{"data":{"skill":{"slug":"agentsecops-sast-bandit","name":"sast-bandit","icon":"📦","repo":"https://github.com/AgentSecOps/SecOpsAgentKit/tree/main/skills/appsec/sast-bandit","status":"approved","author":"AgentSecOps","authorVersion":"0.1.0","skillstoreRevision":2},"audit":{"id":"36356369-c4e4-4c4b-83c1-00248aad2baa","skill_id":"a4a35343-dcc6-4de1-bf45-51cdeca54af7","version":10,"content_hash":"v3:9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2:2136f3e3934b62184785bf564e354428b51697a7b55db36586738d8b4a0fdcfc:a45a86923bb12730187410147f200c9ef0b1e97f6290826a8e5713443fb2fbfd:736b696c6c732f6167656e747365636f70732f736173742d62616e646974:0475288fd011590f8fd59d62fd41617b","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"Most static matches are false positives from configuration lists, Markdown formatting, references, and labeled vulnerable examples. Confirmed risks include unsafe eval suppression, unvalidated subprocess guidance, fragile xargs filename handling, and unsafe pickle suppression. Third-party hooks and actions also use mutable references.","remediation":[{"issue":"The examples suppress Bandit warnings around eval and pickle deserialization.","severity":"high","suggestion":"Remove these suppression examples. Use a structured parser, or enforce strict trusted-source and integrity controls when replacement is impossible."},{"issue":"A safe-labeled subprocess example accepts an unvalidated filename.","severity":"high","suggestion":"Resolve the path within an approved directory, reject traversal and option-like values, and prefer direct file APIs over cat."},{"issue":"The changed-file pipeline passes repository filenames through unsafe xargs parsing.","severity":"medium","suggestion":"Use null-delimited filenames, terminate options explicitly, and reject paths that Bandit could interpret as command options."},{"issue":"Remote hooks and actions use mutable version tags.","severity":"medium","suggestion":"Pin executable dependencies to reviewed commit hashes and use automated updates to keep those hashes current."},{"issue":"The skill references scripts/bandit_analyzer.py, but the file is absent.","severity":"low","suggestion":"Bundle and audit the script, or remove claims that depend on enhanced reporting and ticket creation."}],"risk_factor_evidence":[{"factor":"scripts","evidence":[{"file":"assets/bandit_config.yaml","line_end":204,"line_start":204},{"file":"references/cwe_owasp_mapping.md","line_end":61,"line_start":61}]},{"factor":"external_commands","evidence":[{"file":"assets/bandit_config.yaml","line_end":117,"line_start":117},{"file":"assets/bandit_config.yaml","line_end":112,"line_start":112},{"file":"assets/bandit_config.yaml","line_end":116,"line_start":116},{"file":"assets/bandit_config.yaml","line_end":112,"line_start":112},{"file":"assets/bandit_config.yaml","line_end":115,"line_start":115},{"file":"references/remediation_guide.md","line_end":187,"line_start":187},{"file":"references/remediation_guide.md","line_end":204,"line_start":204},{"file":"references/remediation_guide.md","line_end":209,"line_start":209},{"file":"references/remediation_guide.md","line_end":228,"line_start":228},{"file":"references/remediation_guide.md","line_end":169,"line_start":169},{"file":"references/remediation_guide.md","line_end":176,"line_start":176},{"file":"references/remediation_guide.md","line_end":172,"line_start":172},{"file":"SKILL.md","line_end":49,"line_start":34},{"file":"SKILL.md","line_end":57,"line_start":49},{"file":"SKILL.md","line_end":59,"line_start":57},{"file":"SKILL.md","line_end":61,"line_start":59},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":79,"line_start":63},{"file":"SKILL.md","line_end":85,"line_start":79},{"file":"SKILL.md","line_end":97,"line_start":85},{"file":"SKILL.md","line_end":110,"line_start":97},{"file":"SKILL.md","line_end":115,"line_start":110},{"file":"SKILL.md","line_end":128,"line_start":115},{"file":"SKILL.md","line_end":132,"line_start":128},{"file":"SKILL.md","line_end":132,"line_start":132},{"file":"SKILL.md","line_end":159,"line_start":140},{"file":"SKILL.md","line_end":161,"line_start":159},{"file":"SKILL.md","line_end":165,"line_start":161},{"file":"SKILL.md","line_end":173,"line_start":165},{"file":"SKILL.md","line_end":177,"line_start":173},{"file":"SKILL.md","line_end":179,"line_start":177},{"file":"SKILL.md","line_end":181,"line_start":179},{"file":"SKILL.md","line_end":183,"line_start":181},{"file":"SKILL.md","line_end":185,"line_start":183},{"file":"SKILL.md","line_end":187,"line_start":185},{"file":"SKILL.md","line_end":189,"line_start":187},{"file":"SKILL.md","line_end":191,"line_start":189},{"file":"SKILL.md","line_end":199,"line_start":191},{"file":"SKILL.md","line_end":206,"line_start":199},{"file":"SKILL.md","line_end":212,"line_start":206},{"file":"SKILL.md","line_end":219,"line_start":212},{"file":"SKILL.md","line_end":225,"line_start":219},{"file":"SKILL.md","line_end":234,"line_start":225},{"file":"SKILL.md","line_end":240,"line_start":234},{"file":"SKILL.md","line_end":247,"line_start":240},{"file":"SKILL.md","line_end":251,"line_start":247},{"file":"SKILL.md","line_end":257,"line_start":251},{"file":"SKILL.md","line_end":264,"line_start":257},{"file":"SKILL.md","line_end":265,"line_start":264},{"file":"SKILL.md","line_end":266,"line_start":265}]},{"factor":"filesystem","evidence":[{"file":"assets/bandit_config.yaml","line_end":8,"line_start":8},{"file":"assets/bandit_config.yaml","line_end":10,"line_start":10},{"file":"assets/bandit_config.yaml","line_end":12,"line_start":12},{"file":"assets/bandit_config.yaml","line_end":19,"line_start":19},{"file":"assets/bandit_config.yaml","line_end":20,"line_start":20},{"file":"assets/bandit_config.yaml","line_end":23,"line_start":23},{"file":"assets/bandit_config.yaml","line_end":27,"line_start":27},{"file":"assets/bandit_config.yaml","line_end":28,"line_start":28},{"file":"assets/bandit_config.yaml","line_end":29,"line_start":29},{"file":"assets/bandit_config.yaml","line_end":30,"line_start":30},{"file":"assets/bandit_config.yaml","line_end":31,"line_start":31},{"file":"assets/bandit_config.yaml","line_end":75,"line_start":75},{"file":"references/cwe_owasp_mapping.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":272,"line_start":272}]},{"factor":"network","evidence":[{"file":"assets/pre-commit-config.yaml","line_end":20,"line_start":20},{"file":"assets/pre-commit-config.yaml","line_end":26,"line_start":26},{"file":"assets/pre-commit-config.yaml","line_end":32,"line_start":32},{"file":"assets/pre-commit-config.yaml","line_end":39,"line_start":39},{"file":"assets/pre-commit-config.yaml","line_end":68,"line_start":68},{"file":"assets/pre-commit-config.yaml","line_end":100,"line_start":100},{"file":"assets/pre-commit-config.yaml","line_end":137,"line_start":137},{"file":"assets/pre-commit-config.yaml","line_end":144,"line_start":144},{"file":"references/remediation_guide.md","line_end":321,"line_start":321},{"file":"references/remediation_guide.md","line_end":338,"line_start":338},{"file":"references/remediation_guide.md","line_end":341,"line_start":341},{"file":"references/remediation_guide.md","line_end":344,"line_start":344},{"file":"references/remediation_guide.md","line_end":348,"line_start":348},{"file":"references/remediation_guide.md","line_end":321,"line_start":321},{"file":"references/remediation_guide.md","line_end":338,"line_start":338},{"file":"references/remediation_guide.md","line_end":341,"line_start":341},{"file":"references/remediation_guide.md","line_end":347,"line_start":347},{"file":"references/remediation_guide.md","line_end":499,"line_start":499},{"file":"references/remediation_guide.md","line_end":523,"line_start":523},{"file":"references/remediation_guide.md","line_end":526,"line_start":526},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":290,"line_start":290},{"file":"SKILL.md","line_end":301,"line_start":301},{"file":"SKILL.md","line_end":302,"line_start":302},{"file":"SKILL.md","line_end":303,"line_start":303},{"file":"SKILL.md","line_end":304,"line_start":304},{"file":"SKILL.md","line_end":305,"line_start":305}]},{"factor":"env_access","evidence":[{"file":"references/remediation_guide.md","line_end":43,"line_start":43},{"file":"references/remediation_guide.md","line_end":49,"line_start":49},{"file":"references/remediation_guide.md","line_end":50,"line_start":50},{"file":"references/remediation_guide.md","line_end":393,"line_start":393},{"file":"references/remediation_guide.md","line_end":510,"line_start":510},{"file":"references/remediation_guide.md","line_end":511,"line_start":511},{"file":"references/remediation_guide.md","line_end":518,"line_start":518},{"file":"references/remediation_guide.md","line_end":37,"line_start":37},{"file":"references/remediation_guide.md","line_end":40,"line_start":40},{"file":"references/remediation_guide.md","line_end":37,"line_start":37},{"file":"references/remediation_guide.md","line_end":40,"line_start":40},{"file":"references/remediation_guide.md","line_end":50,"line_start":50},{"file":"references/remediation_guide.md","line_end":301,"line_start":301},{"file":"references/remediation_guide.md","line_end":304,"line_start":304},{"file":"references/remediation_guide.md","line_end":393,"line_start":393},{"file":"references/remediation_guide.md","line_end":398,"line_start":398},{"file":"references/remediation_guide.md","line_end":406,"line_start":406},{"file":"references/remediation_guide.md","line_end":416,"line_start":416},{"file":"references/remediation_guide.md","line_end":518,"line_start":518}]}],"critical_findings":[],"high_findings":[{"title":"Dynamic code evaluation with eval()","locations":[{"file":"assets/bandit_config.yaml","line_end":204,"line_start":204}],"confidence":0.88,"description":"#   result = eval(safe_expression)  # nosec B307","review_kind":"capability","source_category":"scripts","source_severity":"high","confidence_reasoning":"The line is non-executable, but it presents eval() with a # nosec suppression and no validation. Copying this guidance can introduce arbitrary code execution."},{"title":"Python subprocess.run","locations":[{"file":"references/remediation_guide.md","line_end":187,"line_start":187}],"confidence":0.96,"description":"subprocess.run([\"cat\", filename], check=True, capture_output=True)","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"The example labels this call safe although filename comes directly from request.GET. An attacker can select arbitrary readable paths or inject options into cat."},{"title":"Unsafe Pickle Suppression Guidance","locations":[{"file":"SKILL.md","line_end":246,"line_start":240}],"confidence":0.97,"description":"The skill presents pickle.load on a caller-provided path as an acceptable # nosec example. A writable cache or attacker-controlled path could enable code execution.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The example directly deserializes a caller-selected file and suppresses B301 without enforcing a trusted directory, ownership, or integrity check."}],"medium_findings":[{"title":"xargs command (can execute arbitrary commands)","locations":[{"file":"SKILL.md","line_end":274,"line_start":274}],"confidence":0.94,"description":"3. Scan only changed files in CI/CD: `git diff --name-only origin/main | grep '.py$' | xargs bandit`","review_kind":"capability","source_category":"external_commands","source_severity":"medium","confidence_reasoning":"Repository-controlled filenames are passed through newline and whitespace parsing into Bandit arguments. Crafted paths can split arguments or be interpreted as Bandit options."},{"title":"Mutable Third-Party Execution References","locations":[{"file":"assets/pre-commit-config.yaml","line_end":40,"line_start":20},{"file":"assets/pre-commit-config.yaml","line_end":145,"line_start":100},{"file":"SKILL.md","line_end":154,"line_start":149}],"confidence":0.93,"description":"Pre-commit hooks and GitHub Actions execute third-party code through release tags instead of immutable commit hashes. A moved or compromised tag could execute altered code.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The cited configurations use version tags for code that runs in developer or CI environments. No immutable commit SHA or package hash is specified."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":6,"total_lines":1527,"audit_model":"codex","audited_at":"2026-07-23T06:28:32.276+00:00","created_at":"2026-07-24T04:02:28.17298+00:00","static_findings":[{"id":"scripts:assets/bandit_config.yaml:204:dynamic-code-evaluation-with-eval","file":"assets/bandit_config.yaml","pattern":"Dynamic code evaluation with eval()","snippet":"#   result = eval(safe_expression)  # nosec B307","category":"scripts","line_end":204,"severity":"high","line_start":204},{"id":"external_commands:assets/bandit_config.yaml:117:python-subprocess-run","file":"assets/bandit_config.yaml","pattern":"Python subprocess.run","snippet":"- subprocess.run","category":"external_commands","line_end":117,"severity":"high","line_start":117},{"id":"external_commands:assets/bandit_config.yaml:112:python-subprocess-popen","file":"assets/bandit_config.yaml","pattern":"Python subprocess.Popen","snippet":"# Default: ['os.system', 'subprocess.call', 'subprocess.Popen']","category":"external_commands","line_end":112,"severity":"high","line_start":112},{"id":"external_commands:assets/bandit_config.yaml:116:python-subprocess-popen","file":"assets/bandit_config.yaml","pattern":"Python subprocess.Popen","snippet":"- subprocess.Popen","category":"external_commands","line_end":116,"severity":"high","line_start":116},{"id":"external_commands:assets/bandit_config.yaml:112:python-subprocess-call","file":"assets/bandit_config.yaml","pattern":"Python subprocess.call","snippet":"# Default: ['os.system', 'subprocess.call', 'subprocess.Popen']","category":"external_commands","line_end":112,"severity":"high","line_start":112},{"id":"external_commands:assets/bandit_config.yaml:115:python-subprocess-call","file":"assets/bandit_config.yaml","pattern":"Python subprocess.call","snippet":"- subprocess.call","category":"external_commands","line_end":115,"severity":"high","line_start":115},{"id":"filesystem:assets/bandit_config.yaml:8:hidden-file-access","file":"assets/bandit_config.yaml","pattern":"Hidden file access","snippet":"- /.venv/","category":"filesystem","line_end":8,"severity":"medium","line_start":8},{"id":"filesystem:assets/bandit_config.yaml:10:hidden-file-access","file":"assets/bandit_config.yaml","pattern":"Hidden file access","snippet":"- /.env/","category":"filesystem","line_end":10,"severity":"medium","line_start":10},{"id":"filesystem:assets/bandit_config.yaml:12:hidden-file-access","file":"assets/bandit_config.yaml","pattern":"Hidden file access","snippet":"- /.virtualenv/","category":"filesystem","line_end":12,"severity":"medium","line_start":12},{"id":"filesystem:assets/bandit_config.yaml:19:hidden-file-access","file":"assets/bandit_config.yaml","pattern":"Hidden file access","snippet":"- /.pytest_cache/","category":"filesystem","line_end":19,"severity":"medium","line_start":19},{"id":"filesystem:assets/bandit_config.yaml:20:hidden-file-access","file":"assets/bandit_config.yaml","pattern":"Hidden file access","snippet":"- /.tox/","category":"filesystem","line_end":20,"severity":"medium","line_start":20},{"id":"filesystem:assets/bandit_config.yaml:23:hidden-file-access","file":"assets/bandit_config.yaml","pattern":"Hidden file access","snippet":"- /.eggs/","category":"filesystem","line_end":23,"severity":"medium","line_start":23},{"id":"filesystem:assets/bandit_config.yaml:27:hidden-file-access","file":"assets/bandit_config.yaml","pattern":"Hidden file access","snippet":"- /.git/","category":"filesystem","line_end":27,"severity":"medium","line_start":27},{"id":"filesystem:assets/bandit_config.yaml:28:hidden-file-access","file":"assets/bandit_config.yaml","pattern":"Hidden file access","snippet":"- /.svn/","category":"filesystem","line_end":28,"severity":"medium","line_start":28},{"id":"filesystem:assets/bandit_config.yaml:29:hidden-file-access","file":"assets/bandit_config.yaml","pattern":"Hidden file access","snippet":"- /.hg/","category":"filesystem","line_end":29,"severity":"medium","line_start":29},{"id":"filesystem:assets/bandit_config.yaml:30:hidden-file-access","file":"assets/bandit_config.yaml","pattern":"Hidden file access","snippet":"- /.idea/","category":"filesystem","line_end":30,"severity":"medium","line_start":30},{"id":"filesystem:assets/bandit_config.yaml:31:hidden-file-access","file":"assets/bandit_config.yaml","pattern":"Hidden file access","snippet":"- /.vscode/","category":"filesystem","line_end":31,"severity":"medium","line_start":31},{"id":"filesystem:assets/bandit_config.yaml:75:temp-file-creation","file":"assets/bandit_config.yaml","pattern":"Temp file creation","snippet":"#   - B306  # Use of mktemp","category":"filesystem","line_end":75,"severity":"low","line_start":75},{"id":"sensitive:assets/bandit_config.yaml:10:environment-file-access","file":"assets/bandit_config.yaml","pattern":"Environment file access","snippet":"- /.env/","category":"sensitive","line_end":10,"severity":"high","line_start":10},{"id":"network:assets/pre-commit-config.yaml:20:hardcoded-url","file":"assets/pre-commit-config.yaml","pattern":"Hardcoded URL","snippet":"- repo: https://github.com/psf/black","category":"network","line_end":20,"severity":"low","line_start":20},{"id":"network:assets/pre-commit-config.yaml:26:hardcoded-url","file":"assets/pre-commit-config.yaml","pattern":"Hardcoded URL","snippet":"- repo: https://github.com/pycqa/isort","category":"network","line_end":26,"severity":"low","line_start":26},{"id":"network:assets/pre-commit-config.yaml:32:hardcoded-url","file":"assets/pre-commit-config.yaml","pattern":"Hardcoded URL","snippet":"- repo: https://github.com/pycqa/flake8","category":"network","line_end":32,"severity":"low","line_start":32},{"id":"network:assets/pre-commit-config.yaml:39:hardcoded-url","file":"assets/pre-commit-config.yaml","pattern":"Hardcoded URL","snippet":"- repo: https://github.com/PyCQA/bandit","category":"network","line_end":39,"severity":"low","line_start":39},{"id":"network:assets/pre-commit-config.yaml:68:hardcoded-url","file":"assets/pre-commit-config.yaml","pattern":"Hardcoded URL","snippet":"# - repo: https://github.com/PyCQA/bandit","category":"network","line_end":68,"severity":"low","line_start":68},{"id":"network:assets/pre-commit-config.yaml:100:hardcoded-url","file":"assets/pre-commit-config.yaml","pattern":"Hardcoded URL","snippet":"- repo: https://github.com/pre-commit/pre-commit-hooks","category":"network","line_end":100,"severity":"low","line_start":100},{"id":"network:assets/pre-commit-config.yaml:137:hardcoded-url","file":"assets/pre-commit-config.yaml","pattern":"Hardcoded URL","snippet":"- repo: https://github.com/Lucas-C/pre-commit-hooks-safety","category":"network","line_end":137,"severity":"low","line_start":137},{"id":"network:assets/pre-commit-config.yaml:144:hardcoded-url","file":"assets/pre-commit-config.yaml","pattern":"Hardcoded URL","snippet":"- repo: https://github.com/Yelp/detect-secrets","category":"network","line_end":144,"severity":"low","line_start":144},{"id":"sensitive:assets/pre-commit-config.yaml:110:crypto-seed-private-key-mention","file":"assets/pre-commit-config.yaml","pattern":"Crypto seed/private key mention","snippet":"# Detect private keys","category":"sensitive","line_end":110,"severity":"high","line_start":110},{"id":"scripts:references/cwe_owasp_mapping.md:61:dynamic-import-expression","file":"references/cwe_owasp_mapping.md","pattern":"Dynamic import() expression","snippet":"| B410 | XML etree import (lxml) | CWE-611 | LOW |","category":"scripts","line_end":61,"severity":"medium","line_start":61},{"id":"filesystem:references/cwe_owasp_mapping.md:23:temp-file-creation","file":"references/cwe_owasp_mapping.md","pattern":"Temp file creation","snippet":"| B306 | Use of insecure and deprecated function (mktemp) | CWE-377 | MEDIUM |","category":"filesystem","line_end":23,"severity":"low","line_start":23},{"id":"blocker:references/cwe_owasp_mapping.md:76:system-reconnaissance","file":"references/cwe_owasp_mapping.md","pattern":"System reconnaissance","snippet":"**Remediation Strategy**: Never concatenate user input into commands, queries, or markup. Use parame","category":"blocker","line_end":76,"severity":"low","line_start":76},{"id":"blocker:references/cwe_owasp_mapping.md:102:system-reconnaissance","file":"references/cwe_owasp_mapping.md","pattern":"System reconnaissance","snippet":"**Remediation Strategy**: Avoid using pickle for untrusted data. Use JSON, MessagePack, or Protocol ","category":"blocker","line_end":102,"severity":"low","line_start":102},{"id":"external_commands:references/remediation_guide.md:187:python-subprocess-run","file":"references/remediation_guide.md","pattern":"Python subprocess.run","snippet":"subprocess.run([\"cat\", filename], check=True, capture_output=True)","category":"external_commands","line_end":187,"severity":"high","line_start":187},{"id":"external_commands:references/remediation_guide.md:204:python-subprocess-run","file":"references/remediation_guide.md","pattern":"Python subprocess.run","snippet":"subprocess.run([\"cat\", str(filename)], check=True, capture_output=True)","category":"external_commands","line_end":204,"severity":"high","line_start":204},{"id":"external_commands:references/remediation_guide.md:209:python-subprocess-run","file":"references/remediation_guide.md","pattern":"Python subprocess.run","snippet":"subprocess.run(shlex.split(command_string), check=True, capture_output=True)","category":"external_commands","line_end":209,"severity":"high","line_start":209},{"id":"external_commands:references/remediation_guide.md:228:python-subprocess-run","file":"references/remediation_guide.md","pattern":"Python subprocess.run","snippet":"subprocess.run(cmd, check=True, capture_output=True, timeout=10)","category":"external_commands","line_end":228,"severity":"high","line_start":228},{"id":"external_commands:references/remediation_guide.md:169:python-subprocess-call","file":"references/remediation_guide.md","pattern":"Python subprocess.call","snippet":"subprocess.call(f\"cat {filename}\", shell=True)","category":"external_commands","line_end":169,"severity":"high","line_start":169},{"id":"external_commands:references/remediation_guide.md:176:python-subprocess-call","file":"references/remediation_guide.md","pattern":"Python subprocess.call","snippet":"subprocess.call(cmd, shell=True)","category":"external_commands","line_end":176,"severity":"high","line_start":176},{"id":"external_commands:references/remediation_guide.md:172:python-os-system","file":"references/remediation_guide.md","pattern":"Python os.system","snippet":"os.system(f\"ping -c 1 {hostname}\")","category":"external_commands","line_end":172,"severity":"high","line_start":172},{"id":"network:references/remediation_guide.md:321:python-http-libraries","file":"references/remediation_guide.md","pattern":"Python HTTP libraries","snippet":"requests.get('https://example.com', verify=False)","category":"network","line_end":321,"severity":"low","line_start":321},{"id":"network:references/remediation_guide.md:338:python-http-libraries","file":"references/remediation_guide.md","pattern":"Python HTTP libraries","snippet":"response = requests.get('https://example.com', verify=True)","category":"network","line_end":338,"severity":"low","line_start":338},{"id":"network:references/remediation_guide.md:341:python-http-libraries","file":"references/remediation_guide.md","pattern":"Python HTTP libraries","snippet":"response = requests.get('https://example.com', verify='/path/to/ca-bundle.crt')","category":"network","line_end":341,"severity":"low","line_start":341},{"id":"network:references/remediation_guide.md:344:python-http-libraries","file":"references/remediation_guide.md","pattern":"Python HTTP libraries","snippet":"import urllib.request","category":"network","line_end":344,"severity":"low","line_start":344},{"id":"network:references/remediation_guide.md:348:python-http-libraries","file":"references/remediation_guide.md","pattern":"Python HTTP libraries","snippet":"response = urllib.request.urlopen(url, context=context, cafile=certifi.where())","category":"network","line_end":348,"severity":"low","line_start":348},{"id":"network:references/remediation_guide.md:321:hardcoded-url","file":"references/remediation_guide.md","pattern":"Hardcoded URL","snippet":"requests.get('https://example.com', verify=False)","category":"network","line_end":321,"severity":"low","line_start":321},{"id":"network:references/remediation_guide.md:338:hardcoded-url","file":"references/remediation_guide.md","pattern":"Hardcoded URL","snippet":"response = requests.get('https://example.com', verify=True)","category":"network","line_end":338,"severity":"low","line_start":338},{"id":"network:references/remediation_guide.md:341:hardcoded-url","file":"references/remediation_guide.md","pattern":"Hardcoded URL","snippet":"response = requests.get('https://example.com', verify='/path/to/ca-bundle.crt')","category":"network","line_end":341,"severity":"low","line_start":341},{"id":"network:references/remediation_guide.md:347:hardcoded-url","file":"references/remediation_guide.md","pattern":"Hardcoded URL","snippet":"url = 'https://example.com'","category":"network","line_end":347,"severity":"low","line_start":347},{"id":"network:references/remediation_guide.md:499:hardcoded-ip-address","file":"references/remediation_guide.md","pattern":"Hardcoded IP address","snippet":"app.run(debug=True, host='0.0.0.0')","category":"network","line_end":499,"severity":"medium","line_start":499},{"id":"network:references/remediation_guide.md:523:hardcoded-ip-address","file":"references/remediation_guide.md","pattern":"Hardcoded IP address","snippet":"# gunicorn -w 4 -b 0.0.0.0:8000 app:app","category":"network","line_end":523,"severity":"medium","line_start":523},{"id":"network:references/remediation_guide.md:526:hardcoded-ip-address","file":"references/remediation_guide.md","pattern":"Hardcoded IP address","snippet":"app.run(debug=DEBUG, host='127.0.0.1', port=5000)","category":"network","line_end":526,"severity":"medium","line_start":526},{"id":"env_access:references/remediation_guide.md:43:python-environment-access","file":"references/remediation_guide.md","pattern":"Python environment access","snippet":"DATABASE_PASSWORD = os.environ.get(\"DATABASE_PASSWORD\")","category":"env_access","line_end":43,"severity":"low","line_start":43},{"id":"env_access:references/remediation_guide.md:49:python-environment-access","file":"references/remediation_guide.md","pattern":"Python environment access","snippet":"host=os.environ.get(\"DB_HOST\", \"localhost\"),","category":"env_access","line_end":49,"severity":"low","line_start":49},{"id":"env_access:references/remediation_guide.md:50:python-environment-access","file":"references/remediation_guide.md","pattern":"Python environment access","snippet":"password=os.environ.get(\"DB_PASSWORD\")","category":"env_access","line_end":50,"severity":"low","line_start":50},{"id":"env_access:references/remediation_guide.md:393:python-environment-access","file":"references/remediation_guide.md","pattern":"Python environment access","snippet":"SECRET_KEY = os.environ['SECRET_KEY'].encode()","category":"env_access","line_end":393,"severity":"low","line_start":393},{"id":"env_access:references/remediation_guide.md:510:python-environment-access","file":"references/remediation_guide.md","pattern":"Python environment access","snippet":"DEBUG = os.environ.get('FLASK_DEBUG', 'false').lower() == 'true'","category":"env_access","line_end":510,"severity":"low","line_start":510},{"id":"env_access:references/remediation_guide.md:511:python-environment-access","file":"references/remediation_guide.md","pattern":"Python environment access","snippet":"ENV = os.environ.get('FLASK_ENV', 'production')","category":"env_access","line_end":511,"severity":"low","line_start":511},{"id":"env_access:references/remediation_guide.md:518:python-environment-access","file":"references/remediation_guide.md","pattern":"Python environment access","snippet":"app.config['SECRET_KEY'] = os.environ['SECRET_KEY']","category":"env_access","line_end":518,"severity":"low","line_start":518},{"id":"env_access:references/remediation_guide.md:37:dotenv-library","file":"references/remediation_guide.md","pattern":"dotenv library","snippet":"from dotenv import load_dotenv","category":"env_access","line_end":37,"severity":"low","line_start":37},{"id":"env_access:references/remediation_guide.md:40:dotenv-library","file":"references/remediation_guide.md","pattern":"dotenv library","snippet":"load_dotenv()","category":"env_access","line_end":40,"severity":"low","line_start":40},{"id":"env_access:references/remediation_guide.md:37:python-dotenv-loader","file":"references/remediation_guide.md","pattern":"Python dotenv loader","snippet":"from dotenv import load_dotenv","category":"env_access","line_end":37,"severity":"low","line_start":37},{"id":"env_access:references/remediation_guide.md:40:python-dotenv-loader","file":"references/remediation_guide.md","pattern":"Python dotenv loader","snippet":"load_dotenv()","category":"env_access","line_end":40,"severity":"low","line_start":40},{"id":"env_access:references/remediation_guide.md:50:database-connection-strings","file":"references/remediation_guide.md","pattern":"Database connection strings","snippet":"password=os.environ.get(\"DB_PASSWORD\")","category":"env_access","line_end":50,"severity":"high","line_start":50},{"id":"env_access:references/remediation_guide.md:301:generic-api-secret-keys","file":"references/remediation_guide.md","pattern":"Generic API/secret keys","snippet":"def create_signature(message: str, secret_key: bytes) -> str:","category":"env_access","line_end":301,"severity":"high","line_start":301},{"id":"env_access:references/remediation_guide.md:304:generic-api-secret-keys","file":"references/remediation_guide.md","pattern":"Generic API/secret keys","snippet":"secret_key,","category":"env_access","line_end":304,"severity":"high","line_start":304},{"id":"env_access:references/remediation_guide.md:393:generic-api-secret-keys","file":"references/remediation_guide.md","pattern":"Generic API/secret keys","snippet":"SECRET_KEY = os.environ['SECRET_KEY'].encode()","category":"env_access","line_end":393,"severity":"high","line_start":393},{"id":"env_access:references/remediation_guide.md:398:generic-api-secret-keys","file":"references/remediation_guide.md","pattern":"Generic API/secret keys","snippet":"signature = hmac.new(SECRET_KEY, pickled, hashlib.sha256).digest()","category":"env_access","line_end":398,"severity":"high","line_start":398},{"id":"env_access:references/remediation_guide.md:406:generic-api-secret-keys","file":"references/remediation_guide.md","pattern":"Generic API/secret keys","snippet":"expected_signature = hmac.new(SECRET_KEY, pickled, hashlib.sha256).digest()","category":"env_access","line_end":406,"severity":"high","line_start":406},{"id":"env_access:references/remediation_guide.md:416:generic-api-secret-keys","file":"references/remediation_guide.md","pattern":"Generic API/secret keys","snippet":"serializer = URLSafeSerializer(SECRET_KEY)","category":"env_access","line_end":416,"severity":"high","line_start":416},{"id":"env_access:references/remediation_guide.md:518:generic-api-secret-keys","file":"references/remediation_guide.md","pattern":"Generic API/secret keys","snippet":"app.config['SECRET_KEY'] = os.environ['SECRET_KEY']","category":"env_access","line_end":518,"severity":"high","line_start":518},{"id":"obfuscation:references/remediation_guide.md:369:python-pickle-deserialization-rce-risk","file":"references/remediation_guide.md","pattern":"Python pickle deserialization (RCE risk)","snippet":"user_data = pickle.loads(request.body)","category":"obfuscation","line_end":369,"severity":"critical","line_start":369},{"id":"obfuscation:references/remediation_guide.md:411:python-pickle-deserialization-rce-risk","file":"references/remediation_guide.md","pattern":"Python pickle deserialization (RCE risk)","snippet":"return pickle.loads(pickled)","category":"obfuscation","line_end":411,"severity":"critical","line_start":411},{"id":"sensitive:references/remediation_guide.md:70:environment-file-access","file":"references/remediation_guide.md","pattern":"Environment file access","snippet":"- Use environment variables with `.env` files (never commit `.env` to version control)","category":"sensitive","line_end":70,"severity":"high","line_start":70},{"id":"sensitive:references/remediation_guide.md:341:certificate-key-files","file":"references/remediation_guide.md","pattern":"Certificate/key files","snippet":"response = requests.get('https://example.com', verify='/path/to/ca-bundle.crt')","category":"sensitive","line_end":341,"severity":"high","line_start":341},{"id":"sensitive:references/remediation_guide.md:135:sqlite-database-file","file":"references/remediation_guide.md","pattern":"SQLite database file","snippet":"from django.db.models import Q","category":"sensitive","line_end":135,"severity":"medium","line_start":135},{"id":"sensitive:references/remediation_guide.md:144:sqlite-database-file","file":"references/remediation_guide.md","pattern":"SQLite database file","snippet":"from django.db import connection","category":"sensitive","line_end":144,"severity":"medium","line_start":144},{"id":"blocker:references/remediation_guide.md:251:weak-cryptographic-algorithm","file":"references/remediation_guide.md","pattern":"Weak cryptographic algorithm","snippet":"password_hash = hashlib.md5(password.encode()).hexdigest()","category":"blocker","line_end":251,"severity":"high","line_start":251},{"id":"blocker:references/remediation_guide.md:84:system-reconnaissance","file":"references/remediation_guide.md","pattern":"System reconnaissance","snippet":"user_id = request.GET['id']","category":"blocker","line_end":84,"severity":"low","line_start":84},{"id":"blocker:references/remediation_guide.md:85:system-reconnaissance","file":"references/remediation_guide.md","pattern":"System reconnaissance","snippet":"query = f\"SELECT * FROM users WHERE id = {user_id}\"","category":"blocker","line_end":85,"severity":"low","line_start":85},{"id":"blocker:references/remediation_guide.md:102:system-reconnaissance","file":"references/remediation_guide.md","pattern":"System reconnaissance","snippet":"user_id = request.GET['id']","category":"blocker","line_end":102,"severity":"low","line_start":102},{"id":"blocker:references/remediation_guide.md:103:system-reconnaissance","file":"references/remediation_guide.md","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = %s\"","category":"blocker","line_end":103,"severity":"low","line_start":103},{"id":"blocker:references/remediation_guide.md:172:system-reconnaissance","file":"references/remediation_guide.md","pattern":"System reconnaissance","snippet":"os.system(f\"ping -c 1 {hostname}\")","category":"blocker","line_end":172,"severity":"low","line_start":172},{"id":"blocker:references/remediation_guide.md:194:system-reconnaissance","file":"references/remediation_guide.md","pattern":"System reconnaissance","snippet":"raise ValueError(\"Invalid filename\")","category":"blocker","line_end":194,"severity":"low","line_start":194},{"id":"blocker:references/remediation_guide.md:223:system-reconnaissance","file":"references/remediation_guide.md","pattern":"System reconnaissance","snippet":"# Validate target (e.g., IP address or hostname)","category":"blocker","line_end":223,"severity":"low","line_start":223},{"id":"blocker:references/remediation_guide.md:225:system-reconnaissance","file":"references/remediation_guide.md","pattern":"System reconnaissance","snippet":"raise ValueError(\"Invalid target\")","category":"blocker","line_end":225,"severity":"low","line_start":225},{"id":"blocker:references/remediation_guide.md:409:system-reconnaissance","file":"references/remediation_guide.md","pattern":"System reconnaissance","snippet":"raise ValueError(\"Invalid signature - data may be tampered\")","category":"blocker","line_end":409,"severity":"low","line_start":409},{"id":"blocker:references/remediation_guide.md:426:system-reconnaissance","file":"references/remediation_guide.md","pattern":"System reconnaissance","snippet":"- Avoid pickle for untrusted data","category":"blocker","line_end":426,"severity":"low","line_start":426},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":49,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":57,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":59,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":61,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Create a configuration file `.bandit` or `.bandit.yaml` to customize scans:","category":"external_commands","line_end":61,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":79,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":85,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":97,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":110,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":115,"severity":"medium","line_start":110},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":128,"severity":"medium","line_start":115},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"For each finding, consult the bundled `references/remediation_guide.md` for secure coding patterns. ","category":"external_commands","line_end":132,"severity":"medium","line_start":128},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Command Injection (B602, B605)**: Avoid `shell=True`, use `shlex.split()` for argument parsing","category":"external_commands","line_end":132,"severity":"medium","line_start":132},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":159,"severity":"medium","line_start":140},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":161,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use the bundled script `scripts/bandit_analyzer.py` for enhanced reporting with OWASP mapping.","category":"external_commands","line_end":165,"severity":"medium","line_start":161},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Sensitive Data Handling**: Bandit reports may contain code snippets with hardcoded credentials. ","category":"external_commands","line_end":173,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **False Positives**: Review LOW confidence findings manually. Use inline `# nosec` comments sparin","category":"external_commands","line_end":177,"severity":"medium","line_start":173},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Scripts (`scripts/`)","category":"external_commands","line_end":179,"severity":"medium","line_start":177},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bandit_analyzer.py` - Enhanced Bandit wrapper that parses JSON output, maps findings to OWASP Top","category":"external_commands","line_end":181,"severity":"medium","line_start":179},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### References (`references/`)","category":"external_commands","line_end":183,"severity":"medium","line_start":181},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `remediation_guide.md` - Detailed secure coding patterns for common Bandit findings, including cod","category":"external_commands","line_end":185,"severity":"medium","line_start":183},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `cwe_owasp_mapping.md` - Complete mapping between Bandit issue codes, CWE identifiers, and OWASP T","category":"external_commands","line_end":187,"severity":"medium","line_start":185},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### Assets (`assets/`)","category":"external_commands","line_end":189,"severity":"medium","line_start":187},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `bandit_config.yaml` - Production-ready Bandit configuration with optimized test selection, exclus","category":"external_commands","line_end":191,"severity":"medium","line_start":189},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `pre-commit-config.yaml` - Pre-commit hook configuration for Bandit integration. Prevents commits ","category":"external_commands","line_end":199,"severity":"medium","line_start":191},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":206,"severity":"medium","line_start":199},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":212,"severity":"medium","line_start":206},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":219,"severity":"medium","line_start":212},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":225,"severity":"medium","line_start":219},{"id":"external_commands:SKILL.md:225:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":234,"severity":"medium","line_start":225},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":240,"severity":"medium","line_start":234},{"id":"external_commands:SKILL.md:240:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```python","category":"external_commands","line_end":247,"severity":"medium","line_start":240},{"id":"external_commands:SKILL.md:247:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":251,"severity":"medium","line_start":247},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **CI/CD**: Integrate as GitHub Actions, GitLab CI, Jenkins pipeline stage, or pre-commit hook. Use","category":"external_commands","line_end":257,"severity":"medium","line_start":251},{"id":"external_commands:SKILL.md:257:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Ticketing Integration**: Use `scripts/bandit_analyzer.py` to automatically create Jira/GitHub is","category":"external_commands","line_end":264,"severity":"medium","line_start":257},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Use confidence filtering: `bandit -r . -i` (HIGH confidence only)","category":"external_commands","line_end":265,"severity":"medium","line_start":264},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Exclude test files: `bandit -r . --exclude /tests/`","category":"external_commands","line_end":266,"severity":"medium","line_start":265},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Customize `.bandit.yaml` to skip specific tests for known safe patterns","category":"external_commands","line_end":267,"severity":"medium","line_start":266},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. Review and suppress with inline `# nosec` comments with justification","category":"external_commands","line_end":272,"severity":"medium","line_start":267},{"id":"external_commands:SKILL.md:272:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Exclude dependencies: Add `/venv/`, `/.venv/`, `/site-packages/` to `.bandit.yaml` exclude_dirs","category":"external_commands","line_end":272,"severity":"medium","line_start":272},{"id":"external_commands:SKILL.md:274:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Scan only changed files in CI/CD: `git diff --name-only origin/main | grep '.py$' | xargs bandit`","category":"external_commands","line_end":279,"severity":"medium","line_start":274},{"id":"external_commands:SKILL.md:279:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Check enabled tests: `bandit -l` (list all tests)","category":"external_commands","line_end":280,"severity":"medium","line_start":279},{"id":"external_commands:SKILL.md:280:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Ensure tests are not skipped in `.bandit.yaml`","category":"external_commands","line_end":282,"severity":"medium","line_start":280},{"id":"external_commands:SKILL.md:282:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. Update Bandit regularly: `pip install --upgrade bandit`","category":"external_commands","line_end":287,"severity":"medium","line_start":282},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Use the bundled `assets/pre-commit-config.yaml`:","category":"external_commands","line_end":289,"severity":"medium","line_start":287},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":295,"severity":"medium","line_start":289},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":297,"severity":"medium","line_start":295},{"id":"external_commands:SKILL.md:274:xargs-command-can-execute-arbitrary-commands","file":"SKILL.md","pattern":"xargs command (can execute arbitrary commands)","snippet":"3. Scan only changed files in CI/CD: `git diff --name-only origin/main | grep '.py$' | xargs bandit`","category":"external_commands","line_end":274,"severity":"medium","line_start":274},{"id":"network:SKILL.md:19:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://github.com/PyCQA/bandit","category":"network","line_end":19,"severity":"low","line_start":19},{"id":"network:SKILL.md:20:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://bandit.readthedocs.io/","category":"network","line_end":20,"severity":"low","line_start":20},{"id":"network:SKILL.md:21:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://owasp.org/www-project-top-ten/","category":"network","line_end":21,"severity":"low","line_start":21},{"id":"network:SKILL.md:290:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- repo: https://github.com/PyCQA/bandit","category":"network","line_end":290,"severity":"low","line_start":290},{"id":"network:SKILL.md:301:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Bandit Documentation](https://bandit.readthedocs.io/)","category":"network","line_end":301,"severity":"low","line_start":301},{"id":"network:SKILL.md:302:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Bandit GitHub Repository](https://github.com/PyCQA/bandit)","category":"network","line_end":302,"severity":"low","line_start":302},{"id":"network:SKILL.md:303:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [OWASP Top 10](https://owasp.org/www-project-top-ten/)","category":"network","line_end":303,"severity":"low","line_start":303},{"id":"network:SKILL.md:304:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [CWE Database](https://cwe.mitre.org/)","category":"network","line_end":304,"severity":"low","line_start":304},{"id":"network:SKILL.md:305:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Python Security Best Practices](https://python.readthedocs.io/en/stable/library/security_warnings","category":"network","line_end":305,"severity":"low","line_start":305},{"id":"filesystem:SKILL.md:68:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"- /.venv/","category":"filesystem","line_end":68,"severity":"medium","line_start":68},{"id":"filesystem:SKILL.md:272:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"1. Exclude dependencies: Add `/venv/`, `/.venv/`, `/site-packages/` to `.bandit.yaml` exclude_dirs","category":"filesystem","line_end":272,"severity":"medium","line_start":272},{"id":"blocker:SKILL.md:133:weak-cryptographic-algorithm","file":"SKILL.md","pattern":"Weak cryptographic algorithm","snippet":"- **Weak Cryptography (B303, B304)**: Replace MD5/SHA1 with SHA256/SHA512 or bcrypt for passwords","category":"blocker","line_end":133,"severity":"high","line_start":133},{"id":"blocker:SKILL.md:132:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Command Injection (B602, B605)**: Avoid `shell=True`, use `shlex.split()` for argument parsing","category":"blocker","line_end":132,"severity":"low","line_start":132},{"id":"blocker:SKILL.md:134:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- **Insecure Deserialization (B301)**: Avoid pickle, use JSON or MessagePack with schema validation","category":"blocker","line_end":134,"severity":"low","line_start":134}],"finding_verdicts":[{"id":"scripts:assets/bandit_config.yaml:204:dynamic-code-evaluation-with-eval","reason":"The line is non-executable, but it presents eval() with a # nosec suppression and no validation. Copying this guidance can introduce arbitrary code execution.","verdict":"confirmed","severity":"high","confidence":0.88},{"id":"external_commands:assets/bandit_config.yaml:117:python-subprocess-run","reason":"This YAML lists function names for Bandit's shell-injection detector. It does not invoke a subprocess or pass any command arguments.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:assets/bandit_config.yaml:112:python-subprocess-popen","reason":"This YAML lists function names for Bandit's shell-injection detector. It does not invoke a subprocess or pass any command arguments.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:assets/bandit_config.yaml:116:python-subprocess-popen","reason":"This YAML lists function names for Bandit's shell-injection detector. It does not invoke a subprocess or pass any command arguments.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:assets/bandit_config.yaml:112:python-subprocess-call","reason":"This YAML lists function names for Bandit's shell-injection detector. It does not invoke a subprocess or pass any command arguments.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:assets/bandit_config.yaml:115:python-subprocess-call","reason":"This YAML lists function names for Bandit's shell-injection detector. It does not invoke a subprocess or pass any command arguments.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:assets/bandit_config.yaml:8:hidden-file-access","reason":"This value is an exclusion pattern for a directory that Bandit should not scan. It does not read, copy, or expose hidden-file contents.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:assets/bandit_config.yaml:10:hidden-file-access","reason":"This value is an exclusion pattern for a directory that Bandit should not scan. It does not read, copy, or expose hidden-file contents.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:assets/bandit_config.yaml:12:hidden-file-access","reason":"This value is an exclusion pattern for a directory that Bandit should not scan. It does not read, copy, or expose hidden-file contents.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:assets/bandit_config.yaml:19:hidden-file-access","reason":"This value is an exclusion pattern for a directory that Bandit should not scan. It does not read, copy, or expose hidden-file contents.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:assets/bandit_config.yaml:20:hidden-file-access","reason":"This value is an exclusion pattern for a directory that Bandit should not scan. It does not read, copy, or expose hidden-file contents.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:assets/bandit_config.yaml:23:hidden-file-access","reason":"This value is an exclusion pattern for a directory that Bandit should not scan. It does not read, copy, or expose hidden-file contents.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:assets/bandit_config.yaml:27:hidden-file-access","reason":"This value is an exclusion pattern for a directory that Bandit should not scan. It does not read, copy, or expose hidden-file contents.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:assets/bandit_config.yaml:28:hidden-file-access","reason":"This value is an exclusion pattern for a directory that Bandit should not scan. It does not read, copy, or expose hidden-file contents.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:assets/bandit_config.yaml:29:hidden-file-access","reason":"This value is an exclusion pattern for a directory that Bandit should not scan. It does not read, copy, or expose hidden-file contents.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:assets/bandit_config.yaml:30:hidden-file-access","reason":"This value is an exclusion pattern for a directory that Bandit should not scan. It does not read, copy, or expose hidden-file contents.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:assets/bandit_config.yaml:31:hidden-file-access","reason":"This value is an exclusion pattern for a directory that Bandit should not scan. It does not read, copy, or expose hidden-file contents.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:assets/bandit_config.yaml:75:temp-file-creation","reason":"The line is a commented Bandit test identifier describing mktemp detection. It does not create a temporary file.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:assets/bandit_config.yaml:10:environment-file-access","reason":"The .env path is an exclusion entry, so the configuration avoids scanning that directory. No environment file is opened or read.","verdict":"false_positive","confidence":0.98},{"id":"network:assets/pre-commit-config.yaml:20:hardcoded-url","reason":"The URL identifies a declared pre-commit hook repository, not an exfiltration endpoint. The separate mutable-reference finding covers its supply-chain risk.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/pre-commit-config.yaml:26:hardcoded-url","reason":"The URL identifies a declared pre-commit hook repository, not an exfiltration endpoint. The separate mutable-reference finding covers its supply-chain risk.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/pre-commit-config.yaml:32:hardcoded-url","reason":"The URL identifies a declared pre-commit hook repository, not an exfiltration endpoint. The separate mutable-reference finding covers its supply-chain risk.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/pre-commit-config.yaml:39:hardcoded-url","reason":"The URL identifies a declared pre-commit hook repository, not an exfiltration endpoint. The separate mutable-reference finding covers its supply-chain risk.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/pre-commit-config.yaml:68:hardcoded-url","reason":"The URL identifies a declared pre-commit hook repository, not an exfiltration endpoint. The separate mutable-reference finding covers its supply-chain risk.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/pre-commit-config.yaml:100:hardcoded-url","reason":"The URL identifies a declared pre-commit hook repository, not an exfiltration endpoint. The separate mutable-reference finding covers its supply-chain risk.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/pre-commit-config.yaml:137:hardcoded-url","reason":"The URL identifies a declared pre-commit hook repository, not an exfiltration endpoint. The separate mutable-reference finding covers its supply-chain risk.","verdict":"false_positive","confidence":0.94},{"id":"network:assets/pre-commit-config.yaml:144:hardcoded-url","reason":"The URL identifies a declared pre-commit hook repository, not an exfiltration endpoint. The separate mutable-reference finding covers its supply-chain risk.","verdict":"false_positive","confidence":0.94},{"id":"sensitive:assets/pre-commit-config.yaml:110:crypto-seed-private-key-mention","reason":"The text is the identifier and comment for a hook that detects private keys. It contains no key material, seed, or credential.","verdict":"false_positive","confidence":0.98},{"id":"scripts:references/cwe_owasp_mapping.md:61:dynamic-import-expression","reason":"The line is a Markdown table row naming Bandit test B410 and lxml imports. It contains no dynamic import expression or executable code.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:references/cwe_owasp_mapping.md:23:temp-file-creation","reason":"The line documents Bandit test B306 and the mktemp weakness in a reference table. It does not create a file.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/cwe_owasp_mapping.md:76:system-reconnaissance","reason":"The matched text is defensive remediation prose about avoiding unsafe input handling. It performs no system discovery or execution.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/cwe_owasp_mapping.md:102:system-reconnaissance","reason":"The matched text is defensive remediation prose about avoiding unsafe input handling. It performs no system discovery or execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/remediation_guide.md:187:python-subprocess-run","reason":"The example labels this call safe although filename comes directly from request.GET. An attacker can select arbitrary readable paths or inject options into cat.","verdict":"confirmed","severity":"high","confidence":0.96},{"id":"external_commands:references/remediation_guide.md:204:python-subprocess-run","reason":"This educational example validates the filename and containment path before using a fixed executable with shell disabled. It is not package runtime behavior.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/remediation_guide.md:209:python-subprocess-run","reason":"This educational example splits a hardcoded command string and runs it without a shell. No untrusted command input is present.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/remediation_guide.md:228:python-subprocess-run","reason":"This educational example uses an allowlisted command, validates the target, disables shell execution, and sets a timeout. It is not package runtime behavior.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/remediation_guide.md:169:python-subprocess-call","reason":"The command appears only in a section explicitly labeled Vulnerable Code and is followed by safer alternatives. The package does not execute it.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/remediation_guide.md:176:python-subprocess-call","reason":"The command appears only in a section explicitly labeled Vulnerable Code and is followed by safer alternatives. The package does not execute it.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/remediation_guide.md:172:python-os-system","reason":"The command appears only in a section explicitly labeled Vulnerable Code and is followed by safer alternatives. The package does not execute it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/remediation_guide.md:321:python-http-libraries","reason":"The request is an explicitly labeled vulnerable TLS example used for instruction. It is not executed by the skill.","verdict":"false_positive","confidence":0.98},{"id":"network:references/remediation_guide.md:338:python-http-libraries","reason":"The HTTP call or import is a documentation example for verified TLS handling. It is not package runtime behavior or an exfiltration request.","verdict":"false_positive","confidence":0.98},{"id":"network:references/remediation_guide.md:341:python-http-libraries","reason":"The HTTP call or import is a documentation example for verified TLS handling. It is not package runtime behavior or an exfiltration request.","verdict":"false_positive","confidence":0.98},{"id":"network:references/remediation_guide.md:344:python-http-libraries","reason":"The HTTP call or import is a documentation example for verified TLS handling. It is not package runtime behavior or an exfiltration request.","verdict":"false_positive","confidence":0.98},{"id":"network:references/remediation_guide.md:348:python-http-libraries","reason":"The HTTP call or import is a documentation example for verified TLS handling. It is not package runtime behavior or an exfiltration request.","verdict":"false_positive","confidence":0.98},{"id":"network:references/remediation_guide.md:321:hardcoded-url","reason":"The example.com URL is a reserved documentation endpoint inside a TLS example. The skill does not contact it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/remediation_guide.md:338:hardcoded-url","reason":"The example.com URL is a reserved documentation endpoint inside a TLS example. The skill does not contact it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/remediation_guide.md:341:hardcoded-url","reason":"The example.com URL is a reserved documentation endpoint inside a TLS example. The skill does not contact it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/remediation_guide.md:347:hardcoded-url","reason":"The example.com URL is a reserved documentation endpoint inside a TLS example. The skill does not contact it.","verdict":"false_positive","confidence":0.98},{"id":"network:references/remediation_guide.md:499:hardcoded-ip-address","reason":"The wildcard bind is inside an explicitly labeled vulnerable Flask example. It is not an active service configuration.","verdict":"false_positive","confidence":0.98},{"id":"network:references/remediation_guide.md:523:hardcoded-ip-address","reason":"The address is part of defensive deployment guidance or a loopback development example. The skill does not open a listener.","verdict":"false_positive","confidence":0.98},{"id":"network:references/remediation_guide.md:526:hardcoded-ip-address","reason":"The address is part of defensive deployment guidance or a loopback development example. The skill does not open a listener.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:43:python-environment-access","reason":"This is a documentation example showing how an application can load configuration without hardcoding secrets. The skill does not access the host environment.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:49:python-environment-access","reason":"This is a documentation example showing how an application can load configuration without hardcoding secrets. The skill does not access the host environment.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:50:python-environment-access","reason":"This is a documentation example showing how an application can load configuration without hardcoding secrets. The skill does not access the host environment.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:393:python-environment-access","reason":"This is a documentation example showing how an application can load configuration without hardcoding secrets. The skill does not access the host environment.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:510:python-environment-access","reason":"This is a documentation example showing how an application can load configuration without hardcoding secrets. The skill does not access the host environment.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:511:python-environment-access","reason":"This is a documentation example showing how an application can load configuration without hardcoding secrets. The skill does not access the host environment.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:518:python-environment-access","reason":"This is a documentation example showing how an application can load configuration without hardcoding secrets. The skill does not access the host environment.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:37:dotenv-library","reason":"This is a documentation example showing how an application can load configuration without hardcoding secrets. The skill does not access the host environment.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:40:dotenv-library","reason":"This is a documentation example showing how an application can load configuration without hardcoding secrets. The skill does not access the host environment.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:37:python-dotenv-loader","reason":"This is a documentation example showing how an application can load configuration without hardcoding secrets. The skill does not access the host environment.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:40:python-dotenv-loader","reason":"This is a documentation example showing how an application can load configuration without hardcoding secrets. The skill does not access the host environment.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:50:database-connection-strings","reason":"The line reads a password from a named environment variable in a defensive example. It contains no connection string or credential value.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:301:generic-api-secret-keys","reason":"The identifier is a placeholder variable used in HMAC or Flask guidance. No literal secret, API key, or credential is embedded.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:304:generic-api-secret-keys","reason":"The identifier is a placeholder variable used in HMAC or Flask guidance. No literal secret, API key, or credential is embedded.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:393:generic-api-secret-keys","reason":"The identifier is a placeholder variable used in HMAC or Flask guidance. No literal secret, API key, or credential is embedded.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:398:generic-api-secret-keys","reason":"The identifier is a placeholder variable used in HMAC or Flask guidance. No literal secret, API key, or credential is embedded.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:406:generic-api-secret-keys","reason":"The identifier is a placeholder variable used in HMAC or Flask guidance. No literal secret, API key, or credential is embedded.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:416:generic-api-secret-keys","reason":"The identifier is a placeholder variable used in HMAC or Flask guidance. No literal secret, API key, or credential is embedded.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/remediation_guide.md:518:generic-api-secret-keys","reason":"The identifier is a placeholder variable used in HMAC or Flask guidance. No literal secret, API key, or credential is embedded.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:references/remediation_guide.md:369:python-pickle-deserialization-rce-risk","reason":"This call is in a section explicitly labeled Vulnerable Code and demonstrates what users should avoid. It is not executed by the package.","verdict":"false_positive","confidence":0.98},{"id":"obfuscation:references/remediation_guide.md:411:python-pickle-deserialization-rce-risk","reason":"This reference example verifies an HMAC before deserialization and is not executed by the package. The separate skill-level suppression example remains unsafe.","verdict":"false_positive","confidence":0.9},{"id":"sensitive:references/remediation_guide.md:70:environment-file-access","reason":"The sentence advises users never to commit .env files. It does not open, read, or transmit an environment file.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:references/remediation_guide.md:341:certificate-key-files","reason":"The path is a placeholder for a public CA certificate bundle used to verify TLS. It is not a private key or credential.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:references/remediation_guide.md:135:sqlite-database-file","reason":"The scanner matched the django.db module name in an ORM example. No SQLite file path or database file access is present.","verdict":"false_positive","confidence":0.98},{"id":"sensitive:references/remediation_guide.md:144:sqlite-database-file","reason":"The scanner matched the django.db module name in an ORM example. No SQLite file path or database file access is present.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/remediation_guide.md:251:weak-cryptographic-algorithm","reason":"The MD5 call is inside an explicitly labeled Vulnerable Code example and is followed by strong alternatives. It is not executed by the package.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/remediation_guide.md:84:system-reconnaissance","reason":"The matched line is defensive sample code or remediation prose. It performs no host, account, process, or network reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/remediation_guide.md:85:system-reconnaissance","reason":"The matched line is defensive sample code or remediation prose. It performs no host, account, process, or network reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/remediation_guide.md:102:system-reconnaissance","reason":"The matched line is defensive sample code or remediation prose. It performs no host, account, process, or network reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/remediation_guide.md:103:system-reconnaissance","reason":"The matched line is defensive sample code or remediation prose. It performs no host, account, process, or network reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/remediation_guide.md:172:system-reconnaissance","reason":"The matched line is defensive sample code or remediation prose. It performs no host, account, process, or network reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/remediation_guide.md:194:system-reconnaissance","reason":"The matched line is defensive sample code or remediation prose. It performs no host, account, process, or network reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/remediation_guide.md:223:system-reconnaissance","reason":"The matched line is defensive sample code or remediation prose. It performs no host, account, process, or network reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/remediation_guide.md:225:system-reconnaissance","reason":"The matched line is defensive sample code or remediation prose. It performs no host, account, process, or network reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/remediation_guide.md:409:system-reconnaissance","reason":"The matched line is defensive sample code or remediation prose. It performs no host, account, process, or network reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/remediation_guide.md:426:system-reconnaissance","reason":"The matched line is defensive sample code or remediation prose. It performs no host, account, process, or network reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:128:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:132:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:173:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:177:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:181:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:191:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:199:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:206:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:212:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:225:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:240:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:247:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:251:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:257:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:272:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:274:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:279:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:280:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:282:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:287:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","reason":"The matched backticks are Markdown code delimiters around documentation. They are not shell command substitution and the package does not execute them automatically.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:274:xargs-command-can-execute-arbitrary-commands","reason":"Repository-controlled filenames are passed through newline and whitespace parsing into Bandit arguments. Crafted paths can split arguments or be interpreted as Bandit options.","verdict":"confirmed","severity":"medium","confidence":0.94},{"id":"network:SKILL.md:19:hardcoded-url","reason":"The URL is a public Bandit, OWASP, CWE, or Python documentation reference. It is not an exfiltration endpoint and no request is made.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:20:hardcoded-url","reason":"The URL is a public Bandit, OWASP, CWE, or Python documentation reference. It is not an exfiltration endpoint and no request is made.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:21:hardcoded-url","reason":"The URL is a public Bandit, OWASP, CWE, or Python documentation reference. It is not an exfiltration endpoint and no request is made.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:290:hardcoded-url","reason":"The URL is a public Bandit, OWASP, CWE, or Python documentation reference. It is not an exfiltration endpoint and no request is made.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:301:hardcoded-url","reason":"The URL is a public Bandit, OWASP, CWE, or Python documentation reference. It is not an exfiltration endpoint and no request is made.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:302:hardcoded-url","reason":"The URL is a public Bandit, OWASP, CWE, or Python documentation reference. It is not an exfiltration endpoint and no request is made.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:303:hardcoded-url","reason":"The URL is a public Bandit, OWASP, CWE, or Python documentation reference. It is not an exfiltration endpoint and no request is made.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:304:hardcoded-url","reason":"The URL is a public Bandit, OWASP, CWE, or Python documentation reference. It is not an exfiltration endpoint and no request is made.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:305:hardcoded-url","reason":"The URL is a public Bandit, OWASP, CWE, or Python documentation reference. It is not an exfiltration endpoint and no request is made.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:68:hidden-file-access","reason":"The hidden directory name is presented as a Bandit exclusion pattern. The skill does not read hidden files.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:272:hidden-file-access","reason":"The hidden directory name is presented as a Bandit exclusion pattern. The skill does not read hidden files.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:133:weak-cryptographic-algorithm","reason":"The text warns users to replace MD5 and SHA1 with stronger choices. It does not implement or endorse weak cryptography.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:132:system-reconnaissance","reason":"The line is defensive guidance against command injection or insecure deserialization. It does not gather system information.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:134:system-reconnaissance","reason":"The line is defensive guidance against command injection or insecure deserialization. It does not gather system information.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[{"title":"Unsafe Pickle Suppression Guidance","severity":"high","locations":[{"file":"SKILL.md","line_end":246,"line_start":240}],"confidence":0.97,"description":"The skill presents pickle.load on a caller-provided path as an acceptable # nosec example. A writable cache or attacker-controlled path could enable code execution.","confidence_reasoning":"The example directly deserializes a caller-selected file and suppresses B301 without enforcing a trusted directory, ownership, or integrity check."},{"title":"Mutable Third-Party Execution References","severity":"medium","locations":[{"file":"assets/pre-commit-config.yaml","line_end":40,"line_start":20},{"file":"assets/pre-commit-config.yaml","line_end":145,"line_start":100},{"file":"SKILL.md","line_end":154,"line_start":149}],"confidence":0.93,"description":"Pre-commit hooks and GitHub Actions execute third-party code through release tags instead of immutable commit hashes. A moved or compromised tag could execute altered code.","confidence_reasoning":"The cited configurations use version tags for code that runs in developer or CI environments. No immutable commit SHA or package hash is specified."}],"subject_marketplace_commit_sha":"9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2","subject_content_hash":"2136f3e3934b62184785bf564e354428b51697a7b55db36586738d8b4a0fdcfc","subject_tree_hash":"a45a86923bb12730187410147f200c9ef0b1e97f6290826a8e5713443fb2fbfd","subject_plugin_path":"skills/agentsecops/sast-bandit","audit_payload_hash":"0475288fd011590f8fd59d62fd41617b","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"9e952417e76879bc9d853e1b8b2cd6d6d8d4a1c2","contentHash":"2136f3e3934b62184785bf564e354428b51697a7b55db36586738d8b4a0fdcfc","treeHash":"a45a86923bb12730187410147f200c9ef0b1e97f6290826a8e5713443fb2fbfd","pluginPath":"skills/agentsecops/sast-bandit","auditPayloadHash":"0475288fd011590f8fd59d62fd41617b"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/agentsecops-sast-bandit/audits/10/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":2,"capabilityReviewCount":3,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}