# CLONE_AUDIT — SPUN Medika

Pre-release audit. Run 2026-07-30 against the ten shipped source files
(`index.html`, `beranda.html`, `rincian-estimasi.html`, `estimasi-resume-medis.html`,
`bandingkan-rumah-sakit.html`, `prosedur-detail.html`, `assets/tokens.css`, `assets/ui.css`,
`assets/data.js`, `assets/estimator.js`, `assets/fonts/fonts.css`).

`audit-clone.mjs --strict` was **not** run — the skill's scripts require a Playwright install in the
project and the script set expects a `RECON/original-recon.json` produced by `recon-site.mjs`, which
was never generated (recon was done directly through the browser MCP, output as
`RECON/original-recon-summary.md`). The equivalent checks were run by hand below and each result is
reproducible from the command shown.

---

## 1. Tracking and telemetry — PASS

```
grep -rniE 'gtag|googletagmanager|google-analytics|fbq\(|facebook\.net|hotjar|clarity\.ms|mixpanel|segment\.com|_paq|matomo' <files>
→ CLEAN
```

No analytics, no tag manager, no pixels, no heatmaps, no session recording. Nothing was inherited
because the pages were authored rather than mirrored, so there was no GA block to excise.

## 2. Original-brand residue — PASS (5 intentional references)

```
grep -rniE 'spun\.global|solutopia|approval insight|semua visa|untuk bisnis|butuh visa|visa waiver|trending visa' <files>
```

Five hits, all deliberate **attribution of the design source**, none of them copied content:

| Location | What it is | Verdict |
|---|---|---|
| `index.html:39` | Launcher prose: "Klon bahasa visual **spun.global/id** yang dialihkan…" | Keep — states plainly that this is a visual-language study of that site |
| `index.html:117` | "…diambil dari computed style spun.global/id" | Keep — provenance of the token set |
| `beranda.html:48` | CSS comment: "resume-medis band (the Approval Insight analogue)" | Keep — developer comment naming the structural analogue |
| `assets/tokens.css:4` | Header comment citing the measurement source | Keep |
| `assets/fonts/fonts.css:2` | Comment recording where the family was measured | Keep |

**Zero** instances of SPUN's own marketing copy, section headings, testimonial text, reviewer names,
Google rating, visa product names, prices, or company legal block. No SPUN logo or wordmark — the
lockup is the string "SPUN Medika" set in the display face, per the logo-usage rule.

> If this were ever published rather than kept as a prototype, the wordmark itself would need to
> change: "SPUN" is the operator's mark regardless of the "Medika" suffix. See §7.

## 3. Asset hotlinks — PASS

```
grep -rhoE 'https?://[^"'\'' )]+' <files> | sort -u
→ https://wa.me/?text=
```

One remote URL, and it is a share intent triggered by a user click — not a resource load. Every
font, image, stylesheet and script is local and referenced by relative path. Verified in-browser:
all six pages load with zero failed resource requests (sole console entry across the whole run was
a dev-server `favicon.ico` 404).

## 4. Placeholder tokens, TODOs and stubs — PASS

```
grep -rnE '__[A-Z]+__|TODO|FIXME|lorem ipsum' <files>
→ CLEAN
```

Two placeholder artefacts were introduced during the build and both were caught and removed before
this audit: a `__DISC__` token in `rincian-estimasi.html` and a stray `${''}` template fragment in
`beranda.html`. No filler copy anywhere; all Indonesian prose is written for its slot.

## 5. Design-system compliance — PASS

```
grep -rniE '#f5f5f7|#1d1d1f|#0071e3|#d2d2d7|#6e6e73|#0066cc|SF Pro' <files>
→ CLEAN
```

Zero Apple-system literals and zero SF Pro references, as required by the clone-target rule: in a
web-clone project the recon-measured palette governs, not the saved default design system. Every
colour literal in `assets/tokens.css` is one of the twelve values in
`RECON/original-recon-summary.md`, plus the three scoped semantic tokens declared in
`design-dna.json`. Type resolves to `"Instrument Sans"` on all six pages (verified via
`getComputedStyle`).

## 6. Content-honesty audit — PASS

This product's main risk is not a tracking script; it is a fabricated number presented as fact.

| Check | Result |
|---|---|
| Every money row carries a provenance badge | PASS — 15/15 rendered rows on the default case; asserted in-browser |
| Items with no defensible figure excluded from totals | PASS — `open[]` rows carry no `low`/`high` and render in a separate "Belum bisa diestimasi" block |
| Market statistics are real and attributed | PASS — the four home stats (970,000+ patients; RM 2.2b; 527,176; 50–80%) are sourced to NST / Malay Mail / Malaysian private-hospital cost guides, cited beneath the strip, and labelled "bukan metrik produk kami" |
| No invented product metrics | PASS — no user counts, no accuracy claims, no approval rates |
| Testimonials labelled as samples | PASS — "Contoh tampilan — bukan ulasan pelanggan nyata" above the block; every card signed "Contoh — …" |
| Weak-basis multipliers flagged in-product | PASS — Singapore ×2.40 and Bangkok ×1.05 carry a `Dasar lemah` badge; the comparison screen carries a standing warning box |
| Hospital names disclosed as placeholders | PASS — footer, comparison takeaway, and `data.js` `placeholder: true` |
| Synthetic patient disclosed | PASS — the sample resume is labelled fictional on the upload screen and in the document pane |

## 7. Pre-release replacement list

Everything below must be resolved **before** any public deployment. None of it blocks use as an
internal prototype.

1. **Rename the product.** "SPUN Medika" borrows the operator's mark. Replace the wordmark, the
   `.brand` lockup in `assets/estimator.js`, and all page `<title>`s.
2. **Re-attribute or replace photography.** The four destination images are CC BY-SA 4.0 / 3.0.
   Share-alike travels with redistribution: keep the footer attribution and `NOTES.md` §9 intact, or
   swap in owned/licensed imagery.
3. **Replace the sample testimonials** with real, consented quotes — or delete the section. Do not
   ship sample quotes without the "Contoh" labelling.
4. **Verify every published tariff against a current source.** The anchors are 2024-data figures
   surfaced in 2026 guides. Refresh before anyone plans money around them.
5. **Confirm the SST rate and its applicability** to foreign patients; the row is currently a 6%
   placeholder on a moving policy target.
6. **Replace the assumed FX rate** with a live feed, keeping the field user-editable.
7. **Legal review of the disclaimer** by someone qualified in Indonesian health and consumer law.
   The current wording is a design placeholder, not vetted copy.
8. **Fill or remove the data gaps** — gastroenterology, endocrinology, and the screening lab panel.
9. **Author a print stylesheet.** "Unduh PDF estimasi" currently calls `window.print()` against the
   screen sheet.
10. **Replace placeholder hospital names** with real partners *and their real quoted prices* — never
    real names against derived prices.

## 8. External-link risk

| Link | Risk |
|---|---|
| `https://wa.me/?text=…` | Low. Opens WhatsApp with a prefilled summary in a new tab with `noopener`. The summary carries the "bukan penawaran resmi maupun nasihat medis" disclaimer. Note that the estimate text leaves the app at this point — if real patient data were ever put into the case fields, this becomes a data-egress path and needs a consent step. |
| `assets/fonts/*.woff2` | None. Self-hosted, OFL. |
| Nav links `#` on Masuk | Dead links by design (no auth in the prototype). Acceptable in a prototype; remove or wire before release. |

## 9. Accessibility spot-checks

Not a full audit. Verified: `lang="id"` on every page; single `<h1>` per page; `aria-pressed` on all
toggle chips; `aria-current="page"` on the active nav item; `aria-label` on every unlabelled select
and icon button; `:focus-visible` ring bound to the accent token; 44px minimum control height;
`aria-expanded` on the collapsible group headers; body text never below 13px and never below 16px
for primary content on mobile.

**Known gaps:** the ledger tables have no `<caption>`; the group disclosure buttons do not use
`aria-controls`; colour-contrast ratios were not measured instrumentally — the semantic tokens are
paired with icons and text labels precisely so colour is never the sole carrier of meaning, but the
`--muted-light` (#bcb0a9) tertiary text on white is likely below AA and should be measured before
release.
