tradeit.gg internal documentation and interactive tools
server/ codebase sweep (296 files; 5 parallel domain agents + adversarial verification). 2 HIGH on public endpoints — crypto deposit webhook double-credit on replay, Steam login open redirect. 3 admin route groups (/commands, /internal, /cron) downgraded to defense-in-depth given Cloudflare Zero Trust gating. Includes prioritized remediation.must_not.assetId filter amplified by JS-side gzip decompression (libuv pool overload) and JSON.parse blocking the event loop. Fix already exists as PR #1284 (Apr 27, OPEN+BLOCKED, 7 days unmerged) — folds in profiler findings from the Apr 16–17 diagnostic.refresh: true; PR #114 backpressure pending