{"data":{"skill":{"slug":"amirtaherkhani-nestjs-code-audit","name":"nestjs-code-audit","icon":"📦","repo":"https://github.com/amirtaherkhani/nestjs-skills/tree/b82cdf0312e1c1bcaf871bb67473e91b2a1befad/skills/nestjs-code-audit","status":"approved","author":"amirtaherkhani","authorVersion":"1.0.3","skillstoreRevision":1},"audit":{"id":"374f9c9f-376a-4c7b-96f2-6ca17c1cacf6","skill_id":"3a99de39-2352-4d77-bc35-3671b845b850","version":1,"content_hash":"v3:c97a1862d1bc82763903ee068cd15acab35d638c:e8f4efa23f0feafd124b09551ce454600e428fbf8ef532b1a4d0ece5f6bbb8c0:75f4d2811777c63447ef55365e2066d398fb3e4d7b9d260673fc38f1de3329aa:736b696c6c732f616d697274616865726b68616e692f6e6573746a732d636f64652d6175646974:4fc425fcc488321657db4f37cc281353","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Most static findings match Markdown, JavaScript strings, or ordinary repository inspection rather than threats. Optional checks execute repository-controlled tooling and pass inherited environment variables, creating execution and credential exposure risks. No evidence found of intentional exfiltration or prompt injection in the reviewed files.","remediation":[{"issue":"The optional check runner trusts local executable names without isolating binaries, ESLint configuration, or plugins.","severity":"high","suggestion":"Require explicit trust approval or sandbox checks without network access and with read-only repository mounts; inspect executable targets and ESLint configuration."},{"issue":"Optional checks inherit all parent environment variables, including any available credentials.","severity":"medium","suggestion":"Pass a minimal environment allowlist and remove credentials and runtime injection variables before executing project tooling."}],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"references/check-policy.md","line_end":7,"line_start":7},{"file":"scripts/collect-quality-evidence.mjs","line_end":7,"line_start":7},{"file":"scripts/collect-quality-evidence.mjs","line_end":134,"line_start":134},{"file":"scripts/collect-quality-evidence.mjs","line_end":192,"line_start":192}]},{"factor":"external_commands","evidence":[{"file":"references/report-template.md","line_end":20,"line_start":19},{"file":"references/report-template.md","line_end":21,"line_start":20},{"file":"references/report-template.md","line_end":39,"line_start":21},{"file":"references/report-template.md","line_end":40,"line_start":39},{"file":"references/report-template.md","line_end":60,"line_start":40},{"file":"scripts/collect-quality-evidence.mjs","line_end":3,"line_start":3},{"file":"scripts/collect-quality-evidence.mjs","line_end":234,"line_start":234},{"file":"scripts/collect-quality-evidence.mjs","line_end":295,"line_start":295},{"file":"scripts/collect-quality-evidence.mjs","line_end":296,"line_start":296},{"file":"scripts/collect-quality-evidence.mjs","line_end":297,"line_start":297},{"file":"scripts/collect-quality-evidence.mjs","line_end":79,"line_start":79},{"file":"scripts/collect-quality-evidence.mjs","line_end":97,"line_start":97},{"file":"scripts/collect-quality-evidence.mjs","line_end":121,"line_start":121},{"file":"scripts/collect-quality-evidence.mjs","line_end":129,"line_start":129},{"file":"scripts/collect-quality-evidence.mjs","line_end":136,"line_start":136},{"file":"scripts/collect-quality-evidence.mjs","line_end":213,"line_start":213},{"file":"scripts/collect-quality-evidence.mjs","line_end":221,"line_start":221},{"file":"scripts/collect-quality-evidence.mjs","line_end":230,"line_start":230},{"file":"scripts/collect-quality-evidence.mjs","line_end":249,"line_start":249},{"file":"scripts/collect-quality-evidence.mjs","line_end":270,"line_start":270},{"file":"scripts/collect-quality-evidence.mjs","line_end":315,"line_start":315},{"file":"scripts/collect-quality-evidence.mjs","line_end":319,"line_start":319},{"file":"scripts/collect-quality-evidence.mjs","line_end":323,"line_start":323},{"file":"scripts/collect-quality-evidence.mjs","line_end":324,"line_start":324},{"file":"scripts/collect-quality-evidence.mjs","line_end":326,"line_start":326},{"file":"scripts/collect-quality-evidence.mjs","line_end":398,"line_start":398},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":49,"line_start":44},{"file":"SKILL.md","line_end":53,"line_start":49},{"file":"SKILL.md","line_end":56,"line_start":53},{"file":"SKILL.md","line_end":58,"line_start":56},{"file":"SKILL.md","line_end":64,"line_start":58},{"file":"SKILL.md","line_end":65,"line_start":64},{"file":"SKILL.md","line_end":66,"line_start":65},{"file":"SKILL.md","line_end":67,"line_start":66},{"file":"SKILL.md","line_end":68,"line_start":67},{"file":"SKILL.md","line_end":69,"line_start":68},{"file":"SKILL.md","line_end":70,"line_start":69},{"file":"SKILL.md","line_end":72,"line_start":70},{"file":"SKILL.md","line_end":79,"line_start":72},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":88,"line_start":80},{"file":"SKILL.md","line_end":90,"line_start":88},{"file":"SKILL.md","line_end":92,"line_start":90},{"file":"SKILL.md","line_end":96,"line_start":92}]},{"factor":"env_access","evidence":[{"file":"references/report-template.md","line_end":47,"line_start":47},{"file":"scripts/collect-quality-evidence.mjs","line_end":237,"line_start":237}]}],"critical_findings":[],"high_findings":[{"title":"Synchronous spawn","locations":[{"file":"scripts/collect-quality-evidence.mjs","line_end":234,"line_start":234}],"confidence":0.96,"description":"const result = spawnSync(command, args, {","review_kind":"capability","source_category":"external_commands","source_severity":"high","confidence_reasoning":"With --run, this executes repository-local binaries and ESLint configuration or plugins without isolation. Non-fixing flags do not prevent malicious tooling from writing files or making network requests."}],"medium_findings":[{"title":"Environment variable object","locations":[{"file":"scripts/collect-quality-evidence.mjs","line_end":237,"line_start":237}],"confidence":0.96,"description":"env: { ...process.env, CI: '1', FORCE_COLOR: '0', NO_COLOR: '1' },","review_kind":"capability","source_category":"env_access","source_severity":"low","confidence_reasoning":"The runner copies every parent environment variable into repository-controlled tools and ESLint plugins. Any inherited credentials become available to that executable code."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":8,"total_lines":839,"audit_model":"codex","audited_at":"2026-10-04T20:33:07.717+00:00","created_at":"2026-10-05T12:54:22.368815+00:00","static_findings":[{"id":"filesystem:references/check-policy.md:7:hidden-file-access","file":"references/check-policy.md","pattern":"Hidden file access","snippet":"The collector may invoke only local executables already present under `node_modules/.bin`:","category":"filesystem","line_end":7,"severity":"medium","line_start":7},{"id":"blocker:references/check-policy.md:33:system-reconnaissance","file":"references/check-policy.md","pattern":"System reconnaissance","snippet":"4. classify the gate as invalid until rerun safely.","category":"blocker","line_end":33,"severity":"low","line_start":33},{"id":"blocker:references/finding-ownership.md:20:system-reconnaissance","file":"references/finding-ownership.md","pattern":"System reconnaissance","snippet":"- Fifty lint diagnostics caused by one invalid parser configuration are one toolchain configuration ","category":"blocker","line_end":20,"severity":"low","line_start":20},{"id":"external_commands:references/report-template.md:19:ruby-shell-backtick-execution","file":"references/report-template.md","pattern":"Ruby/shell backtick execution","snippet":"| TypeScript/syntax | pass/fail/not run | `<command>` or reason |","category":"external_commands","line_end":20,"severity":"medium","line_start":19},{"id":"external_commands:references/report-template.md:20:ruby-shell-backtick-execution","file":"references/report-template.md","pattern":"Ruby/shell backtick execution","snippet":"| Lint | pass/fail/not run | `<command>` or reason |","category":"external_commands","line_end":21,"severity":"medium","line_start":20},{"id":"external_commands:references/report-template.md:21:ruby-shell-backtick-execution","file":"references/report-template.md","pattern":"Ruby/shell backtick execution","snippet":"| Tests | pass/fail/not run | `<command>` or reason |","category":"external_commands","line_end":39,"severity":"medium","line_start":21},{"id":"external_commands:references/report-template.md:39:ruby-shell-backtick-execution","file":"references/report-template.md","pattern":"Ruby/shell backtick execution","snippet":"- Owner: `nestjs-architecture-principles`","category":"external_commands","line_end":40,"severity":"medium","line_start":39},{"id":"external_commands:references/report-template.md:40:ruby-shell-backtick-execution","file":"references/report-template.md","pattern":"Ruby/shell backtick execution","snippet":"- Evidence: `src/example/example.service.ts:42` plus import/call path or diagnostic","category":"external_commands","line_end":60,"severity":"medium","line_start":40},{"id":"env_access:references/report-template.md:47:configuration-library","file":"references/report-template.md","pattern":"Configuration library","snippet":"| Candidate | Why unconfirmed | Smallest next check |","category":"env_access","line_end":47,"severity":"low","line_start":47},{"id":"blocker:references/semantic-review.md:17:system-reconnaissance","file":"references/semantic-review.md","pattern":"System reconnaissance","snippet":"Trace input through actual pipes/DTO transformation, guards, handlers, filters, and response mapping","category":"blocker","line_end":17,"severity":"low","line_start":17},{"id":"external_commands:scripts/collect-quality-evidence.mjs:3:node-js-child-process-module","file":"scripts/collect-quality-evidence.mjs","pattern":"Node.js child_process module","snippet":"import { spawnSync } from 'node:child_process';","category":"external_commands","line_end":3,"severity":"high","line_start":3},{"id":"external_commands:scripts/collect-quality-evidence.mjs:234:synchronous-spawn","file":"scripts/collect-quality-evidence.mjs","pattern":"Synchronous spawn","snippet":"const result = spawnSync(command, args, {","category":"external_commands","line_end":234,"severity":"high","line_start":234},{"id":"external_commands:scripts/collect-quality-evidence.mjs:295:synchronous-spawn","file":"scripts/collect-quality-evidence.mjs","pattern":"Synchronous spawn","snippet":"const branch = spawnSync('git', ['branch', '--show-current'], { cwd: root, encoding: 'utf8' });","category":"external_commands","line_end":295,"severity":"high","line_start":295},{"id":"external_commands:scripts/collect-quality-evidence.mjs:296:synchronous-spawn","file":"scripts/collect-quality-evidence.mjs","pattern":"Synchronous spawn","snippet":"const revision = spawnSync('git', ['rev-parse', '--short', 'HEAD'], { cwd: root, encoding: 'utf8' })","category":"external_commands","line_end":296,"severity":"high","line_start":296},{"id":"external_commands:scripts/collect-quality-evidence.mjs:297:synchronous-spawn","file":"scripts/collect-quality-evidence.mjs","pattern":"Synchronous spawn","snippet":"const status = spawnSync('git', ['status', '--short'], { cwd: root, encoding: 'utf8' });","category":"external_commands","line_end":297,"severity":"high","line_start":297},{"id":"external_commands:scripts/collect-quality-evidence.mjs:79:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"process.stderr.write(`${message}\\n`);","category":"external_commands","line_end":79,"severity":"medium","line_start":79},{"id":"external_commands:scripts/collect-quality-evidence.mjs:97:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"if (!value) fail(`Missing value for ${argument}.`);","category":"external_commands","line_end":97,"severity":"medium","line_start":97},{"id":"external_commands:scripts/collect-quality-evidence.mjs:121:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"fail(`Unknown argument: ${argument}`);","category":"external_commands","line_end":121,"severity":"medium","line_start":121},{"id":"external_commands:scripts/collect-quality-evidence.mjs:129:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"return candidate === root || candidate.startsWith(`${root}${sep}`);","category":"external_commands","line_end":129,"severity":"medium","line_start":129},{"id":"external_commands:scripts/collect-quality-evidence.mjs:136:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"fail(`Cannot parse ${label} at ${path}: ${error.message}`);","category":"external_commands","line_end":136,"severity":"medium","line_start":136},{"id":"external_commands:scripts/collect-quality-evidence.mjs:213:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"const path = join(root, 'node_modules', '.bin', `${name}${suffix}`);","category":"external_commands","line_end":213,"severity":"medium","line_start":213},{"id":"external_commands:scripts/collect-quality-evidence.mjs:221:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"return `${normalized.slice(0, MAX_OUTPUT_CHARS)}\\n[output truncated]`;","category":"external_commands","line_end":221,"severity":"medium","line_start":221},{"id":"external_commands:scripts/collect-quality-evidence.mjs:230:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"reason: `Local ${id === 'lint' ? 'ESLint' : 'TypeScript'} executable is unavailable; dependencies we","category":"external_commands","line_end":230,"severity":"medium","line_start":230},{"id":"external_commands:scripts/collect-quality-evidence.mjs:249:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"reason: `Timed out after ${timeoutMs} ms.`,","category":"external_commands","line_end":249,"severity":"medium","line_start":249},{"id":"external_commands:scripts/collect-quality-evidence.mjs:270:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"&& /TS(?:6310|6379)|may not disable incremental compilation|Referenced project .* may not disable em","category":"external_commands","line_end":270,"severity":"medium","line_start":270},{"id":"external_commands:scripts/collect-quality-evidence.mjs:315:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"fail(`Repository root does not exist or is not a directory: ${requestedRoot}`);","category":"external_commands","line_end":315,"severity":"medium","line_start":315},{"id":"external_commands:scripts/collect-quality-evidence.mjs:319:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"if (!existsSync(manifestPath)) fail(`No package.json found at repository root: ${root}`);","category":"external_commands","line_end":319,"severity":"medium","line_start":319},{"id":"external_commands:scripts/collect-quality-evidence.mjs:323:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"if (!insideRoot(root, unresolvedScope)) fail(`Scope escapes repository root: ${options.scope}`);","category":"external_commands","line_end":323,"severity":"medium","line_start":323},{"id":"external_commands:scripts/collect-quality-evidence.mjs:324:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"if (!existsSync(unresolvedScope)) fail(`Scope does not exist: ${options.scope}`);","category":"external_commands","line_end":324,"severity":"medium","line_start":324},{"id":"external_commands:scripts/collect-quality-evidence.mjs:326:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"if (!insideRoot(root, scopePath)) fail(`Scope resolves outside repository root: ${options.scope}`);","category":"external_commands","line_end":326,"severity":"medium","line_start":326},{"id":"external_commands:scripts/collect-quality-evidence.mjs:398:ruby-shell-backtick-execution","file":"scripts/collect-quality-evidence.mjs","pattern":"Ruby/shell backtick execution","snippet":"process.stdout.write(`${JSON.stringify(output, null, 2)}\\n`);","category":"external_commands","line_end":398,"severity":"medium","line_start":398},{"id":"filesystem:scripts/collect-quality-evidence.mjs:7:synchronous-file-operations","file":"scripts/collect-quality-evidence.mjs","pattern":"Synchronous file operations","snippet":"readFileSync,","category":"filesystem","line_end":7,"severity":"medium","line_start":7},{"id":"filesystem:scripts/collect-quality-evidence.mjs:134:synchronous-file-operations","file":"scripts/collect-quality-evidence.mjs","pattern":"Synchronous file operations","snippet":"return JSON.parse(readFileSync(path, 'utf8'));","category":"filesystem","line_end":134,"severity":"medium","line_start":134},{"id":"filesystem:scripts/collect-quality-evidence.mjs:192:synchronous-file-operations","file":"scripts/collect-quality-evidence.mjs","pattern":"Synchronous file operations","snippet":"const lines = readFileSync(file, 'utf8').split(/\\r?\\n/);","category":"filesystem","line_end":192,"severity":"medium","line_start":192},{"id":"env_access:scripts/collect-quality-evidence.mjs:237:environment-variable-object","file":"scripts/collect-quality-evidence.mjs","pattern":"Environment variable object","snippet":"env: { ...process.env, CI: '1', FORCE_COLOR: '0', NO_COLOR: '1' },","category":"env_access","line_end":237,"severity":"low","line_start":237},{"id":"obfuscation:scripts/collect-quality-evidence.mjs:219:unicode-escape-sequence","file":"scripts/collect-quality-evidence.mjs","pattern":"Unicode escape sequence","snippet":"const normalized = value.toString().replace(/\\u001b\\[[0-9;]*m/g, '').trim();","category":"obfuscation","line_end":219,"severity":"low","line_start":219},{"id":"sensitive:scripts/collect-quality-evidence.mjs:237:environment-file-access","file":"scripts/collect-quality-evidence.mjs","pattern":"Environment file access","snippet":"env: { ...process.env, CI: '1', FORCE_COLOR: '0', NO_COLOR: '1' },","category":"sensitive","line_end":237,"severity":"high","line_start":237},{"id":"sensitive:scripts/collect-quality-evidence.mjs:337:certificate-key-files","file":"scripts/collect-quality-evidence.mjs","pattern":"Certificate/key files","snippet":"const scriptNames = Object.keys(manifest.scripts ?? {}).sort();","category":"sensitive","line_end":337,"severity":"high","line_start":337},{"id":"blocker:scripts/collect-quality-evidence.mjs:230:system-reconnaissance","file":"scripts/collect-quality-evidence.mjs","pattern":"System reconnaissance","snippet":"reason: `Local ${id === 'lint' ? 'ESLint' : 'TypeScript'} executable is unavailable; dependencies we","category":"blocker","line_end":230,"severity":"low","line_start":230},{"id":"blocker:scripts/collect-quality-evidence.mjs:269:system-reconnaissance","file":"scripts/collect-quality-evidence.mjs","pattern":"System reconnaissance","snippet":"const safeTypecheckUnsupported = id === 'typescript'","category":"blocker","line_end":269,"severity":"low","line_start":269},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-architecture-principles`: module, dependency, data, and transaction boundaries.","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-oop-design-patterns`: object responsibilities, invariants, and patterns.","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-features-performance`: lifecycle, API/security, testing, runtime, and performance.","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-professional-software-engineering`: implementation and verification.","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-feature-audit`: branch-specific roadmap gate and feature reporting.","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-git-commit-pr-message`: authorized Git publication and CI follow-up.","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```text","category":"external_commands","line_end":49,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":53,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```text","category":"external_commands","line_end":56,"severity":"medium","line_start":53},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":58,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Codex does not provide arbitrary bare user-defined commands such as `/Nestjs audit`; keep the suppor","category":"external_commands","line_end":64,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `full` (default) | Safe static gates plus architecture, object design, runtime, security, testing,","category":"external_commands","line_end":65,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `static` | Syntax, TypeScript, lint, configuration, and directly related toolchain failures |","category":"external_commands","line_end":66,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `architecture` | Modules, dependencies, data/write ownership, transactions, events, ports, and ser","category":"external_commands","line_end":67,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `design` | Responsibilities, invariants, coupling, abstractions, patterns, and refactoring risks |","category":"external_commands","line_end":68,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `runtime` | Nest lifecycle, API/errors, reliability, performance evidence, health, shutdown, and d","category":"external_commands","line_end":69,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `security` | Input, identity/access, tenant isolation, secrets, output, abuse controls, and securi","category":"external_commands","line_end":70,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `tests` | Test-layer choice, missing boundary coverage, flaky lifecycle risks, and safely runnable","category":"external_commands","line_end":72,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"An optional repository-relative scope follows the action. If the first argument is not a recognized ","category":"external_commands","line_end":79,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Read `AGENTS.md` and other repository instructions, `package.json`, lockfiles, `nest-cli.json`, T","category":"external_commands","line_end":79,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Verify that `@nestjs/core` is declared or that the repository is clearly a NestJS workspace. If n","category":"external_commands","line_end":88,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":90,"severity":"medium","line_start":88},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":92,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Add `--scope <relative-path>` when the user requested a narrower audit. The collector:","category":"external_commands","line_end":96,"severity":"medium","line_start":92},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- runs only allow-listed, non-fixing ESLint and `tsc --noEmit` commands when `--run` is present;","category":"external_commands","line_end":96,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If dependencies are missing or a command is unsafe, unavailable, timed out, or outside scope, record","category":"external_commands","line_end":126,"severity":"medium","line_start":100},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- a stable ID: `TOOL`, `ARCH`, `OOP`, `RUN`, `SEC`, or `TEST` plus a number;","category":"external_commands","line_end":126,"severity":"medium","line_start":126},{"id":"blocker:SKILL.md:104:network-reconnaissance","file":"SKILL.md","pattern":"Network reconnaissance","snippet":"#### Toolchain correctness","category":"blocker","line_end":106,"severity":"low","line_start":104}],"finding_verdicts":[{"id":"filesystem:references/check-policy.md:7:hidden-file-access","reason":"The hidden directory is node_modules/.bin, a conventional local tool location. This prose does not request hidden credential or personal file access.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/check-policy.md:33:system-reconnaissance","reason":"The instruction invalidates a check that changed files. It does not collect system information or invoke reconnaissance commands.","verdict":"false_positive","confidence":1},{"id":"blocker:references/finding-ownership.md:20:system-reconnaissance","reason":"This sentence explains deduplication of lint diagnostics caused by invalid configuration. No system reconnaissance occurs.","verdict":"false_positive","confidence":1},{"id":"external_commands:references/report-template.md:19:ruby-shell-backtick-execution","reason":"Backticks format a command placeholder within a Markdown report table. They are not executable shell syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:references/report-template.md:20:ruby-shell-backtick-execution","reason":"The lint row contains an inline Markdown placeholder for recorded evidence. Nothing here executes a command.","verdict":"false_positive","confidence":1},{"id":"external_commands:references/report-template.md:21:ruby-shell-backtick-execution","reason":"This report template records a test command or a reason for omission. Markdown backticks do not cause execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:references/report-template.md:39:ruby-shell-backtick-execution","reason":"The inline code span names a finding owner. It is a skill identifier, not a shell command.","verdict":"false_positive","confidence":1},{"id":"external_commands:references/report-template.md:40:ruby-shell-backtick-execution","reason":"The backticks format an illustrative evidence location in a report. This text does not read or execute the referenced example.","verdict":"false_positive","confidence":1},{"id":"env_access:references/report-template.md:47:configuration-library","reason":"The line is a table heading for unconfirmed findings. It contains no configuration library call or environment access.","verdict":"false_positive","confidence":1},{"id":"blocker:references/semantic-review.md:17:system-reconnaissance","reason":"The guidance reviews request parsing and authorization behavior in the target application. It does not enumerate the host system.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:scripts/collect-quality-evidence.mjs:3:node-js-child-process-module","reason":"Importing spawnSync does not itself execute code. The unsafe trust boundary in the optional runner is adjudicated separately at its execution call.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:scripts/collect-quality-evidence.mjs:234:synchronous-spawn","reason":"With --run, this executes repository-local binaries and ESLint configuration or plugins without isolation. Non-fixing flags do not prevent malicious tooling from writing files or making network requests.","verdict":"confirmed","confidence":0.96},{"id":"external_commands:scripts/collect-quality-evidence.mjs:295:synchronous-spawn","reason":"Git receives fixed arguments to report the current branch. No user text is interpolated into a shell command.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:scripts/collect-quality-evidence.mjs:296:synchronous-spawn","reason":"Git receives fixed rev-parse arguments to record revision metadata. This is expected local audit evidence collection without shell interpolation.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:scripts/collect-quality-evidence.mjs:297:synchronous-spawn","reason":"The fixed git status command records existing changes without requesting mutation. No evidence found of malicious Git configuration in the reviewed skill.","verdict":"false_positive","confidence":0.9},{"id":"external_commands:scripts/collect-quality-evidence.mjs:79:ruby-shell-backtick-execution","reason":"This JavaScript template literal formats a stderr message. It is not shell command substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:97:ruby-shell-backtick-execution","reason":"The template literal produces an argument validation error. Its contents are not executed.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:121:ruby-shell-backtick-execution","reason":"Unknown arguments are rejected with a formatted error message. Backticks are JavaScript string syntax, not shell execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:129:ruby-shell-backtick-execution","reason":"The template literal constructs a repository path prefix for a containment comparison. No external command is invoked.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:136:ruby-shell-backtick-execution","reason":"This template literal describes a JSON parsing failure. It is only passed to the local error reporter.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:213:ruby-shell-backtick-execution","reason":"JavaScript interpolation builds a local binary filename. The backticks themselves do not execute a shell command.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:221:ruby-shell-backtick-execution","reason":"The template literal appends an output truncation notice. It does not execute captured output.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:230:ruby-shell-backtick-execution","reason":"This string explains why an unavailable local check was not run. It does not execute commands or install dependencies.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:249:ruby-shell-backtick-execution","reason":"The backticks format a timeout explanation in the result object. They are not executable shell syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:270:ruby-shell-backtick-execution","reason":"A template literal combines stdout and stderr for diagnostic matching. Captured text is tested by a regular expression, not executed.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:315:ruby-shell-backtick-execution","reason":"This is a formatted validation error for a missing repository root. No shell command is constructed.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:319:ruby-shell-backtick-execution","reason":"The template literal reports a missing package manifest. It is printed as an error rather than executed.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:323:ruby-shell-backtick-execution","reason":"The code rejects a scope outside the repository and formats an error. Backticks here are ordinary JavaScript string delimiters.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:324:ruby-shell-backtick-execution","reason":"A missing scope triggers a local validation error. The argument appears only in a message, not in shell syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:326:ruby-shell-backtick-execution","reason":"This error rejects a resolved scope that escapes the repository. JavaScript interpolation does not execute the scope value.","verdict":"false_positive","confidence":1},{"id":"external_commands:scripts/collect-quality-evidence.mjs:398:ruby-shell-backtick-execution","reason":"The template literal writes serialized audit evidence to stdout with a newline. It performs no command substitution.","verdict":"false_positive","confidence":1},{"id":"filesystem:scripts/collect-quality-evidence.mjs:7:synchronous-file-operations","reason":"This imports a file-reading API used for repository manifests and bounded source inspection. The collector imports no file-writing API.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:scripts/collect-quality-evidence.mjs:134:synchronous-file-operations","reason":"The caller uses this helper to parse the target repository package manifest. This read supports project identification and does not transmit file contents.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:scripts/collect-quality-evidence.mjs:192:synchronous-file-operations","reason":"The collector reads selected TypeScript files after scoped traversal with file limits and symlink skipping. It reports heuristic locations rather than exporting source contents.","verdict":"false_positive","confidence":0.98},{"id":"env_access:scripts/collect-quality-evidence.mjs:237:environment-variable-object","reason":"The runner copies every parent environment variable into repository-controlled tools and ESLint plugins. Any inherited credentials become available to that executable code.","verdict":"confirmed","severity":"medium","confidence":0.96},{"id":"obfuscation:scripts/collect-quality-evidence.mjs:219:unicode-escape-sequence","reason":"The Unicode escape matches ANSI escape sequences to remove terminal color codes. It does not conceal or decode an executable payload.","verdict":"false_positive","confidence":1},{"id":"sensitive:scripts/collect-quality-evidence.mjs:237:environment-file-access","reason":"process.env is an in-memory environment object, not an environment file read. The actual inherited-environment exposure is retained under the env_access finding.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:scripts/collect-quality-evidence.mjs:337:certificate-key-files","reason":"Object.keys enumerates package script names. It does not access certificate files, private keys, or credential material.","verdict":"false_positive","confidence":1},{"id":"blocker:scripts/collect-quality-evidence.mjs:230:system-reconnaissance","reason":"The result explains that an expected local quality executable is unavailable. It does not enumerate system services or hardware.","verdict":"false_positive","confidence":1},{"id":"blocker:scripts/collect-quality-evidence.mjs:269:system-reconnaissance","reason":"This boolean selects handling for incompatible TypeScript configuration. It performs no host reconnaissance.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"The Markdown code span names an optional architecture skill. It is not executable command substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The backticks format an optional design skill identifier. No shell execution is specified.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"This inline Markdown span identifies an optional runtime review skill. It does not invoke a subprocess.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The line lists implementation ownership using a formatted skill name. It does not authorize or execute implementation commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The code span names an optional feature audit workflow. It is descriptive Markdown, not shell syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The line identifies ownership of separately authorized Git publication. It neither invokes that workflow nor grants publication permission during this audit.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"Triple backticks open a text block containing skill invocation examples. They are Markdown delimiters, not shell execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The line closes a Markdown text fence. No command is executed by the delimiter.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:53:ruby-shell-backtick-execution","reason":"This fence introduces examples of an optional custom prompt alias. It is document formatting rather than executable shell syntax.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The line closes the custom prompt example block. Markdown backticks do not launch commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"An inline span illustrates an unsupported invocation alias. The sentence explicitly warns against treating that alias as available.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"Backticks format the full review mode in an action table. They do not execute review commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The static label is a documented mode name. This table row contains no executable command substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The inline architecture label describes review coverage. It is Markdown text rather than a shell command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The design code span is a mode identifier in documentation. It does not execute code.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The runtime mode name is formatted with Markdown backticks. No subprocess invocation occurs in this row.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The security label describes an audit lane. Markdown formatting is not shell command substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The tests mode label describes test review coverage. It does not automatically execute tests.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"The inline full label documents argument interpretation and scope selection. The paragraph contains no shell evaluation.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"Code spans identify repository instructions, manifests, and configuration to inspect. They are file names rather than executable shell expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The inline package identifier is used to establish NestJS eligibility. It does not install or execute that package.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:88:ruby-shell-backtick-execution","reason":"The fence formats the bundled collector invocation, not shell backtick substitution. Risks from its optional execution path are retained at the actual spawn.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"This line closes the collector command example. The delimiter itself performs no execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:92:ruby-shell-backtick-execution","reason":"The scope flag appears as inline Markdown documentation. It is not interpolated into an executable shell expression here.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"Backticks format documented TypeScript and runner flags. The actual tooling trust risk is retained at the collector spawn call.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:100:ruby-shell-backtick-execution","reason":"The text forbids fixing, deployment, and unsafe shared-infrastructure checks. Its inline command examples are restrictions, not requests to execute them.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:126:ruby-shell-backtick-execution","reason":"The backticks format report finding prefixes such as TOOL and SEC. These identifiers are not executable commands.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:104:network-reconnaissance","reason":"The heading introduces compiler and lint diagnostic review. It contains no network probing or reconnaissance instruction.","verdict":"false_positive","confidence":1}],"semantic_findings":[],"subject_marketplace_commit_sha":"c97a1862d1bc82763903ee068cd15acab35d638c","subject_content_hash":"e8f4efa23f0feafd124b09551ce454600e428fbf8ef532b1a4d0ece5f6bbb8c0","subject_tree_hash":"75f4d2811777c63447ef55365e2066d398fb3e4d7b9d260673fc38f1de3329aa","subject_plugin_path":"skills/amirtaherkhani/nestjs-code-audit","audit_payload_hash":"4fc425fcc488321657db4f37cc281353","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"c97a1862d1bc82763903ee068cd15acab35d638c","contentHash":"e8f4efa23f0feafd124b09551ce454600e428fbf8ef532b1a4d0ece5f6bbb8c0","treeHash":"75f4d2811777c63447ef55365e2066d398fb3e4d7b9d260673fc38f1de3329aa","pluginPath":"skills/amirtaherkhani/nestjs-code-audit","auditPayloadHash":"4fc425fcc488321657db4f37cc281353"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/amirtaherkhani-nestjs-code-audit/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":2,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}