{"data":{"skill":{"slug":"agentsecops-api-mitmproxy","name":"api-mitmproxy","icon":"📦","repo":"https://github.com/AgentSecOps/SecOpsAgentKit/tree/main/skills/appsec/api-mitmproxy","status":"approved","author":"AgentSecOps","authorVersion":"0.1.0","skillstoreRevision":2},"audit":{"id":"f78da470-8785-476e-97a7-aad495c66775","skill_id":"f5d1c2c7-c89b-4f97-bc09-e3d0ad7379f6","version":9,"content_hash":"v3:9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2:ea21648bbd8444229d48ebaefcf2fefd63e5662a7c91bc129728b7aa61cbe7bf:efd9417852a4535c32327ef4d4f7dad1517f7e1e201b5c6ce24984f56b5719d6:736b696c6c732f6167656e747365636f70732f6170692d6d69746d70726f7879:3653911491b1702d9ef23c11d7fc2451","risk_level":"critical","is_blocked":true,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"blocked","manual_install_policy":"allowed_with_warning","summary":"Most static alerts are false positives caused by Markdown fences, educational vulnerable-code examples, and documented security references. Confirmed risks include a mutable remote script piped to Bash, third-party token access, unauthenticated all-interface proxy bindings, and destructive certificate reset guidance. Additional concerns are mutable CI action references, authorization token logging, and persistent interception CA trust.","remediation":[{"issue":"Remote installer is piped directly to Bash.","severity":"critical","suggestion":"Download a versioned release, verify its checksum, then execute the local file in a separate step."},{"issue":"Third-party actions use mutable references and receive repository access.","severity":"high","suggestion":"Pin every action to a reviewed commit SHA and move permissions to the smallest job scope."},{"issue":"Proxy examples bind to every network interface.","severity":"medium","suggestion":"Default to loopback and require explicit authentication, firewall restrictions, and authorization before remote binding."},{"issue":"Certificate reset recursively deletes all mitmproxy state.","severity":"high","suggestion":"Back up the directory and delete only generated certificate files after explicit confirmation."},{"issue":"The addon logs part of intercepted authorization tokens.","severity":"medium","suggestion":"Remove token output or replace the complete value with a nonreversible fingerprint."},{"issue":"Trusted interception certificates can remain installed after testing.","severity":"medium","suggestion":"Add cleanup steps for every platform and protect the mitmproxy CA private key throughout testing."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"assets/ci-config-template.yml","line_end":298,"line_start":298},{"file":"assets/ci-config-template.yml","line_end":301,"line_start":301},{"file":"assets/ci-config-template.yml","line_end":304,"line_start":304},{"file":"assets/ci-config-template.yml","line_end":307,"line_start":307},{"file":"assets/ci-config-template.yml","line_end":310,"line_start":310},{"file":"assets/ci-config-template.yml","line_end":134,"line_start":134},{"file":"assets/ci-config-template.yml","line_end":250,"line_start":250},{"file":"assets/ci-config-template.yml","line_end":291,"line_start":291},{"file":"SKILL.md","line_end":52,"line_start":40},{"file":"SKILL.md","line_end":63,"line_start":52},{"file":"SKILL.md","line_end":69,"line_start":63},{"file":"SKILL.md","line_end":100,"line_start":69},{"file":"SKILL.md","line_end":102,"line_start":100},{"file":"SKILL.md","line_end":106,"line_start":102},{"file":"SKILL.md","line_end":112,"line_start":106},{"file":"SKILL.md","line_end":114,"line_start":112},{"file":"SKILL.md","line_end":118,"line_start":114},{"file":"SKILL.md","line_end":124,"line_start":118},{"file":"SKILL.md","line_end":125,"line_start":124},{"file":"SKILL.md","line_end":142,"line_start":125},{"file":"SKILL.md","line_end":144,"line_start":142},{"file":"SKILL.md","line_end":148,"line_start":144},{"file":"SKILL.md","line_end":162,"line_start":148},{"file":"SKILL.md","line_end":164,"line_start":162},{"file":"SKILL.md","line_end":173,"line_start":164},{"file":"SKILL.md","line_end":175,"line_start":173},{"file":"SKILL.md","line_end":179,"line_start":175},{"file":"SKILL.md","line_end":181,"line_start":179},{"file":"SKILL.md","line_end":185,"line_start":181},{"file":"SKILL.md","line_end":187,"line_start":185},{"file":"SKILL.md","line_end":191,"line_start":187},{"file":"SKILL.md","line_end":193,"line_start":191},{"file":"SKILL.md","line_end":207,"line_start":193},{"file":"SKILL.md","line_end":223,"line_start":207},{"file":"SKILL.md","line_end":245,"line_start":223},{"file":"SKILL.md","line_end":251,"line_start":245},{"file":"SKILL.md","line_end":268,"line_start":251},{"file":"SKILL.md","line_end":274,"line_start":268},{"file":"SKILL.md","line_end":295,"line_start":274},{"file":"SKILL.md","line_end":301,"line_start":295},{"file":"SKILL.md","line_end":317,"line_start":301},{"file":"SKILL.md","line_end":320,"line_start":317},{"file":"SKILL.md","line_end":322,"line_start":320},{"file":"SKILL.md","line_end":347,"line_start":322},{"file":"SKILL.md","line_end":360,"line_start":347},{"file":"SKILL.md","line_end":378,"line_start":360},{"file":"SKILL.md","line_end":390,"line_start":378},{"file":"SKILL.md","line_end":396,"line_start":390},{"file":"SKILL.md","line_end":402,"line_start":396},{"file":"SKILL.md","line_end":408,"line_start":402}]},{"factor":"network","evidence":[{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240},{"file":"assets/rule-template.yaml","line_end":43,"line_start":43},{"file":"assets/rule-template.yaml","line_end":44,"line_start":44},{"file":"assets/rule-template.yaml","line_end":45,"line_start":45},{"file":"assets/rule-template.yaml","line_end":73,"line_start":73},{"file":"assets/rule-template.yaml","line_end":118,"line_start":118},{"file":"assets/rule-template.yaml","line_end":119,"line_start":119},{"file":"assets/rule-template.yaml","line_end":151,"line_start":151},{"file":"assets/rule-template.yaml","line_end":191,"line_start":191},{"file":"assets/rule-template.yaml","line_end":192,"line_start":192},{"file":"assets/rule-template.yaml","line_end":193,"line_start":193},{"file":"assets/rule-template.yaml","line_end":217,"line_start":217},{"file":"assets/rule-template.yaml","line_end":260,"line_start":260},{"file":"assets/rule-template.yaml","line_end":261,"line_start":261},{"file":"assets/rule-template.yaml","line_end":288,"line_start":288},{"file":"SKILL.md","line_end":129,"line_start":129},{"file":"SKILL.md","line_end":231,"line_start":231},{"file":"SKILL.md","line_end":256,"line_start":256},{"file":"SKILL.md","line_end":280,"line_start":280},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":163,"line_start":163},{"file":"SKILL.md","line_end":186,"line_start":186},{"file":"SKILL.md","line_end":192,"line_start":192},{"file":"SKILL.md","line_end":202,"line_start":202},{"file":"SKILL.md","line_end":353,"line_start":353},{"file":"SKILL.md","line_end":354,"line_start":354},{"file":"SKILL.md","line_end":481,"line_start":481},{"file":"SKILL.md","line_end":482,"line_start":482},{"file":"SKILL.md","line_end":483,"line_start":483},{"file":"SKILL.md","line_end":484,"line_start":484},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":163,"line_start":163},{"file":"SKILL.md","line_end":443,"line_start":443},{"file":"SKILL.md","line_end":353,"line_start":353},{"file":"SKILL.md","line_end":354,"line_start":354}]},{"factor":"filesystem","evidence":[{"file":"assets/ci-config-template.yml","line_end":323,"line_start":323},{"file":"assets/ci-config-template.yml","line_end":323,"line_start":323},{"file":"SKILL.md","line_end":260,"line_start":260},{"file":"SKILL.md","line_end":207,"line_start":207},{"file":"SKILL.md","line_end":431,"line_start":431},{"file":"SKILL.md","line_end":434,"line_start":434},{"file":"SKILL.md","line_end":207,"line_start":207},{"file":"SKILL.md","line_end":431,"line_start":431},{"file":"SKILL.md","line_end":434,"line_start":434}]},{"factor":"env_access","evidence":[{"file":"assets/ci-config-template.yml","line_end":164,"line_start":164},{"file":"assets/rule-template.yaml","line_end":148,"line_start":148},{"file":"assets/rule-template.yaml","line_end":148,"line_start":148},{"file":"assets/rule-template.yaml","line_end":147,"line_start":147},{"file":"assets/rule-template.yaml","line_end":162,"line_start":162},{"file":"assets/rule-template.yaml","line_end":132,"line_start":132},{"file":"assets/rule-template.yaml","line_end":147,"line_start":147},{"file":"assets/rule-template.yaml","line_end":148,"line_start":148},{"file":"assets/rule-template.yaml","line_end":156,"line_start":156},{"file":"assets/rule-template.yaml","line_end":157,"line_start":157},{"file":"assets/rule-template.yaml","line_end":162,"line_start":162},{"file":"assets/rule-template.yaml","line_end":163,"line_start":163},{"file":"assets/rule-template.yaml","line_end":164,"line_start":164},{"file":"assets/rule-template.yaml","line_end":165,"line_start":165},{"file":"references/EXAMPLE.md","line_end":423,"line_start":423},{"file":"references/EXAMPLE.md","line_end":423,"line_start":423},{"file":"references/EXAMPLE.md","line_end":424,"line_start":424},{"file":"references/EXAMPLE.md","line_end":425,"line_start":425},{"file":"references/EXAMPLE.md","line_end":427,"line_start":427},{"file":"references/EXAMPLE.md","line_end":430,"line_start":430},{"file":"references/EXAMPLE.md","line_end":432,"line_start":432},{"file":"references/EXAMPLE.md","line_end":437,"line_start":437},{"file":"references/EXAMPLE.md","line_end":444,"line_start":444}]},{"factor":"scripts","evidence":[{"file":"references/EXAMPLE.md","line_end":138,"line_start":138},{"file":"references/EXAMPLE.md","line_end":137,"line_start":137}]}],"critical_findings":[{"title":"Pipe to shell pattern","locations":[{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240}],"confidence":0.99,"description":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","review_kind":"security","source_category":"blocker","source_severity":"critical","confidence_reasoning":"The workflow pipes an unverified installer from a mutable GitHub branch directly into Bash. This creates a direct CI supply-chain execution path."},{"title":"Recursive delete on root/home","locations":[{"file":"SKILL.md","line_end":434,"line_start":434}],"confidence":0.96,"description":"rm -rf ~/.mitmproxy/","review_kind":"security","source_category":"blocker","source_severity":"critical","confidence_reasoning":"The troubleshooting command recursively deletes the entire mitmproxy home directory without backup or confirmation. It can destroy custom configuration, certificates, keys, and saved state."}],"high_findings":[{"title":"Git platform tokens","locations":[{"file":"assets/ci-config-template.yml","line_end":164,"line_start":164}],"confidence":0.84,"description":"GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}","review_kind":"capability","source_category":"env_access","source_severity":"high","confidence_reasoning":"The workflow provides GITHUB_TOKEN to a third-party action referenced by a mutable version tag. A compromised action could use the token's repository permissions."},{"title":"Hidden file in home directory","locations":[{"file":"SKILL.md","line_end":434,"line_start":434}],"confidence":0.96,"description":"rm -rf ~/.mitmproxy/","review_kind":"capability","source_category":"filesystem","source_severity":"high","confidence_reasoning":"The troubleshooting command recursively deletes the entire mitmproxy home directory without backup or confirmation. It can destroy custom configuration, certificates, keys, and saved state."},{"title":"Mutable Third-Party CI Actions","locations":[{"file":"assets/ci-config-template.yml","line_end":164,"line_start":161},{"file":"assets/ci-config-template.yml","line_end":199,"line_start":196}],"confidence":0.97,"description":"The CI template executes third-party actions through mutable tags, including @master, while exposing repository data and a GitHub token.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The action references are visibly tag-based, and @master is mutable. GitHub Actions execute code with job workspace and permission access."}],"medium_findings":[{"title":"Hardcoded IP address","locations":[{"file":"SKILL.md","line_end":65,"line_start":65}],"confidence":0.96,"description":"mitmproxy --mode regular --listen-host 0.0.0.0 --listen-port 8080","review_kind":"capability","source_category":"network","source_severity":"medium","confidence_reasoning":"The guidance binds an intercepting proxy to 0.0.0.0 without requiring authentication or firewall restrictions. Other reachable hosts could abuse the proxy or access traffic."},{"title":"Hardcoded IP address","locations":[{"file":"SKILL.md","line_end":68,"line_start":68}],"confidence":0.96,"description":"mitmweb --mode regular --listen-host 0.0.0.0 --listen-port 8080","review_kind":"capability","source_category":"network","source_severity":"medium","confidence_reasoning":"The guidance binds an intercepting proxy to 0.0.0.0 without requiring authentication or firewall restrictions. Other reachable hosts could abuse the proxy or access traffic."},{"title":"Hardcoded IP address","locations":[{"file":"SKILL.md","line_end":163,"line_start":163}],"confidence":0.96,"description":"mitmproxy --mode reverse:https://api.example.com --listen-host 0.0.0.0 --listen-port 443","review_kind":"capability","source_category":"network","source_severity":"medium","confidence_reasoning":"The guidance binds an intercepting proxy to 0.0.0.0 without requiring authentication or firewall restrictions. Other reachable hosts could abuse the proxy or access traffic."},{"title":"Hardcoded IP address","locations":[{"file":"SKILL.md","line_end":443,"line_start":443}],"confidence":0.96,"description":"- Ensure mitmproxy is listening on correct interface (0.0.0.0)","review_kind":"capability","source_category":"network","source_severity":"medium","confidence_reasoning":"The guidance binds an intercepting proxy to 0.0.0.0 without requiring authentication or firewall restrictions. Other reachable hosts could abuse the proxy or access traffic."},{"title":"Hidden file access","locations":[{"file":"SKILL.md","line_end":434,"line_start":434}],"confidence":0.96,"description":"rm -rf ~/.mitmproxy/","review_kind":"capability","source_category":"filesystem","source_severity":"medium","confidence_reasoning":"The troubleshooting command recursively deletes the entire mitmproxy home directory without backup or confirmation. It can destroy custom configuration, certificates, keys, and saved state."},{"title":"Authorization Token Logging","locations":[{"file":"SKILL.md","line_end":242,"line_start":227}],"confidence":0.97,"description":"An addon captures Authorization values and prints the first 20 characters, which can expose reusable credential material in console or CI logs.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The example explicitly stores Authorization header values and prints a token prefix. Log access can reveal sensitive credential material."},{"title":"Persistent Interception CA Trust","locations":[{"file":"SKILL.md","line_end":215,"line_start":196}],"confidence":0.94,"description":"The workflow installs and enables trust for an interception CA on client devices without directing users to remove that trust after testing.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The instructions install and trust the mitmproxy CA on Android and iOS. No cleanup step removes the trusted CA after the assessment."}],"low_findings":[{"title":"Hardcoded URL","locations":[{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240}],"confidence":0.99,"description":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The URL selects a mutable branch-hosted installer and sends its response directly to Bash. Changed or compromised remote content would execute in CI."}],"dangerous_patterns":[{"title":"Pipe to shell pattern","locations":[{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240}],"confidence":0.99,"description":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","review_kind":"security","source_category":"blocker","source_severity":"critical","confidence_reasoning":"The workflow pipes an unverified installer from a mutable GitHub branch directly into Bash. This creates a direct CI supply-chain execution path."},{"title":"Recursive delete on root/home","locations":[{"file":"SKILL.md","line_end":434,"line_start":434}],"confidence":0.96,"description":"rm -rf ~/.mitmproxy/","review_kind":"security","source_category":"blocker","source_severity":"critical","confidence_reasoning":"The troubleshooting command recursively deletes the entire mitmproxy home directory without backup or confirmation. It can destroy custom configuration, certificates, keys, and saved state."}],"files_scanned":6,"total_lines":2014,"audit_model":"codex","audited_at":"2026-07-23T05:00:26.235+00:00","created_at":"2026-07-24T04:00:13.262424+00:00","static_findings":[{"id":"external_commands:assets/ci-config-template.yml:298:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `sast-results`","category":"external_commands","line_end":298,"severity":"medium","line_start":298},{"id":"external_commands:assets/ci-config-template.yml:301:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `dependency-scan-results`","category":"external_commands","line_end":301,"severity":"medium","line_start":301},{"id":"external_commands:assets/ci-config-template.yml:304:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `secrets-scan-results`","category":"external_commands","line_end":304,"severity":"medium","line_start":304},{"id":"external_commands:assets/ci-config-template.yml:307:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `container-scan-results`","category":"external_commands","line_end":307,"severity":"medium","line_start":307},{"id":"external_commands:assets/ci-config-template.yml:310:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `iac-scan-results`","category":"external_commands","line_end":310,"severity":"medium","line_start":310},{"id":"external_commands:assets/ci-config-template.yml:134:shell-command-substitution","file":"assets/ci-config-template.yml","pattern":"Shell command substitution","snippet":"critical_count=$(python3 -c \"import json; data=json.load(open('${{ env.REPORT_DIR }}/safety-results.","category":"external_commands","line_end":134,"severity":"medium","line_start":134},{"id":"external_commands:assets/ci-config-template.yml:250:shell-command-substitution","file":"assets/ci-config-template.yml","pattern":"Shell command substitution","snippet":"critical_count=$(python3 -c \"import json; data=json.load(open('${{ env.REPORT_DIR }}/checkov-results","category":"external_commands","line_end":250,"severity":"medium","line_start":250},{"id":"external_commands:assets/ci-config-template.yml:291:shell-command-substitution","file":"assets/ci-config-template.yml","pattern":"Shell command substitution","snippet":"**Scan Date**: $(date -u +\"%Y-%m-%d %H:%M:%S UTC\")","category":"external_commands","line_end":291,"severity":"medium","line_start":291},{"id":"network:assets/ci-config-template.yml:240:hardcoded-url","file":"assets/ci-config-template.yml","pattern":"Hardcoded URL","snippet":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","category":"network","line_end":240,"severity":"low","line_start":240},{"id":"filesystem:assets/ci-config-template.yml:323:node-js-fs-operations","file":"assets/ci-config-template.yml","pattern":"Node.js fs operations","snippet":"const report = fs.readFileSync('consolidated-report/security-summary.md', 'utf8');","category":"filesystem","line_end":323,"severity":"medium","line_start":323},{"id":"filesystem:assets/ci-config-template.yml:323:synchronous-file-operations","file":"assets/ci-config-template.yml","pattern":"Synchronous file operations","snippet":"const report = fs.readFileSync('consolidated-report/security-summary.md', 'utf8');","category":"filesystem","line_end":323,"severity":"medium","line_start":323},{"id":"env_access:assets/ci-config-template.yml:164:git-platform-tokens","file":"assets/ci-config-template.yml","pattern":"Git platform tokens","snippet":"GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}","category":"env_access","line_end":164,"severity":"high","line_start":164},{"id":"blocker:assets/ci-config-template.yml:240:pipe-to-shell-pattern","file":"assets/ci-config-template.yml","pattern":"Pipe to shell pattern","snippet":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","category":"blocker","line_end":240,"severity":"critical","line_start":240},{"id":"network:assets/rule-template.yaml:43:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-community/attacks/SQL_Injection\"","category":"network","line_end":43,"severity":"low","line_start":43},{"id":"network:assets/rule-template.yaml:44:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/89.html\"","category":"network","line_end":44,"severity":"low","line_start":44},{"id":"network:assets/rule-template.yaml:45:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html\"","category":"network","line_end":45,"severity":"low","line_start":45},{"id":"network:assets/rule-template.yaml:73:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://owasp.org/www-community/attacks/SQL_Injection","category":"network","line_end":73,"severity":"low","line_start":73},{"id":"network:assets/rule-template.yaml:118:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/798.html\"","category":"network","line_end":118,"severity":"low","line_start":118},{"id":"network:assets/rule-template.yaml:119:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-community/vulnerabilities/Use_of_hard-coded_password\"","category":"network","line_end":119,"severity":"low","line_start":119},{"id":"network:assets/rule-template.yaml:151:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://cwe.mitre.org/data/definitions/798.html","category":"network","line_end":151,"severity":"low","line_start":151},{"id":"network:assets/rule-template.yaml:191:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-community/attacks/xss/\"","category":"network","line_end":191,"severity":"low","line_start":191},{"id":"network:assets/rule-template.yaml:192:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/79.html\"","category":"network","line_end":192,"severity":"low","line_start":192},{"id":"network:assets/rule-template.yaml:193:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html\"","category":"network","line_end":193,"severity":"low","line_start":193},{"id":"network:assets/rule-template.yaml:217:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://owasp.org/www-community/attacks/xss/","category":"network","line_end":217,"severity":"low","line_start":217},{"id":"network:assets/rule-template.yaml:260:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/327.html\"","category":"network","line_end":260,"severity":"low","line_start":260},{"id":"network:assets/rule-template.yaml:261:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testin","category":"network","line_end":261,"severity":"low","line_start":261},{"id":"network:assets/rule-template.yaml:288:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://cwe.mitre.org/data/definitions/327.html","category":"network","line_end":288,"severity":"low","line_start":288},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-access-dot-notation","file":"assets/rule-template.yaml","pattern":"Environment variable access (dot notation)","snippet":"- Node.js: process.env.API_KEY","category":"env_access","line_end":148,"severity":"low","line_start":148},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-object","file":"assets/rule-template.yaml","pattern":"Environment variable object","snippet":"- Node.js: process.env.API_KEY","category":"env_access","line_end":148,"severity":"low","line_start":148},{"id":"env_access:assets/rule-template.yaml:147:python-environment-access","file":"assets/rule-template.yaml","pattern":"Python environment access","snippet":"- Python: os.environ.get('API_KEY')","category":"env_access","line_end":147,"severity":"low","line_start":147},{"id":"env_access:assets/rule-template.yaml:162:python-environment-access","file":"assets/rule-template.yaml","pattern":"Python environment access","snippet":"api_key = os.environ.get('API_KEY')","category":"env_access","line_end":162,"severity":"low","line_start":162},{"id":"env_access:assets/rule-template.yaml:132:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api_key = \"...\"","category":"env_access","line_end":132,"severity":"high","line_start":132},{"id":"env_access:assets/rule-template.yaml:147:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"- Python: os.environ.get('API_KEY')","category":"env_access","line_end":147,"severity":"high","line_start":147},{"id":"env_access:assets/rule-template.yaml:148:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"- Node.js: process.env.API_KEY","category":"env_access","line_end":148,"severity":"high","line_start":148},{"id":"env_access:assets/rule-template.yaml:156:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api_key = \"sk-1234567890abcdef\"","category":"env_access","line_end":156,"severity":"high","line_start":156},{"id":"env_access:assets/rule-template.yaml:157:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api.authenticate(api_key)","category":"env_access","line_end":157,"severity":"high","line_start":157},{"id":"env_access:assets/rule-template.yaml:162:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api_key = os.environ.get('API_KEY')","category":"env_access","line_end":162,"severity":"high","line_start":162},{"id":"env_access:assets/rule-template.yaml:163:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"if not api_key:","category":"env_access","line_end":163,"severity":"high","line_start":163},{"id":"env_access:assets/rule-template.yaml:164:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"raise ValueError(\"API_KEY environment variable not set\")","category":"env_access","line_end":164,"severity":"high","line_start":164},{"id":"env_access:assets/rule-template.yaml:165:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api.authenticate(api_key)","category":"env_access","line_end":165,"severity":"high","line_start":165},{"id":"sensitive:assets/rule-template.yaml:148:environment-file-access","file":"assets/rule-template.yaml","pattern":"Environment file access","snippet":"- Node.js: process.env.API_KEY","category":"sensitive","line_end":148,"severity":"high","line_start":148},{"id":"blocker:assets/rule-template.yaml:70:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"- Python: cursor.execute(\"SELECT * FROM users WHERE id = ?\", (user_id,))","category":"blocker","line_end":70,"severity":"low","line_start":70},{"id":"blocker:assets/rule-template.yaml:71:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"- JavaScript: db.query(\"SELECT * FROM users WHERE id = $1\", [userId])","category":"blocker","line_end":71,"severity":"low","line_start":71},{"id":"blocker:assets/rule-template.yaml:83:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"user_id = request.GET['id']","category":"blocker","line_end":83,"severity":"low","line_start":83},{"id":"blocker:assets/rule-template.yaml:84:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = \" + user_id","category":"blocker","line_end":84,"severity":"low","line_start":84},{"id":"blocker:assets/rule-template.yaml:89:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"user_id = request.GET['id']","category":"blocker","line_end":89,"severity":"low","line_start":89},{"id":"blocker:assets/rule-template.yaml:90:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = ?\"","category":"blocker","line_end":90,"severity":"low","line_start":90},{"id":"scripts:references/EXAMPLE.md:138:document-write-injection","file":"references/EXAMPLE.md","pattern":"document.write injection","snippet":"document.write(userInput);","category":"scripts","line_end":138,"severity":"high","line_start":138},{"id":"scripts:references/EXAMPLE.md:137:innerhtml-assignment-xss-risk","file":"references/EXAMPLE.md","pattern":"innerHTML assignment (XSS risk)","snippet":"element.innerHTML = userInput;","category":"scripts","line_end":137,"severity":"medium","line_start":137},{"id":"env_access:references/EXAMPLE.md:423:python-environment-access","file":"references/EXAMPLE.md","pattern":"Python environment access","snippet":"VALID_API_KEY = os.environ.get('API_KEY')","category":"env_access","line_end":423,"severity":"low","line_start":423},{"id":"env_access:references/EXAMPLE.md:423:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"VALID_API_KEY = os.environ.get('API_KEY')","category":"env_access","line_end":423,"severity":"high","line_start":423},{"id":"env_access:references/EXAMPLE.md:424:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"if not VALID_API_KEY:","category":"env_access","line_end":424,"severity":"high","line_start":424},{"id":"env_access:references/EXAMPLE.md:425:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"raise ValueError(\"API_KEY environment variable not set\")","category":"env_access","line_end":425,"severity":"high","line_start":425},{"id":"env_access:references/EXAMPLE.md:427:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"def require_api_key(f):","category":"env_access","line_end":427,"severity":"high","line_start":427},{"id":"env_access:references/EXAMPLE.md:430:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"api_key = request.headers.get('X-API-Key')","category":"env_access","line_end":430,"severity":"high","line_start":430},{"id":"env_access:references/EXAMPLE.md:432:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"if not api_key:","category":"env_access","line_end":432,"severity":"high","line_start":432},{"id":"env_access:references/EXAMPLE.md:437:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"if not hmac.compare_digest(api_key, VALID_API_KEY):","category":"env_access","line_end":437,"severity":"high","line_start":437},{"id":"env_access:references/EXAMPLE.md:444:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"@require_api_key","category":"env_access","line_end":444,"severity":"high","line_start":444},{"id":"blocker:references/EXAMPLE.md:276:c2-keywords","file":"references/EXAMPLE.md","pattern":"C2 keywords","snippet":"- **T1041**: Exfiltration Over C2 Channel","category":"blocker","line_end":276,"severity":"high","line_start":276},{"id":"blocker:references/EXAMPLE.md:97:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = \" + user_id","category":"blocker","line_end":97,"severity":"low","line_start":97},{"id":"blocker:references/EXAMPLE.md:113:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = ?\"","category":"blocker","line_end":113,"severity":"low","line_start":113},{"id":"blocker:references/EXAMPLE.md:242:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"- **T1078**: Valid Accounts","category":"blocker","line_end":242,"severity":"low","line_start":242},{"id":"blocker:references/EXAMPLE.md:298:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"cursor.execute(\"SELECT * FROM users WHERE id = ?\", (user_id,))","category":"blocker","line_end":298,"severity":"low","line_start":298},{"id":"blocker:references/EXAMPLE.md:301:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"cursor.execute(\"SELECT * FROM users WHERE id = %s\", (user_id,))","category":"blocker","line_end":301,"severity":"low","line_start":301},{"id":"blocker:references/EXAMPLE.md:305:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"result = session.execute(text(\"SELECT * FROM users WHERE id = :id\"), {\"id\": user_id})","category":"blocker","line_end":305,"severity":"low","line_start":305},{"id":"blocker:references/EXAMPLE.md:314:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"raise ValueError(\"Invalid user ID format\")","category":"blocker","line_end":314,"severity":"low","line_start":314},{"id":"blocker:references/EXAMPLE.md:438:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"return jsonify({'error': 'Invalid API key'}), 403","category":"blocker","line_end":438,"severity":"low","line_start":438},{"id":"blocker:references/EXAMPLE.md:471:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"is_valid = verify_password(\"user_password\", stored_hash)  # True","category":"blocker","line_end":471,"severity":"low","line_start":471},{"id":"blocker:references/EXAMPLE.md:523:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"raise ValueError(\"Invalid file type\")","category":"blocker","line_end":523,"severity":"low","line_start":523},{"id":"blocker:references/EXAMPLE.md:529:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"import uuid","category":"blocker","line_end":530,"severity":"low","line_start":529},{"id":"blocker:references/EXAMPLE.md:381:network-reconnaissance","file":"references/EXAMPLE.md","pattern":"Network reconnaissance","snippet":"- xss","category":"blocker","line_end":382,"severity":"low","line_start":381},{"id":"blocker:references/WORKFLOW_CHECKLIST.md:193:malware-type-keywords","file":"references/WORKFLOW_CHECKLIST.md","pattern":"Malware type keywords","snippet":"[ ] 10. Remove malicious artifacts (malware, backdoors, webshells)","category":"blocker","line_end":193,"severity":"high","line_start":193},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":52,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":63,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":69,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":100,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":102,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":106,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":112,"severity":"medium","line_start":106},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":114,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":118,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":124,"severity":"medium","line_start":118},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Create Python addon script (`api-test.py`):","category":"external_commands","line_end":125,"severity":"medium","line_start":124},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":142,"severity":"medium","line_start":125},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":144,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":148,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":162,"severity":"medium","line_start":148},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":164,"severity":"medium","line_start":162},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":173,"severity":"medium","line_start":164},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":175,"severity":"medium","line_start":173},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":179,"severity":"medium","line_start":175},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":181,"severity":"medium","line_start":179},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":185,"severity":"medium","line_start":181},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":187,"severity":"medium","line_start":185},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":191,"severity":"medium","line_start":187},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":193,"severity":"medium","line_start":191},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":207,"severity":"medium","line_start":193},{"id":"external_commands:SKILL.md:207:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Push certificate to device: `adb push ~/.mitmproxy/mitmproxy-ca-cert.cer /sdcard/`","category":"external_commands","line_end":223,"severity":"medium","line_start":207},{"id":"external_commands:SKILL.md:223:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":245,"severity":"medium","line_start":223},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":251,"severity":"medium","line_start":245},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":268,"severity":"medium","line_start":251},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":274,"severity":"medium","line_start":268},{"id":"external_commands:SKILL.md:274:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":295,"severity":"medium","line_start":274},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":301,"severity":"medium","line_start":295},{"id":"external_commands:SKILL.md:301:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":317,"severity":"medium","line_start":301},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":320,"severity":"medium","line_start":317},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":322,"severity":"medium","line_start":320},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":347,"severity":"medium","line_start":322},{"id":"external_commands:SKILL.md:347:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":360,"severity":"medium","line_start":347},{"id":"external_commands:SKILL.md:360:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":378,"severity":"medium","line_start":360},{"id":"external_commands:SKILL.md:378:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":390,"severity":"medium","line_start":378},{"id":"external_commands:SKILL.md:390:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":396,"severity":"medium","line_start":390},{"id":"external_commands:SKILL.md:396:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":402,"severity":"medium","line_start":396},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":408,"severity":"medium","line_start":402},{"id":"external_commands:SKILL.md:408:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":422,"severity":"medium","line_start":408},{"id":"external_commands:SKILL.md:422:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":429,"severity":"medium","line_start":422},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":436,"severity":"medium","line_start":429},{"id":"external_commands:SKILL.md:436:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":449,"severity":"medium","line_start":436},{"id":"external_commands:SKILL.md:449:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":454,"severity":"medium","line_start":449},{"id":"external_commands:SKILL.md:454:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":459,"severity":"medium","line_start":454},{"id":"external_commands:SKILL.md:459:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":462,"severity":"medium","line_start":459},{"id":"network:SKILL.md:129:http-client-library","file":"SKILL.md","pattern":"HTTP client library","snippet":"def request(self, flow: http.HTTPFlow) -> None:","category":"network","line_end":129,"severity":"low","line_start":129},{"id":"network:SKILL.md:231:http-client-library","file":"SKILL.md","pattern":"HTTP client library","snippet":"def request(self, flow: http.HTTPFlow):","category":"network","line_end":231,"severity":"low","line_start":231},{"id":"network:SKILL.md:256:http-client-library","file":"SKILL.md","pattern":"HTTP client library","snippet":"def request(self, flow: http.HTTPFlow):","category":"network","line_end":256,"severity":"low","line_start":256},{"id":"network:SKILL.md:280:http-client-library","file":"SKILL.md","pattern":"HTTP client library","snippet":"def request(self, flow: http.HTTPFlow):","category":"network","line_end":280,"severity":"low","line_start":280},{"id":"network:SKILL.md:20:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://mitmproxy.org/","category":"network","line_end":20,"severity":"low","line_start":20},{"id":"network:SKILL.md:21:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://docs.mitmproxy.org/","category":"network","line_end":21,"severity":"low","line_start":21},{"id":"network:SKILL.md:47:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"# Start web interface (default: http://127.0.0.1:8081)","category":"network","line_end":47,"severity":"low","line_start":47},{"id":"network:SKILL.md:163:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"mitmproxy --mode reverse:https://api.example.com --listen-host 0.0.0.0 --listen-port 443","category":"network","line_end":163,"severity":"low","line_start":163},{"id":"network:SKILL.md:186:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"mitmproxy --mode reverse:https://api.example.com --listen-port 443","category":"network","line_end":186,"severity":"low","line_start":186},{"id":"network:SKILL.md:192:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"mitmproxy --mode upstream:http://corporate-proxy:8080","category":"network","line_end":192,"severity":"low","line_start":192},{"id":"network:SKILL.md:202:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"2. Visit http://mitm.it","category":"network","line_end":202,"severity":"low","line_start":202},{"id":"network:SKILL.md:353:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"export HTTP_PROXY=http://localhost:8080","category":"network","line_end":353,"severity":"low","line_start":353},{"id":"network:SKILL.md:354:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"export HTTPS_PROXY=http://localhost:8080","category":"network","line_end":354,"severity":"low","line_start":354},{"id":"network:SKILL.md:481:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [mitmproxy Documentation](https://docs.mitmproxy.org/)","category":"network","line_end":481,"severity":"low","line_start":481},{"id":"network:SKILL.md:482:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [mitmproxy GitHub](https://github.com/mitmproxy/mitmproxy)","category":"network","line_end":482,"severity":"low","line_start":482},{"id":"network:SKILL.md:483:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [OWASP API Security Top 10](https://owasp.org/www-project-api-security/)","category":"network","line_end":483,"severity":"low","line_start":483},{"id":"network:SKILL.md:484:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [mitmproxy Addon Examples](https://github.com/mitmproxy/mitmproxy/tree/main/examples)","category":"network","line_end":484,"severity":"low","line_start":484},{"id":"network:SKILL.md:47:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"# Start web interface (default: http://127.0.0.1:8081)","category":"network","line_end":47,"severity":"medium","line_start":47},{"id":"network:SKILL.md:65:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"mitmproxy --mode regular --listen-host 0.0.0.0 --listen-port 8080","category":"network","line_end":65,"severity":"medium","line_start":65},{"id":"network:SKILL.md:68:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"mitmweb --mode regular --listen-host 0.0.0.0 --listen-port 8080","category":"network","line_end":68,"severity":"medium","line_start":68},{"id":"network:SKILL.md:163:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"mitmproxy --mode reverse:https://api.example.com --listen-host 0.0.0.0 --listen-port 443","category":"network","line_end":163,"severity":"medium","line_start":163},{"id":"network:SKILL.md:443:hardcoded-ip-address","file":"SKILL.md","pattern":"Hardcoded IP address","snippet":"- Ensure mitmproxy is listening on correct interface (0.0.0.0)","category":"network","line_end":443,"severity":"medium","line_start":443},{"id":"network:SKILL.md:353:proxy-environment-variable","file":"SKILL.md","pattern":"Proxy environment variable","snippet":"export HTTP_PROXY=http://localhost:8080","category":"network","line_end":353,"severity":"medium","line_start":353},{"id":"network:SKILL.md:354:proxy-environment-variable","file":"SKILL.md","pattern":"Proxy environment variable","snippet":"export HTTPS_PROXY=http://localhost:8080","category":"network","line_end":354,"severity":"medium","line_start":354},{"id":"filesystem:SKILL.md:260:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"payloads = [\"' OR '1'='1\", \"<script>alert(1)</script>\", \"../../../etc/passwd\"]","category":"filesystem","line_end":260,"severity":"high","line_start":260},{"id":"filesystem:SKILL.md:207:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"1. Push certificate to device: `adb push ~/.mitmproxy/mitmproxy-ca-cert.cer /sdcard/`","category":"filesystem","line_end":207,"severity":"high","line_start":207},{"id":"filesystem:SKILL.md:431:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"ls ~/.mitmproxy/","category":"filesystem","line_end":431,"severity":"high","line_start":431},{"id":"filesystem:SKILL.md:434:hidden-file-in-home-directory","file":"SKILL.md","pattern":"Hidden file in home directory","snippet":"rm -rf ~/.mitmproxy/","category":"filesystem","line_end":434,"severity":"high","line_start":434},{"id":"filesystem:SKILL.md:207:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"1. Push certificate to device: `adb push ~/.mitmproxy/mitmproxy-ca-cert.cer /sdcard/`","category":"filesystem","line_end":207,"severity":"medium","line_start":207},{"id":"filesystem:SKILL.md:431:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"ls ~/.mitmproxy/","category":"filesystem","line_end":431,"severity":"medium","line_start":431},{"id":"filesystem:SKILL.md:434:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"rm -rf ~/.mitmproxy/","category":"filesystem","line_end":434,"severity":"medium","line_start":434},{"id":"sensitive:SKILL.md:207:certificate-key-files","file":"SKILL.md","pattern":"Certificate/key files","snippet":"1. Push certificate to device: `adb push ~/.mitmproxy/mitmproxy-ca-cert.cer /sdcard/`","category":"sensitive","line_end":207,"severity":"high","line_start":207},{"id":"blocker:SKILL.md:260:system-password-file-access","file":"SKILL.md","pattern":"System password file access","snippet":"payloads = [\"' OR '1'='1\", \"<script>alert(1)</script>\", \"../../../etc/passwd\"]","category":"blocker","line_end":260,"severity":"critical","line_start":260},{"id":"blocker:SKILL.md:434:recursive-delete-on-root-home","file":"SKILL.md","pattern":"Recursive delete on root/home","snippet":"rm -rf ~/.mitmproxy/","category":"blocker","line_end":434,"severity":"critical","line_start":434},{"id":"blocker:SKILL.md:330:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Safe Defaults**: Use isolated testing environments. Avoid intercepting production traffic withou","category":"blocker","line_end":330,"severity":"low","line_start":330},{"id":"blocker:SKILL.md:364:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"Standard workflow for iOS/Android apps:","category":"blocker","line_end":364,"severity":"low","line_start":364},{"id":"blocker:SKILL.md:450:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"# Android with Frida","category":"blocker","line_end":450,"severity":"low","line_start":450}],"finding_verdicts":[{"id":"external_commands:assets/ci-config-template.yml:298:ruby-shell-backtick-execution","reason":"The backticks delimit Markdown artifact names inside a single-quoted heredoc. They are report formatting, not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/ci-config-template.yml:301:ruby-shell-backtick-execution","reason":"The backticks delimit Markdown artifact names inside a single-quoted heredoc. They are report formatting, not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/ci-config-template.yml:304:ruby-shell-backtick-execution","reason":"The backticks delimit Markdown artifact names inside a single-quoted heredoc. They are report formatting, not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/ci-config-template.yml:307:ruby-shell-backtick-execution","reason":"The backticks delimit Markdown artifact names inside a single-quoted heredoc. They are report formatting, not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/ci-config-template.yml:310:ruby-shell-backtick-execution","reason":"The backticks delimit Markdown artifact names inside a single-quoted heredoc. They are report formatting, not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:assets/ci-config-template.yml:134:shell-command-substitution","reason":"The substitution runs a fixed Python parser against a workflow-generated local report path. No untrusted value is interpolated into the command.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/ci-config-template.yml:250:shell-command-substitution","reason":"The substitution runs a fixed Python parser against a workflow-generated local report path. No untrusted value is interpolated into the command.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/ci-config-template.yml:291:shell-command-substitution","reason":"The date expression is inside a single-quoted heredoc, so the shell writes it literally. It is not evaluated as command substitution.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/ci-config-template.yml:240:hardcoded-url","reason":"The URL selects a mutable branch-hosted installer and sends its response directly to Bash. Changed or compromised remote content would execute in CI.","verdict":"confirmed","confidence":0.99},{"id":"filesystem:assets/ci-config-template.yml:323:node-js-fs-operations","reason":"The script reads one fixed, workflow-generated Markdown report before posting it to the current pull request. No external path controls the read.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:assets/ci-config-template.yml:323:synchronous-file-operations","reason":"The script reads one fixed, workflow-generated Markdown report before posting it to the current pull request. No external path controls the read.","verdict":"false_positive","confidence":0.98},{"id":"env_access:assets/ci-config-template.yml:164:git-platform-tokens","reason":"The workflow provides GITHUB_TOKEN to a third-party action referenced by a mutable version tag. A compromised action could use the token's repository permissions.","verdict":"confirmed","confidence":0.84},{"id":"blocker:assets/ci-config-template.yml:240:pipe-to-shell-pattern","reason":"The workflow pipes an unverified installer from a mutable GitHub branch directly into Bash. This creates a direct CI supply-chain execution path.","verdict":"confirmed","confidence":0.99},{"id":"network:assets/rule-template.yaml:43:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or MITRE guidance in a security-rule template. The template does not fetch or execute the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:44:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or MITRE guidance in a security-rule template. The template does not fetch or execute the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:45:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or MITRE guidance in a security-rule template. The template does not fetch or execute the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:73:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or MITRE guidance in a security-rule template. The template does not fetch or execute the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:118:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or MITRE guidance in a security-rule template. The template does not fetch or execute the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:119:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or MITRE guidance in a security-rule template. The template does not fetch or execute the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:151:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or MITRE guidance in a security-rule template. The template does not fetch or execute the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:191:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or MITRE guidance in a security-rule template. The template does not fetch or execute the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:192:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or MITRE guidance in a security-rule template. The template does not fetch or execute the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:193:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or MITRE guidance in a security-rule template. The template does not fetch or execute the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:217:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or MITRE guidance in a security-rule template. The template does not fetch or execute the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:260:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or MITRE guidance in a security-rule template. The template does not fetch or execute the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:261:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or MITRE guidance in a security-rule template. The template does not fetch or execute the URL.","verdict":"false_positive","confidence":0.99},{"id":"network:assets/rule-template.yaml:288:hardcoded-url","reason":"This is a documentation reference to OWASP, CWE, or MITRE guidance in a security-rule template. The template does not fetch or execute the URL.","verdict":"false_positive","confidence":0.99},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-access-dot-notation","reason":"The text is part of a rule explaining hardcoded-secret detection and its environment-variable remediation. The displayed key is an explicit dummy vulnerable example.","verdict":"false_positive","confidence":0.98},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-object","reason":"The text is part of a rule explaining hardcoded-secret detection and its environment-variable remediation. The displayed key is an explicit dummy vulnerable example.","verdict":"false_positive","confidence":0.98},{"id":"env_access:assets/rule-template.yaml:147:python-environment-access","reason":"The text is part of a rule explaining hardcoded-secret detection and its environment-variable remediation. The displayed key is an explicit dummy vulnerable example.","verdict":"false_positive","confidence":0.98},{"id":"env_access:assets/rule-template.yaml:162:python-environment-access","reason":"The text is part of a rule explaining hardcoded-secret detection and its environment-variable remediation. The displayed key is an explicit dummy vulnerable example.","verdict":"false_positive","confidence":0.98},{"id":"env_access:assets/rule-template.yaml:132:generic-api-secret-keys","reason":"The text is part of a rule explaining hardcoded-secret detection and its environment-variable remediation. The displayed key is an explicit dummy vulnerable example.","verdict":"false_positive","confidence":0.98},{"id":"env_access:assets/rule-template.yaml:147:generic-api-secret-keys","reason":"The text is part of a rule explaining hardcoded-secret detection and its environment-variable remediation. The displayed key is an explicit dummy vulnerable example.","verdict":"false_positive","confidence":0.98},{"id":"env_access:assets/rule-template.yaml:148:generic-api-secret-keys","reason":"The text is part of a rule explaining hardcoded-secret detection and its environment-variable remediation. The displayed key is an explicit dummy vulnerable example.","verdict":"false_positive","confidence":0.98},{"id":"env_access:assets/rule-template.yaml:156:generic-api-secret-keys","reason":"The text is part of a rule explaining hardcoded-secret detection and its environment-variable remediation. The displayed key is an explicit dummy vulnerable example.","verdict":"false_positive","confidence":0.98},{"id":"env_access:assets/rule-template.yaml:157:generic-api-secret-keys","reason":"The text is part of a rule explaining hardcoded-secret detection and its environment-variable remediation. The displayed key is an explicit dummy vulnerable example.","verdict":"false_positive","confidence":0.98},{"id":"env_access:assets/rule-template.yaml:162:generic-api-secret-keys","reason":"The text is part of a rule explaining hardcoded-secret detection and its environment-variable remediation. The displayed key is an explicit dummy vulnerable example.","verdict":"false_positive","confidence":0.98},{"id":"env_access:assets/rule-template.yaml:163:generic-api-secret-keys","reason":"The text is part of a rule explaining hardcoded-secret detection and its environment-variable remediation. The displayed key is an explicit dummy vulnerable example.","verdict":"false_positive","confidence":0.98},{"id":"env_access:assets/rule-template.yaml:164:generic-api-secret-keys","reason":"The text is part of a rule explaining hardcoded-secret detection and its environment-variable remediation. The displayed key is an explicit dummy vulnerable example.","verdict":"false_positive","confidence":0.98},{"id":"env_access:assets/rule-template.yaml:165:generic-api-secret-keys","reason":"The text is part of a rule explaining hardcoded-secret detection and its environment-variable remediation. The displayed key is an explicit dummy vulnerable example.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:assets/rule-template.yaml:148:environment-file-access","reason":"The text is part of a rule explaining hardcoded-secret detection and its environment-variable remediation. The displayed key is an explicit dummy vulnerable example.","verdict":"false_positive","confidence":0.98},{"id":"blocker:assets/rule-template.yaml:70:system-reconnaissance","reason":"The cited line is an educational SQL injection example or parameterized remediation. It performs no host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/rule-template.yaml:71:system-reconnaissance","reason":"The cited line is an educational SQL injection example or parameterized remediation. It performs no host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/rule-template.yaml:83:system-reconnaissance","reason":"The cited line is an educational SQL injection example or parameterized remediation. It performs no host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/rule-template.yaml:84:system-reconnaissance","reason":"The cited line is an educational SQL injection example or parameterized remediation. It performs no host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/rule-template.yaml:89:system-reconnaissance","reason":"The cited line is an educational SQL injection example or parameterized remediation. It performs no host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:assets/rule-template.yaml:90:system-reconnaissance","reason":"The cited line is an educational SQL injection example or parameterized remediation. It performs no host or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"scripts:references/EXAMPLE.md:138:document-write-injection","reason":"The reference labels this code as vulnerable XSS and immediately presents safe remediation. It is teaching content, not executable skill behavior.","verdict":"false_positive","confidence":0.99},{"id":"scripts:references/EXAMPLE.md:137:innerhtml-assignment-xss-risk","reason":"The reference labels this code as vulnerable XSS and immediately presents safe remediation. It is teaching content, not executable skill behavior.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/EXAMPLE.md:423:python-environment-access","reason":"This secure authentication example reads a named key from the environment and validates requests. It neither contains a real credential nor exports one.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/EXAMPLE.md:423:generic-api-secret-keys","reason":"This secure authentication example reads a named key from the environment and validates requests. It neither contains a real credential nor exports one.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/EXAMPLE.md:424:generic-api-secret-keys","reason":"This secure authentication example reads a named key from the environment and validates requests. It neither contains a real credential nor exports one.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/EXAMPLE.md:425:generic-api-secret-keys","reason":"This secure authentication example reads a named key from the environment and validates requests. It neither contains a real credential nor exports one.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/EXAMPLE.md:427:generic-api-secret-keys","reason":"This secure authentication example reads a named key from the environment and validates requests. It neither contains a real credential nor exports one.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/EXAMPLE.md:430:generic-api-secret-keys","reason":"This secure authentication example reads a named key from the environment and validates requests. It neither contains a real credential nor exports one.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/EXAMPLE.md:432:generic-api-secret-keys","reason":"This secure authentication example reads a named key from the environment and validates requests. It neither contains a real credential nor exports one.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/EXAMPLE.md:437:generic-api-secret-keys","reason":"This secure authentication example reads a named key from the environment and validates requests. It neither contains a real credential nor exports one.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/EXAMPLE.md:444:generic-api-secret-keys","reason":"This secure authentication example reads a named key from the environment and validates requests. It neither contains a real credential nor exports one.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/EXAMPLE.md:276:c2-keywords","reason":"The phrase is the title of MITRE ATT&CK technique T1041 in an educational taxonomy. No command-and-control channel or implementation is present.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:97:system-reconnaissance","reason":"The cited content is secure coding guidance, sample validation, or a scanner rule name. It does not discover local systems, accounts, files, or services.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:113:system-reconnaissance","reason":"The cited content is secure coding guidance, sample validation, or a scanner rule name. It does not discover local systems, accounts, files, or services.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:242:system-reconnaissance","reason":"The cited content is secure coding guidance, sample validation, or a scanner rule name. It does not discover local systems, accounts, files, or services.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:298:system-reconnaissance","reason":"The cited content is secure coding guidance, sample validation, or a scanner rule name. It does not discover local systems, accounts, files, or services.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:301:system-reconnaissance","reason":"The cited content is secure coding guidance, sample validation, or a scanner rule name. It does not discover local systems, accounts, files, or services.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:305:system-reconnaissance","reason":"The cited content is secure coding guidance, sample validation, or a scanner rule name. It does not discover local systems, accounts, files, or services.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:314:system-reconnaissance","reason":"The cited content is secure coding guidance, sample validation, or a scanner rule name. It does not discover local systems, accounts, files, or services.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:438:system-reconnaissance","reason":"The cited content is secure coding guidance, sample validation, or a scanner rule name. It does not discover local systems, accounts, files, or services.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:471:system-reconnaissance","reason":"The cited content is secure coding guidance, sample validation, or a scanner rule name. It does not discover local systems, accounts, files, or services.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:523:system-reconnaissance","reason":"The cited content is secure coding guidance, sample validation, or a scanner rule name. It does not discover local systems, accounts, files, or services.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:529:system-reconnaissance","reason":"The cited content is secure coding guidance, sample validation, or a scanner rule name. It does not discover local systems, accounts, files, or services.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:381:network-reconnaissance","reason":"The cited content is secure coding guidance, sample validation, or a scanner rule name. It does not discover local systems, accounts, files, or services.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/WORKFLOW_CHECKLIST.md:193:malware-type-keywords","reason":"The incident-response checklist instructs defenders to remove malware, backdoors, and webshells. It does not create or deploy malicious software.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:124:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:125:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:162:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:164:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:193:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:207:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:223:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:274:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:301:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:347:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:360:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:378:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:390:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:396:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:408:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:422:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:436:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:449:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:454:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:459:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in mitmproxy documentation. It is not a Ruby backtick expression or shell command substitution.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:129:http-client-library","reason":"The request method is a mitmproxy addon callback that receives an intercepted flow. The cited definition does not initiate an outbound HTTP request.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:231:http-client-library","reason":"The request method is a mitmproxy addon callback that receives an intercepted flow. The cited definition does not initiate an outbound HTTP request.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:256:http-client-library","reason":"The request method is a mitmproxy addon callback that receives an intercepted flow. The cited definition does not initiate an outbound HTTP request.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:280:http-client-library","reason":"The request method is a mitmproxy addon callback that receives an intercepted flow. The cited definition does not initiate an outbound HTTP request.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:20:hardcoded-url","reason":"The URL is an official reference, a loopback service, or an explicit example endpoint used to explain proxy configuration. It is not a covert destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:21:hardcoded-url","reason":"The URL is an official reference, a loopback service, or an explicit example endpoint used to explain proxy configuration. It is not a covert destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:47:hardcoded-url","reason":"The URL is an official reference, a loopback service, or an explicit example endpoint used to explain proxy configuration. It is not a covert destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:163:hardcoded-url","reason":"The URL is an official reference, a loopback service, or an explicit example endpoint used to explain proxy configuration. It is not a covert destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:186:hardcoded-url","reason":"The URL is an official reference, a loopback service, or an explicit example endpoint used to explain proxy configuration. It is not a covert destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:192:hardcoded-url","reason":"The URL is an official reference, a loopback service, or an explicit example endpoint used to explain proxy configuration. It is not a covert destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:202:hardcoded-url","reason":"The URL is an official reference, a loopback service, or an explicit example endpoint used to explain proxy configuration. It is not a covert destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:353:hardcoded-url","reason":"The URL is an official reference, a loopback service, or an explicit example endpoint used to explain proxy configuration. It is not a covert destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:354:hardcoded-url","reason":"The URL is an official reference, a loopback service, or an explicit example endpoint used to explain proxy configuration. It is not a covert destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:481:hardcoded-url","reason":"The URL is an official reference, a loopback service, or an explicit example endpoint used to explain proxy configuration. It is not a covert destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:482:hardcoded-url","reason":"The URL is an official reference, a loopback service, or an explicit example endpoint used to explain proxy configuration. It is not a covert destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:483:hardcoded-url","reason":"The URL is an official reference, a loopback service, or an explicit example endpoint used to explain proxy configuration. It is not a covert destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:484:hardcoded-url","reason":"The URL is an official reference, a loopback service, or an explicit example endpoint used to explain proxy configuration. It is not a covert destination.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:47:hardcoded-ip-address","reason":"The address is the IPv4 loopback interface for mitmweb's documented local default. It does not expose the service beyond the host.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:65:hardcoded-ip-address","reason":"The guidance binds an intercepting proxy to 0.0.0.0 without requiring authentication or firewall restrictions. Other reachable hosts could abuse the proxy or access traffic.","verdict":"confirmed","confidence":0.96},{"id":"network:SKILL.md:68:hardcoded-ip-address","reason":"The guidance binds an intercepting proxy to 0.0.0.0 without requiring authentication or firewall restrictions. Other reachable hosts could abuse the proxy or access traffic.","verdict":"confirmed","confidence":0.96},{"id":"network:SKILL.md:163:hardcoded-ip-address","reason":"The guidance binds an intercepting proxy to 0.0.0.0 without requiring authentication or firewall restrictions. Other reachable hosts could abuse the proxy or access traffic.","verdict":"confirmed","confidence":0.96},{"id":"network:SKILL.md:443:hardcoded-ip-address","reason":"The guidance binds an intercepting proxy to 0.0.0.0 without requiring authentication or firewall restrictions. Other reachable hosts could abuse the proxy or access traffic.","verdict":"confirmed","confidence":0.96},{"id":"network:SKILL.md:353:proxy-environment-variable","reason":"The variables intentionally route CI test traffic to a loopback mitmproxy instance. They do not reference an external proxy or persist beyond the job.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:354:proxy-environment-variable","reason":"The variables intentionally route CI test traffic to a loopback mitmproxy instance. They do not reference an external proxy or persist beyond the job.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:260:path-traversal-sequence","reason":"The traversal text is an explicit fuzzing payload printed by an API-testing example. The skill does not use it to access the auditor's local filesystem.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:207:hidden-file-in-home-directory","reason":"The command reads mitmproxy's documented application directory to copy its public CA certificate to an authorized test device. It does not inspect unrelated hidden files.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:431:hidden-file-in-home-directory","reason":"The command lists only mitmproxy's own application directory while troubleshooting certificate generation. It does not enumerate unrelated home-directory data.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:434:hidden-file-in-home-directory","reason":"The troubleshooting command recursively deletes the entire mitmproxy home directory without backup or confirmation. It can destroy custom configuration, certificates, keys, and saved state.","verdict":"confirmed","confidence":0.96},{"id":"filesystem:SKILL.md:207:hidden-file-access","reason":"The command reads mitmproxy's documented application directory to copy its public CA certificate to an authorized test device. It does not inspect unrelated hidden files.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:431:hidden-file-access","reason":"The command lists only mitmproxy's own application directory while troubleshooting certificate generation. It does not enumerate unrelated home-directory data.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:434:hidden-file-access","reason":"The troubleshooting command recursively deletes the entire mitmproxy home directory without backup or confirmation. It can destroy custom configuration, certificates, keys, and saved state.","verdict":"confirmed","confidence":0.96},{"id":"sensitive:SKILL.md:207:certificate-key-files","reason":"The command copies a public .cer CA certificate from mitmproxy's standard directory. It does not copy the CA private key or another secret key file.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:260:system-password-file-access","reason":"The passwd path is a string used as an API fuzzing payload. No local file-open operation or command reads the host's password file.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:434:recursive-delete-on-root-home","reason":"The troubleshooting command recursively deletes the entire mitmproxy home directory without backup or confirmation. It can destroy custom configuration, certificates, keys, and saved state.","verdict":"confirmed","confidence":0.96},{"id":"blocker:SKILL.md:330:system-reconnaissance","reason":"The cited line is an authorization warning, a mobile testing heading, or a Frida example comment. It does not perform system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:364:system-reconnaissance","reason":"The cited line is an authorization warning, a mobile testing heading, or a Frida example comment. It does not perform system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:450:system-reconnaissance","reason":"The cited line is an authorization warning, a mobile testing heading, or a Frida example comment. It does not perform system reconnaissance.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Mutable Third-Party CI Actions","severity":"high","locations":[{"file":"assets/ci-config-template.yml","line_end":164,"line_start":161},{"file":"assets/ci-config-template.yml","line_end":199,"line_start":196}],"confidence":0.97,"description":"The CI template executes third-party actions through mutable tags, including @master, while exposing repository data and a GitHub token.","confidence_reasoning":"The action references are visibly tag-based, and @master is mutable. GitHub Actions execute code with job workspace and permission access."},{"title":"Authorization Token Logging","severity":"medium","locations":[{"file":"SKILL.md","line_end":242,"line_start":227}],"confidence":0.97,"description":"An addon captures Authorization values and prints the first 20 characters, which can expose reusable credential material in console or CI logs.","confidence_reasoning":"The example explicitly stores Authorization header values and prints a token prefix. Log access can reveal sensitive credential material."},{"title":"Persistent Interception CA Trust","severity":"medium","locations":[{"file":"SKILL.md","line_end":215,"line_start":196}],"confidence":0.94,"description":"The workflow installs and enables trust for an interception CA on client devices without directing users to remove that trust after testing.","confidence_reasoning":"The instructions install and trust the mitmproxy CA on Android and iOS. No cleanup step removes the trusted CA after the assessment."}],"subject_marketplace_commit_sha":"9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2","subject_content_hash":"ea21648bbd8444229d48ebaefcf2fefd63e5662a7c91bc129728b7aa61cbe7bf","subject_tree_hash":"efd9417852a4535c32327ef4d4f7dad1517f7e1e201b5c6ce24984f56b5719d6","subject_plugin_path":"skills/agentsecops/api-mitmproxy","audit_payload_hash":"3653911491b1702d9ef23c11d7fc2451","confirmed_risk_level":"critical","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2","contentHash":"ea21648bbd8444229d48ebaefcf2fefd63e5662a7c91bc129728b7aa61cbe7bf","treeHash":"efd9417852a4535c32327ef4d4f7dad1517f7e1e201b5c6ce24984f56b5719d6","pluginPath":"skills/agentsecops/api-mitmproxy","auditPayloadHash":"3653911491b1702d9ef23c11d7fc2451"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/agentsecops-api-mitmproxy/audits/9/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"critical","confirmedFindingCount":5,"capabilityReviewCount":8,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"blocked","manualInstallPolicy":"allowed_with_warning","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}