{"data":{"skill":{"slug":"atri10-executor-handoff","name":"executor-handoff","icon":"📦","repo":"https://github.com/atri10/executor/tree/39ddcfe1d9f3497102622b72aa235fb0770187fe/skills/executor-handoff","status":"approved","author":"atri10","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"e48a3a96-b94a-4eca-94ec-30427186aaef","skill_id":"ce3698f8-e955-44b1-a5dc-82875abf72e5","version":1,"content_hash":"v3:6d0b11444384184b7ae743742a7e233a9a705cd9:c58a5a2d096c324adc2cc95497f30befc1bc31fe230aea79741cb896433eddf5:e99a47913b71949495af2612920496191b3dc872eb11b871c2f0627d16b6af57:736b696c6c732f6174726931302f6578656375746f722d68616e646f6666:8ea90dbd88a44a7493bbdfe651e03602","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 182 static findings are false positives involving Markdown syntax, fixed dependency references, ordinary Git queries, or deletion safeguards. One semantic risk remains: directory names authorize worktree removal without independent ownership evidence. No evidence found of credential exfiltration or prompt injection; referenced helper implementations are outside this audit.","remediation":[{"issue":"Directory names are treated as ownership evidence when authorizing worktree removal.","severity":"medium","suggestion":"Require trusted creation records matching the canonical worktree path to this initiative before cleanup. Preserve host-managed worktrees regardless of directory names. If provenance is absent, require explicit human approval naming the exact removal target."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"SKILL.md","line_end":36,"line_start":23},{"file":"SKILL.md","line_end":45,"line_start":36},{"file":"SKILL.md","line_end":46,"line_start":45},{"file":"SKILL.md","line_end":47,"line_start":46},{"file":"SKILL.md","line_end":47,"line_start":47},{"file":"SKILL.md","line_end":50,"line_start":48},{"file":"SKILL.md","line_end":51,"line_start":50},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":56,"line_start":52},{"file":"SKILL.md","line_end":58,"line_start":56},{"file":"SKILL.md","line_end":63,"line_start":58},{"file":"SKILL.md","line_end":65,"line_start":63},{"file":"SKILL.md","line_end":75,"line_start":65},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":86,"line_start":84},{"file":"SKILL.md","line_end":87,"line_start":86},{"file":"SKILL.md","line_end":87,"line_start":87},{"file":"SKILL.md","line_end":90,"line_start":89},{"file":"SKILL.md","line_end":94,"line_start":90},{"file":"SKILL.md","line_end":96,"line_start":94},{"file":"SKILL.md","line_end":99,"line_start":96},{"file":"SKILL.md","line_end":101,"line_start":99},{"file":"SKILL.md","line_end":101,"line_start":101},{"file":"SKILL.md","line_end":110,"line_start":106},{"file":"SKILL.md","line_end":116,"line_start":110},{"file":"SKILL.md","line_end":120,"line_start":116},{"file":"SKILL.md","line_end":121,"line_start":120},{"file":"SKILL.md","line_end":122,"line_start":121},{"file":"SKILL.md","line_end":130,"line_start":122},{"file":"SKILL.md","line_end":134,"line_start":130},{"file":"SKILL.md","line_end":137,"line_start":134},{"file":"SKILL.md","line_end":139,"line_start":137},{"file":"SKILL.md","line_end":143,"line_start":139},{"file":"SKILL.md","line_end":146,"line_start":143},{"file":"SKILL.md","line_end":148,"line_start":146},{"file":"SKILL.md","line_end":149,"line_start":148},{"file":"SKILL.md","line_end":155,"line_start":149},{"file":"SKILL.md","line_end":155,"line_start":155},{"file":"SKILL.md","line_end":157,"line_start":156},{"file":"SKILL.md","line_end":158,"line_start":157},{"file":"SKILL.md","line_end":165,"line_start":158},{"file":"SKILL.md","line_end":168,"line_start":165},{"file":"SKILL.md","line_end":170,"line_start":168},{"file":"SKILL.md","line_end":175,"line_start":170},{"file":"SKILL.md","line_end":180,"line_start":175},{"file":"SKILL.md","line_end":189,"line_start":180},{"file":"SKILL.md","line_end":189,"line_start":189},{"file":"SKILL.md","line_end":213,"line_start":190}]},{"factor":"filesystem","evidence":[{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":50,"line_start":50},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":170,"line_start":170},{"file":"SKILL.md","line_end":274,"line_start":274},{"file":"SKILL.md","line_end":609,"line_start":609},{"file":"SKILL.md","line_end":612,"line_start":612},{"file":"SKILL.md","line_end":614,"line_start":614},{"file":"SKILL.md","line_end":167,"line_start":167},{"file":"SKILL.md","line_end":214,"line_start":214},{"file":"SKILL.md","line_end":215,"line_start":215}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Directory Names Substitute for Worktree Ownership","locations":[{"file":"SKILL.md","line_end":360,"line_start":355},{"file":"SKILL.md","line_end":383,"line_start":382},{"file":"SKILL.md","line_end":636,"line_start":636}],"confidence":0.88,"description":"The rule says: \"If `WORKTREE_PATH` is under `.worktrees/` or `worktrees/`: we own it.\" It then authorizes removal without checking a creation record or requesting separate cleanup approval. Host-managed worktrees can use these directory names, so choosing local integration can remove a workspace that the agent does not own. Git refusal handling limits deletion of modified files but does not establish ownership.","review_kind":"security","source_category":"semantic","source_severity":"medium","confidence_reasoning":"The ownership rule directly precedes worktree removal and is repeated in the cleanup checklist. Confidence is high, although unauthorized removal depends on host directory conventions."}],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":642,"audit_model":"codex","audited_at":"2026-10-05T17:32:35.971+00:00","created_at":"2026-10-06T06:52:05.687493+00:00","static_findings":[{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Scripts referenced below live in `../executor/scripts/` and are","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"written here as `exec-*`. Never hand-build a store path; resolve it.","category":"external_commands","line_end":14,"severity":"medium","line_start":14},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```mermaid","category":"external_commands","line_end":36,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":45,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Every task in every plan is complete | each plan's `.executor/<INIT>/<Pnn>/progress.md` |","category":"external_commands","line_end":46,"severity":"medium","line_start":45},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Every task has a clean or accepted verdict | `reviews/verdicts/` |","category":"external_commands","line_end":47,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| The LATEST final verdict is clean | `reviews/verdicts/` — if any `<PLAN-ID>-final-R<n>-verdict.md`","category":"external_commands","line_end":47,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Verification produced observed evidence, not expectation | `docs/executor/<INIT>-*/verification/` ","category":"external_commands","line_end":50,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| The thinking store passes the store check — every document registered, statuses truthful, cross-li","category":"external_commands","line_end":51,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Every executed plan has a run row and a workspace | `.executor/INDEX.md` vs `.executor/INIT-*/` — ","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Every plan's VRFY outcomes are filled — no \"To be filled\" placeholder survives execution | `docs/e","category":"external_commands","line_end":56,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":58,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":63,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":65,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":75,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"plan's `rulings.md` and a `.local/decisions/NNNN-*-ruling.md` record — so","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`.executor/<INIT>/<Pnn>/rulings.md` top to bottom. It is append-only, so","category":"external_commands","line_end":86,"severity":"medium","line_start":84},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`## <task-id> — <utc>`, **Decided**, **Why**, **Cost if wrong**.","category":"external_commands","line_end":87,"severity":"medium","line_start":86},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. Read `.executor/<INIT>/<Pnn>/preflight-scan.md`. Its `Ruling` column","category":"external_commands","line_end":87,"severity":"medium","line_start":87},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"in `rulings.md` is a gap.","category":"external_commands","line_end":90,"severity":"medium","line_start":89},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. Read `reviews/verdicts/*`. Findings marked parked, deferred, or","category":"external_commands","line_end":94,"severity":"medium","line_start":90},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`exec-ruling` still applies:","category":"external_commands","line_end":96,"severity":"medium","line_start":94},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":99,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":101,"severity":"medium","line_start":99},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"It appends to that plan's `rulings.md` and writes the `.local/decisions/`","category":"external_commands","line_end":101,"severity":"medium","line_start":101},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"In the final message, under a heading exactly `Rulings I made`, in the","category":"external_commands","line_end":110,"severity":"medium","line_start":106},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":116,"severity":"medium","line_start":110},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **preflight** — Task 4 and task 6 both touch `router.ts`; ran them","category":"external_commands","line_end":120,"severity":"medium","line_start":116},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Full text: `.executor/INIT-0004/P01/rulings.md` ·","category":"external_commands","line_end":121,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"mirrored in `.local/decisions/`.","category":"external_commands","line_end":122,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":130,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```markdown","category":"external_commands","line_end":134,"severity":"medium","line_start":130},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":137,"severity":"medium","line_start":134},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"findings, or preflight conflicts and an empty `rulings.md` means rulings","category":"external_commands","line_end":139,"severity":"medium","line_start":137},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"ledger, record them with `exec-ruling`, then report.","category":"external_commands","line_end":143,"severity":"medium","line_start":139},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":146,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":148,"severity":"medium","line_start":146},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Exit 0 prints `clean: no credential-shaped content found in N store(s)` and","category":"external_commands","line_end":149,"severity":"medium","line_start":148},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"handoff proceeds. Exit 1 prints one `file:line: possible <kind>` per","category":"external_commands","line_end":155,"severity":"medium","line_start":149},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"resolves `docs/executor/` from the working-tree root and `.executor/` from","category":"external_commands","line_end":155,"severity":"medium","line_start":155},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"the main repository root (`git rev-parse --git-common-dir`), so a bare","category":"external_commands","line_end":157,"severity":"medium","line_start":156},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`exec-scan-secrets` inside a linked worktree still scans the shared","category":"external_commands","line_end":158,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"execution store. Read the count in the clean line anyway: `in 1 store(s)`","category":"external_commands","line_end":165,"severity":"medium","line_start":158},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":168,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":170,"severity":"medium","line_start":168},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"On any finding, follow `../executor/references/safety.md`:","category":"external_commands","line_end":175,"severity":"medium","line_start":170},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Only in `.executor/`, never committed | That file is the only copy. The human chooses redact-in-pl","category":"external_commands","line_end":180,"severity":"medium","line_start":175},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"A finding inside `reviews/diffs/` means the secret is in git history too,","category":"external_commands","line_end":189,"severity":"medium","line_start":180},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run the project's full suite (`npm test` / `cargo test` / `pytest` /","category":"external_commands","line_end":189,"severity":"medium","line_start":189},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`go test ./...` — whatever this repo uses) **on the current tree**, now.","category":"external_commands","line_end":213,"severity":"medium","line_start":190},{"id":"external_commands:SKILL.md:213:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":219,"severity":"medium","line_start":213},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":223,"severity":"medium","line_start":219},{"id":"external_commands:SKILL.md:223:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `GIT_DIR == GIT_COMMON` (normal repo) | Standard 3 options | No worktree to handle |","category":"external_commands","line_end":224,"severity":"medium","line_start":223},{"id":"external_commands:SKILL.md:224:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `GIT_DIR != GIT_COMMON`, named branch | Standard 3 options | Provenance-based (§7) |","category":"external_commands","line_end":225,"severity":"medium","line_start":224},{"id":"external_commands:SKILL.md:225:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `GIT_DIR != GIT_COMMON`, detached HEAD | Reduced 2 options (no merge) | Externally managed — leave","category":"external_commands","line_end":228,"severity":"medium","line_start":225},{"id":"external_commands:SKILL.md:228:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`docs/executor/` resolves from `exec_root` (the working-tree root), so","category":"external_commands","line_end":228,"severity":"medium","line_start":228},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"with the merge. `.executor/` resolves from `exec_main_root` (the main","category":"external_commands","line_end":230,"severity":"medium","line_start":230},{"id":"external_commands:SKILL.md:231:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"repository root, derived from `git rev-parse --git-common-dir`), so the","category":"external_commands","line_end":238,"severity":"medium","line_start":231},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`INDEX.md` carries a `**Branch:**` line naming the branch and its fork","category":"external_commands","line_end":238,"severity":"medium","line_start":238},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"point (written by `exec-initiative branch`). Read it; the base branch is","category":"external_commands","line_end":244,"severity":"medium","line_start":239},{"id":"external_commands:SKILL.md:244:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":246,"severity":"medium","line_start":244},{"id":"external_commands:SKILL.md:246:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":255,"severity":"medium","line_start":246},{"id":"external_commands:SKILL.md:255:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":263,"severity":"medium","line_start":255},{"id":"external_commands:SKILL.md:263:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":267,"severity":"medium","line_start":263},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"verdict — `exec-branch merge` refuses without it). This menu is for the","category":"external_commands","line_end":273,"severity":"medium","line_start":267},{"id":"external_commands:SKILL.md:273:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":275,"severity":"medium","line_start":273},{"id":"external_commands:SKILL.md:275:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":282,"severity":"medium","line_start":275},{"id":"external_commands:SKILL.md:282:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":289,"severity":"medium","line_start":282},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":304,"severity":"medium","line_start":289},{"id":"external_commands:SKILL.md:304:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Never commit to a protected default branch | `main` stays deployable; branch first, always |","category":"external_commands","line_end":305,"severity":"medium","line_start":304},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Conventional Commits, imperative, ≤72 chars | `feat(router): add cell placement scoring` |","category":"external_commands","line_end":306,"severity":"medium","line_start":305},{"id":"external_commands:SKILL.md:306:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Review `git diff --cached` before every commit | Last chance to catch a secret or a generated arti","category":"external_commands","line_end":307,"severity":"medium","line_start":306},{"id":"external_commands:SKILL.md:307:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Never stage `.executor/` unless the human asked | It is ignored by design; committing it makes it ","category":"external_commands","line_end":308,"severity":"medium","line_start":307},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Squash a feature branch into clean history | A trail of `wip` commits is not a record; `rulings.md","category":"external_commands","line_end":308,"severity":"medium","line_start":308},{"id":"external_commands:SKILL.md:313:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":322,"severity":"medium","line_start":313},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":331,"severity":"medium","line_start":322},{"id":"external_commands:SKILL.md:331:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":333,"severity":"medium","line_start":331},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":340,"severity":"medium","line_start":333},{"id":"external_commands:SKILL.md:340:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**The execution store survives this.** `.executor/` lives at the main","category":"external_commands","line_end":345,"severity":"medium","line_start":340},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **If `GIT_DIR == GIT_COMMON`:** normal repo, nothing to do.","category":"external_commands","line_end":349,"severity":"medium","line_start":345},{"id":"external_commands:SKILL.md:349:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":351,"severity":"medium","line_start":349},{"id":"external_commands:SKILL.md:351:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":355,"severity":"medium","line_start":351},{"id":"external_commands:SKILL.md:355:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **If `WORKTREE_PATH` is under `.worktrees/` or `worktrees/`:** we own it.","category":"external_commands","line_end":355,"severity":"medium","line_start":355},{"id":"external_commands:SKILL.md:357:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":360,"severity":"medium","line_start":357},{"id":"external_commands:SKILL.md:360:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":362,"severity":"medium","line_start":360},{"id":"external_commands:SKILL.md:362:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **If removal is refused** (`contains modified or untracked files`): those","category":"external_commands","line_end":363,"severity":"medium","line_start":362},{"id":"external_commands:SKILL.md:363:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"files exist nowhere else. Never `--force` on your own initiative. Show","category":"external_commands","line_end":366,"severity":"medium","line_start":363},{"id":"external_commands:SKILL.md:366:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":368,"severity":"medium","line_start":366},{"id":"external_commands:SKILL.md:368:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":370,"severity":"medium","line_start":368},{"id":"external_commands:SKILL.md:370:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":380,"severity":"medium","line_start":370},{"id":"external_commands:SKILL.md:380:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":383,"severity":"medium","line_start":380},{"id":"external_commands:SKILL.md:383:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"up only worktrees under `.worktrees/` or `worktrees/`.","category":"external_commands","line_end":383,"severity":"medium","line_start":383},{"id":"external_commands:SKILL.md:387:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":391,"severity":"medium","line_start":387},{"id":"external_commands:SKILL.md:391:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":393,"severity":"medium","line_start":391},{"id":"external_commands:SKILL.md:393:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Create the pull request against `<base-branch>` with the forge's tooling —","category":"external_commands","line_end":402,"severity":"medium","line_start":393},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Report: `Keeping branch <name>. Worktree preserved at <path>.` Then still","category":"external_commands","line_end":410,"severity":"medium","line_start":402},{"id":"external_commands:SKILL.md:410:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":417,"severity":"medium","line_start":410},{"id":"external_commands:SKILL.md:417:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":424,"severity":"medium","line_start":417},{"id":"external_commands:SKILL.md:424:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":426,"severity":"medium","line_start":424},{"id":"external_commands:SKILL.md:426:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":428,"severity":"medium","line_start":426},{"id":"external_commands:SKILL.md:428:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Set the initiative status to `abandoned`, not `complete`, and say why in","category":"external_commands","line_end":428,"severity":"medium","line_start":428},{"id":"external_commands:SKILL.md:435:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 1. Merge locally | yes | — | — | yes (`-d`) |","category":"external_commands","line_end":438,"severity":"medium","line_start":435},{"id":"external_commands:SKILL.md:438:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Discard (explicit request only) | — | — | — | yes (`-D`) |","category":"external_commands","line_end":444,"severity":"medium","line_start":438},{"id":"external_commands:SKILL.md:444:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**1. The run registry — `.executor/INDEX.md`.** Edit the plan's row in","category":"external_commands","line_end":445,"severity":"medium","line_start":444},{"id":"external_commands:SKILL.md:445:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"place (no script writes it after `exec-workspace` created it): `Status` →","category":"external_commands","line_end":445,"severity":"medium","line_start":445},{"id":"external_commands:SKILL.md:446:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`complete`, `Tasks` → `N/N`, `Finished` → today's UTC date. One row per","category":"external_commands","line_end":446,"severity":"medium","line_start":446},{"id":"external_commands:SKILL.md:452:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":454,"severity":"medium","line_start":452},{"id":"external_commands:SKILL.md:454:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":457,"severity":"medium","line_start":454},{"id":"external_commands:SKILL.md:457:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`**Phase:**` header line, and updates the phase and updated cells in","category":"external_commands","line_end":458,"severity":"medium","line_start":457},{"id":"external_commands:SKILL.md:458:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`docs/executor/INDEX.md`.","category":"external_commands","line_end":462,"severity":"medium","line_start":458},{"id":"external_commands:SKILL.md:462:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":464,"severity":"medium","line_start":462},{"id":"external_commands:SKILL.md:464:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":466,"severity":"medium","line_start":464},{"id":"external_commands:SKILL.md:466:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Valid: `active`, `complete`, `superseded`, `abandoned`, `paused`. It","category":"external_commands","line_end":466,"severity":"medium","line_start":466},{"id":"external_commands:SKILL.md:467:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"updates the initiative INDEX header and the registry row. Use `superseded`","category":"external_commands","line_end":468,"severity":"medium","line_start":467},{"id":"external_commands:SKILL.md:468:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"only alongside a `supersedes_initiative` pointer in the replacing","category":"external_commands","line_end":480,"severity":"medium","line_start":468},{"id":"external_commands:SKILL.md:480:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"stays. Their index rows stay and read `complete`. Pruning either store is a","category":"external_commands","line_end":485,"severity":"medium","line_start":480},{"id":"external_commands:SKILL.md:485:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"outside the two stores — probe scripts, temp diffs, `/tmp` artifacts — are","category":"external_commands","line_end":511,"severity":"medium","line_start":485},{"id":"external_commands:SKILL.md:511:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `paused` | Suspended deliberately; the work is still wanted | Yes — resume protocol below |","category":"external_commands","line_end":512,"severity":"medium","line_start":511},{"id":"external_commands:SKILL.md:512:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `abandoned` | Stopped on purpose; the work is no longer wanted | No — charter body says why |","category":"external_commands","line_end":513,"severity":"medium","line_start":512},{"id":"external_commands:SKILL.md:513:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `blocked` (run row) | Execution stopped on one of the four stop conditions | Yes, once the conditi","category":"external_commands","line_end":514,"severity":"medium","line_start":513},{"id":"external_commands:SKILL.md:514:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `paused` (run row) | The run's initiative is paused; the plan is resumable as-is | Yes — resume pr","category":"external_commands","line_end":521,"severity":"medium","line_start":514},{"id":"external_commands:SKILL.md:521:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Ledger** — `progress.md` reflects the true state of every task. A task","category":"external_commands","line_end":523,"severity":"medium","line_start":521},{"id":"external_commands:SKILL.md:523:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Rulings** — every decision made this session is in `rulings.md` via","category":"external_commands","line_end":524,"severity":"medium","line_start":523},{"id":"external_commands:SKILL.md:524:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`exec-ruling`. Write them now; a ruling reconstructed next session is a","category":"external_commands","line_end":526,"severity":"medium","line_start":524},{"id":"external_commands:SKILL.md:526:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Dispatches** — `dispatches.md` rows carry an outcome for every","category":"external_commands","line_end":529,"severity":"medium","line_start":526},{"id":"external_commands:SKILL.md:529:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Phase** — `exec-initiative phase INIT-0004 <phase> entered` for","category":"external_commands","line_end":532,"severity":"medium","line_start":529},{"id":"external_commands:SKILL.md:532:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Status** — `exec-initiative status INIT-0004 paused`.","category":"external_commands","line_end":533,"severity":"medium","line_start":532},{"id":"external_commands:SKILL.md:533:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. **Run row** — set `.executor/INDEX.md` to `paused` for a run whose","category":"external_commands","line_end":533,"severity":"medium","line_start":533},{"id":"external_commands:SKILL.md:535:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`blocked` only when execution stopped on one of the four stop","category":"external_commands","line_end":540,"severity":"medium","line_start":535},{"id":"external_commands:SKILL.md:540:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"8. **Session record** — a `.local/handoff/session/` record per","category":"external_commands","line_end":541,"severity":"medium","line_start":540},{"id":"external_commands:SKILL.md:541:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`local-context-tracking`: numbered `NNNN-YYYYMMDDTHHMMSSZ-topic.md`,","category":"external_commands","line_end":541,"severity":"medium","line_start":541},{"id":"external_commands:SKILL.md:542:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"full frontmatter, plus branch, HEAD, `git status --short`, the","category":"external_commands","line_end":557,"severity":"medium","line_start":542},{"id":"external_commands:SKILL.md:557:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 1 | `docs/executor/INDEX.md` | Which initiatives exist, their status and phase |","category":"external_commands","line_end":558,"severity":"medium","line_start":557},{"id":"external_commands:SKILL.md:558:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 2 | `docs/executor/INIT-NNNN-*/INDEX.md` | The phase log — **where work stopped**, and what is ski","category":"external_commands","line_end":559,"severity":"medium","line_start":558},{"id":"external_commands:SKILL.md:559:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 3 | `.executor/INDEX.md` | Which plans ran, which are complete, where their workspaces are |","category":"external_commands","line_end":560,"severity":"medium","line_start":559},{"id":"external_commands:SKILL.md:560:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 4 | `<workspace>/progress.md` | Which tasks are done, which are mid-flight |","category":"external_commands","line_end":561,"severity":"medium","line_start":560},{"id":"external_commands:SKILL.md:561:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 5 | `<workspace>/rulings.md` | What was already decided — do not re-decide it |","category":"external_commands","line_end":562,"severity":"medium","line_start":561},{"id":"external_commands:SKILL.md:562:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 6 | `<workspace>/preflight-scan.md` | Known cross-task conflicts and their adjudications |","category":"external_commands","line_end":563,"severity":"medium","line_start":562},{"id":"external_commands:SKILL.md:563:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 7 | `<workspace>/dispatches.md` | Whether a live agent can be resumed instead of replaced |","category":"external_commands","line_end":564,"severity":"medium","line_start":563},{"id":"external_commands:SKILL.md:564:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| 8 | `.local/handoff/session/` (highest sequence, not superseded) | The previous session's continua","category":"external_commands","line_end":568,"severity":"medium","line_start":564},{"id":"external_commands:SKILL.md:568:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":572,"severity":"medium","line_start":568},{"id":"external_commands:SKILL.md:572:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":575,"severity":"medium","line_start":572},{"id":"external_commands:SKILL.md:575:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"state beats stored records. If `progress.md` says task 5 is complete and","category":"external_commands","line_end":577,"severity":"medium","line_start":575},{"id":"external_commands:SKILL.md:577:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"rather than editing the old one, per `local-context-tracking`'s append-only","category":"external_commands","line_end":581,"severity":"medium","line_start":577},{"id":"external_commands:SKILL.md:581:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"context.** No `.executor/<INIT>/` means that plan never ran. No `.local/`","category":"external_commands","line_end":581,"severity":"medium","line_start":581},{"id":"external_commands:SKILL.md:592:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Does the rulings report list every ruling in every `rulings.md`**,","category":"external_commands","line_end":600,"severity":"medium","line_start":592},{"id":"external_commands:SKILL.md:600:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"listed from `git branch --merged` and `git ls-remote`, deletion only on","category":"external_commands","line_end":600,"severity":"medium","line_start":600},{"id":"external_commands:SKILL.md:609:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. `../executor/scripts/exec-scan-secrets` — exit 0 over both stores","category":"external_commands","line_end":612,"severity":"medium","line_start":609},{"id":"external_commands:SKILL.md:612:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. `../executor/scripts/exec-store-check` — no finding for this","category":"external_commands","line_end":614,"severity":"medium","line_start":612},{"id":"external_commands:SKILL.md:614:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. `../executor/scripts/exec-run \"$PLAN\" check` for every plan — exit 0.","category":"external_commands","line_end":615,"severity":"medium","line_start":614},{"id":"external_commands:SKILL.md:615:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. After a merge: `git branch --merged <integration>` and","category":"external_commands","line_end":616,"severity":"medium","line_start":615},{"id":"external_commands:SKILL.md:616:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"`git ls-remote --heads origin` — the cleanup candidate list.","category":"external_commands","line_end":623,"severity":"medium","line_start":616},{"id":"external_commands:SKILL.md:623:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"The rulings are in `rulings.md`, that's the record\" | It is the durable record. The report is how","category":"external_commands","line_end":632,"severity":"medium","line_start":623},{"id":"external_commands:SKILL.md:632:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"'Yeah, get rid of it' counts as confirmation\" | Only the typed word `discard` authorizes deletion","category":"external_commands","line_end":636,"severity":"medium","line_start":632},{"id":"external_commands:SKILL.md:636:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"This other worktree looks stale — I'll clean it too\" | Only `.worktrees/` and `worktrees/`. Every","category":"external_commands","line_end":636,"severity":"medium","line_start":636},{"id":"external_commands:SKILL.md:637:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"Removal refused — `--force` finishes the cleanup\" | The refusal means files exist only there. Sho","category":"external_commands","line_end":639,"severity":"medium","line_start":637},{"id":"external_commands:SKILL.md:639:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| \"I'll copy `.executor/` out before removing the worktree\" | It already lives at the main root. A c","category":"external_commands","line_end":642,"severity":"medium","line_start":639},{"id":"external_commands:SKILL.md:166:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"MAIN_ROOT=$(git -C \"$(git rev-parse --git-common-dir)/..\" rev-parse --show-toplevel)","category":"external_commands","line_end":166,"severity":"medium","line_start":166},{"id":"external_commands:SKILL.md:214:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"GIT_DIR=$(cd \"$(git rev-parse --git-dir)\" 2>/dev/null && pwd -P)","category":"external_commands","line_end":214,"severity":"medium","line_start":214},{"id":"external_commands:SKILL.md:215:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"GIT_COMMON=$(cd \"$(git rev-parse --git-common-dir)\" 2>/dev/null && pwd -P)","category":"external_commands","line_end":215,"severity":"medium","line_start":215},{"id":"external_commands:SKILL.md:218:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"WORKTREE_PATH=$(git rev-parse --show-toplevel)","category":"external_commands","line_end":218,"severity":"medium","line_start":218},{"id":"external_commands:SKILL.md:314:shell-command-substitution","file":"SKILL.md","pattern":"Shell command substitution","snippet":"MAIN_ROOT=$(git -C \"$(git rev-parse --git-common-dir)/..\" rev-parse --show-toplevel)","category":"external_commands","line_end":314,"severity":"medium","line_start":314},{"id":"external_commands:SKILL.md:165:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":168,"severity":"medium","line_start":165},{"id":"external_commands:SKILL.md:213:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":219,"severity":"medium","line_start":213},{"id":"external_commands:SKILL.md:313:template-literal-with-command-substitution","file":"SKILL.md","pattern":"Template literal with command substitution","snippet":"```bash","category":"external_commands","line_end":322,"severity":"medium","line_start":313},{"id":"filesystem:SKILL.md:13:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"Scripts referenced below live in `../executor/scripts/` and are","category":"filesystem","line_end":13,"severity":"high","line_start":13},{"id":"filesystem:SKILL.md:50:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"| The thinking store passes the store check — every document registered, statuses truthful, cross-li","category":"filesystem","line_end":50,"severity":"high","line_start":50},{"id":"filesystem:SKILL.md:57:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-store-check  # thinking-store integrity; exit 0 required","category":"filesystem","line_end":57,"severity":"high","line_start":57},{"id":"filesystem:SKILL.md:97:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"exec-ruling docs/executor/INIT-0004-.../plans/INIT-0004-P01-cell-router.md \\","category":"filesystem","line_end":97,"severity":"high","line_start":97},{"id":"filesystem:SKILL.md:170:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"On any finding, follow `../executor/references/safety.md`:","category":"filesystem","line_end":170,"severity":"high","line_start":170},{"id":"filesystem:SKILL.md:274:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"../executor/scripts/exec-run \"$PLAN\" check","category":"filesystem","line_end":274,"severity":"high","line_start":274},{"id":"filesystem:SKILL.md:609:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"1. `../executor/scripts/exec-scan-secrets` — exit 0 over both stores","category":"filesystem","line_end":609,"severity":"high","line_start":609},{"id":"filesystem:SKILL.md:612:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"3. `../executor/scripts/exec-store-check` — no finding for this","category":"filesystem","line_end":612,"severity":"high","line_start":612},{"id":"filesystem:SKILL.md:614:path-traversal-sequence","file":"SKILL.md","pattern":"Path traversal sequence","snippet":"4. `../executor/scripts/exec-run \"$PLAN\" check` for every plan — exit 0.","category":"filesystem","line_end":614,"severity":"high","line_start":614},{"id":"filesystem:SKILL.md:167:hidden-file-access","file":"SKILL.md","pattern":"Hidden file access","snippet":"exec-scan-secrets docs/executor \"$MAIN_ROOT/.executor\"","category":"filesystem","line_end":167,"severity":"medium","line_start":167},{"id":"filesystem:SKILL.md:214:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"GIT_DIR=$(cd \"$(git rev-parse --git-dir)\" 2>/dev/null && pwd -P)","category":"filesystem","line_end":214,"severity":"low","line_start":214},{"id":"filesystem:SKILL.md:215:standard-device-file-access","file":"SKILL.md","pattern":"Standard device file access","snippet":"GIT_COMMON=$(cd \"$(git rev-parse --git-common-dir)\" 2>/dev/null && pwd -P)","category":"filesystem","line_end":215,"severity":"low","line_start":215},{"id":"blocker:SKILL.md:23:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"```mermaid","category":"blocker","line_end":24,"severity":"low","line_start":23},{"id":"blocker:SKILL.md:419:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"Wait for that exact word. \"Yeah, get rid of it\" is not it. On confirmation:","category":"blocker","line_end":419,"severity":"low","line_start":419},{"id":"blocker:SKILL.md:531:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"did not approve.","category":"blocker","line_end":531,"severity":"low","line_start":531},{"id":"blocker:SKILL.md:599:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"4. **After a merge, did you offer stale-branch cleanup** — candidates","category":"blocker","line_end":599,"severity":"low","line_start":599},{"id":"blocker:SKILL.md:632:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| \"'Yeah, get rid of it' counts as confirmation\" | Only the typed word `discard` authorizes deletion","category":"blocker","line_end":632,"severity":"low","line_start":632}],"finding_verdicts":[{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"Backticks mark a helper directory in Markdown, not an executable shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:14:ruby-shell-backtick-execution","reason":"Backticks format the exec-* helper naming convention; they do not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:23:ruby-shell-backtick-execution","reason":"This is a Markdown fence enclosing a Mermaid workflow diagram, not shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"This delimiter closes the Mermaid documentation fence; it is not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:45:ruby-shell-backtick-execution","reason":"Backticks format a task-progress document path in a prerequisite table, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"Backticks format the review-verdict directory in a prerequisite table; no command is evaluated.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The inline code names verdict files and requires the latest clean review, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"Markdown code spans identify verification evidence paths; they are not shell backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"The helper path is Markdown-formatted prerequisite documentation, not shell backtick evaluation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"Inline code identifies execution registry and workspace paths for consistency checking, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"Backticks format verification-record paths in the prerequisite table; no shell backtick expression exists.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"This opens a Markdown Bash example for a store-integrity check; it is not shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"This closes a Markdown command example; the fence is not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"This opens a Markdown example recording handoff phase entry, not a backtick command expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"This is a closing Markdown fence, not executable shell backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"Backticks format durable ruling-record paths in prose; they do not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:84:ruby-shell-backtick-execution","reason":"This is a Markdown-formatted rulings document path used for review, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:86:ruby-shell-backtick-execution","reason":"Inline code describes a ruling entry heading and timestamp format, not an executable expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:87:ruby-shell-backtick-execution","reason":"Backticks format a preflight document path and its column name; no shell command is evaluated.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:89:ruby-shell-backtick-execution","reason":"The rulings filename is an inline Markdown code span, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:90:ruby-shell-backtick-execution","reason":"The review-verdict glob is a Markdown-formatted document reference, not backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:94:ruby-shell-backtick-execution","reason":"Backticks name the ruling-record helper in prose; they are not an executable shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"This opens a Markdown example for recording a ruling; no backtick command evaluation occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:99:ruby-shell-backtick-execution","reason":"This is a closing Markdown fence, not shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:101:ruby-shell-backtick-execution","reason":"The code spans describe ruling-record destinations; they do not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:106:ruby-shell-backtick-execution","reason":"The required report heading is formatted as inline Markdown code, not shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","reason":"This opens a Markdown report example, not an executable shell block.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"The router filename is inline Markdown inside an example ruling, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"Backticks format a report pointer to a rulings document; no command is evaluated.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"The decision-record directory is a Markdown reference, not shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"This closes a Markdown report example and does not evaluate shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","reason":"This opens a Markdown example reporting zero rulings, not shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","reason":"This closes the empty-rulings report example; it is documentation syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:137:ruby-shell-backtick-execution","reason":"Backticks format the rulings filename while discussing missing records, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"The helper name is inline Markdown describing decision recording; no backtick expression is evaluated.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"This is a Markdown fence around intended secret-scanning examples, not shell backtick evaluation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:146:ruby-shell-backtick-execution","reason":"This closes the documented scanning examples; the fence is not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:148:ruby-shell-backtick-execution","reason":"Backticks quote the scanner's documented clean-result message, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:149:ruby-shell-backtick-execution","reason":"Inline code specifies redacted finding output format; it is not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:155:ruby-shell-backtick-execution","reason":"Backticks identify the two project store paths in prose, not shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:156:ruby-shell-backtick-execution","reason":"The quoted Git query documents repository-root resolution; the Markdown code span does not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"The scanner name is inline Markdown describing worktree coverage, not shell backtick evaluation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:158:ruby-shell-backtick-execution","reason":"Backticks quote a store-count output fragment used to detect incomplete scanning, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:165:ruby-shell-backtick-execution","reason":"This is a Markdown Bash fence; its documented root lookup uses dollar substitution rather than executable backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:168:ruby-shell-backtick-execution","reason":"This closes the explicit store-scanning example, not a shell backtick command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:170:ruby-shell-backtick-execution","reason":"The safety reference is a Markdown-formatted document path, not an executable expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:175:ruby-shell-backtick-execution","reason":"The execution-store path is inline Markdown in a human-controlled secret-remediation table, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"The review-diff directory is a Markdown reference explaining credential exposure, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:189:ruby-shell-backtick-execution","reason":"Markdown code spans name ordinary project test runners required for verification, not shell backtick evaluation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:190:ruby-shell-backtick-execution","reason":"The Go test example is inline Markdown for intended verification, not an executable backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:213:ruby-shell-backtick-execution","reason":"This opens a Markdown Bash example containing ordinary Git environment queries, not shell backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","reason":"This closes the Git environment detection example; the delimiter is documentation syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:223:ruby-shell-backtick-execution","reason":"The code span displays a comparison of Git directory variables, not shell command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:224:ruby-shell-backtick-execution","reason":"Inline code displays the directory comparison used to identify worktrees, not a backtick command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:225:ruby-shell-backtick-execution","reason":"The Markdown comparison documents detached-worktree handling and does not evaluate shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:228:ruby-shell-backtick-execution","reason":"Code spans identify a store path and its root variable in prose, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:230:ruby-shell-backtick-execution","reason":"Backticks name the shared execution store and root variable, not executable shell expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:231:ruby-shell-backtick-execution","reason":"The Git query is quoted as documentation for root derivation; the backticks are Markdown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","reason":"Code spans name an index document and its branch metadata field, not shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","reason":"The helper name is Markdown-formatted explanatory text about branch records, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:244:ruby-shell-backtick-execution","reason":"This opens a fenced human-facing base-branch question, not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:246:ruby-shell-backtick-execution","reason":"This closes the human-facing branch question; it is a Markdown delimiter.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:255:ruby-shell-backtick-execution","reason":"This opens a fenced integration-choice menu, not a shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:263:ruby-shell-backtick-execution","reason":"This closes the integration-choice menu; the fence does not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","reason":"The helper command is quoted in prose describing review gating, not evaluated through shell backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:273:ruby-shell-backtick-execution","reason":"This opens a Markdown example of a plan consistency check, not backtick command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:275:ruby-shell-backtick-execution","reason":"This is the closing Markdown fence for a check example, not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:282:ruby-shell-backtick-execution","reason":"This opens a fenced detached-HEAD menu for the human, not shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:289:ruby-shell-backtick-execution","reason":"This closes the detached-HEAD menu and does not evaluate shell expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:304:ruby-shell-backtick-execution","reason":"The default branch name is inline Markdown within a branch-protection rule, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","reason":"The code span contains a Conventional Commit message example, not an executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:306:ruby-shell-backtick-execution","reason":"The documented staged-diff review is ordinary safety guidance; its Markdown backticks do not execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:307:ruby-shell-backtick-execution","reason":"Backticks format the store path in a rule against publishing it without permission, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","reason":"Inline code formats a commit label and rulings filename; neither is evaluated as shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:313:ruby-shell-backtick-execution","reason":"The Markdown fence contains the human-selected merge workflow, not executable shell backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:322:ruby-shell-backtick-execution","reason":"This closes the documented local-merge example; the fence is not a shell backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:331:ruby-shell-backtick-execution","reason":"This opens a Markdown example of ordinary merged-branch deletion, not shell backtick evaluation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","reason":"This closes the merged-branch deletion example; it is documentation syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:340:ruby-shell-backtick-execution","reason":"The execution-store path is inline Markdown explaining record retention, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","reason":"The Git-directory equality test is displayed in Markdown, not evaluated using shell backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:349:ruby-shell-backtick-execution","reason":"This opens a Markdown workspace-location check example, not an executable backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:351:ruby-shell-backtick-execution","reason":"This closes the workspace-location check example; it is a Markdown delimiter.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:355:ruby-shell-backtick-execution","reason":"Backticks format variables and directory names, not shell execution. The ownership-policy risk is recorded separately as a semantic finding.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:357:ruby-shell-backtick-execution","reason":"The match is a Markdown fence, not shell backticks. The cleanup authorization weakness is recorded separately.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:360:ruby-shell-backtick-execution","reason":"This closes a Markdown cleanup example; it is not executable backtick syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:362:ruby-shell-backtick-execution","reason":"Inline code quotes Git's removal-refusal message, not an executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:363:ruby-shell-backtick-execution","reason":"The force option is quoted in a prohibition on unilateral deletion, not executed through backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:366:ruby-shell-backtick-execution","reason":"This opens a Markdown example of read-only worktree status inspection, not shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:368:ruby-shell-backtick-execution","reason":"This closes the status-inspection example; the Markdown fence is not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:370:ruby-shell-backtick-execution","reason":"This opens a fenced human confirmation menu for uncommitted files, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:380:ruby-shell-backtick-execution","reason":"This closes the uncommitted-file confirmation menu; it is documentation syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:383:ruby-shell-backtick-execution","reason":"Backticks format directory names rather than executing commands. The directory-based ownership weakness is addressed separately.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:387:ruby-shell-backtick-execution","reason":"This opens a Markdown push example that follows an explicit human integration choice, not shell backtick evaluation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:391:ruby-shell-backtick-execution","reason":"This closes the documented push example; it is a Markdown delimiter.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:393:ruby-shell-backtick-execution","reason":"The base-branch placeholder is inline Markdown in the authorized pull-request workflow, not executable backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:402:ruby-shell-backtick-execution","reason":"Inline code contains a human-facing branch-preservation message, not a shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:410:ruby-shell-backtick-execution","reason":"This opens a fenced discard-confirmation message, not shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:417:ruby-shell-backtick-execution","reason":"This closes the explicit discard-confirmation message; it is documentation syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:424:ruby-shell-backtick-execution","reason":"This opens a Markdown branch-deletion example gated by explicit typed confirmation, not backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:426:ruby-shell-backtick-execution","reason":"This closes the confirmed-discard example; the delimiter is Markdown syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:428:ruby-shell-backtick-execution","reason":"Backticks format lifecycle status values after confirmed abandonment, not commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:435:ruby-shell-backtick-execution","reason":"The branch-deletion flag is formatted in a workflow comparison table, not executed through backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:438:ruby-shell-backtick-execution","reason":"The force-deletion flag is documentation for explicit-request discards, not backtick command evaluation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:444:ruby-shell-backtick-execution","reason":"Backticks identify the execution registry document for lifecycle updates, not shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:445:ruby-shell-backtick-execution","reason":"Inline code names the workspace helper and registry column; it is not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:446:ruby-shell-backtick-execution","reason":"Code spans show registry status and task-count values, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:452:ruby-shell-backtick-execution","reason":"This opens a Markdown phase-closure command example, not shell backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:454:ruby-shell-backtick-execution","reason":"This closes the phase-closure example; it is a Markdown delimiter.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:457:ruby-shell-backtick-execution","reason":"Inline code identifies a phase metadata field in explanatory prose, not an executable expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:458:ruby-shell-backtick-execution","reason":"The registry path is a Markdown document reference, not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:462:ruby-shell-backtick-execution","reason":"This opens a Markdown lifecycle-status update example, not executable backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:464:ruby-shell-backtick-execution","reason":"This closes the lifecycle-status example; it does not evaluate shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:466:ruby-shell-backtick-execution","reason":"Backticks delimit allowed lifecycle status names, not executable commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:467:ruby-shell-backtick-execution","reason":"The lifecycle status name is inline Markdown within update guidance, not shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:468:ruby-shell-backtick-execution","reason":"The charter metadata key is an inline Markdown identifier, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:480:ruby-shell-backtick-execution","reason":"The completed status is formatted in record-retention prose, not executed as a shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:485:ruby-shell-backtick-execution","reason":"Backticks format the temporary-files directory in scoped scratch-cleanup guidance, not command evaluation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:511:ruby-shell-backtick-execution","reason":"The paused status is an inline Markdown value in a lifecycle table, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:512:ruby-shell-backtick-execution","reason":"The abandoned status is a documented lifecycle label, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:513:ruby-shell-backtick-execution","reason":"The blocked status is an inline Markdown run-state label, not an executable expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:514:ruby-shell-backtick-execution","reason":"The paused run-state label is Markdown documentation, not shell backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:521:ruby-shell-backtick-execution","reason":"The progress ledger filename is inline Markdown describing honest task recording, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:523:ruby-shell-backtick-execution","reason":"Backticks format the rulings document and recording helper in pause instructions, not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:524:ruby-shell-backtick-execution","reason":"The ruling-record helper is named in prose, not evaluated by backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:526:ruby-shell-backtick-execution","reason":"The dispatch ledger filename is inline Markdown describing outcome recording, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:529:ruby-shell-backtick-execution","reason":"The phase command is documented inline for truthful pause-state recording, not executed with shell backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:532:ruby-shell-backtick-execution","reason":"The status command is an inline Markdown example of pausing an initiative, not backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:533:ruby-shell-backtick-execution","reason":"Code spans name the run registry and paused status for continuity tracking, not shell expressions.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:535:ruby-shell-backtick-execution","reason":"The blocked status is a Markdown-formatted state value, not an executable command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:540:ruby-shell-backtick-execution","reason":"The session-record directory is inline Markdown specifying continuity storage, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:541:ruby-shell-backtick-execution","reason":"Code spans identify a companion skill and session filename convention, not commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:542:ruby-shell-backtick-execution","reason":"The ordinary Git status query is quoted as session evidence to record; the backticks are Markdown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:557:ruby-shell-backtick-execution","reason":"The initiative registry path is a Markdown reference in the resume reading order, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:558:ruby-shell-backtick-execution","reason":"The initiative index pattern is a Markdown document reference, not a backtick command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:559:ruby-shell-backtick-execution","reason":"The run registry path is inline Markdown for resume review, not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:560:ruby-shell-backtick-execution","reason":"The progress document placeholder is a Markdown reading-order reference, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:561:ruby-shell-backtick-execution","reason":"The rulings document placeholder is a Markdown reference to prior decisions, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:562:ruby-shell-backtick-execution","reason":"The preflight document placeholder is a Markdown reference for conflict review, not an executable expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:563:ruby-shell-backtick-execution","reason":"The dispatch ledger placeholder is a Markdown reference for agent continuity, not shell backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:564:ruby-shell-backtick-execution","reason":"The session-record directory is a Markdown reading-order reference, not executable shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:568:ruby-shell-backtick-execution","reason":"This opens a Markdown example of read-only Git state checks before resumption, not shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:572:ruby-shell-backtick-execution","reason":"This closes the read-only Git state example; the fence is documentation syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:575:ruby-shell-backtick-execution","reason":"The progress filename is inline Markdown in repository-versus-record reconciliation guidance, not shell commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:577:ruby-shell-backtick-execution","reason":"The companion skill name is a Markdown reference describing correction records, not an executable expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:581:ruby-shell-backtick-execution","reason":"Backticks identify project stores while prohibiting invented history, not shell command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:592:ruby-shell-backtick-execution","reason":"The rulings filename is Markdown in a report-completeness checklist, not a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:600:ruby-shell-backtick-execution","reason":"The quoted Git branch and remote queries enumerate cleanup candidates; Markdown backticks do not evaluate them.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:609:ruby-shell-backtick-execution","reason":"The secret-scanner helper is quoted as required verification documentation, not shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:612:ruby-shell-backtick-execution","reason":"The store-check helper is inline Markdown in a verification checklist, not an executable backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:614:ruby-shell-backtick-execution","reason":"The plan-check command is inline Markdown documentation with a quoted plan argument, not shell backtick evaluation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:615:ruby-shell-backtick-execution","reason":"The merged-branch listing is a quoted read-only verification command, not executable backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:616:ruby-shell-backtick-execution","reason":"The remote-head listing is documented for cleanup candidates on the configured origin, not executed through Markdown backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:623:ruby-shell-backtick-execution","reason":"The rulings filename is formatted in a quoted reporting rationalization, not a shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:632:ruby-shell-backtick-execution","reason":"The discard word is a typed confirmation token in safety guidance, not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:636:ruby-shell-backtick-execution","reason":"Backticks format worktree directory names, not commands. Their ownership implications are covered by the semantic finding.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:637:ruby-shell-backtick-execution","reason":"The force flag is quoted in guidance against bypassing removal refusal, not executed through shell backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:639:ruby-shell-backtick-execution","reason":"The shared store path is Markdown in record-preservation guidance, not shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:166:shell-command-substitution","reason":"Fixed Git queries derive the main repository root with quoted path arguments. Command output is not evaluated as shell code.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:214:shell-command-substitution","reason":"Fixed Git and pwd queries canonicalize the Git directory using a quoted path. This is ordinary worktree detection without dynamic code evaluation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:215:shell-command-substitution","reason":"Fixed Git and pwd queries canonicalize the common Git directory using a quoted path. Output is used as data, not executable code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:218:shell-command-substitution","reason":"The fixed git rev-parse query records the current workspace root. No user-controlled command or code evaluation is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:314:shell-command-substitution","reason":"Fixed Git queries derive the main repository root before a human-selected merge. Quoted output supplies a path, not executable shell code.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:165:template-literal-with-command-substitution","reason":"This is a fenced Bash documentation example, not a JavaScript template literal. Its fixed Git substitutions derive paths for scanning.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:213:template-literal-with-command-substitution","reason":"This is a fenced Bash worktree-detection example, not a JavaScript template literal. Fixed Git queries treat their output as path data.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:313:template-literal-with-command-substitution","reason":"This is a fenced Bash merge workflow, not a JavaScript template literal. The root substitution uses fixed Git commands and quoted paths.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:13:path-traversal-sequence","reason":"The fixed parent-relative directory identifies sibling Executor helpers, not attacker-controlled traversal. Helper implementations are outside this audit.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:50:path-traversal-sequence","reason":"The fixed sibling helper reference documents a store-integrity gate. No untrusted path concatenation or traversal exploit is shown.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:57:path-traversal-sequence","reason":"The fixed parent-relative helper invocation runs the documented store check. Relative dependency layout alone does not establish a traversal vulnerability.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:97:path-traversal-sequence","reason":"The INIT-0004-... component abbreviates an example initiative directory. It is not a parent-directory component or traversal operation.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:170:path-traversal-sequence","reason":"The fixed sibling safety-document reference supports secret handling. It does not use attacker-controlled path traversal.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:274:path-traversal-sequence","reason":"The fixed sibling plan-check helper takes a quoted plan argument. No evidence shows path-boundary bypass or malicious traversal.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:609:path-traversal-sequence","reason":"The fixed sibling scanner path is a verification dependency reference, not attacker-controlled traversal. Its implementation is unavailable in this package.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:612:path-traversal-sequence","reason":"The fixed sibling store-check path is verification documentation. No attacker-controlled path construction or boundary bypass is present.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:614:path-traversal-sequence","reason":"The fixed sibling plan-check path is documented with a quoted argument. The parent component denotes dependency layout, not a demonstrated traversal attack.","verdict":"false_positive","confidence":0.97},{"id":"filesystem:SKILL.md:167:hidden-file-access","reason":"The hidden .executor directory is the designated execution store scanned for credentials. The workflow prohibits printing secret values or unauthorized publication.","verdict":"false_positive","confidence":0.98},{"id":"filesystem:SKILL.md:214:standard-device-file-access","reason":"The /dev/null redirection suppresses directory-resolution errors. It does not read sensitive devices or exfiltrate data.","verdict":"false_positive","confidence":0.99},{"id":"filesystem:SKILL.md:215:standard-device-file-access","reason":"The /dev/null redirection suppresses routine path-resolution errors. It is a standard output sink, not sensitive-device access.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:23:system-reconnaissance","reason":"The Mermaid workflow depicts project verification and integration gates. It contains no host reconnaissance or information-harvesting instructions.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:419:system-reconnaissance","reason":"The text requires an exact human discard confirmation before deletion. It does not collect host information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:531:system-reconnaissance","reason":"This completes a rule against falsely recording human-approved gates. No system reconnaissance occurs.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:599:system-reconnaissance","reason":"The checklist requests branch cleanup candidates from ordinary Git listings, with deletion only on approval. It does not harvest unrelated system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:632:system-reconnaissance","reason":"The guidance requires typed discard authorization and rejects ambiguous assent. It is deletion protection, not system reconnaissance.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Directory Names Substitute for Worktree Ownership","severity":"medium","locations":[{"file":"SKILL.md","line_end":360,"line_start":355},{"file":"SKILL.md","line_end":383,"line_start":382},{"file":"SKILL.md","line_end":636,"line_start":636}],"confidence":0.88,"description":"The rule says: \"If `WORKTREE_PATH` is under `.worktrees/` or `worktrees/`: we own it.\" It then authorizes removal without checking a creation record or requesting separate cleanup approval. Host-managed worktrees can use these directory names, so choosing local integration can remove a workspace that the agent does not own. Git refusal handling limits deletion of modified files but does not establish ownership.","confidence_reasoning":"The ownership rule directly precedes worktree removal and is repeated in the cleanup checklist. Confidence is high, although unauthorized removal depends on host directory conventions."}],"subject_marketplace_commit_sha":"6d0b11444384184b7ae743742a7e233a9a705cd9","subject_content_hash":"c58a5a2d096c324adc2cc95497f30befc1bc31fe230aea79741cb896433eddf5","subject_tree_hash":"e99a47913b71949495af2612920496191b3dc872eb11b871c2f0627d16b6af57","subject_plugin_path":"skills/atri10/executor-handoff","audit_payload_hash":"8ea90dbd88a44a7493bbdfe651e03602","confirmed_risk_level":"medium","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"6d0b11444384184b7ae743742a7e233a9a705cd9","contentHash":"c58a5a2d096c324adc2cc95497f30befc1bc31fe230aea79741cb896433eddf5","treeHash":"e99a47913b71949495af2612920496191b3dc872eb11b871c2f0627d16b6af57","pluginPath":"skills/atri10/executor-handoff","auditPayloadHash":"8ea90dbd88a44a7493bbdfe651e03602"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/atri10-executor-handoff/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}