The scan omitted six files the config itself cites, so jsdelivr.net, api.github.com and image.tmdb.org were listed as system-only while no scanned source referenced them; changing those hosts would have fallen through to the base config and its user certificate authorities undetected. Also assert the reverse direction, so a domain no scanned source produces fails instead of silently losing its guard.