{"data":{"skill":{"slug":"atri10-executor-discovery","name":"executor-discovery","icon":"📦","repo":"https://github.com/atri10/executor/tree/39ddcfe1d9f3497102622b72aa235fb0770187fe/skills/executor-discovery","status":"approved","author":"atri10","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"80ab2497-3e91-4099-bd6a-a7375a678a03","skill_id":"645486ac-7287-427e-871b-753f6d57923d","version":1,"content_hash":"v3:6d0b11444384184b7ae743742a7e233a9a705cd9:96d0728e7077cb8b07ed55cb1c77890816d714b94996fa81f9e6354fc5a13ecd:9ec5dbec2e05f6f782d13304faf236cf2641f98124dc0815fabb10fdadb3bbdf:736b696c6c732f6174726931302f6578656375746f722d646973636f76657279:f74a8aad809034588948b72ad649ac35","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Of 130 static findings, 129 concern Markdown syntax, fixed relative references, or legitimate workflow operations. One confirmed risk concerns binding the visual server to all interfaces, exposing token-protected HTTP beyond localhost. No evidence found of prompt injection or deliberate exfiltration; referenced scripts are absent from the reviewed files, so their implementations remain unverified.","remediation":[{"issue":"The remote-access example binds the visual server to all network interfaces over HTTP.","severity":"medium","suggestion":"Prefer loopback with authenticated port forwarding. Require explicit consent for non-loopback binding, restrict reachable interfaces, and protect remote connections with TLS."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":9,"line_start":9},{"file":"SKILL.md","line_end":10,"line_start":10},{"file":"SKILL.md","line_end":18,"line_start":18},{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":20,"line_start":20},{"file":"SKILL.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":70,"line_start":55},{"file":"SKILL.md","line_end":78,"line_start":70},{"file":"SKILL.md","line_end":79,"line_start":78},{"file":"SKILL.md","line_end":115,"line_start":79},{"file":"SKILL.md","line_end":116,"line_start":115},{"file":"SKILL.md","line_end":116,"line_start":116},{"file":"SKILL.md","line_end":122,"line_start":120},{"file":"SKILL.md","line_end":127,"line_start":122},{"file":"SKILL.md","line_end":131,"line_start":127},{"file":"SKILL.md","line_end":142,"line_start":131},{"file":"SKILL.md","line_end":144,"line_start":142},{"file":"SKILL.md","line_end":144,"line_start":144},{"file":"SKILL.md","line_end":145,"line_start":145},{"file":"SKILL.md","line_end":147,"line_start":146},{"file":"SKILL.md","line_end":154,"line_start":147},{"file":"SKILL.md","line_end":158,"line_start":154},{"file":"SKILL.md","line_end":159,"line_start":158},{"file":"SKILL.md","line_end":165,"line_start":159},{"file":"SKILL.md","line_end":168,"line_start":165},{"file":"SKILL.md","line_end":170,"line_start":168},{"file":"SKILL.md","line_end":172,"line_start":170},{"file":"SKILL.md","line_end":187,"line_start":172},{"file":"SKILL.md","line_end":196,"line_start":187},{"file":"SKILL.md","line_end":227,"line_start":196},{"file":"SKILL.md","line_end":227,"line_start":227},{"file":"SKILL.md","line_end":234,"line_start":232},{"file":"SKILL.md","line_end":236,"line_start":234},{"file":"SKILL.md","line_end":238,"line_start":236},{"file":"SKILL.md","line_end":254,"line_start":238},{"file":"SKILL.md","line_end":256,"line_start":254},{"file":"SKILL.md","line_end":256,"line_start":256},{"file":"SKILL.md","line_end":261,"line_start":257},{"file":"SKILL.md","line_end":282,"line_start":261},{"file":"SKILL.md","line_end":284,"line_start":282},{"file":"SKILL.md","line_end":290,"line_start":284},{"file":"SKILL.md","line_end":291,"line_start":290},{"file":"SKILL.md","line_end":295,"line_start":291},{"file":"SKILL.md","line_end":295,"line_start":295},{"file":"SKILL.md","line_end":299,"line_start":296},{"file":"SKILL.md","line_end":299,"line_start":299},{"file":"SKILL.md","line_end":312,"line_start":307},{"file":"SKILL.md","line_end":316,"line_start":312},{"file":"SKILL.md","line_end":317,"line_start":316}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":184,"line_start":184},{"file":"visual-companion.md","line_end":93,"line_start":93},{"file":"visual-companion.md","line_end":179,"line_start":179}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":19,"line_start":19},{"file":"SKILL.md","line_end":25,"line_start":25},{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":166,"line_start":166},{"file":"SKILL.md","line_end":184,"line_start":184},{"file":"SKILL.md","line_end":233,"line_start":233},{"file":"SKILL.md","line_end":296,"line_start":296},{"file":"SKILL.md","line_end":354,"line_start":354},{"file":"SKILL.md","line_end":377,"line_start":377},{"file":"SKILL.md","line_end":395,"line_start":395},{"file":"SKILL.md","line_end":426,"line_start":426},{"file":"SKILL.md","line_end":432,"line_start":432},{"file":"SKILL.md","line_end":434,"line_start":434},{"file":"visual-companion.md","line_end":9,"line_start":9},{"file":"visual-companion.md","line_end":85,"line_start":85},{"file":"visual-companion.md","line_end":90,"line_start":90},{"file":"visual-companion.md","line_end":94,"line_start":94},{"file":"visual-companion.md","line_end":95,"line_start":95},{"file":"visual-companion.md","line_end":107,"line_start":107},{"file":"visual-companion.md","line_end":136,"line_start":136},{"file":"visual-companion.md","line_end":150,"line_start":150},{"file":"visual-companion.md","line_end":157,"line_start":157},{"file":"visual-companion.md","line_end":166,"line_start":166},{"file":"visual-companion.md","line_end":177,"line_start":177},{"file":"visual-companion.md","line_end":387,"line_start":387},{"file":"visual-companion.md","line_end":409,"line_start":409},{"file":"visual-companion.md","line_end":420,"line_start":420},{"file":"visual-companion.md","line_end":421,"line_start":421}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Hardcoded IP address","locations":[{"file":"visual-companion.md","line_end":179,"line_start":179}],"confidence":0.96,"description":"--host 0.0.0.0 \\","review_kind":"capability","source_category":"network","source_severity":"medium","confidence_reasoning":"Binding to 0.0.0.0 exposes the visual server on every IPv4 interface. The documented HTTP URL lacks transport encryption; token authentication mitigates but does not eliminate exposure."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":2,"total_lines":875,"audit_model":"codex","audited_at":"2026-10-05T17:17:29.614+00:00","created_at":"2026-10-06T06:51:48.875467+00:00","static_findings":[{"id":"external_commands:SKILL.md:9:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"and **which approach wins**. Its outputs are research documents (`RSCH`), an","category":"external_commands","line_end":9,"severity":"medium","line_start":9},{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"options comparison (`OPTS`), and one human decision recorded in the phase log.","category":"external_commands","line_end":10,"severity":"medium","line_start":10},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Entry** | Charter exists and its intake gate passed (`executor-initiative`) |","category":"external_commands","line_end":18,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Owns** | `docs/executor/INIT-NNNN-<slug>/discovery/`, `.../brainstorm/sessions/` |","category":"external_commands","line_end":19,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Produces** | `INIT-NNNN-RSCH-nn`, `INIT-NNNN-OPTS-nn` |","category":"external_commands","line_end":20,"severity":"medium","line_start":20},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Next** | `executor-architecture` |","category":"external_commands","line_end":22,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Scripts live in `../executor/scripts/`; invocations below are written with","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```mermaid","category":"external_commands","line_end":70,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":78,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Gather evidence** into `RSCH` documents when a claim needs support.","category":"external_commands","line_end":79,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Write the `OPTS` document** — 2-3 approaches, identical axes, one lead","category":"external_commands","line_end":115,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| The pieces ship, fail, and are reviewed **independently**, and each produces a deliverable that ou","category":"external_commands","line_end":116,"severity":"medium","line_start":115},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| The pieces share one architecture, one set of interfaces, and one success definition, but are too ","category":"external_commands","line_end":116,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"is hard: a document inside `INIT-0004` may never cite an ID from another","category":"external_commands","line_end":122,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"reference — only as `depends_on` at the charter level, with each side","category":"external_commands","line_end":127,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Decomposition into initiatives is `executor-initiative`'s work — hand it the","category":"external_commands","line_end":131,"severity":"medium","line_start":127},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"## Research Documents (`RSCH`)","category":"external_commands","line_end":142,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Value of `confidence` | Means |","category":"external_commands","line_end":144,"severity":"medium","line_start":142},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `measured` | **You ran it.** The command is in `sources` and its output is in the body. |","category":"external_commands","line_end":144,"severity":"medium","line_start":144},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `cited` | You read it in a named source. The URL or path is in `sources`. |","category":"external_commands","line_end":145,"severity":"medium","line_start":145},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `inferred` | You reasoned from measured or cited facts. The reasoning is in the body. |","category":"external_commands","line_end":147,"severity":"medium","line_start":146},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `unverified` | You believe it and have not checked. Named as such, or not written at all. |","category":"external_commands","line_end":154,"severity":"medium","line_start":147},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Mixed document → `confidence` takes the **weakest** value present, and each","category":"external_commands","line_end":158,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Paste the actual command and its actual output for anything `measured`. A","category":"external_commands","line_end":159,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"measurement with no reproducible command is `unverified`.","category":"external_commands","line_end":165,"severity":"medium","line_start":159},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":168,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":170,"severity":"medium","line_start":168},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Path: `docs/executor/INIT-0004-<slug>/discovery/INIT-0004-RSCH-02-<topic-slug>.md`","category":"external_commands","line_end":172,"severity":"medium","line_start":170},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":187,"severity":"medium","line_start":172},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":196,"severity":"medium","line_start":187},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"## Options Documents (`OPTS`)","category":"external_commands","line_end":227,"severity":"medium","line_start":196},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"undo. `two-way` doors deserve less agonising than `one-way` doors, and","category":"external_commands","line_end":227,"severity":"medium","line_start":227},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":234,"severity":"medium","line_start":232},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":236,"severity":"medium","line_start":234},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Path: `docs/executor/INIT-0004-<slug>/discovery/INIT-0004-OPTS-01-<topic-slug>.md`","category":"external_commands","line_end":238,"severity":"medium","line_start":236},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```yaml","category":"external_commands","line_end":254,"severity":"medium","line_start":238},{"id":"external_commands:SKILL.md:254:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":256,"severity":"medium","line_start":254},{"id":"external_commands:SKILL.md:256:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`status: draft` while the human has not picked; `active` once they have.","category":"external_commands","line_end":256,"severity":"medium","line_start":256},{"id":"external_commands:SKILL.md:257:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`recommends: null` until then.","category":"external_commands","line_end":261,"severity":"medium","line_start":257},{"id":"external_commands:SKILL.md:261:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":282,"severity":"medium","line_start":261},{"id":"external_commands:SKILL.md:282:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":284,"severity":"medium","line_start":282},{"id":"external_commands:SKILL.md:284:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Every ID in `sources` begins with this initiative's ID. If a fact came from","category":"external_commands","line_end":290,"severity":"medium","line_start":284},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`exec-ruling` is an execution-time tool: it appends to a *plan's*","category":"external_commands","line_end":291,"severity":"medium","line_start":290},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`rulings.md`, so calling it before a plan exists is an error, not a shortcut.","category":"external_commands","line_end":295,"severity":"medium","line_start":291},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Discovery, architecture, specification | An **ADR** (`INIT-NNNN-ADR-nn`), written by `executor-arc","category":"external_commands","line_end":295,"severity":"medium","line_start":295},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| A plan already running | A **ruling** via `../executor/scripts/exec-ruling`, controller decides al","category":"external_commands","line_end":299,"severity":"medium","line_start":296},{"id":"external_commands:SKILL.md:299:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"the `OPTS` or `RSCH` body where it applies. A decision big enough to need one","category":"external_commands","line_end":299,"severity":"medium","line_start":299},{"id":"external_commands:SKILL.md:307:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`executor-brainstorm`**: the seven-stage design session, the parallel","category":"external_commands","line_end":312,"severity":"medium","line_start":307},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"For a new feature or use case, discovery is where its `design`-mode session","category":"external_commands","line_end":316,"severity":"medium","line_start":312},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`exec-initiative phase <INIT> specification entered` refuses until a","category":"external_commands","line_end":317,"severity":"medium","line_start":316},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"session with `status: active` and `feeds:` naming `specification` exists.","category":"external_commands","line_end":317,"severity":"medium","line_start":317},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```text","category":"external_commands","line_end":325,"severity":"medium","line_start":323},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":331,"severity":"medium","line_start":325},{"id":"external_commands:SKILL.md:331:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`INDEX.md` — one line containing \"brainstorm\":","category":"external_commands","line_end":332,"severity":"medium","line_start":331},{"id":"external_commands:SKILL.md:332:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`*Brainstorming considered at discovery entry: not needed — <reason>.*`","category":"external_commands","line_end":339,"severity":"medium","line_start":332},{"id":"external_commands:SKILL.md:339:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"An empty `brainstorm/sessions/` directory with no recorded session or skip","category":"external_commands","line_end":340,"severity":"medium","line_start":339},{"id":"external_commands:SKILL.md:340:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"is a gap `exec-store-check` fails on.","category":"external_commands","line_end":348,"severity":"medium","line_start":340},{"id":"external_commands:SKILL.md:348:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"[visual-companion.md](visual-companion.md); `executor-brainstorm` calls","category":"external_commands","line_end":363,"severity":"medium","line_start":348},{"id":"external_commands:SKILL.md:363:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Write their choice into the `OPTS` body's `## Decision` section, in their","category":"external_commands","line_end":363,"severity":"medium","line_start":363},{"id":"external_commands:SKILL.md:365:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Set `recommends` to the ID, within this initiative, of the document","category":"external_commands","line_end":366,"severity":"medium","line_start":365},{"id":"external_commands:SKILL.md:366:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"carrying the chosen approach — the `OPTS` document's own ID when all","category":"external_commands","line_end":367,"severity":"medium","line_start":366},{"id":"external_commands:SKILL.md:367:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"approaches live in one document. Set `status: active` and bump","category":"external_commands","line_end":368,"severity":"medium","line_start":367},{"id":"external_commands:SKILL.md:368:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`updated_at`. The chosen option's letter and name live in `## Decision`;","category":"external_commands","line_end":368,"severity":"medium","line_start":368},{"id":"external_commands:SKILL.md:369:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`recommends` is the machine-readable pointer to where the decision is","category":"external_commands","line_end":371,"severity":"medium","line_start":369},{"id":"external_commands:SKILL.md:371:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Append every discovery document to the initiative's `INDEX.md` document","category":"external_commands","line_end":372,"severity":"medium","line_start":371},{"id":"external_commands:SKILL.md:372:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"table (`ID | Kind | Title | Status | Path`), sorted by ID, in this same","category":"external_commands","line_end":376,"severity":"medium","line_start":372},{"id":"external_commands:SKILL.md:376:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":378,"severity":"medium","line_start":376},{"id":"external_commands:SKILL.md:378:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":381,"severity":"medium","line_start":378},{"id":"external_commands:SKILL.md:381:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"row. Use `entered` when discovery starts, `passed` when the human picks.","category":"external_commands","line_end":381,"severity":"medium","line_start":381},{"id":"external_commands:SKILL.md:382:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. Route to `executor-architecture`. Invoke no other skill.","category":"external_commands","line_end":385,"severity":"medium","line_start":382},{"id":"external_commands:SKILL.md:385:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"revision: write the new approach into the document (or a new `OPTS` document","category":"external_commands","line_end":386,"severity":"medium","line_start":385},{"id":"external_commands:SKILL.md:386:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"that `supersedes` it, if the framing changed), and present again. The gate","category":"external_commands","line_end":394,"severity":"medium","line_start":386},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":396,"severity":"medium","line_start":394},{"id":"external_commands:SKILL.md:396:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":398,"severity":"medium","line_start":396},{"id":"external_commands:SKILL.md:398:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"and the charter's `skipped_phases` gains `discovery` with the reason in its","category":"external_commands","line_end":398,"severity":"medium","line_start":398},{"id":"external_commands:SKILL.md:399:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"body. The `skipped` row is what tells a later reader the difference between","category":"external_commands","line_end":408,"severity":"medium","line_start":399},{"id":"external_commands:SKILL.md:408:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"cited, or assumed? One `measured` claim that was only read in a doc","category":"external_commands","line_end":426,"severity":"medium","line_start":408},{"id":"external_commands:SKILL.md:426:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `../executor/scripts/exec-store-check` — no finding for this","category":"external_commands","line_end":428,"severity":"medium","line_start":426},{"id":"external_commands:SKILL.md:428:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"session, D8 requires an active OPTS to carry `recommends` and a filled","category":"external_commands","line_end":429,"severity":"medium","line_start":428},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`## Decision`.","category":"external_commands","line_end":430,"severity":"medium","line_start":429},{"id":"external_commands:SKILL.md:430:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Every RSCH and OPTS document has a Documents-table row — `exec-store-check`","category":"external_commands","line_end":432,"severity":"medium","line_start":430},{"id":"external_commands:SKILL.md:432:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. `../executor/scripts/exec-scan-secrets docs/executor/<INIT>-<slug>` —","category":"external_commands","line_end":434,"severity":"medium","line_start":432},{"id":"external_commands:SKILL.md:434:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. `../executor/scripts/exec-initiative phase <INIT> discovery passed \"...\"`","category":"external_commands","line_end":445,"severity":"medium","line_start":434},{"id":"external_commands:SKILL.md:445:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"The docs say it's 40ms, close enough to measured\" | That is `cited`. Marking it `measured` corrup","category":"external_commands","line_end":445,"severity":"medium","line_start":445},{"id":"network:SKILL.md:184:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"sources: [\"bench/place.sh --tenants 10000\", \"https://.../sharding-guide\"]","category":"network","line_end":184,"severity":"low","line_start":184},{"id":"filesystem:SKILL.md:19:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"| **Owns** | `docs/executor/INIT-NNNN-<slug>/discovery/`, `.../brainstorm/sessions/` |","category":"filesystem","line_end":19,"severity":"high","line_start":19},{"id":"filesystem:SKILL.md:25:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"[layout](../executor/references/layout.md) ·","category":"filesystem","line_end":25,"severity":"high","line_start":25},{"id":"filesystem:SKILL.md:26:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"[frontmatter](../executor/references/frontmatter.md) ·","category":"filesystem","line_end":26,"severity":"high","line_start":26},{"id":"filesystem:SKILL.md:27:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"[indexes](../executor/references/indexes.md) ·","category":"filesystem","line_end":27,"severity":"high","line_start":27},{"id":"filesystem:SKILL.md:28:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"[safety](../executor/references/safety.md).","category":"filesystem","line_end":28,"severity":"high","line_start":28},{"id":"filesystem:SKILL.md:30:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Scripts live in `../executor/scripts/`; invocations below are written with","category":"filesystem","line_end":30,"severity":"high","line_start":30},{"id":"filesystem:SKILL.md:166:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-id INIT-0004 RSCH          # → INIT-0004-RSCH-02","category":"filesystem","line_end":166,"severity":"high","line_start":166},{"id":"filesystem:SKILL.md:184:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"sources: [\"bench/place.sh --tenants 10000\", \"https://.../sharding-guide\"]","category":"filesystem","line_end":184,"severity":"high","line_start":184},{"id":"filesystem:SKILL.md:233:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-id INIT-0004 OPTS          # → INIT-0004-OPTS-01","category":"filesystem","line_end":233,"severity":"high","line_start":233},{"id":"filesystem:SKILL.md:296:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"| A plan already running | A **ruling** via `../executor/scripts/exec-ruling`, controller decides al","category":"filesystem","line_end":296,"severity":"high","line_start":296},{"id":"filesystem:SKILL.md:354:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"written. See [safety](../executor/references/safety.md).","category":"filesystem","line_end":354,"severity":"high","line_start":354},{"id":"filesystem:SKILL.md:377:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-initiative phase INIT-0004 discovery passed \"approach B chosen\"","category":"filesystem","line_end":377,"severity":"high","line_start":377},{"id":"filesystem:SKILL.md:395:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-initiative phase INIT-0004 discovery skipped \"single viable approach; see c","category":"filesystem","line_end":395,"severity":"high","line_start":395},{"id":"filesystem:SKILL.md:426:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"1. `../executor/scripts/exec-store-check` — no finding for this","category":"filesystem","line_end":426,"severity":"high","line_start":426},{"id":"filesystem:SKILL.md:432:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"3. `../executor/scripts/exec-scan-secrets docs/executor/<INIT>-<slug>` —","category":"filesystem","line_end":432,"severity":"high","line_start":432},{"id":"filesystem:SKILL.md:434:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"4. `../executor/scripts/exec-initiative phase <INIT> discovery passed \"...\"`","category":"filesystem","line_end":434,"severity":"high","line_start":434},{"id":"blocker:SKILL.md:352:screen-capture-upload","file":"SKILL.md","pattern":"Screen capture upload","snippet":"**Synthetic data only** in every mockup and screen — session state can capture","category":"blocker","line_end":352,"severity":"high","line_start":352},{"id":"blocker:SKILL.md:55:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"```mermaid","category":"blocker","line_end":56,"severity":"low","line_start":55},{"id":"blocker:SKILL.md:166:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"../executor/scripts/exec-id INIT-0004 RSCH          # → INIT-0004-RSCH-02","category":"blocker","line_end":166,"severity":"low","line_start":166},{"id":"blocker:SKILL.md:233:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"../executor/scripts/exec-id INIT-0004 OPTS          # → INIT-0004-OPTS-01","category":"blocker","line_end":233,"severity":"low","line_start":233},{"id":"blocker:SKILL.md:337:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"discovery did not need ideation; it does not say the feature was designed.","category":"blocker","line_end":337,"severity":"low","line_start":337},{"id":"blocker:SKILL.md:417:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"5. **Did you ask one question at a time**, and did every answer land in a","category":"blocker","line_end":417,"severity":"low","line_start":417},{"id":"external_commands:visual-companion.md:85:shell-command-substitution","file":"visual-companion.md","pattern":"Shell command substitution","snippet":"INIT_DIR=$(../executor/scripts/exec-initiative resolve INIT-0004)","category":"external_commands","line_end":85,"severity":"medium","line_start":85},{"id":"external_commands:visual-companion.md:86:shell-command-substitution","file":"visual-companion.md","pattern":"Shell command substitution","snippet":"STAMP=$(date -u +%Y%m%dT%H%M%SZ)","category":"external_commands","line_end":86,"severity":"medium","line_start":86},{"id":"external_commands:visual-companion.md:165:powershell-invocation","file":"visual-companion.md","pattern":"PowerShell invocation","snippet":"# (on Windows, call Git Bash's bash.exe from the PowerShell tool).","category":"external_commands","line_end":165,"severity":"high","line_start":165},{"id":"network:visual-companion.md:93:hardcoded-url","file":"visual-companion.md","pattern":"Hardcoded URL","snippet":"#           \"url\":\"http://localhost:52341/?key=...\",","category":"network","line_end":93,"severity":"low","line_start":93},{"id":"network:visual-companion.md:179:hardcoded-ip-address","file":"visual-companion.md","pattern":"Hardcoded IP address","snippet":"--host 0.0.0.0 \\","category":"network","line_end":179,"severity":"medium","line_start":179},{"id":"filesystem:visual-companion.md:9:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"[safety](../executor/references/safety.md) before putting anything on screen.","category":"filesystem","line_end":9,"severity":"high","line_start":9},{"id":"filesystem:visual-companion.md:85:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"INIT_DIR=$(../executor/scripts/exec-initiative resolve INIT-0004)","category":"filesystem","line_end":85,"severity":"high","line_start":85},{"id":"filesystem:visual-companion.md:90:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/visual-companion/start-server.sh --project-dir \"$SESSION\" --open","category":"filesystem","line_end":90,"severity":"high","line_start":90},{"id":"filesystem:visual-companion.md:94:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"#           \"screen_dir\":\".../<STAMP>-layout-options/content\",","category":"filesystem","line_end":94,"severity":"high","line_start":94},{"id":"filesystem:visual-companion.md:95:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"#           \"events_file\":\".../<STAMP>-layout-options/events\",","category":"filesystem","line_end":95,"severity":"high","line_start":95},{"id":"filesystem:visual-companion.md:107:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"[safety](../executor/references/safety.md) declares it public. The session key","category":"filesystem","line_end":107,"severity":"high","line_start":107},{"id":"filesystem:visual-companion.md:136:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/visual-companion/start-server.sh --project-dir \"$SESSION\" --open","category":"filesystem","line_end":136,"severity":"high","line_start":136},{"id":"filesystem:visual-companion.md:150:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/visual-companion/start-server.sh --project-dir \"$SESSION\" --open","category":"filesystem","line_end":150,"severity":"high","line_start":150},{"id":"filesystem:visual-companion.md:157:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/visual-companion/start-server.sh --project-dir \"$SESSION\" --open --foreground","category":"filesystem","line_end":157,"severity":"high","line_start":157},{"id":"filesystem:visual-companion.md:166:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"bash ../executor/scripts/visual-companion/start-server.sh --project-dir \"$SESSION\" --open --foregrou","category":"filesystem","line_end":166,"severity":"high","line_start":166},{"id":"filesystem:visual-companion.md:177:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/visual-companion/start-server.sh \\","category":"filesystem","line_end":177,"severity":"high","line_start":177},{"id":"filesystem:visual-companion.md:387:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"See [safety](../executor/references/safety.md) for the required scan and what","category":"filesystem","line_end":387,"severity":"high","line_start":387},{"id":"filesystem:visual-companion.md:409:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/visual-companion/stop-server.sh \"$state_dir\"","category":"filesystem","line_end":409,"severity":"high","line_start":409},{"id":"filesystem:visual-companion.md:420:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"- Frame template (CSS reference): `../executor/scripts/visual-companion/frame-template.html`","category":"filesystem","line_end":420,"severity":"high","line_start":420},{"id":"filesystem:visual-companion.md:421:path-traversal-sequence","file":"visual-companion.md","pattern":"Path traversal sequence","snippet":"- Helper script (client-side): `../executor/scripts/visual-companion/helper.js`","category":"filesystem","line_end":421,"severity":"high","line_start":421},{"id":"blocker:visual-companion.md:129:system-reconnaissance","file":"visual-companion.md","pattern":"System reconnaissance","snippet":"background and did not capture stdout, read that file for the URL and port.","category":"blocker","line_end":129,"severity":"low","line_start":129},{"id":"blocker:visual-companion.md:183:system-reconnaissance","file":"visual-companion.md","pattern":"System reconnaissance","snippet":"`--url-host` controls only the hostname printed in the returned URL JSON.","category":"blocker","line_end":183,"severity":"low","line_start":183},{"id":"blocker:visual-companion.md:369:system-reconnaissance","file":"visual-companion.md","pattern":"System reconnaissance","snippet":"If `$EVENTS_FILE` does not exist, the user did not interact with the","category":"blocker","line_end":369,"severity":"low","line_start":369}],"finding_verdicts":[{"id":"external_commands:SKILL.md:9:ruby-shell-backtick-execution","reason":"RSCH is a document label enclosed in Markdown backticks. No executable backtick expression appears here.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:10:ruby-shell-backtick-execution","reason":"OPTS is an inline document label, not shell command substitution. The sentence describes discovery outputs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"The table names the prerequisite executor-initiative skill. Markdown formatting does not execute that name.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"The backticks delimit documentation paths in an ownership table. They are not Ruby or shell execution syntax in this Markdown context.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:20:ruby-shell-backtick-execution","reason":"The table lists research and options document ID formats. These are formatted identifiers, not commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"The inline identifier names the next workflow skill. No shell substitution or executable payload is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The sentence identifies the sibling script directory with inline Markdown. It does not use executable shell backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"This is a Mermaid code-fence opener containing a workflow diagram. Triple backticks are Markdown delimiters, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"This line closes the Mermaid diagram fence. The nearby RSCH label is also documentation formatting.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"RSCH names an evidence document in a procedure step. The backticks are inline Markdown, not an execution operator.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"OPTS names the options document the workflow produces. There is no Ruby or shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","reason":"depends_on is a charter metadata field in a decomposition table. Its backticks do not execute code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"The table lists specification ID examples in inline Markdown. These are identifiers rather than shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"INIT-0004 is an illustrative initiative identifier. The prose explains citation boundaries, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"depends_on is quoted as a metadata key. No execution syntax or command interpolation occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"executor-initiative is a workflow skill name in prose. The instruction concerns delegation, not backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","reason":"RSCH appears in a section heading as a document abbreviation. This is Markdown formatting only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:142:ruby-shell-backtick-execution","reason":"confidence is the name of a research metadata field. The table heading contains no executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:144:ruby-shell-backtick-execution","reason":"measured and sources are metadata terms explaining evidence provenance. Backticks are not used for shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:145:ruby-shell-backtick-execution","reason":"cited and sources are documentation field labels. The sentence describes recording sources, not executing them.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","reason":"inferred is an evidence classification in a Markdown table. No execution expression appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:147:ruby-shell-backtick-execution","reason":"unverified is a provenance label in the table. Its inline formatting is not a shell operator.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"confidence names a metadata field whose value must reflect the weakest evidence. No backtick execution occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"measured is an inline evidence label. Requiring reproducible measurements is legitimate research guidance, not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:159:ruby-shell-backtick-execution","reason":"unverified is a formatted classification for unsupported measurements. This line does not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"The triple backticks open a Bash example for document IDs and timestamps. They are not shell command-substitution backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","reason":"This closes the Bash documentation fence. No Ruby or shell backtick expression is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","reason":"The inline text specifies a research document output path. Markdown path formatting cannot execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:172:ruby-shell-backtick-execution","reason":"This opens a YAML frontmatter example. The code fence is a documentation delimiter, not executable backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:187:ruby-shell-backtick-execution","reason":"This closes the YAML frontmatter example. No shell or Ruby expression is shown on this line.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","reason":"OPTS is a document abbreviation in a heading. It is not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:227:ruby-shell-backtick-execution","reason":"two-way and one-way are formatted terms describing decision reversibility. There is no executable backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","reason":"This is a Bash code-fence opener for allocating an options document ID. The backticks are Markdown syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:234:ruby-shell-backtick-execution","reason":"This line closes the document-ID command example. It is not executable command substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:236:ruby-shell-backtick-execution","reason":"The line specifies the options document output path. Its inline backticks are formatting only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","reason":"This opens a YAML options-document metadata example. Triple backticks do not execute that example.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:254:ruby-shell-backtick-execution","reason":"This is the closing YAML code fence. No shell substitution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:256:ruby-shell-backtick-execution","reason":"status: draft and active describe approval-state metadata. They are inline Markdown values, not commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:257:ruby-shell-backtick-execution","reason":"recommends: null is an options-document metadata value before approval. It has no executable meaning here.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:261:ruby-shell-backtick-execution","reason":"This opens a Markdown document skeleton. The fence contains headings and placeholders, not shell backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:282:ruby-shell-backtick-execution","reason":"This closes the options document skeleton. It is a Markdown fence rather than execution syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:284:ruby-shell-backtick-execution","reason":"sources names a metadata field used for initiative-local citations. No command execution appears in the sentence.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:290:ruby-shell-backtick-execution","reason":"exec-ruling is named to explain why it should not be used during discovery. The backticks only format its name.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:291:ruby-shell-backtick-execution","reason":"rulings.md is a formatted filename in explanatory prose. No shell command or substitution is shown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:295:ruby-shell-backtick-execution","reason":"The table lists architecture decision IDs and the responsible skill. These are inline names rather than executable backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:296:ruby-shell-backtick-execution","reason":"The table names the execution-time ruling tool for comparison. It does not invoke a shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:299:ruby-shell-backtick-execution","reason":"OPTS and RSCH are document labels for recording small decisions. Their backticks are Markdown only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:307:ruby-shell-backtick-execution","reason":"executor-brainstorm names a companion skill responsible for design sessions. It is not a shell command-substitution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","reason":"design is a formatted session-mode name in prose. The line contains no command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","reason":"The inline command names an initiative phase check and explains its prerequisites. Markdown backticks are not executable substitution syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","reason":"status: active, feeds:, and specification are session metadata values. This is documentation, not code execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:323:ruby-shell-backtick-execution","reason":"This opens a plain-text session path example. Triple backticks are Markdown delimiters.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","reason":"This closes the plain-text session path fence. No executable shell backticks appear.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:331:ruby-shell-backtick-execution","reason":"INDEX.md is the document where a brainstorming skip is recorded. Formatting this filename does not execute anything.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:332:ruby-shell-backtick-execution","reason":"The inline example is a sentence documenting a brainstorming skip. It is not a shell or Ruby expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:339:ruby-shell-backtick-execution","reason":"brainstorm/sessions/ is a directory name in a validation explanation. Its backticks are formatting only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:340:ruby-shell-backtick-execution","reason":"exec-store-check names the workflow validator in prose. No shell substitution or executable payload appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:348:ruby-shell-backtick-execution","reason":"executor-brainstorm is named alongside the visual companion link. This is a skill reference, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:363:ruby-shell-backtick-execution","reason":"OPTS and Decision identify a document and section receiving the human choice. Their inline backticks do not execute code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:365:ruby-shell-backtick-execution","reason":"recommends is the metadata pointer updated after approval. The sentence contains no executable backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:366:ruby-shell-backtick-execution","reason":"OPTS names the document carrying the chosen approach. Backticks are document-label formatting only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:367:ruby-shell-backtick-execution","reason":"status: active is the approved document state. It is a formatted metadata value, not an executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:368:ruby-shell-backtick-execution","reason":"updated_at and Decision identify metadata and a document section. No shell or Ruby evaluation is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:369:ruby-shell-backtick-execution","reason":"recommends names a machine-readable document pointer. Inline Markdown does not execute this field name.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:371:ruby-shell-backtick-execution","reason":"INDEX.md is the initiative registry document being updated. This is a filename reference, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:372:ruby-shell-backtick-execution","reason":"The inline text lists document table column names. It contains no executable backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:376:ruby-shell-backtick-execution","reason":"This opens a Bash example for recording an approved discovery phase. The fence itself is not shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:378:ruby-shell-backtick-execution","reason":"This closes the discovery-phase command example. Triple backticks are Markdown delimiters.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:381:ruby-shell-backtick-execution","reason":"entered and passed are phase-state labels described in prose. No executable backtick expression occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:382:ruby-shell-backtick-execution","reason":"executor-architecture is the next workflow skill. Formatting its name is not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:385:ruby-shell-backtick-execution","reason":"OPTS names a revised options document. The sentence concerns revising documentation, not executing code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:386:ruby-shell-backtick-execution","reason":"supersedes is a document revision metadata field. Markdown backticks here do not invoke a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:394:ruby-shell-backtick-execution","reason":"This is a Bash code-fence opener for a documented discovery skip. It is not executable backtick substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:396:ruby-shell-backtick-execution","reason":"This closes the discovery-skip example fence. No Ruby or shell backtick expression appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:398:ruby-shell-backtick-execution","reason":"skipped_phases and discovery are charter metadata terms. They are not executable commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:399:ruby-shell-backtick-execution","reason":"skipped is a phase-log state in explanatory prose. Inline formatting is not code execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:408:ruby-shell-backtick-execution","reason":"measured is an evidence label used in a quality checklist. The line contains no shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:426:ruby-shell-backtick-execution","reason":"The inline command names a document-store validation step. Its Markdown backticks do not perform command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:428:ruby-shell-backtick-execution","reason":"recommends is a metadata field required by the document validator. No executable code is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:429:ruby-shell-backtick-execution","reason":"Decision names a required Markdown section. Formatting a heading does not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:430:ruby-shell-backtick-execution","reason":"exec-store-check names the validator enforcing document registration. The backticks are inline documentation, not shell substitution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:432:ruby-shell-backtick-execution","reason":"The documented command scans initiative artifacts for secrets as a verification step. Backticks format that command rather than execute a substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:434:ruby-shell-backtick-execution","reason":"The inline command records a human-approved discovery gate. No Ruby or shell backtick execution syntax is used.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:445:ruby-shell-backtick-execution","reason":"cited and measured are evidence classifications in a warning table. Their backticks are Markdown only.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:184:hardcoded-url","reason":"The URL is an incomplete placeholder in example research-source metadata. No data transmission or concrete external destination is specified.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:19:path-traversal-sequence","reason":"The three dots abbreviate the initiative path in an ownership table. This is not a parent-directory traversal operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:25:path-traversal-sequence","reason":"The fixed relative link targets the sibling Executor layout reference. No attacker-controlled path or unauthorized file access is demonstrated.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:26:path-traversal-sequence","reason":"This is a fixed documentation link to sibling frontmatter guidance. Parent-relative navigation alone does not establish a traversal vulnerability.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:27:path-traversal-sequence","reason":"The relative link names the sibling indexes reference. There is no user-controlled path escaping a security boundary.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:28:path-traversal-sequence","reason":"This is a fixed link to the sibling safety reference. No unauthorized file-read or write operation is shown.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:30:path-traversal-sequence","reason":"The line describes the expected sibling script installation directory. No attacker-supplied traversal input is present; script implementations are outside the reviewed files.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:166:path-traversal-sequence","reason":"A fixed sibling exec-id path allocates a research document identifier. This reference does not demonstrate arbitrary file traversal; its implementation is not included.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:184:path-traversal-sequence","reason":"The dots belong to a placeholder citation URL in YAML metadata. No filesystem traversal operation occurs.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:233:path-traversal-sequence","reason":"The fixed sibling exec-id command allocates an options document identifier. No attacker-controlled traversal path is shown; the script implementation is not included.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:296:path-traversal-sequence","reason":"The table references the sibling ruling tool for execution-time use, which discovery explicitly excludes. A fixed tool reference is not a traversal exploit.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:354:path-traversal-sequence","reason":"The relative link points to synthetic-data safety guidance. It is a documentation reference, not an unauthorized filesystem operation.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:377:path-traversal-sequence","reason":"The fixed sibling command records the discovery phase after a human choice. No arbitrary traversal input is shown; underlying script behavior is unverified.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:395:path-traversal-sequence","reason":"The fixed sibling command records a reasoned discovery skip. Its relative installation path does not establish a traversal vulnerability.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:426:path-traversal-sequence","reason":"The fixed sibling exec-store-check reference is for initiative-document validation. No malicious path manipulation is demonstrated; the validator implementation is absent.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:432:path-traversal-sequence","reason":"The sibling secret-scanner command targets the initiative documentation directory. Placeholder arguments describe intended use rather than an attacker-controlled traversal payload.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:SKILL.md:434:path-traversal-sequence","reason":"The relative command records an approved workflow transition using an initiative identifier. No filesystem-boundary bypass is shown in the documented invocation.","verdict":"false_positive","confidence":0.96},{"id":"blocker:SKILL.md:352:screen-capture-upload","reason":"The text warns that tracked session artifacts may capture screen content and explicitly requires synthetic data. No screen-upload command or exfiltration destination appears.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:55:system-reconnaissance","reason":"This is a Mermaid workflow diagram followed by repository-context review. No host reconnaissance command or system-data collection is shown.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:166:system-reconnaissance","reason":"exec-id allocates a document identifier in the described workflow. It is not the standalone system identity command; the example shows an RSCH ID output.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:233:system-reconnaissance","reason":"The example uses exec-id to allocate an OPTS document identifier. It does not invoke a system reconnaissance utility.","verdict":"false_positive","confidence":0.98},{"id":"blocker:SKILL.md:337:system-reconnaissance","reason":"The sentence distinguishes a brainstorming skip from completing feature design. It contains no reconnaissance behavior.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:417:system-reconnaissance","reason":"The checklist asks whether questions and answers were documented. No system information gathering occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:visual-companion.md:85:shell-command-substitution","reason":"The substitution resolves a fixed initiative ID through the sibling workflow helper. Its output becomes quoted path data, not executable shell input.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:visual-companion.md:86:shell-command-substitution","reason":"The substitution runs date with a fixed UTC format to name a session. It includes no user-controlled command text.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:visual-companion.md:165:powershell-invocation","reason":"This comment explains invoking Git Bash from a Windows shell tool. No encoded PowerShell payload, policy bypass, or destructive operation is specified.","verdict":"false_positive","confidence":0.98},{"id":"network:visual-companion.md:93:hardcoded-url","reason":"The localhost URL is an illustrative startup response for the consent-based visual companion. Its key is a placeholder, not an external exfiltration destination.","verdict":"false_positive","confidence":0.98},{"id":"network:visual-companion.md:179:hardcoded-ip-address","reason":"Binding to 0.0.0.0 exposes the visual server on every IPv4 interface. The documented HTTP URL lacks transport encryption; token authentication mitigates but does not eliminate exposure.","verdict":"confirmed","confidence":0.96},{"id":"filesystem:visual-companion.md:9:path-traversal-sequence","reason":"The fixed relative link points to sibling safety documentation. No attacker-controlled path or unauthorized file operation is shown.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:visual-companion.md:85:path-traversal-sequence","reason":"The fixed sibling helper resolves the example initiative directory. Parent-relative installation navigation does not demonstrate traversal abuse; the helper implementation is absent.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:visual-companion.md:90:path-traversal-sequence","reason":"The fixed sibling launcher receives a quoted session directory after user consent. No arbitrary filesystem traversal is demonstrated; launcher internals are outside the reviewed files.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:visual-companion.md:94:path-traversal-sequence","reason":"The three dots abbreviate an example returned content directory. This comment does not perform a filesystem operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:visual-companion.md:95:path-traversal-sequence","reason":"The dots abbreviate an example returned events path. They are not an executable parent-directory traversal sequence.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:visual-companion.md:107:path-traversal-sequence","reason":"The relative safety link supports keeping session credentials outside the tracked repository. It does not direct unauthorized file access.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:visual-companion.md:136:path-traversal-sequence","reason":"This uses a fixed sibling server launcher with a quoted session path for Claude Code. No traversal payload is shown; the script itself is not included.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:visual-companion.md:150:path-traversal-sequence","reason":"The fixed relative server launcher is documented for Codex runtime handling. Its installation path is not attacker-supplied traversal input.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:visual-companion.md:157:path-traversal-sequence","reason":"The fixed launcher path and foreground flag describe process lifecycle handling. No unauthorized filesystem access or traversal argument is demonstrated.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:visual-companion.md:166:path-traversal-sequence","reason":"Bash invokes a fixed sibling launcher with a quoted session path. The documented invocation contains no attacker-controlled parent traversal.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:visual-companion.md:177:path-traversal-sequence","reason":"The launcher uses a fixed sibling installation path, not a traversal payload. The separate wildcard network-binding risk is retained under its network finding.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:visual-companion.md:387:path-traversal-sequence","reason":"The fixed safety-document link concerns scanning synthetic mockups for sensitive data. It is not an arbitrary file-read operation.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:visual-companion.md:409:path-traversal-sequence","reason":"The fixed sibling shutdown helper receives the quoted runtime directory returned at startup. No traversal exploit is shown; shutdown implementation is not included.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:visual-companion.md:420:path-traversal-sequence","reason":"The relative path names the companion frame template as a CSS reference. This fixed asset reference does not demonstrate traversal abuse.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:visual-companion.md:421:path-traversal-sequence","reason":"The fixed relative path names the companion client helper asset. No attacker-controlled path or unauthorized filesystem operation is present.","verdict":"false_positive","confidence":0.98},{"id":"blocker:visual-companion.md:129:system-reconnaissance","reason":"The instruction reads the companion startup record to recover its own URL and port. This is service lifecycle bookkeeping, not broad host reconnaissance.","verdict":"false_positive","confidence":0.98},{"id":"blocker:visual-companion.md:183:system-reconnaissance","reason":"The sentence explains that url-host changes only the displayed connection hostname. No system probing or host-data collection occurs.","verdict":"false_positive","confidence":0.99},{"id":"blocker:visual-companion.md:369:system-reconnaissance","reason":"Checking whether the session events file exists determines whether browser feedback is available. It does not enumerate system users, hardware, or network state.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"6d0b11444384184b7ae743742a7e233a9a705cd9","subject_content_hash":"96d0728e7077cb8b07ed55cb1c77890816d714b94996fa81f9e6354fc5a13ecd","subject_tree_hash":"9ec5dbec2e05f6f782d13304faf236cf2641f98124dc0815fabb10fdadb3bbdf","subject_plugin_path":"skills/atri10/executor-discovery","audit_payload_hash":"f74a8aad809034588948b72ad649ac35","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"6d0b11444384184b7ae743742a7e233a9a705cd9","contentHash":"96d0728e7077cb8b07ed55cb1c77890816d714b94996fa81f9e6354fc5a13ecd","treeHash":"9ec5dbec2e05f6f782d13304faf236cf2641f98124dc0815fabb10fdadb3bbdf","pluginPath":"skills/atri10/executor-discovery","auditPayloadHash":"f74a8aad809034588948b72ad649ac35"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/atri10-executor-discovery/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}