To make the output concrete, here’s an example from scanning an intentionally bad-practice demo app:
https://github.com/Privalyse/privalyse-cli/blob/main/example...
The goal is to surface privacy/security risks (PII, secrets, GDPR-relevant issues) in a way that’s readable for developers and non-security folks, rather than raw logs.