{"data":{"skill":{"slug":"agentsecops-container-hadolint","name":"container-hadolint","icon":"📦","repo":"https://github.com/AgentSecOps/SecOpsAgentKit/tree/main/skills/devsecops/container-hadolint","status":"approved","author":"AgentSecOps","authorVersion":"0.1.0","skillstoreRevision":2},"audit":{"id":"f2eb07ca-78e4-41b5-b4db-5a59f4debef7","skill_id":"45d711c0-a1c7-45d5-b2a6-ef5f7f2808a4","version":10,"content_hash":"v3:9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2:f1075c27a23683dc9528e5df913b872c7ae0a2638a5500f4b5f580d0aeb2a1f2:ad081f994b552d00bab1fb3668b857a086d82b2b647940fbbaf84bc9e2baebd3:736b696c6c732f6167656e747365636f70732f636f6e7461696e65722d6861646f6c696e74:ed7608224d35707e8d6ffe2c6506ed59","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most alerts are false positives from Markdown, reference links, placeholder credentials, and examples labeled as insecure. Actionable risks include unsafe CI filename handling and unverified latest-binary downloads. Mutable CI dependencies add supply-chain exposure, while no prompt injection or malicious intent was found.","remediation":[{"issue":"Repository filenames can influence CI shell parsing","severity":"high","suggestion":"Use null-delimited file discovery and loops, then pass values through environment variables without direct expression interpolation."},{"issue":"Hadolint binaries are downloaded from a mutable latest URL","severity":"medium","suggestion":"Pin an exact Hadolint release and verify its published checksum before making the binary executable."},{"issue":"CI actions and images use mutable version references","severity":"medium","suggestion":"Pin GitHub Actions to commit hashes and GitLab container images to immutable digests, then review updates through automation."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"assets/github-actions.yml","line_end":68,"line_start":68},{"file":"assets/gitlab-ci.yml","line_end":15,"line_start":15},{"file":"references/security_rules.md","line_end":258,"line_start":258},{"file":"SKILL.md","line_end":46,"line_start":36},{"file":"SKILL.md","line_end":50,"line_start":46},{"file":"SKILL.md","line_end":59,"line_start":50},{"file":"SKILL.md","line_end":63,"line_start":59},{"file":"SKILL.md","line_end":72,"line_start":63},{"file":"SKILL.md","line_end":80,"line_start":72},{"file":"SKILL.md","line_end":92,"line_start":80},{"file":"SKILL.md","line_end":95,"line_start":92},{"file":"SKILL.md","line_end":99,"line_start":95},{"file":"SKILL.md","line_end":109,"line_start":99},{"file":"SKILL.md","line_end":132,"line_start":109},{"file":"SKILL.md","line_end":136,"line_start":132},{"file":"SKILL.md","line_end":146,"line_start":136},{"file":"SKILL.md","line_end":152,"line_start":146},{"file":"SKILL.md","line_end":154,"line_start":152},{"file":"SKILL.md","line_end":178,"line_start":154},{"file":"SKILL.md","line_end":180,"line_start":178},{"file":"SKILL.md","line_end":181,"line_start":180},{"file":"SKILL.md","line_end":182,"line_start":181},{"file":"SKILL.md","line_end":183,"line_start":182},{"file":"SKILL.md","line_end":191,"line_start":183},{"file":"SKILL.md","line_end":203,"line_start":191},{"file":"SKILL.md","line_end":212,"line_start":203},{"file":"SKILL.md","line_end":218,"line_start":212},{"file":"SKILL.md","line_end":224,"line_start":218},{"file":"SKILL.md","line_end":238,"line_start":224},{"file":"SKILL.md","line_end":251,"line_start":238},{"file":"SKILL.md","line_end":260,"line_start":251},{"file":"SKILL.md","line_end":268,"line_start":260},{"file":"SKILL.md","line_end":281,"line_start":268},{"file":"SKILL.md","line_end":291,"line_start":281},{"file":"SKILL.md","line_end":293,"line_start":291},{"file":"SKILL.md","line_end":294,"line_start":293},{"file":"SKILL.md","line_end":295,"line_start":294},{"file":"SKILL.md","line_end":296,"line_start":295},{"file":"SKILL.md","line_end":298,"line_start":296},{"file":"SKILL.md","line_end":300,"line_start":298},{"file":"SKILL.md","line_end":301,"line_start":300},{"file":"SKILL.md","line_end":302,"line_start":301},{"file":"SKILL.md","line_end":303,"line_start":302},{"file":"SKILL.md","line_end":305,"line_start":303},{"file":"SKILL.md","line_end":307,"line_start":305},{"file":"SKILL.md","line_end":308,"line_start":307},{"file":"SKILL.md","line_end":309,"line_start":308},{"file":"SKILL.md","line_end":310,"line_start":309},{"file":"SKILL.md","line_end":311,"line_start":310},{"file":"SKILL.md","line_end":312,"line_start":311}]},{"factor":"network","evidence":[{"file":"assets/github-actions.yml","line_end":75,"line_start":75},{"file":"references/security_rules.md","line_end":206,"line_start":206},{"file":"references/security_rules.md","line_end":213,"line_start":213},{"file":"references/security_rules.md","line_end":251,"line_start":251},{"file":"references/security_rules.md","line_end":258,"line_start":258},{"file":"references/security_rules.md","line_end":274,"line_start":274},{"file":"references/security_rules.md","line_end":281,"line_start":281},{"file":"references/security_rules.md","line_end":333,"line_start":333},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":594,"line_start":594},{"file":"SKILL.md","line_end":595,"line_start":595},{"file":"SKILL.md","line_end":596,"line_start":596},{"file":"SKILL.md","line_end":597,"line_start":597},{"file":"SKILL.md","line_end":598,"line_start":598}]},{"factor":"filesystem","evidence":[{"file":"references/security_rules.md","line_end":206,"line_start":206}]},{"factor":"env_access","evidence":[{"file":"references/security_rules.md","line_end":250,"line_start":250},{"file":"references/security_rules.md","line_end":251,"line_start":251},{"file":"references/security_rules.md","line_end":257,"line_start":257},{"file":"references/security_rules.md","line_end":258,"line_start":258}]}],"critical_findings":[],"high_findings":[{"title":"Shell command substitution","locations":[{"file":"assets/github-actions.yml","line_end":68,"line_start":68}],"confidence":0.98,"description":"DOCKERFILES=$(find . -type f \\( -name \"Dockerfile*\" -o -name \"*.dockerfile\" \\) | tr '\\n' ' ')","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The workflow converts repository-controlled filenames into one string, then interpolates that output into shell code on line 80. A crafted filename can execute commands in CI."}],"medium_findings":[{"title":"Hardcoded URL","locations":[{"file":"assets/github-actions.yml","line_end":75,"line_start":75}],"confidence":0.98,"description":"wget -O /usr/local/bin/hadolint https://github.com/hadolint/hadolint/releases/latest/download/hadoli","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The workflow downloads a mutable latest Hadolint binary into an executable path without a version pin or integrity check. A compromised asset would execute in CI."},{"title":"Shell command substitution","locations":[{"file":"assets/gitlab-ci.yml","line_end":15,"line_start":15}],"confidence":0.93,"description":"DOCKERFILES=$(find . -type f \\( -name \"Dockerfile*\" -o -name \"*.dockerfile\" \\))","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"The pipeline stores repository-controlled paths in a scalar and later iterates with unquoted field splitting. Crafted filenames can avoid accurate linting and bypass the security gate."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":41,"line_start":41}],"confidence":0.98,"description":"wget -O /usr/local/bin/hadolint https://github.com/hadolint/hadolint/releases/latest/download/hadoli","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"The installation example downloads the mutable latest Hadolint binary directly into an executable path without integrity verification. Following it creates avoidable supply-chain exposure."},{"title":"Mutable CI Dependencies","locations":[{"file":"assets/github-actions.yml","line_end":31,"line_start":31},{"file":"assets/github-actions.yml","line_end":34,"line_start":34},{"file":"assets/github-actions.yml","line_end":44,"line_start":44},{"file":"assets/github-actions.yml","line_end":51,"line_start":51},{"file":"assets/github-actions.yml","line_end":91,"line_start":91},{"file":"assets/gitlab-ci.yml","line_end":11,"line_start":11},{"file":"assets/gitlab-ci.yml","line_end":52,"line_start":52},{"file":"assets/gitlab-ci.yml","line_end":62,"line_start":62}],"confidence":0.98,"description":"Workflow templates execute third-party actions by movable version tags and GitLab images tagged latest-debian. Retagged or compromised dependencies would run inside trusted CI jobs.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The templates visibly use action tags and latest-debian instead of immutable commit hashes or image digests."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":9,"total_lines":1399,"audit_model":"codex","audited_at":"2026-07-23T05:17:45.906+00:00","created_at":"2026-07-24T04:00:42.998299+00:00","static_findings":[{"id":"external_commands:assets/github-actions.yml:68:shell-command-substitution","file":"assets/github-actions.yml","pattern":"Shell command substitution","snippet":"DOCKERFILES=$(find . -type f \\( -name \"Dockerfile*\" -o -name \"*.dockerfile\" \\) | tr '\\n' ' ')","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"network:assets/github-actions.yml:75:hardcoded-url","file":"assets/github-actions.yml","pattern":"Hardcoded URL","snippet":"wget -O /usr/local/bin/hadolint https://github.com/hadolint/hadolint/releases/latest/download/hadoli","category":"network","line_end":75,"severity":"low","line_start":75},{"id":"external_commands:assets/gitlab-ci.yml:15:shell-command-substitution","file":"assets/gitlab-ci.yml","pattern":"Shell command substitution","snippet":"DOCKERFILES=$(find . -type f \\( -name \"Dockerfile*\" -o -name \"*.dockerfile\" \\))","category":"external_commands","line_end":15,"severity":"medium","line_start":15},{"id":"blocker:assets/hadolint-strict.yaml:33:system-reconnaissance","file":"assets/hadolint-strict.yaml","pattern":"System reconnaissance","snippet":"- DL3015  # Avoid additional packages","category":"blocker","line_end":33,"severity":"low","line_start":33},{"id":"blocker:references/EXAMPLE.md:38:network-reconnaissance","file":"references/EXAMPLE.md","pattern":"Network reconnaissance","snippet":"- TA0001: Initial Access","category":"blocker","line_end":39,"severity":"low","line_start":38},{"id":"external_commands:references/security_rules.md:258:shell-command-substitution","file":"references/security_rules.md","pattern":"Shell command substitution","snippet":"curl -H \"Authorization: $(cat /run/secrets/api_key)\" https://api.example.com","category":"external_commands","line_end":258,"severity":"medium","line_start":258},{"id":"network:references/security_rules.md:206:hardcoded-url","file":"references/security_rules.md","pattern":"Hardcoded URL","snippet":"ADD https://example.com/file.txt /tmp/","category":"network","line_end":206,"severity":"low","line_start":206},{"id":"network:references/security_rules.md:213:hardcoded-url","file":"references/security_rules.md","pattern":"Hardcoded URL","snippet":"RUN curl -O https://example.com/file.txt","category":"network","line_end":213,"severity":"low","line_start":213},{"id":"network:references/security_rules.md:251:hardcoded-url","file":"references/security_rules.md","pattern":"Hardcoded URL","snippet":"RUN curl -H \"Authorization: $API_KEY\" https://api.example.com","category":"network","line_end":251,"severity":"low","line_start":251},{"id":"network:references/security_rules.md:258:hardcoded-url","file":"references/security_rules.md","pattern":"Hardcoded URL","snippet":"curl -H \"Authorization: $(cat /run/secrets/api_key)\" https://api.example.com","category":"network","line_end":258,"severity":"low","line_start":258},{"id":"network:references/security_rules.md:274:hardcoded-url","file":"references/security_rules.md","pattern":"Hardcoded URL","snippet":"RUN curl -O https://example.com/file","category":"network","line_end":274,"severity":"low","line_start":274},{"id":"network:references/security_rules.md:281:hardcoded-url","file":"references/security_rules.md","pattern":"Hardcoded URL","snippet":"curl -O https://example.com/file && \\","category":"network","line_end":281,"severity":"low","line_start":281},{"id":"network:references/security_rules.md:333:hardcoded-url","file":"references/security_rules.md","pattern":"Hardcoded URL","snippet":"CMD curl -f http://localhost:8080/health || exit 1","category":"network","line_end":333,"severity":"low","line_start":333},{"id":"filesystem:references/security_rules.md:206:temp-directory-access","file":"references/security_rules.md","pattern":"Temp directory access","snippet":"ADD https://example.com/file.txt /tmp/","category":"filesystem","line_end":206,"severity":"medium","line_start":206},{"id":"env_access:references/security_rules.md:250:generic-api-secret-keys","file":"references/security_rules.md","pattern":"Generic API/secret keys","snippet":"ARG API_KEY=secret123","category":"env_access","line_end":250,"severity":"high","line_start":250},{"id":"env_access:references/security_rules.md:251:generic-api-secret-keys","file":"references/security_rules.md","pattern":"Generic API/secret keys","snippet":"RUN curl -H \"Authorization: $API_KEY\" https://api.example.com","category":"env_access","line_end":251,"severity":"high","line_start":251},{"id":"env_access:references/security_rules.md:257:generic-api-secret-keys","file":"references/security_rules.md","pattern":"Generic API/secret keys","snippet":"RUN --mount=type=secret,id=api_key \\","category":"env_access","line_end":257,"severity":"high","line_start":257},{"id":"env_access:references/security_rules.md:258:generic-api-secret-keys","file":"references/security_rules.md","pattern":"Generic API/secret keys","snippet":"curl -H \"Authorization: $(cat /run/secrets/api_key)\" https://api.example.com","category":"env_access","line_end":258,"severity":"high","line_start":258},{"id":"blocker:references/security_rules.md:285:system-reconnaissance","file":"references/security_rules.md","pattern":"System reconnaissance","snippet":"**Note**: Balance between layer caching and image size. For development, separate RUN instructions m","category":"blocker","line_end":285,"severity":"low","line_start":285},{"id":"blocker:references/security_rules.md:406:system-reconnaissance","file":"references/security_rules.md","pattern":"System reconnaissance","snippet":"- DL3015: Avoid additional packages","category":"blocker","line_end":406,"severity":"low","line_start":406},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":46,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":50,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":59,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":63,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":72,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":80,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":92,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":95,"severity":"medium","line_start":92},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":99,"severity":"medium","line_start":95},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":109,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":132,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":136,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":146,"severity":"medium","line_start":136},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":152,"severity":"medium","line_start":146},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Create `.hadolint.yaml` to customize rules:","category":"external_commands","line_end":154,"severity":"medium","line_start":152},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":178,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":180,"severity":"medium","line_start":178},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use bundled templates in `assets/`:","category":"external_commands","line_end":181,"severity":"medium","line_start":180},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `assets/hadolint-strict.yaml` - Strict security enforcement (CRITICAL/HIGH only)","category":"external_commands","line_end":182,"severity":"medium","line_start":181},{"id":"external_commands:SKILL.md:182:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `assets/hadolint-balanced.yaml` - Balanced validation (recommended)","category":"external_commands","line_end":183,"severity":"medium","line_start":182},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `assets/hadolint-permissive.yaml` - Permissive for legacy Dockerfiles","category":"external_commands","line_end":191,"severity":"medium","line_start":183},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":203,"severity":"medium","line_start":191},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":212,"severity":"medium","line_start":203},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"See `references/security_rules.md` for complete security rule catalog with CIS mappings.","category":"external_commands","line_end":218,"severity":"medium","line_start":212},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":224,"severity":"medium","line_start":218},{"id":"external_commands:SKILL.md:224:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":238,"severity":"medium","line_start":224},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":251,"severity":"medium","line_start":238},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":260,"severity":"medium","line_start":251},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Build Secrets**: Use Docker BuildKit secrets (`RUN --mount=type=secret`) instead of ARG for cred","category":"external_commands","line_end":268,"severity":"medium","line_start":260},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Trusted Registries**: Configure `trustedRegistries` to enforce approved base image sources","category":"external_commands","line_end":281,"severity":"medium","line_start":268},{"id":"external_commands:SKILL.md:281:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **CIS Docker Benchmark 1.6**: Hadolint rules map to CIS controls (see `references/cis_mapping.md`)","category":"external_commands","line_end":291,"severity":"medium","line_start":281},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Scripts (`scripts/`)","category":"external_commands","line_end":293,"severity":"medium","line_start":291},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `hadolint_scan.py` - Comprehensive scanning with multiple Dockerfiles and output formats","category":"external_commands","line_end":294,"severity":"medium","line_start":293},{"id":"external_commands:SKILL.md:294:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `hadolint_multistage.py` - Multi-stage Dockerfile analysis with stage-specific validation","category":"external_commands","line_end":295,"severity":"medium","line_start":294},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `install_precommit.sh` - Automated pre-commit hook installation","category":"external_commands","line_end":296,"severity":"medium","line_start":295},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `ci_integration.sh` - CI/CD integration examples for multiple platforms","category":"external_commands","line_end":298,"severity":"medium","line_start":296},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### References (`references/`)","category":"external_commands","line_end":300,"severity":"medium","line_start":298},{"id":"external_commands:SKILL.md:300:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `security_rules.md` - Complete Hadolint security rules with CIS Benchmark mappings","category":"external_commands","line_end":301,"severity":"medium","line_start":300},{"id":"external_commands:SKILL.md:301:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `cis_mapping.md` - Detailed CIS Docker Benchmark control mapping","category":"external_commands","line_end":302,"severity":"medium","line_start":301},{"id":"external_commands:SKILL.md:302:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `remediation_guide.md` - Rule-by-rule remediation guidance with secure examples","category":"external_commands","line_end":303,"severity":"medium","line_start":302},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `shellcheck_integration.md` - ShellCheck rules for RUN instruction validation","category":"external_commands","line_end":305,"severity":"medium","line_start":303},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Assets (`assets/`)","category":"external_commands","line_end":307,"severity":"medium","line_start":305},{"id":"external_commands:SKILL.md:307:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `hadolint-strict.yaml` - Strict security configuration","category":"external_commands","line_end":308,"severity":"medium","line_start":307},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `hadolint-balanced.yaml` - Production-ready configuration (recommended)","category":"external_commands","line_end":309,"severity":"medium","line_start":308},{"id":"external_commands:SKILL.md:309:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `hadolint-permissive.yaml` - Legacy Dockerfile migration configuration","category":"external_commands","line_end":310,"severity":"medium","line_start":309},{"id":"external_commands:SKILL.md:310:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `github-actions.yml` - Complete GitHub Actions workflow","category":"external_commands","line_end":311,"severity":"medium","line_start":310},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `gitlab-ci.yml` - Complete GitLab CI pipeline","category":"external_commands","line_end":312,"severity":"medium","line_start":311},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `precommit-config.yaml` - Pre-commit framework configuration","category":"external_commands","line_end":320,"severity":"medium","line_start":312},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":336,"severity":"medium","line_start":320},{"id":"external_commands:SKILL.md:336:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":342,"severity":"medium","line_start":336},{"id":"external_commands:SKILL.md:342:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":354,"severity":"medium","line_start":342},{"id":"external_commands:SKILL.md:354:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":360,"severity":"medium","line_start":354},{"id":"external_commands:SKILL.md:360:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```dockerfile","category":"external_commands","line_end":399,"severity":"medium","line_start":360},{"id":"external_commands:SKILL.md:399:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":402,"severity":"medium","line_start":399},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":404,"severity":"medium","line_start":402},{"id":"external_commands:SKILL.md:404:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":410,"severity":"medium","line_start":404},{"id":"external_commands:SKILL.md:410:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":422,"severity":"medium","line_start":410},{"id":"external_commands:SKILL.md:422:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":457,"severity":"medium","line_start":422},{"id":"external_commands:SKILL.md:457:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":465,"severity":"medium","line_start":457},{"id":"external_commands:SKILL.md:465:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":467,"severity":"medium","line_start":465},{"id":"external_commands:SKILL.md:467:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Consult `references/remediation_guide.md` for rule-specific guidance.","category":"external_commands","line_end":474,"severity":"medium","line_start":467},{"id":"external_commands:SKILL.md:474:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":480,"severity":"medium","line_start":474},{"id":"external_commands:SKILL.md:480:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":487,"severity":"medium","line_start":480},{"id":"external_commands:SKILL.md:487:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```dockerfile","category":"external_commands","line_end":497,"severity":"medium","line_start":487},{"id":"external_commands:SKILL.md:497:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":499,"severity":"medium","line_start":497},{"id":"external_commands:SKILL.md:499:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"See `references/shellcheck_integration.md` for complete ShellCheck guidance.","category":"external_commands","line_end":506,"severity":"medium","line_start":499},{"id":"external_commands:SKILL.md:506:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```dockerfile","category":"external_commands","line_end":514,"severity":"medium","line_start":506},{"id":"external_commands:SKILL.md:514:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":521,"severity":"medium","line_start":514},{"id":"external_commands:SKILL.md:521:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":531,"severity":"medium","line_start":521},{"id":"external_commands:SKILL.md:531:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":537,"severity":"medium","line_start":531},{"id":"external_commands:SKILL.md:537:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":547,"severity":"medium","line_start":537},{"id":"external_commands:SKILL.md:547:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":551,"severity":"medium","line_start":547},{"id":"external_commands:SKILL.md:551:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```dockerfile","category":"external_commands","line_end":563,"severity":"medium","line_start":551},{"id":"external_commands:SKILL.md:563:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":567,"severity":"medium","line_start":563},{"id":"external_commands:SKILL.md:567:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":577,"severity":"medium","line_start":567},{"id":"external_commands:SKILL.md:577:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":581,"severity":"medium","line_start":577},{"id":"external_commands:SKILL.md:581:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":588,"severity":"medium","line_start":581},{"id":"external_commands:SKILL.md:245:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"for dockerfile in $(git diff --cached --name-only | grep -E 'Dockerfile'); do","category":"external_commands","line_end":245,"severity":"medium","line_start":245},{"id":"external_commands:SKILL.md:327:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"output_file=\"security-reports/$(echo $dockerfile | tr '/' '_').json\"","category":"external_commands","line_end":327,"severity":"medium","line_start":327},{"id":"external_commands:SKILL.md:238:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":251,"severity":"medium","line_start":238},{"id":"external_commands:SKILL.md:320:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":336,"severity":"medium","line_start":320},{"id":"external_commands:SKILL.md:244:unix-shell-invocation","file":"SKILL.md","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":244,"severity":"medium","line_start":244},{"id":"network:SKILL.md:19:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://github.com/hadolint/hadolint","category":"network","line_end":19,"severity":"low","line_start":19},{"id":"network:SKILL.md:20:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://www.cisecurity.org/benchmark/docker","category":"network","line_end":20,"severity":"low","line_start":20},{"id":"network:SKILL.md:21:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://docs.docker.com/develop/develop-images/dockerfile_best-practices/","category":"network","line_end":21,"severity":"low","line_start":21},{"id":"network:SKILL.md:41:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"wget -O /usr/local/bin/hadolint https://github.com/hadolint/hadolint/releases/latest/download/hadoli","category":"network","line_end":41,"severity":"low","line_start":41},{"id":"network:SKILL.md:594:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Hadolint GitHub Repository](https://github.com/hadolint/hadolint)","category":"network","line_end":594,"severity":"low","line_start":594},{"id":"network:SKILL.md:595:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [CIS Docker Benchmark](https://www.cisecurity.org/benchmark/docker)","category":"network","line_end":595,"severity":"low","line_start":595},{"id":"network:SKILL.md:596:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Docker Best Practices](https://docs.docker.com/develop/develop-images/dockerfile_best-practices/)","category":"network","line_end":596,"severity":"low","line_start":596},{"id":"network:SKILL.md:597:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [ShellCheck Documentation](https://www.shellcheck.net/)","category":"network","line_end":597,"severity":"low","line_start":597},{"id":"network:SKILL.md:598:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [OCI Image Specification](https://github.com/opencontainers/image-spec)","category":"network","line_end":598,"severity":"low","line_start":598},{"id":"blocker:SKILL.md:460:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- DL3059  # Multiple RUN instructions (valid for complex builds)","category":"blocker","line_end":460,"severity":"low","line_start":460},{"id":"blocker:SKILL.md:571:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"- gcr.io/distroless      # Google distroless","category":"blocker","line_end":572,"severity":"low","line_start":571}],"finding_verdicts":[{"id":"external_commands:assets/github-actions.yml:68:shell-command-substitution","reason":"The workflow converts repository-controlled filenames into one string, then interpolates that output into shell code on line 80. A crafted filename can execute commands in CI.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"network:assets/github-actions.yml:75:hardcoded-url","reason":"The workflow downloads a mutable latest Hadolint binary into an executable path without a version pin or integrity check. A compromised asset would execute in CI.","verdict":"confirmed","severity":"medium","confidence":0.98},{"id":"external_commands:assets/gitlab-ci.yml:15:shell-command-substitution","reason":"The pipeline stores repository-controlled paths in a scalar and later iterates with unquoted field splitting. Crafted filenames can avoid accurate linting and bypass the security gate.","verdict":"confirmed","severity":"medium","confidence":0.93},{"id":"blocker:assets/hadolint-strict.yaml:33:system-reconnaissance","reason":"The text is a Hadolint rule identifier with a configuration comment, not system reconnaissance. It performs no command or data collection.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/EXAMPLE.md:38:network-reconnaissance","reason":"The text is a MITRE ATT&CK tactic label in a reference template, not an instruction to probe networks. It performs no reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/security_rules.md:258:shell-command-substitution","reason":"This is a nonexecuting Dockerfile example showing a BuildKit-mounted secret and a placeholder endpoint. The skill neither reads a real secret nor runs the command.","verdict":"false_positive","confidence":0.99},{"id":"network:references/security_rules.md:206:hardcoded-url","reason":"The URL appears only in a Dockerfile example within a security reference. It uses example.com or localhost and is not contacted by the skill.","verdict":"false_positive","confidence":0.99},{"id":"network:references/security_rules.md:213:hardcoded-url","reason":"The URL appears only in a Dockerfile example within a security reference. It uses example.com or localhost and is not contacted by the skill.","verdict":"false_positive","confidence":0.99},{"id":"network:references/security_rules.md:251:hardcoded-url","reason":"The URL appears only in a Dockerfile example within a security reference. It uses example.com or localhost and is not contacted by the skill.","verdict":"false_positive","confidence":0.99},{"id":"network:references/security_rules.md:258:hardcoded-url","reason":"The URL appears only in a Dockerfile example within a security reference. It uses example.com or localhost and is not contacted by the skill.","verdict":"false_positive","confidence":0.99},{"id":"network:references/security_rules.md:274:hardcoded-url","reason":"The URL appears only in a Dockerfile example within a security reference. It uses example.com or localhost and is not contacted by the skill.","verdict":"false_positive","confidence":0.99},{"id":"network:references/security_rules.md:281:hardcoded-url","reason":"The URL appears only in a Dockerfile example within a security reference. It uses example.com or localhost and is not contacted by the skill.","verdict":"false_positive","confidence":0.99},{"id":"network:references/security_rules.md:333:hardcoded-url","reason":"The URL appears only in a Dockerfile example within a security reference. It uses example.com or localhost and is not contacted by the skill.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:references/security_rules.md:206:temp-directory-access","reason":"The /tmp destination appears in a Dockerfile example explicitly labeled Bad. The reference file does not access the host filesystem.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/security_rules.md:250:generic-api-secret-keys","reason":"The placeholder API key appears in a Dockerfile example explicitly labeled Bad. It is not a real credential and the surrounding text warns against this pattern.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/security_rules.md:251:generic-api-secret-keys","reason":"The placeholder API key appears in a Dockerfile example explicitly labeled Bad. It is not a real credential and the surrounding text warns against this pattern.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/security_rules.md:257:generic-api-secret-keys","reason":"The identifier appears in a nonexecuting example of recommended BuildKit secret mounting. No real credential is present or accessed by the skill.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/security_rules.md:258:generic-api-secret-keys","reason":"The identifier appears in a nonexecuting example of recommended BuildKit secret mounting. No real credential is present or accessed by the skill.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/security_rules.md:285:system-reconnaissance","reason":"The matched prose describes Docker layer caching or lists a Hadolint rule. It contains no system discovery command or reconnaissance intent.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/security_rules.md:406:system-reconnaissance","reason":"The matched prose describes Docker layer caching or lists a Hadolint rule. It contains no system discovery command or reconnaissance intent.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:136:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:178:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:182:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:203:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:224:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:281:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:293:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:294:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:300:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:301:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:302:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:303:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:307:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:309:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:310:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:320:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:336:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:342:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:354:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:360:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:399:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:404:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:410:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:422:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:457:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:465:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:467:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:474:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:480:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:487:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:497:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:499:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:506:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:514:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:521:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:531:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:537:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:547:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:551:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:563:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:567:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:577:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:581:ruby-shell-backtick-execution","reason":"The match is a Markdown code fence or inline code span in SKILL.md, not backtick command execution. This location defines no executable Ruby or shell implementation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:245:shell-command-substitution","reason":"This documented hook runs fixed git and grep commands; repository text is not evaluated as shell code. The example is not executed automatically by the skill.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:327:shell-command-substitution","reason":"This documented assignment uses fixed echo and tr commands to derive a report filename. The result remains inside a quoted assignment and is not evaluated as code.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:238:template-literal-with-command-substitution","reason":"The match is a fenced Bash example in Markdown, not a JavaScript template literal. SKILL.md does not execute the example automatically.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:320:template-literal-with-command-substitution","reason":"The match is a fenced Bash example in Markdown, not a JavaScript template literal. SKILL.md does not execute the example automatically.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:244:unix-shell-invocation","reason":"The shebang is text inside a documented pre-commit heredoc. It is not an invocation performed by the skill.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:19:hardcoded-url","reason":"This is a documentation link to the Hadolint, Docker, CIS, ShellCheck, or OCI project. Referencing public documentation does not cause a network request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:20:hardcoded-url","reason":"This is a documentation link to the Hadolint, Docker, CIS, ShellCheck, or OCI project. Referencing public documentation does not cause a network request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:21:hardcoded-url","reason":"This is a documentation link to the Hadolint, Docker, CIS, ShellCheck, or OCI project. Referencing public documentation does not cause a network request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:41:hardcoded-url","reason":"The installation example downloads the mutable latest Hadolint binary directly into an executable path without integrity verification. Following it creates avoidable supply-chain exposure.","verdict":"confirmed","severity":"medium","confidence":0.98},{"id":"network:SKILL.md:594:hardcoded-url","reason":"This is a documentation link to the Hadolint, Docker, CIS, ShellCheck, or OCI project. Referencing public documentation does not cause a network request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:595:hardcoded-url","reason":"This is a documentation link to the Hadolint, Docker, CIS, ShellCheck, or OCI project. Referencing public documentation does not cause a network request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:596:hardcoded-url","reason":"This is a documentation link to the Hadolint, Docker, CIS, ShellCheck, or OCI project. Referencing public documentation does not cause a network request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:597:hardcoded-url","reason":"This is a documentation link to the Hadolint, Docker, CIS, ShellCheck, or OCI project. Referencing public documentation does not cause a network request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:598:hardcoded-url","reason":"This is a documentation link to the Hadolint, Docker, CIS, ShellCheck, or OCI project. Referencing public documentation does not cause a network request.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:460:system-reconnaissance","reason":"The text is a Hadolint rule comment about multiple RUN instructions. It does not inspect the system or collect environment details.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:571:network-reconnaissance","reason":"The text is a trusted container registry entry in a Hadolint configuration example. It does not scan or probe any network.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Mutable CI Dependencies","severity":"medium","locations":[{"file":"assets/github-actions.yml","line_end":31,"line_start":31},{"file":"assets/github-actions.yml","line_end":34,"line_start":34},{"file":"assets/github-actions.yml","line_end":44,"line_start":44},{"file":"assets/github-actions.yml","line_end":51,"line_start":51},{"file":"assets/github-actions.yml","line_end":91,"line_start":91},{"file":"assets/gitlab-ci.yml","line_end":11,"line_start":11},{"file":"assets/gitlab-ci.yml","line_end":52,"line_start":52},{"file":"assets/gitlab-ci.yml","line_end":62,"line_start":62}],"confidence":0.98,"description":"Workflow templates execute third-party actions by movable version tags and GitLab images tagged latest-debian. Retagged or compromised dependencies would run inside trusted CI jobs.","confidence_reasoning":"The templates visibly use action tags and latest-debian instead of immutable commit hashes or image digests."}],"subject_marketplace_commit_sha":"9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2","subject_content_hash":"f1075c27a23683dc9528e5df913b872c7ae0a2638a5500f4b5f580d0aeb2a1f2","subject_tree_hash":"ad081f994b552d00bab1fb3668b857a086d82b2b647940fbbaf84bc9e2baebd3","subject_plugin_path":"skills/agentsecops/container-hadolint","audit_payload_hash":"ed7608224d35707e8d6ffe2c6506ed59","confirmed_risk_level":"medium","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2","contentHash":"f1075c27a23683dc9528e5df913b872c7ae0a2638a5500f4b5f580d0aeb2a1f2","treeHash":"ad081f994b552d00bab1fb3668b857a086d82b2b647940fbbaf84bc9e2baebd3","pluginPath":"skills/agentsecops/container-hadolint","auditPayloadHash":"ed7608224d35707e8d6ffe2c6506ed59"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/agentsecops-container-hadolint/audits/10/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":4,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}