{"data":{"skill":{"slug":"agentsecops-analysis-tshark","name":"analysis-tshark","icon":"📦","repo":"https://github.com/AgentSecOps/SecOpsAgentKit/tree/main/skills/offsec/analysis-tshark","status":"approved","author":"AgentSecOps","authorVersion":"0.1.0","skillstoreRevision":2},"audit":{"id":"81f2a8d1-2946-424c-afe1-4904ad739023","skill_id":"c87338c5-c834-40fe-9a1b-f71b8d48f252","version":9,"content_hash":"v3:9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2:a15da51d3a7d9bb75ade1c16d712c14d476c77786b43ef61c157ed837b24473b:64fddcc9ac26ba0028bf68183d39850673c0c7659b2a3a57b98a65b58c700dc5:736b696c6c732f6167656e747365636f70732f616e616c797369732d74736861726b:f8690380404b1c4d21ab8398f2bd0098","risk_level":"critical","is_blocked":true,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"blocked","manual_install_policy":"allowed_with_warning","summary":"Most static alerts are false positives caused by Markdown formatting, defensive examples, offline packet filters, and framework terminology. Confirmed risks include remote pipe-to-shell installation, mutable third-party token exposure, privileged packet capture, and TLS key handling. Credential extraction and packet-metadata email alerts add sensitive-data exposure.","remediation":[{"issue":"The CI template pipes a remote script from a mutable branch directly to bash.","severity":"critical","suggestion":"Pin tfsec to a reviewed release, download it separately, verify its checksum or signature, and execute only after validation."},{"issue":"A mutable third-party action receives GITHUB_TOKEN.","severity":"high","suggestion":"Pin the action to a reviewed commit SHA and reduce job permissions to the minimum required for the scan."},{"issue":"Many live-capture examples run the full TShark process with sudo.","severity":"high","suggestion":"Require confirmation before live capture and prefer narrowly scoped dumpcap permissions or capabilities over running TShark as root."},{"issue":"Credential, POST-body, NTLM, TLS-key, and private-key workflows handle highly sensitive data.","severity":"high","suggestion":"Add mandatory redaction, encrypted storage, access logging, retention limits, and secure deletion steps beside every extraction workflow."},{"issue":"The monitoring script emails packet-derived metadata.","severity":"medium","suggestion":"Require an approved internal destination, minimize alert fields, protect mail transport, and prevent raw credentials or payloads from entering messages."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"assets/ci-config-template.yml","line_end":298,"line_start":298},{"file":"assets/ci-config-template.yml","line_end":301,"line_start":301},{"file":"assets/ci-config-template.yml","line_end":304,"line_start":304},{"file":"assets/ci-config-template.yml","line_end":307,"line_start":307},{"file":"assets/ci-config-template.yml","line_end":310,"line_start":310},{"file":"assets/ci-config-template.yml","line_end":134,"line_start":134},{"file":"assets/ci-config-template.yml","line_end":250,"line_start":250},{"file":"assets/ci-config-template.yml","line_end":291,"line_start":291},{"file":"SKILL.md","line_end":51,"line_start":36},{"file":"SKILL.md","line_end":82,"line_start":51},{"file":"SKILL.md","line_end":98,"line_start":82},{"file":"SKILL.md","line_end":111,"line_start":98},{"file":"SKILL.md","line_end":126,"line_start":111},{"file":"SKILL.md","line_end":129,"line_start":126},{"file":"SKILL.md","line_end":130,"line_start":129},{"file":"SKILL.md","line_end":131,"line_start":130},{"file":"SKILL.md","line_end":132,"line_start":131},{"file":"SKILL.md","line_end":133,"line_start":132},{"file":"SKILL.md","line_end":139,"line_start":133},{"file":"SKILL.md","line_end":157,"line_start":139},{"file":"SKILL.md","line_end":160,"line_start":157},{"file":"SKILL.md","line_end":161,"line_start":160},{"file":"SKILL.md","line_end":162,"line_start":161},{"file":"SKILL.md","line_end":163,"line_start":162},{"file":"SKILL.md","line_end":164,"line_start":163},{"file":"SKILL.md","line_end":165,"line_start":164},{"file":"SKILL.md","line_end":171,"line_start":165},{"file":"SKILL.md","line_end":189,"line_start":171},{"file":"SKILL.md","line_end":193,"line_start":189},{"file":"SKILL.md","line_end":208,"line_start":193},{"file":"SKILL.md","line_end":216,"line_start":208},{"file":"SKILL.md","line_end":228,"line_start":216},{"file":"SKILL.md","line_end":232,"line_start":228},{"file":"SKILL.md","line_end":244,"line_start":232},{"file":"SKILL.md","line_end":248,"line_start":244},{"file":"SKILL.md","line_end":260,"line_start":248},{"file":"SKILL.md","line_end":264,"line_start":260},{"file":"SKILL.md","line_end":273,"line_start":264},{"file":"SKILL.md","line_end":281,"line_start":273},{"file":"SKILL.md","line_end":287,"line_start":281},{"file":"SKILL.md","line_end":291,"line_start":287},{"file":"SKILL.md","line_end":297,"line_start":291},{"file":"SKILL.md","line_end":301,"line_start":297},{"file":"SKILL.md","line_end":307,"line_start":301},{"file":"SKILL.md","line_end":311,"line_start":307},{"file":"SKILL.md","line_end":320,"line_start":311},{"file":"SKILL.md","line_end":326,"line_start":320},{"file":"SKILL.md","line_end":338,"line_start":326},{"file":"SKILL.md","line_end":342,"line_start":338},{"file":"SKILL.md","line_end":348,"line_start":342}]},{"factor":"network","evidence":[{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240},{"file":"assets/rule-template.yaml","line_end":43,"line_start":43},{"file":"assets/rule-template.yaml","line_end":44,"line_start":44},{"file":"assets/rule-template.yaml","line_end":45,"line_start":45},{"file":"assets/rule-template.yaml","line_end":73,"line_start":73},{"file":"assets/rule-template.yaml","line_end":118,"line_start":118},{"file":"assets/rule-template.yaml","line_end":119,"line_start":119},{"file":"assets/rule-template.yaml","line_end":151,"line_start":151},{"file":"assets/rule-template.yaml","line_end":191,"line_start":191},{"file":"assets/rule-template.yaml","line_end":192,"line_start":192},{"file":"assets/rule-template.yaml","line_end":193,"line_start":193},{"file":"assets/rule-template.yaml","line_end":217,"line_start":217},{"file":"assets/rule-template.yaml","line_end":260,"line_start":260},{"file":"assets/rule-template.yaml","line_end":261,"line_start":261},{"file":"assets/rule-template.yaml","line_end":288,"line_start":288},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":173,"line_start":173},{"file":"SKILL.md","line_end":195,"line_start":195},{"file":"SKILL.md","line_end":218,"line_start":218},{"file":"SKILL.md","line_end":365,"line_start":365},{"file":"SKILL.md","line_end":470,"line_start":470},{"file":"SKILL.md","line_end":480,"line_start":480},{"file":"SKILL.md","line_end":483,"line_start":483},{"file":"SKILL.md","line_end":535,"line_start":535},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":634,"line_start":634},{"file":"SKILL.md","line_end":635,"line_start":635},{"file":"SKILL.md","line_end":636,"line_start":636},{"file":"SKILL.md","line_end":637,"line_start":637},{"file":"SKILL.md","line_end":638,"line_start":638},{"file":"SKILL.md","line_end":144,"line_start":144},{"file":"SKILL.md","line_end":147,"line_start":147},{"file":"SKILL.md","line_end":611,"line_start":611},{"file":"SKILL.md","line_end":312,"line_start":312},{"file":"SKILL.md","line_end":313,"line_start":313}]},{"factor":"filesystem","evidence":[{"file":"assets/ci-config-template.yml","line_end":323,"line_start":323},{"file":"assets/ci-config-template.yml","line_end":323,"line_start":323}]},{"factor":"env_access","evidence":[{"file":"assets/ci-config-template.yml","line_end":164,"line_start":164},{"file":"assets/rule-template.yaml","line_end":148,"line_start":148},{"file":"assets/rule-template.yaml","line_end":148,"line_start":148},{"file":"assets/rule-template.yaml","line_end":147,"line_start":147},{"file":"assets/rule-template.yaml","line_end":162,"line_start":162},{"file":"assets/rule-template.yaml","line_end":132,"line_start":132},{"file":"assets/rule-template.yaml","line_end":147,"line_start":147},{"file":"assets/rule-template.yaml","line_end":148,"line_start":148},{"file":"assets/rule-template.yaml","line_end":156,"line_start":156},{"file":"assets/rule-template.yaml","line_end":157,"line_start":157},{"file":"assets/rule-template.yaml","line_end":162,"line_start":162},{"file":"assets/rule-template.yaml","line_end":163,"line_start":163},{"file":"assets/rule-template.yaml","line_end":164,"line_start":164},{"file":"assets/rule-template.yaml","line_end":165,"line_start":165},{"file":"references/EXAMPLE.md","line_end":423,"line_start":423},{"file":"references/EXAMPLE.md","line_end":423,"line_start":423},{"file":"references/EXAMPLE.md","line_end":424,"line_start":424},{"file":"references/EXAMPLE.md","line_end":425,"line_start":425},{"file":"references/EXAMPLE.md","line_end":427,"line_start":427},{"file":"references/EXAMPLE.md","line_end":430,"line_start":430},{"file":"references/EXAMPLE.md","line_end":432,"line_start":432},{"file":"references/EXAMPLE.md","line_end":437,"line_start":437},{"file":"references/EXAMPLE.md","line_end":444,"line_start":444}]},{"factor":"scripts","evidence":[{"file":"references/EXAMPLE.md","line_end":138,"line_start":138},{"file":"references/EXAMPLE.md","line_end":137,"line_start":137}]}],"critical_findings":[{"title":"Pipe to shell pattern","locations":[{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240}],"confidence":0.99,"description":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","review_kind":"security","source_category":"blocker","source_severity":"critical","confidence_reasoning":"The CI template downloads a script from a mutable upstream branch and pipes it directly to bash. A compromised repository or changed script would gain code execution in the CI runner."}],"high_findings":[{"title":"Hardcoded URL","locations":[{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240}],"confidence":0.99,"description":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This URL retrieves executable installation code from a mutable upstream branch. The network dependency directly supports the unsafe pipe-to-shell command on the same line."},{"title":"Git platform tokens","locations":[{"file":"assets/ci-config-template.yml","line_end":164,"line_start":164}],"confidence":0.92,"description":"GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The workflow exposes GITHUB_TOKEN to a third-party action referenced by a mutable version tag. Compromise of that action could disclose or misuse the job token within its granted permissions."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":38,"line_start":38}],"confidence":0.96,"description":"sudo tshark -i eth0","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":41,"line_start":41}],"confidence":0.96,"description":"sudo tshark -i eth0 -c 100 -w capture.pcap","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":87,"line_start":87}],"confidence":0.96,"description":"sudo tshark -D","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":90,"line_start":90}],"confidence":0.96,"description":"sudo tshark -i eth0","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":91,"line_start":91}],"confidence":0.96,"description":"sudo tshark -i wlan0","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":94,"line_start":94}],"confidence":0.96,"description":"sudo tshark -i any","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":97,"line_start":97}],"confidence":0.96,"description":"sudo tshark -i eth0 -i wlan0","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":113,"line_start":113}],"confidence":0.96,"description":"sudo tshark -i eth0","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":116,"line_start":116}],"confidence":0.96,"description":"sudo tshark -i eth0 -c 1000","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":119,"line_start":119}],"confidence":0.96,"description":"sudo tshark -i eth0 -a duration:60","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":122,"line_start":122}],"confidence":0.96,"description":"sudo tshark -i eth0 -w capture.pcap","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":125,"line_start":125}],"confidence":0.96,"description":"sudo tshark -i eth0 -w capture.pcap -b filesize:100000 -b files:5","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":141,"line_start":141}],"confidence":0.96,"description":"sudo tshark -i eth0 -f \"tcp port 80\"","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":144,"line_start":144}],"confidence":0.96,"description":"sudo tshark -i eth0 -f \"host 192.168.1.100\"","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":147,"line_start":147}],"confidence":0.96,"description":"sudo tshark -i eth0 -f \"net 192.168.1.0/24\"","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":150,"line_start":150}],"confidence":0.96,"description":"sudo tshark -i eth0 -f \"tcp port 80 or tcp port 443\"","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":153,"line_start":153}],"confidence":0.96,"description":"sudo tshark -i eth0 -f \"not port 22\"","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":156,"line_start":156}],"confidence":0.96,"description":"sudo tshark -i eth0 -f \"tcp[tcpflags] & tcp-syn != 0\"","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":441,"line_start":441}],"confidence":0.96,"description":"sudo tshark -i eth0 -w incident_$(date +%Y%m%d_%H%M%S).pcap -a duration:300","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":458,"line_start":458}],"confidence":0.96,"description":"sudo tshark -i eth0 -w malware_traffic.pcap","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":477,"line_start":477}],"confidence":0.96,"description":"sudo tshark -i eth0 -Y \"(http.authorization or ftp or pop or imap) and not tls\" -T fields -e ip.src ","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":509,"line_start":509}],"confidence":0.96,"description":"sudo tshark -i mon0 -w wireless_capture.pcap","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":550,"line_start":550}],"confidence":0.96,"description":"sudo tshark -i $INTERFACE -Y \"$ALERT_FILTER\" -T fields -e frame.time -e ip.src -e ip.dst -e http.hos","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":565,"line_start":565}],"confidence":0.96,"description":"sudo tshark -i eth0","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":568,"line_start":568}],"confidence":0.98,"description":"sudo usermod -a -G wireshark $USER","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command uses sudo to persistently add the current user to the wireshark group. That expands packet-capture access beyond the current session and requires explicit administrator approval."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":569,"line_start":569}],"confidence":0.99,"description":"sudo setcap cap_net_raw,cap_net_admin+eip /usr/bin/tshark","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This command uses sudo to grant TShark raw-network and network-administration capabilities. Those persistent capabilities permit sensitive packet capture without future sudo prompts."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":582,"line_start":582}],"confidence":0.96,"description":"sudo tshark -D","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":594,"line_start":594}],"confidence":0.96,"description":"sudo tshark -i eth0 -f \"not port 22\" -w capture.pcap","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":597,"line_start":597}],"confidence":0.96,"description":"sudo tshark -i eth0 -w capture.pcap -b filesize:100000 -b files:5","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"sudo privilege escalation","locations":[{"file":"SKILL.md","line_end":600,"line_start":600}],"confidence":0.96,"description":"sudo tshark -i eth0 -s 128 -w capture.pcap","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk."},{"title":"Certificate/key files","locations":[{"file":"SKILL.md","line_end":608,"line_start":608}],"confidence":0.98,"description":"tshark -r capture.pcap -o tls.keylog_file:sslkeys.log -Y \"http\"","review_kind":"security","source_category":"sensitive","source_severity":"high","confidence_reasoning":"The command consumes a TLS key-log file to decrypt captured traffic. Key-log files contain session secrets and require strict access, retention, and deletion controls."},{"title":"Certificate/key files","locations":[{"file":"SKILL.md","line_end":611,"line_start":611}],"confidence":0.98,"description":"tshark -r capture.pcap -o tls.keys_list:192.168.1.100,443,http,/path/to/server.key","review_kind":"security","source_category":"sensitive","source_severity":"high","confidence_reasoning":"The command directs TShark to read a server private-key file for traffic decryption. Private-key access is highly sensitive and can expose protected sessions if mishandled."},{"title":"Credential and Authentication Artifact Extraction","locations":[{"file":"SKILL.md","line_end":320,"line_start":275},{"file":"SKILL.md","line_end":487,"line_start":473}],"confidence":0.99,"description":"The guide instructs users to extract plaintext credentials, NTLM responses, HTTP POST bodies, and authentication data from captures. These dual-use workflows can expose reusable secrets and personal data if authorization or storage controls fail.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The cited sections explicitly provide commands for credential extraction and writing POST data or NTLM responses to local files."}],"medium_findings":[{"title":"Packet Metadata Disclosure Through Email Alerts","locations":[{"file":"SKILL.md","line_end":555,"line_start":550}],"confidence":0.94,"description":"The monitoring example emails packet-derived source, destination, host, and DNS data to a configured mailbox. This can disclose monitored network metadata through an external mail path.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The script pipes each TShark alert line into the mail command, and the selected fields include internal addresses, HTTP hosts, and DNS names."}],"low_findings":[],"dangerous_patterns":[{"title":"Pipe to shell pattern","locations":[{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240}],"confidence":0.99,"description":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","review_kind":"security","source_category":"blocker","source_severity":"critical","confidence_reasoning":"The CI template downloads a script from a mutable upstream branch and pipes it directly to bash. A compromised repository or changed script would gain code execution in the CI runner."}],"files_scanned":6,"total_lines":2168,"audit_model":"codex","audited_at":"2026-07-23T04:53:57.965+00:00","created_at":"2026-07-24T04:00:03.115863+00:00","static_findings":[{"id":"external_commands:assets/ci-config-template.yml:298:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `sast-results`","category":"external_commands","line_end":298,"severity":"medium","line_start":298},{"id":"external_commands:assets/ci-config-template.yml:301:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `dependency-scan-results`","category":"external_commands","line_end":301,"severity":"medium","line_start":301},{"id":"external_commands:assets/ci-config-template.yml:304:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `secrets-scan-results`","category":"external_commands","line_end":304,"severity":"medium","line_start":304},{"id":"external_commands:assets/ci-config-template.yml:307:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `container-scan-results`","category":"external_commands","line_end":307,"severity":"medium","line_start":307},{"id":"external_commands:assets/ci-config-template.yml:310:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `iac-scan-results`","category":"external_commands","line_end":310,"severity":"medium","line_start":310},{"id":"external_commands:assets/ci-config-template.yml:134:shell-command-substitution","file":"assets/ci-config-template.yml","pattern":"Shell command substitution","snippet":"critical_count=$(python3 -c \"import json; data=json.load(open('${{ env.REPORT_DIR }}/safety-results.","category":"external_commands","line_end":134,"severity":"medium","line_start":134},{"id":"external_commands:assets/ci-config-template.yml:250:shell-command-substitution","file":"assets/ci-config-template.yml","pattern":"Shell command substitution","snippet":"critical_count=$(python3 -c \"import json; data=json.load(open('${{ env.REPORT_DIR }}/checkov-results","category":"external_commands","line_end":250,"severity":"medium","line_start":250},{"id":"external_commands:assets/ci-config-template.yml:291:shell-command-substitution","file":"assets/ci-config-template.yml","pattern":"Shell command substitution","snippet":"**Scan Date**: $(date -u +\"%Y-%m-%d %H:%M:%S UTC\")","category":"external_commands","line_end":291,"severity":"medium","line_start":291},{"id":"network:assets/ci-config-template.yml:240:hardcoded-url","file":"assets/ci-config-template.yml","pattern":"Hardcoded URL","snippet":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","category":"network","line_end":240,"severity":"low","line_start":240},{"id":"filesystem:assets/ci-config-template.yml:323:node-js-fs-operations","file":"assets/ci-config-template.yml","pattern":"Node.js fs operations","snippet":"const report = fs.readFileSync('consolidated-report/security-summary.md', 'utf8');","category":"filesystem","line_end":323,"severity":"medium","line_start":323},{"id":"filesystem:assets/ci-config-template.yml:323:synchronous-file-operations","file":"assets/ci-config-template.yml","pattern":"Synchronous file operations","snippet":"const report = fs.readFileSync('consolidated-report/security-summary.md', 'utf8');","category":"filesystem","line_end":323,"severity":"medium","line_start":323},{"id":"env_access:assets/ci-config-template.yml:164:git-platform-tokens","file":"assets/ci-config-template.yml","pattern":"Git platform tokens","snippet":"GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}","category":"env_access","line_end":164,"severity":"high","line_start":164},{"id":"blocker:assets/ci-config-template.yml:240:pipe-to-shell-pattern","file":"assets/ci-config-template.yml","pattern":"Pipe to shell pattern","snippet":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","category":"blocker","line_end":240,"severity":"critical","line_start":240},{"id":"network:assets/rule-template.yaml:43:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-community/attacks/SQL_Injection\"","category":"network","line_end":43,"severity":"low","line_start":43},{"id":"network:assets/rule-template.yaml:44:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/89.html\"","category":"network","line_end":44,"severity":"low","line_start":44},{"id":"network:assets/rule-template.yaml:45:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html\"","category":"network","line_end":45,"severity":"low","line_start":45},{"id":"network:assets/rule-template.yaml:73:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://owasp.org/www-community/attacks/SQL_Injection","category":"network","line_end":73,"severity":"low","line_start":73},{"id":"network:assets/rule-template.yaml:118:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/798.html\"","category":"network","line_end":118,"severity":"low","line_start":118},{"id":"network:assets/rule-template.yaml:119:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-community/vulnerabilities/Use_of_hard-coded_password\"","category":"network","line_end":119,"severity":"low","line_start":119},{"id":"network:assets/rule-template.yaml:151:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://cwe.mitre.org/data/definitions/798.html","category":"network","line_end":151,"severity":"low","line_start":151},{"id":"network:assets/rule-template.yaml:191:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-community/attacks/xss/\"","category":"network","line_end":191,"severity":"low","line_start":191},{"id":"network:assets/rule-template.yaml:192:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/79.html\"","category":"network","line_end":192,"severity":"low","line_start":192},{"id":"network:assets/rule-template.yaml:193:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html\"","category":"network","line_end":193,"severity":"low","line_start":193},{"id":"network:assets/rule-template.yaml:217:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://owasp.org/www-community/attacks/xss/","category":"network","line_end":217,"severity":"low","line_start":217},{"id":"network:assets/rule-template.yaml:260:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/327.html\"","category":"network","line_end":260,"severity":"low","line_start":260},{"id":"network:assets/rule-template.yaml:261:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testin","category":"network","line_end":261,"severity":"low","line_start":261},{"id":"network:assets/rule-template.yaml:288:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://cwe.mitre.org/data/definitions/327.html","category":"network","line_end":288,"severity":"low","line_start":288},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-access-dot-notation","file":"assets/rule-template.yaml","pattern":"Environment variable access (dot notation)","snippet":"- Node.js: process.env.API_KEY","category":"env_access","line_end":148,"severity":"low","line_start":148},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-object","file":"assets/rule-template.yaml","pattern":"Environment variable object","snippet":"- Node.js: process.env.API_KEY","category":"env_access","line_end":148,"severity":"low","line_start":148},{"id":"env_access:assets/rule-template.yaml:147:python-environment-access","file":"assets/rule-template.yaml","pattern":"Python environment access","snippet":"- Python: os.environ.get('API_KEY')","category":"env_access","line_end":147,"severity":"low","line_start":147},{"id":"env_access:assets/rule-template.yaml:162:python-environment-access","file":"assets/rule-template.yaml","pattern":"Python environment access","snippet":"api_key = os.environ.get('API_KEY')","category":"env_access","line_end":162,"severity":"low","line_start":162},{"id":"env_access:assets/rule-template.yaml:132:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api_key = \"...\"","category":"env_access","line_end":132,"severity":"high","line_start":132},{"id":"env_access:assets/rule-template.yaml:147:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"- Python: os.environ.get('API_KEY')","category":"env_access","line_end":147,"severity":"high","line_start":147},{"id":"env_access:assets/rule-template.yaml:148:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"- Node.js: process.env.API_KEY","category":"env_access","line_end":148,"severity":"high","line_start":148},{"id":"env_access:assets/rule-template.yaml:156:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api_key = \"sk-1234567890abcdef\"","category":"env_access","line_end":156,"severity":"high","line_start":156},{"id":"env_access:assets/rule-template.yaml:157:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api.authenticate(api_key)","category":"env_access","line_end":157,"severity":"high","line_start":157},{"id":"env_access:assets/rule-template.yaml:162:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api_key = os.environ.get('API_KEY')","category":"env_access","line_end":162,"severity":"high","line_start":162},{"id":"env_access:assets/rule-template.yaml:163:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"if not api_key:","category":"env_access","line_end":163,"severity":"high","line_start":163},{"id":"env_access:assets/rule-template.yaml:164:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"raise ValueError(\"API_KEY environment variable not set\")","category":"env_access","line_end":164,"severity":"high","line_start":164},{"id":"env_access:assets/rule-template.yaml:165:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api.authenticate(api_key)","category":"env_access","line_end":165,"severity":"high","line_start":165},{"id":"sensitive:assets/rule-template.yaml:148:environment-file-access","file":"assets/rule-template.yaml","pattern":"Environment file access","snippet":"- Node.js: process.env.API_KEY","category":"sensitive","line_end":148,"severity":"high","line_start":148},{"id":"blocker:assets/rule-template.yaml:70:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"- Python: cursor.execute(\"SELECT * FROM users WHERE id = ?\", (user_id,))","category":"blocker","line_end":70,"severity":"low","line_start":70},{"id":"blocker:assets/rule-template.yaml:71:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"- JavaScript: db.query(\"SELECT * FROM users WHERE id = $1\", [userId])","category":"blocker","line_end":71,"severity":"low","line_start":71},{"id":"blocker:assets/rule-template.yaml:83:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"user_id = request.GET['id']","category":"blocker","line_end":83,"severity":"low","line_start":83},{"id":"blocker:assets/rule-template.yaml:84:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = \" + user_id","category":"blocker","line_end":84,"severity":"low","line_start":84},{"id":"blocker:assets/rule-template.yaml:89:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"user_id = request.GET['id']","category":"blocker","line_end":89,"severity":"low","line_start":89},{"id":"blocker:assets/rule-template.yaml:90:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = ?\"","category":"blocker","line_end":90,"severity":"low","line_start":90},{"id":"scripts:references/EXAMPLE.md:138:document-write-injection","file":"references/EXAMPLE.md","pattern":"document.write injection","snippet":"document.write(userInput);","category":"scripts","line_end":138,"severity":"high","line_start":138},{"id":"scripts:references/EXAMPLE.md:137:innerhtml-assignment-xss-risk","file":"references/EXAMPLE.md","pattern":"innerHTML assignment (XSS risk)","snippet":"element.innerHTML = userInput;","category":"scripts","line_end":137,"severity":"medium","line_start":137},{"id":"env_access:references/EXAMPLE.md:423:python-environment-access","file":"references/EXAMPLE.md","pattern":"Python environment access","snippet":"VALID_API_KEY = os.environ.get('API_KEY')","category":"env_access","line_end":423,"severity":"low","line_start":423},{"id":"env_access:references/EXAMPLE.md:423:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"VALID_API_KEY = os.environ.get('API_KEY')","category":"env_access","line_end":423,"severity":"high","line_start":423},{"id":"env_access:references/EXAMPLE.md:424:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"if not VALID_API_KEY:","category":"env_access","line_end":424,"severity":"high","line_start":424},{"id":"env_access:references/EXAMPLE.md:425:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"raise ValueError(\"API_KEY environment variable not set\")","category":"env_access","line_end":425,"severity":"high","line_start":425},{"id":"env_access:references/EXAMPLE.md:427:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"def require_api_key(f):","category":"env_access","line_end":427,"severity":"high","line_start":427},{"id":"env_access:references/EXAMPLE.md:430:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"api_key = request.headers.get('X-API-Key')","category":"env_access","line_end":430,"severity":"high","line_start":430},{"id":"env_access:references/EXAMPLE.md:432:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"if not api_key:","category":"env_access","line_end":432,"severity":"high","line_start":432},{"id":"env_access:references/EXAMPLE.md:437:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"if not hmac.compare_digest(api_key, VALID_API_KEY):","category":"env_access","line_end":437,"severity":"high","line_start":437},{"id":"env_access:references/EXAMPLE.md:444:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"@require_api_key","category":"env_access","line_end":444,"severity":"high","line_start":444},{"id":"blocker:references/EXAMPLE.md:276:c2-keywords","file":"references/EXAMPLE.md","pattern":"C2 keywords","snippet":"- **T1041**: Exfiltration Over C2 Channel","category":"blocker","line_end":276,"severity":"high","line_start":276},{"id":"blocker:references/EXAMPLE.md:97:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = \" + user_id","category":"blocker","line_end":97,"severity":"low","line_start":97},{"id":"blocker:references/EXAMPLE.md:113:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = ?\"","category":"blocker","line_end":113,"severity":"low","line_start":113},{"id":"blocker:references/EXAMPLE.md:242:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"- **T1078**: Valid Accounts","category":"blocker","line_end":242,"severity":"low","line_start":242},{"id":"blocker:references/EXAMPLE.md:298:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"cursor.execute(\"SELECT * FROM users WHERE id = ?\", (user_id,))","category":"blocker","line_end":298,"severity":"low","line_start":298},{"id":"blocker:references/EXAMPLE.md:301:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"cursor.execute(\"SELECT * FROM users WHERE id = %s\", (user_id,))","category":"blocker","line_end":301,"severity":"low","line_start":301},{"id":"blocker:references/EXAMPLE.md:305:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"result = session.execute(text(\"SELECT * FROM users WHERE id = :id\"), {\"id\": user_id})","category":"blocker","line_end":305,"severity":"low","line_start":305},{"id":"blocker:references/EXAMPLE.md:314:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"raise ValueError(\"Invalid user ID format\")","category":"blocker","line_end":314,"severity":"low","line_start":314},{"id":"blocker:references/EXAMPLE.md:438:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"return jsonify({'error': 'Invalid API key'}), 403","category":"blocker","line_end":438,"severity":"low","line_start":438},{"id":"blocker:references/EXAMPLE.md:471:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"is_valid = verify_password(\"user_password\", stored_hash)  # True","category":"blocker","line_end":471,"severity":"low","line_start":471},{"id":"blocker:references/EXAMPLE.md:523:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"raise ValueError(\"Invalid file type\")","category":"blocker","line_end":523,"severity":"low","line_start":523},{"id":"blocker:references/EXAMPLE.md:529:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"import uuid","category":"blocker","line_end":530,"severity":"low","line_start":529},{"id":"blocker:references/EXAMPLE.md:381:network-reconnaissance","file":"references/EXAMPLE.md","pattern":"Network reconnaissance","snippet":"- xss","category":"blocker","line_end":382,"severity":"low","line_start":381},{"id":"blocker:references/WORKFLOW_CHECKLIST.md:193:malware-type-keywords","file":"references/WORKFLOW_CHECKLIST.md","pattern":"Malware type keywords","snippet":"[ ] 10. Remove malicious artifacts (malware, backdoors, webshells)","category":"blocker","line_end":193,"severity":"high","line_start":193},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":51,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":82,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":98,"severity":"medium","line_start":82},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":111,"severity":"medium","line_start":98},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":126,"severity":"medium","line_start":111},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":129,"severity":"medium","line_start":126},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `-c <count>`: Capture packet count","category":"external_commands","line_end":130,"severity":"medium","line_start":129},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `-a duration:<sec>`: Auto-stop after duration","category":"external_commands","line_end":131,"severity":"medium","line_start":130},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `-w <file>`: Write to file","category":"external_commands","line_end":132,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `-b filesize:<KB>`: Rotate at file size","category":"external_commands","line_end":133,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `-b files:<num>`: Keep N ring buffer files","category":"external_commands","line_end":139,"severity":"medium","line_start":133},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":157,"severity":"medium","line_start":139},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":160,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `host <ip>`: Traffic to/from IP","category":"external_commands","line_end":161,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `net <cidr>`: Traffic to/from network","category":"external_commands","line_end":162,"severity":"medium","line_start":161},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `port <port>`: Specific port","category":"external_commands","line_end":163,"severity":"medium","line_start":162},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `tcp|udp|icmp`: Protocol type","category":"external_commands","line_end":164,"severity":"medium","line_start":163},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `src|dst`: Direction filter","category":"external_commands","line_end":165,"severity":"medium","line_start":164},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `and|or|not`: Logical operators","category":"external_commands","line_end":171,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":189,"severity":"medium","line_start":171},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":193,"severity":"medium","line_start":189},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":208,"severity":"medium","line_start":193},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":216,"severity":"medium","line_start":208},{"id":"external_commands:SKILL.md:216:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":228,"severity":"medium","line_start":216},{"id":"external_commands:SKILL.md:228:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":232,"severity":"medium","line_start":228},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":244,"severity":"medium","line_start":232},{"id":"external_commands:SKILL.md:244:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":248,"severity":"medium","line_start":244},{"id":"external_commands:SKILL.md:248:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":260,"severity":"medium","line_start":248},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":264,"severity":"medium","line_start":260},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":273,"severity":"medium","line_start":264},{"id":"external_commands:SKILL.md:273:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":281,"severity":"medium","line_start":273},{"id":"external_commands:SKILL.md:281:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":287,"severity":"medium","line_start":281},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":291,"severity":"medium","line_start":287},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":297,"severity":"medium","line_start":291},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":301,"severity":"medium","line_start":297},{"id":"external_commands:SKILL.md:301:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":307,"severity":"medium","line_start":301},{"id":"external_commands:SKILL.md:307:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":311,"severity":"medium","line_start":307},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":320,"severity":"medium","line_start":311},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":326,"severity":"medium","line_start":320},{"id":"external_commands:SKILL.md:326:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":338,"severity":"medium","line_start":326},{"id":"external_commands:SKILL.md:338:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":342,"severity":"medium","line_start":338},{"id":"external_commands:SKILL.md:342:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":348,"severity":"medium","line_start":342},{"id":"external_commands:SKILL.md:348:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":354,"severity":"medium","line_start":348},{"id":"external_commands:SKILL.md:354:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":369,"severity":"medium","line_start":354},{"id":"external_commands:SKILL.md:369:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":375,"severity":"medium","line_start":369},{"id":"external_commands:SKILL.md:375:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":396,"severity":"medium","line_start":375},{"id":"external_commands:SKILL.md:396:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":439,"severity":"medium","line_start":396},{"id":"external_commands:SKILL.md:439:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":452,"severity":"medium","line_start":439},{"id":"external_commands:SKILL.md:452:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":456,"severity":"medium","line_start":452},{"id":"external_commands:SKILL.md:456:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":471,"severity":"medium","line_start":456},{"id":"external_commands:SKILL.md:471:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":475,"severity":"medium","line_start":471},{"id":"external_commands:SKILL.md:475:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":487,"severity":"medium","line_start":475},{"id":"external_commands:SKILL.md:487:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":491,"severity":"medium","line_start":487},{"id":"external_commands:SKILL.md:491:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":503,"severity":"medium","line_start":491},{"id":"external_commands:SKILL.md:503:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":507,"severity":"medium","line_start":503},{"id":"external_commands:SKILL.md:507:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":522,"severity":"medium","line_start":507},{"id":"external_commands:SKILL.md:522:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":530,"severity":"medium","line_start":522},{"id":"external_commands:SKILL.md:530:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":539,"severity":"medium","line_start":530},{"id":"external_commands:SKILL.md:539:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":543,"severity":"medium","line_start":539},{"id":"external_commands:SKILL.md:543:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":556,"severity":"medium","line_start":543},{"id":"external_commands:SKILL.md:556:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":563,"severity":"medium","line_start":556},{"id":"external_commands:SKILL.md:563:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":572,"severity":"medium","line_start":563},{"id":"external_commands:SKILL.md:572:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":577,"severity":"medium","line_start":572},{"id":"external_commands:SKILL.md:577:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":587,"severity":"medium","line_start":577},{"id":"external_commands:SKILL.md:587:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":592,"severity":"medium","line_start":587},{"id":"external_commands:SKILL.md:592:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":601,"severity":"medium","line_start":592},{"id":"external_commands:SKILL.md:601:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":606,"severity":"medium","line_start":601},{"id":"external_commands:SKILL.md:606:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":612,"severity":"medium","line_start":606},{"id":"external_commands:SKILL.md:359:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"tshark -r capture.pcap -Y \"dns.qry.name\" -T fields -e dns.qry.name | awk -F'.' '{print $(NF-1)\".\"$NF","category":"external_commands","line_end":359,"severity":"medium","line_start":359},{"id":"external_commands:SKILL.md:441:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"sudo tshark -i eth0 -w incident_$(date +%Y%m%d_%H%M%S).pcap -a duration:300","category":"external_commands","line_end":441,"severity":"medium","line_start":441},{"id":"external_commands:SKILL.md:552:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"echo \"[ALERT] $(date): $line\" | tee -a security_alerts.log","category":"external_commands","line_end":552,"severity":"medium","line_start":552},{"id":"external_commands:SKILL.md:354:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":369,"severity":"medium","line_start":354},{"id":"external_commands:SKILL.md:439:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":452,"severity":"medium","line_start":439},{"id":"external_commands:SKILL.md:543:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":556,"severity":"medium","line_start":543},{"id":"external_commands:SKILL.md:548:windows-cmd-exe","file":"SKILL.md","pattern":"Windows cmd.exe","snippet":"ALERT_FILTER=\"http contains \\\"cmd.exe\\\" or dns.qry.name contains \\\".tk\\\" or dns.qry.name contains \\\"","category":"external_commands","line_end":548,"severity":"high","line_start":548},{"id":"external_commands:SKILL.md:544:unix-shell-invocation","file":"SKILL.md","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":544,"severity":"medium","line_start":544},{"id":"external_commands:SKILL.md:38:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0","category":"external_commands","line_end":38,"severity":"high","line_start":38},{"id":"external_commands:SKILL.md:41:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -c 100 -w capture.pcap","category":"external_commands","line_end":41,"severity":"high","line_start":41},{"id":"external_commands:SKILL.md:87:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -D","category":"external_commands","line_end":87,"severity":"high","line_start":87},{"id":"external_commands:SKILL.md:90:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0","category":"external_commands","line_end":90,"severity":"high","line_start":90},{"id":"external_commands:SKILL.md:91:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i wlan0","category":"external_commands","line_end":91,"severity":"high","line_start":91},{"id":"external_commands:SKILL.md:94:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i any","category":"external_commands","line_end":94,"severity":"high","line_start":94},{"id":"external_commands:SKILL.md:97:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -i wlan0","category":"external_commands","line_end":97,"severity":"high","line_start":97},{"id":"external_commands:SKILL.md:113:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0","category":"external_commands","line_end":113,"severity":"high","line_start":113},{"id":"external_commands:SKILL.md:116:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -c 1000","category":"external_commands","line_end":116,"severity":"high","line_start":116},{"id":"external_commands:SKILL.md:119:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -a duration:60","category":"external_commands","line_end":119,"severity":"high","line_start":119},{"id":"external_commands:SKILL.md:122:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -w capture.pcap","category":"external_commands","line_end":122,"severity":"high","line_start":122},{"id":"external_commands:SKILL.md:125:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -w capture.pcap -b filesize:100000 -b files:5","category":"external_commands","line_end":125,"severity":"high","line_start":125},{"id":"external_commands:SKILL.md:141:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -f \"tcp port 80\"","category":"external_commands","line_end":141,"severity":"high","line_start":141},{"id":"external_commands:SKILL.md:144:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -f \"host 192.168.1.100\"","category":"external_commands","line_end":144,"severity":"high","line_start":144},{"id":"external_commands:SKILL.md:147:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -f \"net 192.168.1.0/24\"","category":"external_commands","line_end":147,"severity":"high","line_start":147},{"id":"external_commands:SKILL.md:150:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -f \"tcp port 80 or tcp port 443\"","category":"external_commands","line_end":150,"severity":"high","line_start":150},{"id":"external_commands:SKILL.md:153:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -f \"not port 22\"","category":"external_commands","line_end":153,"severity":"high","line_start":153},{"id":"external_commands:SKILL.md:156:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -f \"tcp[tcpflags] & tcp-syn != 0\"","category":"external_commands","line_end":156,"severity":"high","line_start":156},{"id":"external_commands:SKILL.md:441:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -w incident_$(date +%Y%m%d_%H%M%S).pcap -a duration:300","category":"external_commands","line_end":441,"severity":"high","line_start":441},{"id":"external_commands:SKILL.md:458:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -w malware_traffic.pcap","category":"external_commands","line_end":458,"severity":"high","line_start":458},{"id":"external_commands:SKILL.md:477:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -Y \"(http.authorization or ftp or pop or imap) and not tls\" -T fields -e ip.src ","category":"external_commands","line_end":477,"severity":"high","line_start":477},{"id":"external_commands:SKILL.md:509:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i mon0 -w wireless_capture.pcap","category":"external_commands","line_end":509,"severity":"high","line_start":509},{"id":"external_commands:SKILL.md:550:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i $INTERFACE -Y \"$ALERT_FILTER\" -T fields -e frame.time -e ip.src -e ip.dst -e http.hos","category":"external_commands","line_end":550,"severity":"high","line_start":550},{"id":"external_commands:SKILL.md:564:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"# Run with sudo","category":"external_commands","line_end":565,"severity":"high","line_start":564},{"id":"external_commands:SKILL.md:565:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0","category":"external_commands","line_end":565,"severity":"high","line_start":565},{"id":"external_commands:SKILL.md:568:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo usermod -a -G wireshark $USER","category":"external_commands","line_end":568,"severity":"high","line_start":568},{"id":"external_commands:SKILL.md:569:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo setcap cap_net_raw,cap_net_admin+eip /usr/bin/tshark","category":"external_commands","line_end":569,"severity":"high","line_start":569},{"id":"external_commands:SKILL.md:581:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"# List interfaces with sudo","category":"external_commands","line_end":582,"severity":"high","line_start":581},{"id":"external_commands:SKILL.md:582:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -D","category":"external_commands","line_end":582,"severity":"high","line_start":582},{"id":"external_commands:SKILL.md:594:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -f \"not port 22\" -w capture.pcap","category":"external_commands","line_end":594,"severity":"high","line_start":594},{"id":"external_commands:SKILL.md:597:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -w capture.pcap -b filesize:100000 -b files:5","category":"external_commands","line_end":597,"severity":"high","line_start":597},{"id":"external_commands:SKILL.md:600:sudo-privilege-escalation","file":"SKILL.md","pattern":"sudo privilege escalation","snippet":"sudo tshark -i eth0 -s 128 -w capture.pcap","category":"external_commands","line_end":600,"severity":"high","line_start":600},{"id":"network:SKILL.md:47:http-https-request","file":"SKILL.md","pattern":"HTTP/HTTPS request","snippet":"tshark -r capture.pcap -Y \"http.request.method == GET\"","category":"network","line_end":47,"severity":"low","line_start":47},{"id":"network:SKILL.md:173:http-https-request","file":"SKILL.md","pattern":"HTTP/HTTPS request","snippet":"tshark -r capture.pcap -Y \"http.request\"","category":"network","line_end":173,"severity":"low","line_start":173},{"id":"network:SKILL.md:195:http-https-request","file":"SKILL.md","pattern":"HTTP/HTTPS request","snippet":"tshark -r capture.pcap -Y \"http.request.method == POST and (http contains \\\"password\\\" or http conta","category":"network","line_end":195,"severity":"low","line_start":195},{"id":"network:SKILL.md:218:http-https-request","file":"SKILL.md","pattern":"HTTP/HTTPS request","snippet":"tshark -r capture.pcap -Y \"http.request\" -T fields -e ip.src -e http.host -e http.request.uri","category":"network","line_end":218,"severity":"low","line_start":218},{"id":"network:SKILL.md:365:http-https-request","file":"SKILL.md","pattern":"HTTP/HTTPS request","snippet":"tshark -r capture.pcap -Y \"http.request.method == POST\" -T fields -e ip.src -e http.content_length |","category":"network","line_end":365,"severity":"low","line_start":365},{"id":"network:SKILL.md:470:http-https-request","file":"SKILL.md","pattern":"HTTP/HTTPS request","snippet":"tshark -r malware_traffic.pcap -Y \"http.request.method == POST\" -T fields -e data.data","category":"network","line_end":470,"severity":"low","line_start":470},{"id":"network:SKILL.md:480:http-https-request","file":"SKILL.md","pattern":"HTTP/HTTPS request","snippet":"tshark -r capture.pcap -Y \"http.request.method == POST\" -T fields -e http.file_data > post_data.txt","category":"network","line_end":480,"severity":"low","line_start":480},{"id":"network:SKILL.md:483:http-https-request","file":"SKILL.md","pattern":"HTTP/HTTPS request","snippet":"tshark -r capture.pcap -Y \"http contains \\\"password\\\" or http contains \\\"passwd\\\"\" -T fields -e ip.s","category":"network","line_end":483,"severity":"low","line_start":483},{"id":"network:SKILL.md:535:http-https-request","file":"SKILL.md","pattern":"HTTP/HTTPS request","snippet":"tshark -r capture.pcap -Y \"http\" -T json -e ip.src -e ip.dst -e http.host -e http.request.uri","category":"network","line_end":535,"severity":"low","line_start":535},{"id":"network:SKILL.md:19:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://www.wireshark.org/docs/man-pages/tshark.html","category":"network","line_end":19,"severity":"low","line_start":19},{"id":"network:SKILL.md:20:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://wiki.wireshark.org/DisplayFilters","category":"network","line_end":20,"severity":"low","line_start":20},{"id":"network:SKILL.md:21:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://attack.mitre.org/techniques/T1040/","category":"network","line_end":21,"severity":"low","line_start":21},{"id":"network:SKILL.md:634:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [TShark Man Page](https://www.wireshark.org/docs/man-pages/tshark.html)","category":"network","line_end":634,"severity":"low","line_start":634},{"id":"network:SKILL.md:635:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Wireshark Display Filters](https://wiki.wireshark.org/DisplayFilters)","category":"network","line_end":635,"severity":"low","line_start":635},{"id":"network:SKILL.md:636:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [MITRE ATT&CK: Network Sniffing](https://attack.mitre.org/techniques/T1040/)","category":"network","line_end":636,"severity":"low","line_start":636},{"id":"network:SKILL.md:637:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [NIST SP 800-92: Guide to Computer Security Log Management](https://csrc.nist.gov/publications/det","category":"network","line_end":637,"severity":"low","line_start":637},{"id":"network:SKILL.md:638:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Practical Packet Analysis Book](https://nostarch.com/packetanalysis3)","category":"network","line_end":638,"severity":"low","line_start":638},{"id":"network:SKILL.md:144:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"sudo tshark -i eth0 -f \"host 192.168.1.100\"","category":"network","line_end":144,"severity":"medium","line_start":144},{"id":"network:SKILL.md:147:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"sudo tshark -i eth0 -f \"net 192.168.1.0/24\"","category":"network","line_end":147,"severity":"medium","line_start":147},{"id":"network:SKILL.md:611:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"tshark -r capture.pcap -o tls.keys_list:192.168.1.100,443,http,/path/to/server.key","category":"network","line_end":611,"severity":"medium","line_start":611},{"id":"network:SKILL.md:312:email-sending-capability","file":"SKILL.md","pattern":"Email sending capability","snippet":"# SMTP authentication","category":"network","line_end":312,"severity":"medium","line_start":312},{"id":"network:SKILL.md:313:email-sending-capability","file":"SKILL.md","pattern":"Email sending capability","snippet":"tshark -r capture.pcap -Y \"smtp.req.command == AUTH\" -T fields -e ip.src","category":"network","line_end":313,"severity":"medium","line_start":313},{"id":"sensitive:SKILL.md:253:certificate-key-files","file":"SKILL.md","pattern":"Certificate/key files","snippet":"tshark -r capture.pcap -Y \"tls.handshake.certificate\" -T fields -e tls.handshake.certificate","category":"sensitive","line_end":253,"severity":"high","line_start":253},{"id":"sensitive:SKILL.md:608:certificate-key-files","file":"SKILL.md","pattern":"Certificate/key files","snippet":"tshark -r capture.pcap -o tls.keylog_file:sslkeys.log -Y \"http\"","category":"sensitive","line_end":608,"severity":"high","line_start":608},{"id":"sensitive:SKILL.md:611:certificate-key-files","file":"SKILL.md","pattern":"Certificate/key files","snippet":"tshark -r capture.pcap -o tls.keys_list:192.168.1.100,443,http,/path/to/server.key","category":"sensitive","line_end":611,"severity":"high","line_start":611},{"id":"blocker:SKILL.md:607:keylogger-keywords","file":"SKILL.md","pattern":"Keylogger keywords","snippet":"# Provide SSL key log file (requires SSLKEYLOGFILE environment variable)","category":"blocker","line_end":607,"severity":"critical","line_start":607},{"id":"blocker:SKILL.md:608:keylogger-keywords","file":"SKILL.md","pattern":"Keylogger keywords","snippet":"tshark -r capture.pcap -o tls.keylog_file:sslkeys.log -Y \"http\"","category":"blocker","line_end":608,"severity":"critical","line_start":608},{"id":"blocker:SKILL.md:355:c2-keywords","file":"SKILL.md","pattern":"C2 keywords","snippet":"# Detect common C2 beaconing patterns","category":"blocker","line_end":355,"severity":"high","line_start":355},{"id":"blocker:SKILL.md:512:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"tshark -r wireless_capture.pcap -Y \"wlan.fc.type_subtype == 0x08\" -T fields -e wlan.ssid -e wlan.bss","category":"blocker","line_end":512,"severity":"low","line_start":512},{"id":"blocker:SKILL.md:521:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"tshark -r wireless_capture.pcap -Y \"wlan.fc.type_subtype == 0x04\" -T fields -e wlan.sa -e wlan.ssid","category":"blocker","line_end":522,"severity":"low","line_start":521},{"id":"blocker:SKILL.md:586:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"ifconfig -a","category":"blocker","line_end":586,"severity":"low","line_start":586}],"finding_verdicts":[{"id":"external_commands:assets/ci-config-template.yml:298:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting around an artifact name inside generated report text. They do not invoke Ruby or a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/ci-config-template.yml:301:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting around an artifact name inside generated report text. They do not invoke Ruby or a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/ci-config-template.yml:304:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting around an artifact name inside generated report text. They do not invoke Ruby or a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/ci-config-template.yml:307:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting around an artifact name inside generated report text. They do not invoke Ruby or a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/ci-config-template.yml:310:ruby-shell-backtick-execution","reason":"The backticks are Markdown formatting around an artifact name inside generated report text. They do not invoke Ruby or a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/ci-config-template.yml:134:shell-command-substitution","reason":"The substitution runs a fixed Python parser against a locally generated scanner result. No untrusted value is evaluated as shell code.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:assets/ci-config-template.yml:250:shell-command-substitution","reason":"The substitution runs a fixed Python parser against a locally generated scanner result. No untrusted value is evaluated as shell code.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:assets/ci-config-template.yml:291:shell-command-substitution","reason":"The date expression appears inside a single-quoted heredoc delimiter, so the shell writes it literally rather than executing it.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/ci-config-template.yml:240:hardcoded-url","reason":"This URL retrieves executable installation code from a mutable upstream branch. The network dependency directly supports the unsafe pipe-to-shell command on the same line.","verdict":"confirmed","severity":"high","confidence":0.99},{"id":"filesystem:assets/ci-config-template.yml:323:node-js-fs-operations","reason":"The GitHub script reads a fixed, locally generated report path before posting it to the current pull request. It does not accept an attacker-controlled filesystem path.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:assets/ci-config-template.yml:323:synchronous-file-operations","reason":"The GitHub script reads a fixed, locally generated report path before posting it to the current pull request. It does not accept an attacker-controlled filesystem path.","verdict":"false_positive","confidence":0.98},{"id":"env_access:assets/ci-config-template.yml:164:git-platform-tokens","reason":"The workflow exposes GITHUB_TOKEN to a third-party action referenced by a mutable version tag. Compromise of that action could disclose or misuse the job token within its granted permissions.","verdict":"confirmed","severity":"high","confidence":0.92},{"id":"blocker:assets/ci-config-template.yml:240:pipe-to-shell-pattern","reason":"The CI template downloads a script from a mutable upstream branch and pipes it directly to bash. A compromised repository or changed script would gain code execution in the CI runner.","verdict":"confirmed","severity":"critical","confidence":0.99},{"id":"network:assets/rule-template.yaml:43:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or an official security guide. The template does not request or execute content from the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:44:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or an official security guide. The template does not request or execute content from the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:45:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or an official security guide. The template does not request or execute content from the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:73:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or an official security guide. The template does not request or execute content from the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:118:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or an official security guide. The template does not request or execute content from the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:119:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or an official security guide. The template does not request or execute content from the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:151:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or an official security guide. The template does not request or execute content from the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:191:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or an official security guide. The template does not request or execute content from the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:192:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or an official security guide. The template does not request or execute content from the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:193:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or an official security guide. The template does not request or execute content from the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:217:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or an official security guide. The template does not request or execute content from the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:260:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or an official security guide. The template does not request or execute content from the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:261:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or an official security guide. The template does not request or execute content from the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:288:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or an official security guide. The template does not request or execute content from the URL.","verdict":"false_positive","confidence":0.99},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-access-dot-notation","reason":"This line is illustrative rule documentation that recommends environment-based secret handling or uses a clearly fake placeholder key. It is not an active credential read or embedded secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-object","reason":"This line is illustrative rule documentation that recommends environment-based secret handling or uses a clearly fake placeholder key. It is not an active credential read or embedded secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:assets/rule-template.yaml:147:python-environment-access","reason":"This line is illustrative rule documentation that recommends environment-based secret handling or uses a clearly fake placeholder key. It is not an active credential read or embedded secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:assets/rule-template.yaml:162:python-environment-access","reason":"This line is illustrative rule documentation that recommends environment-based secret handling or uses a clearly fake placeholder key. It is not an active credential read or embedded secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:assets/rule-template.yaml:132:generic-api-secret-keys","reason":"This line is illustrative rule documentation that recommends environment-based secret handling or uses a clearly fake placeholder key. It is not an active credential read or embedded secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:assets/rule-template.yaml:147:generic-api-secret-keys","reason":"This line is illustrative rule documentation that recommends environment-based secret handling or uses a clearly fake placeholder key. It is not an active credential read or embedded secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:assets/rule-template.yaml:148:generic-api-secret-keys","reason":"This line is illustrative rule documentation that recommends environment-based secret handling or uses a clearly fake placeholder key. It is not an active credential read or embedded secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:assets/rule-template.yaml:156:generic-api-secret-keys","reason":"This line is illustrative rule documentation that recommends environment-based secret handling or uses a clearly fake placeholder key. It is not an active credential read or embedded secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:assets/rule-template.yaml:157:generic-api-secret-keys","reason":"This line is illustrative rule documentation that recommends environment-based secret handling or uses a clearly fake placeholder key. It is not an active credential read or embedded secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:assets/rule-template.yaml:162:generic-api-secret-keys","reason":"This line is illustrative rule documentation that recommends environment-based secret handling or uses a clearly fake placeholder key. It is not an active credential read or embedded secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:assets/rule-template.yaml:163:generic-api-secret-keys","reason":"This line is illustrative rule documentation that recommends environment-based secret handling or uses a clearly fake placeholder key. It is not an active credential read or embedded secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:assets/rule-template.yaml:164:generic-api-secret-keys","reason":"This line is illustrative rule documentation that recommends environment-based secret handling or uses a clearly fake placeholder key. It is not an active credential read or embedded secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:assets/rule-template.yaml:165:generic-api-secret-keys","reason":"This line is illustrative rule documentation that recommends environment-based secret handling or uses a clearly fake placeholder key. It is not an active credential read or embedded secret.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:assets/rule-template.yaml:148:environment-file-access","reason":"This line is illustrative rule documentation that recommends environment-based secret handling or uses a clearly fake placeholder key. It is not an active credential read or embedded secret.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/rule-template.yaml:70:system-reconnaissance","reason":"The matched text is SQL-injection rule documentation showing vulnerable and parameterized queries. It performs no host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/rule-template.yaml:71:system-reconnaissance","reason":"The matched text is SQL-injection rule documentation showing vulnerable and parameterized queries. It performs no host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/rule-template.yaml:83:system-reconnaissance","reason":"The matched text is SQL-injection rule documentation showing vulnerable and parameterized queries. It performs no host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/rule-template.yaml:84:system-reconnaissance","reason":"The matched text is SQL-injection rule documentation showing vulnerable and parameterized queries. It performs no host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/rule-template.yaml:89:system-reconnaissance","reason":"The matched text is SQL-injection rule documentation showing vulnerable and parameterized queries. It performs no host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/rule-template.yaml:90:system-reconnaissance","reason":"The matched text is SQL-injection rule documentation showing vulnerable and parameterized queries. It performs no host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"scripts:references/EXAMPLE.md:138:document-write-injection","reason":"The unsafe DOM statement is explicitly labeled as a vulnerable example and is followed by safe remediation. It is inert Markdown reference content, not shipped application code.","verdict":"false_positive","confidence":0.99},{"id":"scripts:references/EXAMPLE.md:137:innerhtml-assignment-xss-risk","reason":"The unsafe DOM statement is explicitly labeled as a vulnerable example and is followed by safe remediation. It is inert Markdown reference content, not shipped application code.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/EXAMPLE.md:423:python-environment-access","reason":"This is a secure authentication example that reads an API key from the environment and compares it in constant time. It neither embeds nor transmits a real secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/EXAMPLE.md:423:generic-api-secret-keys","reason":"This is a secure authentication example that reads an API key from the environment and compares it in constant time. It neither embeds nor transmits a real secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/EXAMPLE.md:424:generic-api-secret-keys","reason":"This is a secure authentication example that reads an API key from the environment and compares it in constant time. It neither embeds nor transmits a real secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/EXAMPLE.md:425:generic-api-secret-keys","reason":"This is a secure authentication example that reads an API key from the environment and compares it in constant time. It neither embeds nor transmits a real secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/EXAMPLE.md:427:generic-api-secret-keys","reason":"This is a secure authentication example that reads an API key from the environment and compares it in constant time. It neither embeds nor transmits a real secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/EXAMPLE.md:430:generic-api-secret-keys","reason":"This is a secure authentication example that reads an API key from the environment and compares it in constant time. It neither embeds nor transmits a real secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/EXAMPLE.md:432:generic-api-secret-keys","reason":"This is a secure authentication example that reads an API key from the environment and compares it in constant time. It neither embeds nor transmits a real secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/EXAMPLE.md:437:generic-api-secret-keys","reason":"This is a secure authentication example that reads an API key from the environment and compares it in constant time. It neither embeds nor transmits a real secret.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/EXAMPLE.md:444:generic-api-secret-keys","reason":"This is a secure authentication example that reads an API key from the environment and compares it in constant time. It neither embeds nor transmits a real secret.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:276:c2-keywords","reason":"The phrase is a MITRE ATT&CK technique label in a defensive framework mapping. It does not implement command-and-control behavior.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:97:system-reconnaissance","reason":"The matched text belongs to educational secure-coding examples or framework labels. It does not enumerate systems, accounts, or networks.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:113:system-reconnaissance","reason":"The matched text belongs to educational secure-coding examples or framework labels. It does not enumerate systems, accounts, or networks.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:242:system-reconnaissance","reason":"The matched text belongs to educational secure-coding examples or framework labels. It does not enumerate systems, accounts, or networks.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:298:system-reconnaissance","reason":"The matched text belongs to educational secure-coding examples or framework labels. It does not enumerate systems, accounts, or networks.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:301:system-reconnaissance","reason":"The matched text belongs to educational secure-coding examples or framework labels. It does not enumerate systems, accounts, or networks.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:305:system-reconnaissance","reason":"The matched text belongs to educational secure-coding examples or framework labels. It does not enumerate systems, accounts, or networks.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:314:system-reconnaissance","reason":"The matched text belongs to educational secure-coding examples or framework labels. It does not enumerate systems, accounts, or networks.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:438:system-reconnaissance","reason":"The matched text belongs to educational secure-coding examples or framework labels. It does not enumerate systems, accounts, or networks.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:471:system-reconnaissance","reason":"The matched text belongs to educational secure-coding examples or framework labels. It does not enumerate systems, accounts, or networks.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:523:system-reconnaissance","reason":"The matched text belongs to educational secure-coding examples or framework labels. It does not enumerate systems, accounts, or networks.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:529:system-reconnaissance","reason":"The matched text belongs to educational secure-coding examples or framework labels. It does not enumerate systems, accounts, or networks.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:381:network-reconnaissance","reason":"The matched text belongs to educational secure-coding examples or framework labels. It does not enumerate systems, accounts, or networks.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/WORKFLOW_CHECKLIST.md:193:malware-type-keywords","reason":"The incident-response checklist instructs defenders to remove malware, backdoors, and webshells. It does not create, deploy, or conceal malware.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:82:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:98:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:129:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:133:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:163:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:208:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:216:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:228:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:244:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:248:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:273:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:281:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:297:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:301:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:307:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:326:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:338:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:342:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:348:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:354:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:369:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:375:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:396:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:439:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:452:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:456:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:471:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:475:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:487:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:491:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:503:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:507:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:522:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:530:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:539:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:543:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:556:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:563:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:572:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:577:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:587:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:592:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:601:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:606:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown code fences or inline option formatting. They delimit TShark documentation and do not execute shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:359:shell-command-substitution","reason":"The dollar expression is an awk field reference inside single quotes, not shell command substitution. It processes DNS names from a local capture.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:441:shell-command-substitution","reason":"The fixed date command only creates a timestamped capture filename and does not evaluate user-controlled input. The separate sudo finding captures the command's privilege risk.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:552:shell-command-substitution","reason":"The fixed date command adds a timestamp to a local alert message. Packet-derived text is echoed as data and is not evaluated as shell code.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:354:template-literal-with-command-substitution","reason":"The matched line is a Markdown bash code fence, not a JavaScript template literal or executable substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:439:template-literal-with-command-substitution","reason":"The matched line is a Markdown bash code fence, not a JavaScript template literal or executable substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:543:template-literal-with-command-substitution","reason":"The matched line is a Markdown bash code fence, not a JavaScript template literal or executable substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:548:windows-cmd-exe","reason":"The string cmd.exe is a defensive TShark display filter used to detect suspicious HTTP traffic. It does not launch the Windows command processor.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:544:unix-shell-invocation","reason":"This is the shebang of a documented monitoring example with fixed commands. It does not evaluate untrusted input as shell code.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:38:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:41:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:87:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:90:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:91:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:94:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:97:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:113:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:116:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:119:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:122:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:125:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:141:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:144:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:147:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:150:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:153:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:156:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:441:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:458:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:477:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:509:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:550:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:564:sudo-privilege-escalation","reason":"This line is a descriptive Markdown comment about using sudo, not an executable privilege-escalation command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:565:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:568:sudo-privilege-escalation","reason":"This command uses sudo to persistently add the current user to the wireshark group. That expands packet-capture access beyond the current session and requires explicit administrator approval.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"external_commands:SKILL.md:569:sudo-privilege-escalation","reason":"This command uses sudo to grant TShark raw-network and network-administration capabilities. Those persistent capabilities permit sensitive packet capture without future sudo prompts.","verdict":"confirmed","severity":"high","confidence":0.99},{"id":"external_commands:SKILL.md:581:sudo-privilege-escalation","reason":"This line is a descriptive Markdown comment about using sudo, not an executable privilege-escalation command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:582:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:594:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:597:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:SKILL.md:600:sudo-privilege-escalation","reason":"This example runs TShark through sudo, granting privileged packet-capture access to network traffic. The authorization warnings reduce misuse but do not remove the privilege and privacy risk.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"network:SKILL.md:47:http-https-request","reason":"The command reads an existing PCAP and filters packets whose protocol fields describe HTTP. It does not initiate an outbound HTTP request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:173:http-https-request","reason":"The command reads an existing PCAP and filters packets whose protocol fields describe HTTP. It does not initiate an outbound HTTP request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:195:http-https-request","reason":"The command reads an existing PCAP and filters packets whose protocol fields describe HTTP. It does not initiate an outbound HTTP request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:218:http-https-request","reason":"The command reads an existing PCAP and filters packets whose protocol fields describe HTTP. It does not initiate an outbound HTTP request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:365:http-https-request","reason":"The command reads an existing PCAP and filters packets whose protocol fields describe HTTP. It does not initiate an outbound HTTP request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:470:http-https-request","reason":"The command reads an existing PCAP and filters packets whose protocol fields describe HTTP. It does not initiate an outbound HTTP request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:480:http-https-request","reason":"The command reads an existing PCAP and filters packets whose protocol fields describe HTTP. It does not initiate an outbound HTTP request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:483:http-https-request","reason":"The command reads an existing PCAP and filters packets whose protocol fields describe HTTP. It does not initiate an outbound HTTP request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:535:http-https-request","reason":"The command reads an existing PCAP and filters packets whose protocol fields describe HTTP. It does not initiate an outbound HTTP request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:19:hardcoded-url","reason":"This is a visible reference link to Wireshark, MITRE, NIST, or a published packet-analysis resource. No code fetches or executes content from it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:20:hardcoded-url","reason":"This is a visible reference link to Wireshark, MITRE, NIST, or a published packet-analysis resource. No code fetches or executes content from it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:21:hardcoded-url","reason":"This is a visible reference link to Wireshark, MITRE, NIST, or a published packet-analysis resource. No code fetches or executes content from it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:634:hardcoded-url","reason":"This is a visible reference link to Wireshark, MITRE, NIST, or a published packet-analysis resource. No code fetches or executes content from it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:635:hardcoded-url","reason":"This is a visible reference link to Wireshark, MITRE, NIST, or a published packet-analysis resource. No code fetches or executes content from it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:636:hardcoded-url","reason":"This is a visible reference link to Wireshark, MITRE, NIST, or a published packet-analysis resource. No code fetches or executes content from it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:637:hardcoded-url","reason":"This is a visible reference link to Wireshark, MITRE, NIST, or a published packet-analysis resource. No code fetches or executes content from it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:638:hardcoded-url","reason":"This is a visible reference link to Wireshark, MITRE, NIST, or a published packet-analysis resource. No code fetches or executes content from it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:144:hardcoded-ip-address","reason":"The address is an RFC 1918 example used to demonstrate capture filters or TLS analysis. It is not a covert destination or production endpoint.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:147:hardcoded-ip-address","reason":"The address is an RFC 1918 example used to demonstrate capture filters or TLS analysis. It is not a covert destination or production endpoint.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:611:hardcoded-ip-address","reason":"The address is an RFC 1918 example used to demonstrate capture filters or TLS analysis. It is not a covert destination or production endpoint.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:312:email-sending-capability","reason":"This line filters SMTP authentication records from a local packet capture. It analyzes email protocol traffic and does not send email.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:313:email-sending-capability","reason":"This line filters SMTP authentication records from a local packet capture. It analyzes email protocol traffic and does not send email.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:253:certificate-key-files","reason":"This command extracts the public certificate field from a packet capture. It does not access a private key or certificate file.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:SKILL.md:608:certificate-key-files","reason":"The command consumes a TLS key-log file to decrypt captured traffic. Key-log files contain session secrets and require strict access, retention, and deletion controls.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"sensitive:SKILL.md:611:certificate-key-files","reason":"The command directs TShark to read a server private-key file for traffic decryption. Private-key access is highly sensitive and can expose protected sessions if mishandled.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"blocker:SKILL.md:607:keylogger-keywords","reason":"The term key log refers to TLS session-secret logging for authorized decryption, not keystroke capture. The underlying sensitive-key handling is adjudicated separately.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:608:keylogger-keywords","reason":"The term key log refers to TLS session-secret logging for authorized decryption, not keystroke capture. The underlying sensitive-key handling is adjudicated separately.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:355:c2-keywords","reason":"The command detects command-and-control beaconing in captured traffic for malware analysis. It does not establish or operate a C2 channel.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:512:system-reconnaissance","reason":"The command analyzes an authorized wireless capture or lists local interfaces for troubleshooting. It does not scan remote systems or services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:521:system-reconnaissance","reason":"The command analyzes an authorized wireless capture or lists local interfaces for troubleshooting. It does not scan remote systems or services.","verdict":"false_positive","confidence":0.97},{"id":"blocker:SKILL.md:586:network-reconnaissance","reason":"The command analyzes an authorized wireless capture or lists local interfaces for troubleshooting. It does not scan remote systems or services.","verdict":"false_positive","confidence":0.97}],"semantic_findings":[{"title":"Credential and Authentication Artifact Extraction","severity":"high","locations":[{"file":"SKILL.md","line_end":320,"line_start":275},{"file":"SKILL.md","line_end":487,"line_start":473}],"confidence":0.99,"description":"The guide instructs users to extract plaintext credentials, NTLM responses, HTTP POST bodies, and authentication data from captures. These dual-use workflows can expose reusable secrets and personal data if authorization or storage controls fail.","confidence_reasoning":"The cited sections explicitly provide commands for credential extraction and writing POST data or NTLM responses to local files."},{"title":"Packet Metadata Disclosure Through Email Alerts","severity":"medium","locations":[{"file":"SKILL.md","line_end":555,"line_start":550}],"confidence":0.94,"description":"The monitoring example emails packet-derived source, destination, host, and DNS data to a configured mailbox. This can disclose monitored network metadata through an external mail path.","confidence_reasoning":"The script pipes each TShark alert line into the mail command, and the selected fields include internal addresses, HTTP hosts, and DNS names."}],"subject_marketplace_commit_sha":"9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2","subject_content_hash":"a15da51d3a7d9bb75ade1c16d712c14d476c77786b43ef61c157ed837b24473b","subject_tree_hash":"64fddcc9ac26ba0028bf68183d39850673c0c7659b2a3a57b98a65b58c700dc5","subject_plugin_path":"skills/agentsecops/analysis-tshark","audit_payload_hash":"f8690380404b1c4d21ab8398f2bd0098","confirmed_risk_level":"critical","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2","contentHash":"a15da51d3a7d9bb75ade1c16d712c14d476c77786b43ef61c157ed837b24473b","treeHash":"64fddcc9ac26ba0028bf68183d39850673c0c7659b2a3a57b98a65b58c700dc5","pluginPath":"skills/agentsecops/analysis-tshark","auditPayloadHash":"f8690380404b1c4d21ab8398f2bd0098"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/agentsecops-analysis-tshark/audits/9/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"critical","confirmedFindingCount":5,"capabilityReviewCount":32,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"blocked","manualInstallPolicy":"allowed_with_warning","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}