],
      "suggestedFix": "Remove or defer noncritical scripts, prioritize the LCP resource, split long tasks, and set performance budgets.",
      "effort": "large"
    },
    {
      "id": "F13",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-fast-and-stable",
      "principleCheckId": "visual-stability",
      "guidanceId": "visually-stable-font-fallbacks",
      "guidanceCategory": "performance",
      "severity": "high",
      "confidence": "high",
      "summary": "Late content causes poor visual stability",
      "evidence": "Mobile layout observer measured CLS 0.214 with a 0.166 shift; 64 of 68 images lacked explicit dimensions.",
      "artifacts": [
        "evidence/layout-mobile.json"
      ],
      "suggestedFix": "Reserve image/banner space with dimensions or aspect-ratio and prevent late promotional insertion from shifting content.",
      "effort": "medium"
    },
    {
      "id": "F14",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-inclusive",
      "principleCheckId": "names-roles-labels",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "ARIA and image alternatives are malformed",
      "evidence": "Lighthouse failed aria-required-attr and image-alt; multiple role=heading nodes lacked aria-level and an image used whitespace-only alt.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Use semantic headings or add aria-level, and replace whitespace alt with empty alt for decorative images or meaningful text.",
      "effort": "medium"
    },
    {
      "id": "F15",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-inclusive",
      "principleCheckId": "sufficient-contrast",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "medium",
      "confidence": "high",
      "summary": "Text contrast falls below WCAG minimum",
      "evidence": "Lighthouse failed color contrast, including red #e31837 text on #f5f5f5 at 4.32:1.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Darken red text or change the surface color so normal text reaches at least 4.5:1.",
      "effort": "small"
    },
    {
      "id": "F16",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-inclusive",
      "principleCheckId": "structure-and-focus",
      "guidanceId": "accessibility",
      "guidanceCategory": "accessibility",
      "severity": "high",
      "confidence": "high",
      "summary": "Heading hierarchy and keyboard focus are inconsistent",
      "evidence": "Rendered DOM contains multiple H1s, including an empty H1 and hidden overlay headings; several focused login links and fields compute outline none.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Keep one meaningful page H1, exclude hidden overlay headings, and restore visible focus for login fields and links.",
      "effort": "medium"
    },
    {
      "id": "F17",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-inclusive",
      "principleCheckId": "zoom-reflow-targets-and-media",
      "guidanceId": "fluid-scaling",
      "guidanceCategory": "css-layout",
      "severity": "medium",
      "confidence": "high",
      "summary": "Touch targets are too small",
      "evidence": "Lighthouse failed target-size and the probe found many links/buttons only 16–20 px high; zoom/reflow is weakened by dense small controls.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Increase hit areas and spacing while preserving narrow-viewport reflow.",
      "effort": "medium"
    },
    {
      "id": "F18",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "follow-best-practices",
      "principleCheckId": "sound-document-and-assets",
      "guidanceId": "optimize-image-priority",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "Images are unsized, oversized, and sometimes distorted",
      "evidence": "Lighthouse found an incorrectly stretched hero image; images primitive found 64 missing dimensions and 15 oversized assets.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Declare dimensions/aspect-ratio and serve responsive sources sized to their rendered slots.",
      "effort": "medium"
    },
    {
      "id": "F19",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "follow-best-practices",
      "principleCheckId": "browser-platform-hygiene",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "medium",
      "confidence": "high",
      "summary": "Deprecated API and inspection hygiene issues remain",
      "evidence": "Lighthouse found a deprecated Shared Storage API call, missing first-party source maps, and browser Inspector cookie issues.",
      "artifacts": [
        "evidence/lighthouse.json",
        "evidence/probe.json"
      ],
      "suggestedFix": "Remove the deprecated Shared Storage call, publish valid source maps securely, and resolve DevTools cookie issues.",
      "effort": "medium"
    },
    {
      "id": "F20",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-private-and-secure",
      "principleCheckId": "secure-transport-and-headers",
      "guidanceId": "security",
      "guidanceCategory": "security",
      "severity": "high",
      "confidence": "high",
      "summary": "Security policy and cookie posture are weaker than expected",
      "evidence": "HTTPS and HSTS are present, but CSP permits unsafe-inline and unsafe-eval; cookie evidence reports 33 of 34 cookies as insecure under its checks, including non-Secure first-party values and widespread SameSite=None.",
      "artifacts": [
        "evidence/reduced-motion.json"
      ],
      "suggestedFix": "Remove unsafe-eval/inline through nonces or hashes and apply Secure, HttpOnly where appropriate, and restrictive SameSite to cookies.",
      "effort": "large"
    },
    {
      "id": "F21",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-private-and-secure",
      "principleCheckId": "data-minimisation-and-third-parties",
      "guidanceId": "privacy",
      "guidanceCategory": "privacy",
      "severity": "high",
      "confidence": "high",
      "summary": "The unauthenticated page has a broad behavioral-data footprint",
      "evidence": "Trackers/network evidence found 15 third-party origins and HAR attributes 114 requests/3.45 MB to origins outside secure.bankofamerica.com, including Tealium, Adobe, Glassbox, Glance, and OneTrust traffic.",
      "artifacts": [
        "evidence/reduced-motion.json"
      ],
      "suggestedFix": "Inventory each third party, remove low-value collection, gate optional analytics on consent, and batch/minimize remaining events.",
      "effort": "large"
    },
    {
      "id": "F22",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-private-and-secure",
      "principleCheckId": "defensive-browser-policies",
      "guidanceId": "security",
      "guidanceCategory": "security",
      "severity": "medium",
      "confidence": "high",
      "summary": "Defensive response policies are incomplete",
      "evidence": "The secure response has HSTS, X-Frame-Options and frame-ancestors, but no observed Referrer-Policy, Permissions-Policy or X-Content-Type-Options and CSP still allows unsafe-inline/unsafe-eval.",
      "artifacts": [
        "evidence/reduced-motion.json"
      ],
      "suggestedFix": "Add nosniff, a strict Referrer-Policy and least-privilege Permissions-Policy; strengthen CSP and consider Trusted Types.",
      "effort": "medium"
    },
    {
      "id": "F23",
      "pathId": "entry",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-resilient",
      "principleCheckId": "progressive-enhancement",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "high",
      "confidence": "high",
      "summary": "Non-JavaScript crawlers receive an empty shell",
      "evidence": "Discoverability fetched only 311 bytes of raw HTML with 0% rendered-word coverage, no title/H1/description, and a blank crawler screenshot: core public content depends on JavaScript.",
      "artifacts": [
        "evidence/discoverability.json",
        "evidence/discoverability-rendered.png",
        "evidence/discoverability-crawler.png"
      ],
      "suggestedFix": "Server-render or statically emit meaningful title, heading, primary content, and links before enhancement.",
      "effort": "large"
    },
    {
      "id": "F24",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-trustworthy",
      "principleCheckId": "no-dark-patterns",
      "guidanceId": "privacy",
      "guidanceCategory": "privacy",
      "severity": "high",
      "confidence": "high",
      "summary": "Tracking begins without an equal reject/control choice",
      "evidence": "Tracking and analytics load on first visit while the visible cookie notice offers only policy links and an X, with no equally prominent reject/control action.",
      "artifacts": [
        "evidence/reduced-motion.json"
      ],
      "suggestedFix": "Present accept/reject/manage choices with equal prominence and defer nonessential tracking until consent.",
      "effort": "large"
    },
    {
      "id": "F25",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-trustworthy",
      "principleCheckId": "trustworthy-input-assistance",
      "guidanceId": "autofill-sign-in-form",
      "guidanceCategory": "forms",
      "severity": "high",
      "confidence": "high",
      "summary": "Login disables secure browser autofill",
      "evidence": "User ID and password inputs both expose autocomplete=off instead of username/current-password, blocking standard secure password-manager/autofill assistance.",
      "artifacts": [
        "evidence/reduced-motion.json"
      ],
      "suggestedFix": "Use autocomplete=username and autocomplete=current-password; keep the passkey option integrated.",
      "effort": "small"
    },
    {
      "id": "F26",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-sustainable",
      "principleCheckId": "optimised-assets",
      "guidanceId": "deliver-optimized-decorative-images",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "Responsive image delivery wastes bytes",
      "evidence": "Images audit found 15 oversized images, 15 missing srcset, 9 legacy-format assets, and 12 below-fold images without lazy loading.",
      "artifacts": [
        "evidence/reduced-motion.json"
      ],
      "suggestedFix": "Generate srcset/sizes, modern formats, lazy-load below-fold imagery, and right-size decorative assets.",
      "effort": "medium"
    },
    {
      "id": "F27",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-sustainable",
      "principleCheckId": "no-wasteful-work",
      "guidanceId": "efficient-background-processing",
      "guidanceCategory": "performance",
      "severity": "high",
      "confidence": "high",
      "summary": "Background analytics and scripts consume excessive work",
      "evidence": "Trace measured 1,181 ms total blocking time and HAR shows extensive analytics/behavior scripts; substantial work continues beyond essential product rendering.",
      "artifacts": [
        "evidence/reduced-motion.json"
      ],
      "suggestedFix": "Defer, batch, pause offscreen/background processing, and remove redundant behavioral tooling.",
      "effort": "large"
    },
    {
      "id": "F28",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-sustainable",
      "principleCheckId": "third-party-and-media-budget",
      "guidanceId": "deprioritize-background-fetches",
      "guidanceCategory": "performance",
      "severity": "high",
      "confidence": "high",
      "summary": "Third-party scripts dominate the page budget",
      "evidence": "HAR recorded 48 scripts (2.28 MB) and 3.45 MB attributed outside the secure origin; Lighthouse page weight was 5,464 KiB.",
      "artifacts": [
        "evidence/reduced-motion.json"
      ],
      "suggestedFix": "Set a third-party byte/request budget and delay nonessential tags until idle or consent.",
      "effort": "large"
    },
    {
      "id": "F29",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-memory-efficient",
      "principleCheckId": "no-leak-under-repeated-interaction",
      "guidanceId": "manage-recurring-intervals",
      "guidanceCategory": "user-experience",
      "severity": "medium",
      "confidence": "medium",
      "summary": "Heap growth signal warrants leak investigation",
      "evidence": "Separate baseline and post-interaction heap summaries grew from 25.7 MB/378k nodes to 76.4 MB/1.11m nodes. Load timing differs, so this is medium-confidence retained-growth evidence requiring a same-session allocation investigation.",
      "artifacts": [
        "evidence/reduced-motion.json"
      ],
      "suggestedFix": "Repeat the interaction in one session with baseline/target/final snapshots and trace retainers, timers, listeners, and caches.",
      "effort": "medium"
    },
    {
      "id": "F30",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-memory-efficient",
      "principleCheckId": "bounded-footprint",
      "guidanceId": "performance",
      "guidanceCategory": "performance",
      "severity": "medium",
      "confidence": "high",
      "summary": "Homepage memory footprint is disproportionate",
      "evidence": "The settled post-interaction homepage retained about 76.4 MB across 1.11m heap nodes, disproportionate for a public marketing/login surface.",
      "artifacts": [
        "evidence/heap-baseline.heapsnapshot",
        "evidence/heap-interaction.heapsnapshot"
      ],
      "suggestedFix": "Profile large script/object populations, remove duplicated runtimes, and lazy-initialize below-fold widgets and analytics.",
      "effort": "large"
    },
    {
      "id": "F31",
      "pathId": "home",
      "url": "https://secure.bankofamerica.com",
      "principleId": "be-discoverable",
      "principleCheckId": "crawlable-and-mobile-friendly",
      "guidanceId": "html",
      "guidanceCategory": "html",
      "severity": "high",
      "confidence": "high",
      "summary": "Public content is invisible to non-JavaScript crawlers",
      "evidence": "The discoverability primitive fetched only 311 bytes of raw HTML with 0% rendered-word coverage and no title, H1, description, or visible content; its crawler screenshot is blank even though the JavaScript browser view is populated.",
      "artifacts": [
        "evidence/discoverability.json",
        "evidence/discoverability-rendered.png",
        "evidence/discoverability-crawler.png"
      ],
      "suggestedFix": "Return meaningful title, heading, primary content, and crawlable links in the server HTML before client enhancement.",
      "effort": "large"
    }
  ],
  "taskList": [
    {
      "id": "T1",
      "title": "Remove or defer noncritical scripts, prioritize the LCP resource, split long tasks, and set performance budgets.",
      "priority": 1,
      "findingIds": [
        "F12"
      ],
      "guidanceId": "performance",
      "status": "open"
    },
    {
      "id": "T2",
      "title": "Reserve image/banner space with dimensions or aspect-ratio and prevent late promotional insertion from shifting content.",
      "priority": 2,
      "findingIds": [
        "F13"
      ],
      "guidanceId": "visually-stable-font-fallbacks",
      "status": "open"
    },
    {
      "id": "T3",
      "title": "Ensure at least 24x24 CSS px targets with spacing and a visible :focus-visible treatment on every control.",
      "priority": 3,
      "findingIds": [
        "F9"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T4",
      "title": "Validate after submit, mark fields aria-invalid, focus the first error, and announce concise recovery guidance in a live region.",
      "priority": 4,
      "findingIds": [
        "F11"
      ],
      "guidanceId": "accessible-error-announcement",
      "status": "open"
    },
    {
      "id": "T5",
      "title": "Use semantic headings or add aria-level, and replace whitespace alt with empty alt for decorative images or meaningful text.",
      "priority": 5,
      "findingIds": [
        "F14"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T6",
      "title": "Keep one meaningful page H1, exclude hidden overlay headings, and restore visible focus for login fields and links.",
      "priority": 6,
      "findingIds": [
        "F16"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T7",
      "title": "Remove unsafe-eval/inline through nonces or hashes and apply Secure, HttpOnly where appropriate, and restrictive SameSite to cookies.",
      "priority": 7,
      "findingIds": [
        "F20"
      ],
      "guidanceId": "security",
      "status": "open"
    },
    {
      "id": "T8",
      "title": "Inventory each third party, remove low-value collection, gate optional analytics on consent, and batch/minimize remaining events.",
      "priority": 8,
      "findingIds": [
        "F21"
      ],
      "guidanceId": "privacy",
      "status": "open"
    },
    {
      "id": "T9",
      "title": "Server-render or statically emit meaningful title, heading, primary content, and links before enhancement.",
      "priority": 9,
      "findingIds": [
        "F23"
      ],
      "guidanceId": "html",
      "status": "open"
    },
    {
      "id": "T10",
      "title": "Return meaningful title, heading, primary content, and crawlable links in the server HTML before client enhancement.",
      "priority": 10,
      "findingIds": [
        "F31"
      ],
      "guidanceId": "html",
      "status": "open"
    },
    {
      "id": "T11",
      "title": "Present accept/reject/manage choices with equal prominence and defer nonessential tracking until consent.",
      "priority": 11,
      "findingIds": [
        "F24"
      ],
      "guidanceId": "privacy",
      "status": "open"
    },
    {
      "id": "T12",
      "title": "Use autocomplete=username and autocomplete=current-password; keep the passkey option integrated.",
      "priority": 12,
      "findingIds": [
        "F25"
      ],
      "guidanceId": "autofill-sign-in-form",
      "status": "open"
    },
    {
      "id": "T13",
      "title": "Defer, batch, pause offscreen/background processing, and remove redundant behavioral tooling.",
      "priority": 13,
      "findingIds": [
        "F27"
      ],
      "guidanceId": "efficient-background-processing",
      "status": "open"
    },
    {
      "id": "T14",
      "title": "Set a third-party byte/request budget and delay nonessential tags until idle or consent.",
      "priority": 14,
      "findingIds": [
        "F28"
      ],
      "guidanceId": "deprioritize-background-fetches",
      "status": "open"
    },
    {
      "id": "T15",
      "title": "Defer the ZIP prompt until rates are needed and make notices non-blocking, dismissible, and content-first.",
      "priority": 15,
      "findingIds": [
        "F5"
      ],
      "guidanceId": "light-dismiss-a-dialog",
      "status": "open"
    },
    {
      "id": "T16",
      "title": "Place a clear Log in action in the initial mobile viewport before promotional card content.",
      "priority": 16,
      "findingIds": [
        "F10"
      ],
      "guidanceId": "scrollability-affordance-hints",
      "status": "open"
    },
    {
      "id": "T17",
      "title": "Use dialog for modal flows and popover for transient layers with native focus, Escape, and light-dismiss behavior.",
      "priority": 17,
      "findingIds": [
        "F6"
      ],
      "guidanceId": "declarative-dialog-popover-control",
      "status": "open"
    },
    {
      "id": "T18",
      "title": "Darken red text or change the surface color so normal text reaches at least 4.5:1.",
      "priority": 18,
      "findingIds": [
        "F15"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T19",
      "title": "Increase hit areas and spacing while preserving narrow-viewport reflow.",
      "priority": 19,
      "findingIds": [
        "F17"
      ],
      "guidanceId": "fluid-scaling",
      "status": "open"
    },
    {
      "id": "T20",
      "title": "Declare dimensions/aspect-ratio and serve responsive sources sized to their rendered slots.",
      "priority": 20,
      "findingIds": [
        "F18"
      ],
      "guidanceId": "optimize-image-priority",
      "status": "open"
    },
    {
      "id": "T21",
      "title": "Remove the deprecated Shared Storage call, publish valid source maps securely, and resolve DevTools cookie issues.",
      "priority": 21,
      "findingIds": [
        "F19"
      ],
      "guidanceId": "html",
      "status": "open"
    },
    {
      "id": "T22",
      "title": "Add nosniff, a strict Referrer-Policy and least-privilege Permissions-Policy; strengthen CSP and consider Trusted Types.",
      "priority": 22,
      "findingIds": [
        "F22"
      ],
      "guidanceId": "security",
      "status": "open"
    },
    {
      "id": "T23",
      "title": "Generate srcset/sizes, modern formats, lazy-load below-fold imagery, and right-size decorative assets.",
      "priority": 23,
      "findingIds": [
        "F26"
      ],
      "guidanceId": "deliver-optimized-decorative-images",
      "status": "open"
    },
    {
      "id": "T24",
      "title": "Repeat the interaction in one session with baseline/target/final snapshots and trace retainers, timers, listeners, and caches.",
      "priority": 24,
      "findingIds": [
        "F29"
      ],
      "guidanceId": "manage-recurring-intervals",
      "status": "open"
    },
    {
      "id": "T25",
      "title": "Profile large script/object populations, remove duplicated runtimes, and lazy-initialize below-fold widgets and analytics.",
      "priority": 25,
      "findingIds": [
        "F30"
      ],
      "guidanceId": "performance",
      "status": "open"
    },
    {
      "id": "T26",
      "title": "Add color-scheme: light dark and theme surfaces with prefers-color-scheme or light-dark().",
      "priority": 26,
      "findingIds": [
        "F1"
      ],
      "guidanceId": "dark-mode",
      "status": "open"
    },
    {
      "id": "T27",
      "title": "Reduce simultaneous promotions and lead with core banking actions, especially on mobile.",
      "priority": 27,
      "findingIds": [
        "F7"
      ],
      "guidanceId": "improve-text-layout-and-legibility",
      "status": "open"
    },
    {
      "id": "T28",
      "title": "Make reused cards/navigation container-aware with @container while retaining viewport fallbacks.",
      "priority": 28,
      "findingIds": [
        "F8"
      ],
      "guidanceId": "size-aware-styling",
      "status": "open"
    },
    {
      "id": "T29",
      "title": "Disable or shorten nonessential transitions and carousel motion inside prefers-reduced-motion: reduce.",
      "priority": 29,
      "findingIds": [
        "F2"
      ],
      "guidanceId": "accessibility",
      "status": "open"
    },
    {
      "id": "T30",
      "title": "Layer View Transitions onto safe same-document and cross-document state changes, with reduced-motion fallbacks.",
      "priority": 30,
      "findingIds": [
        "F3"
      ],
      "guidanceId": "same-document-transitions",
      "status": "open"
    },
    {
      "id": "T31",
      "title": "Use scroll-state queries for a compact sticky header, progress, or return affordance where useful.",
      "priority": 31,
      "findingIds": [
        "F4"
      ],
      "guidanceId": "scroll-position-aware-elements",
      "status": "open"
    }
  ],
  "budget": {
    "pathCount": 6,
    "auditPasses": 1
  },
  "agent": "pi",
  "runId": "2026-07-26T06-54-27-296Z"
}
